August 24, 2026
Updated: August 24, 2026
Canada's own darknet market: drugs on the front page, stolen Canadian cards and credentials behind them.
Abdalla Mohamed

WeTheNorth (WTN) is a Canada-focused darknet marketplace, a Tor-based underground shop named after the Toronto Raptors slogan that sells drugs alongside fraud tools, stolen data, malware, and counterfeit documents to a mostly Canadian audience. It launched in 2021 to replace an earlier Canadian market and has grown into the country's best-known regional darknet platform. This guide explains what WeTheNorth Market is, its history, everything it sells, how it operates, the 2025 RCMP enforcement action against Canadian vendors, and how both individuals and businesses can defend against the harm it fuels.
Updated: August 2026. A defensive, threat-intelligence and law-enforcement overview for security teams, Canadian organizations, and the public. It contains no marketplace addresses, mirror links, or access instructions, and does not endorse or assist any illegal activity.
A note on the name. "WeTheNorth" here refers to the Canadian darknet marketplace. It is unrelated to cryptocurrency tickers like WETH (Wrapped Ether) or any stock "market cap," which autocomplete sometimes suggests. This article is strictly about the dark web market.
Here is the whole picture in one table; the rest of this guide expands each row.
| Question | Short answer |
|---|---|
| What is it? | A Canada-focused darknet marketplace on Tor |
| Since when? | Launched 2021, after The Canadian HeadQuarters shut down |
| Why the name? | A nod to the Toronto Raptors' "We The North" slogan |
| What does it sell? | Mainly drugs, plus fraud tools, stolen cards, credentials, malware, fake documents |
| How does it work? | Bitcoin and Monero, escrow, bilingual (English/French) support |
| Is it still active? | Reported active into 2026; no confirmed takedown of the market itself |
| Is using it legal? | Buying controlled drugs, stolen credentials, malware, or fraud services can violate Canadian criminal and drug laws; exact offenses depend on the conduct involved |
The one line to remember: WeTheNorth is a regional darknet market built to serve Canada, and its stolen-data listings put Canadian organizations directly in scope.
WeTheNorth is a darknet marketplace that operates over the Tor network and deliberately targets a Canadian user base. Where global markets serve everyone, WTN positions itself as a home-grown option, with bilingual support and a brand built around national identity. It was discovered and profiled by Recorded Future's Insikt Group, whose research remains the authoritative account of its origins.
It belongs to the ecosystem we map in our top dark web marketplaces roundup, and like other hidden services it is reached through anonymity software, explained in dark web vs darknet vs Tor. While drugs make up most of its volume, the reason it matters to security teams is the other half of its catalog: the fraud tools, stolen credentials, and malware that make it a regional outlet for cybercrime against Canadians.
The name is a direct nod to the Toronto Raptors' "We The North" slogan, the rallying cry of Canada's only NBA team. The administrators leaned into national branding to present the market as one built to protect Canadian buyers and sellers specifically. It is marketing, not ethics, a criminal marketplace does not become trustworthy because it waves a flag, but the branding is a real and telling detail. It signals the market's whole strategy: be the local, familiar, Canada-first option in a global underground.
WeTheNorth did not appear in a vacuum. It filled a gap left by the collapse of its predecessor.
| Date | Event |
|---|---|
| Before 2021 | The Canadian HeadQuarters (CanadianHQ) is the dominant Canadian market |
| July 2021 | CanadianHQ shuts down, leaving a regional gap |
| 2021 | WeTheNorth launches; Insikt Group discovers it via ads on open forums including Reddit |
| 2021 to 2024 | WTN grows into one of the most visible Canada-focused regional markets |
| June 2025 | Archetyp Market is dismantled in a coordinated European operation, reshaping the darknet marketplace landscape |
| 2025 to 2026 | Reported still active; roughly 9,000 marketplace-displayed listings were observed in 2025, though counts can change quickly |
Recorded Future's Insikt Group judged, with moderate confidence, that WeTheNorth was created specifically to replace The Canadian HeadQuarters. That succession pattern, one market falling and another rising to serve the same regional audience, is the defining rhythm of the darknet economy, and it is why takedowns rarely end the underlying demand. We track these transitions in dark web marketplace takedowns.
WTN is a generalist market, but its catalog splits cleanly into two worlds: the drugs that drive its volume and the cyber goods that make it a security concern.
| Category | Examples | Who it harms |
|---|---|---|
| Drugs and chemicals | Marijuana, cocaine, party drugs | Public health, individuals |
| Fraud tools | Carding kits, scam guides | Banks, consumers |
| Stolen financial data | Credit card data, bank details | Cardholders, issuers |
| Stolen credentials | Account logins | Individuals, businesses |
| Malware and hacking services | Malicious software, access-for-hire | Organizations |
| Counterfeit documents | Fake and fraudulent IDs | Identity-verification systems |
| Digital guides | Fraud and hacking how-tos | Enables new offenders |
Drugs, chiefly cannabis, cocaine, and party drugs, are the bulk of the trade. But for a security audience, the important columns are the stolen data, credentials, and malware, because those are the products that turn WeTheNorth from a drug problem into a cybersecurity one.

Most coverage of WeTheNorth focuses on drugs. For defenders, the more relevant story is that it is another marketplace where stolen Canadian data is bought and sold.
The regional angle sharpens the risk. A Canada-focused market can create a concentrated venue for Canada-specific fraud goods, credentials, and identity data, which makes Canadian banks, retailers, and their customers particularly relevant to what trades there.
WTN runs on the same playbook as other established darknet markets, tuned for its Canadian audience.
| Feature | Detail |
|---|---|
| Access | Tor hidden service (darknet) |
| Payments | Bitcoin and Monero |
| Escrow | Holds funds until both sides complete a deal |
| Support | 24/7 customer service in English and French |
| Positioning | Canada-only, marketed as "scam-free" and no-logs |
| Vendors | Vetted, with a reputation system |
Two details stand out. The bilingual support underscores how deliberately Canadian the market is. And the acceptance of Monero alongside Bitcoin matters for law enforcement: Monero is a privacy coin designed to obscure transaction trails, which complicates the blockchain tracing that police use to follow the money, a challenge we return to in the enforcement section.
A word on the market's advertised "rules." WeTheNorth publicly prohibits certain categories, and markets often tout such rules to appear principled. This is not ethics; it is business and self-preservation. A marketplace trafficking drugs, stolen data, and malware is a criminal enterprise regardless of what it bans, and its "rules" should be read as reputation management, not a moral stance.
WeTheNorth's Canada-first model is a strategy, and understanding why it works explains why regional markets keep appearing.
This is the same succession dynamic that keeps the whole ecosystem alive: demand is regional and persistent, so when one market dies, another rises to serve the same buyers.
WeTheNorth is best understood next to the markets it sits beside, because its regional niche is what defines it.
| Market | Focus | Reach | Status |
|---|---|---|---|
| WeTheNorth | Drugs plus cyber goods | Canada-only | Reported active |
| Russian Market | Infostealer logs (credentials, cookies) | Global | Active |
| STYX Market | Financial fraud and laundering | Global | Reported active |
| BriansClub | Magnetic-stripe card dumps | Global | Contested |
| The Canadian HeadQuarters | Generalist | Canada | Shut down 2021 |
The contrast is the point. The global markets specialize by product, one does logs, one does fraud services, one did card dumps. WeTheNorth specializes by geography, offering a bit of everything to one country. That regional model is less about scale and more about trust and logistics, and it is why a smaller market can hold a loyal national audience even as larger global platforms rise and fall.
WeTheNorth exists because of conditions specific to Canada, and those conditions explain why it persists.
For defenders, the lesson is that a regional market is a regional risk. A Canada-focused platform concentrates stolen Canadian data, so Canadian organizations cannot treat the darknet as a distant, foreign problem, some of it is aimed at them specifically.
While WeTheNorth itself has not been confirmed taken down, its vendors and users are squarely in law enforcement's sights, and 2025 brought one of Canada's largest darknet drug enforcement actions.
In September 2025, the Ontario RCMP dismantled a major dark web drug trafficking network and charged seven people from the Greater Toronto Area, aged 30 to 46. The operation centered on a Canadian vendor known as "RoadRunna," described as a sophisticated enterprise shipping roughly 400 packages a week across the country, as CBC and other outlets reported.
| Detail | Figure (RCMP, Sept 2025) |
|---|---|
| People charged | 7 (GTA, ages 30 to 46) |
| Vendor | "RoadRunna" |
| Weekly shipments | ~400 packages |
| Narcotics seized | 75 kilograms |
| Pills seized | 10,000 prescription and non-prescription |
The most instructive detail is how it started: the RCMP investigation began after German authorities took down a darknet marketplace and flagged Canadian users to their Canadian counterparts. Public RCMP reporting did not identify that marketplace by name. That is the modern reality of darknet enforcement, international, cooperative, and patient. A separate 2025 US case saw a Canadian dark web vendor sentenced for importing millions of counterfeit Xanax pills, underscoring that Canadian darknet activity draws cross-border prosecution.

The financial side of enforcement is evolving alongside the operations. The RCMP and Canadian financial-intelligence bodies increasingly treat darknet crime as a money-laundering problem to be solved with blockchain analytics.
For businesses, the takeaway is that darknet proceeds move through the regular financial system eventually, and the same monitoring that catches fraud can surface laundering, if it is in place.
The RoadRunna takedown is more than a headline; it is a case study in how darknet enforcement actually works, and the lessons apply well beyond drugs.
For a corporate security team, the parallel is direct: the criminals who buy your stolen credentials on a market like WeTheNorth are not untouchable, and the same evidence trail that convicts a drug vendor can support the investigation of a fraud or breach against your organization. Preserving logs, monitoring for your exposed data, and engaging law enforcement early all feed that process, which is a core part of any mature incident response plan.
Searches asking whether WeTheNorth is "real," how to reach it, or which link is genuine are common, and the honest answer is a warning, not a directory.
So "real or fake" resolves to: real enough to get you charged or scammed, and surrounded by clone sites that are pure traps. The safe move is to stay away entirely.
The harm from a market like WTN falls on two very different groups.
| Who | How they are exposed |
|---|---|
| Individuals (buyers) | Adulterated or dangerous drugs, scams, malware, criminal charges |
| Cardholders and account holders | Stolen cards and credentials sold and abused |
| Canadian banks and fintechs | Fraud losses, account takeover of customers |
| Businesses generally | Malware, access-for-hire, and stolen credentials enabling breaches |
| Communities | Drug harms, including from adulterated supply |
The common thread for a security audience is that a regional market concentrates regional victims. If your customers and staff are Canadian, a Canada-focused market is where their stolen data is most likely to surface.
There is no safe way to use a darknet drug market, and the defensive advice is simple and firm.
For organizations, WeTheNorth is a reminder that your data may be traded on markets you never see. The defense is the same disciplined program that counters the broader darknet economy.
| Control | What it addresses |
|---|---|
| Dark-web and stealer-log monitoring for your brand and customers | Stolen Canadian credentials and cards surfacing for sale |
| Phishing-resistant MFA (FIDO2/passkeys) | Account takeover from stolen credentials |
| Fraud and transaction monitoring | Cash-out and mule activity from stolen data |
| Endpoint detection and response | Malware and access-broker activity |
| Strong identity verification (KYC/KYB) | Counterfeit documents defeating onboarding |
| A tested incident response plan | Fast containment when credentials leak |
| Regular penetration testing of auth and payment flows | The technical gaps attackers buy tools to exploit |
The single highest-value move for most organizations is continuous monitoring for their own exposed credentials, combined with authentication strong enough that a leaked password alone is not enough to get in. When something does leak, a rehearsed incident response plan decides how contained the damage stays.
For a security team, the abstract threat of a market like WeTheNorth becomes concrete when stolen data is put to use. Recognizing the pattern helps you catch it early.
| Stage | What happens | Where to catch it |
|---|---|---|
| Listing | Your customer's or employee's credentials appear for sale | Dark-web and stealer-log monitoring |
| Purchase | A buyer acquires the credentials cheaply | Not directly visible; assume it happens |
| Access attempt | The buyer tries the login against your systems | Impossible-travel and anomalous-login alerts |
| Takeover | If MFA is weak, they get in | Phishing-resistant MFA blocks this stage |
| Abuse | Fraud, data theft, or lateral movement follows | Fraud monitoring, EDR, segmentation |
The critical insight is that you rarely see the first two stages, they happen on markets you cannot watch. Your leverage is at the access and takeover stages, where strong authentication and monitoring decide whether a leaked credential becomes a breach. That is why defense assumes the leak has already happened and focuses on making it worthless.
WeTheNorth illustrates a point that is easy to miss when darknet coverage fixates on drugs: every generalist market is also a data market. Stolen Canadian cards, logins, and malware trade there beside the narcotics, which means a Toronto retailer or a Montreal fintech can be harmed by a market it will never visit. Our dark web statistics roundup shows how much stolen data circulates and how quickly it moves from breach to marketplace.
That is why defense cannot stop at the firewall. It has to assume your credentials may already be for sale and validate that your controls survive it. DeepStrike's penetration testing is manual-first and adversary-realistic: our team probes the authentication, payment, and access paths that darknet-bought credentials and malware target, confirms whether your defenses actually hold, and delivers the concrete fixes before your data becomes someone's listing. For US-based organizations, see our US penetration testing services.
WeTheNorth (WTN) is a Canada-focused darknet marketplace on the Tor network. It sells mainly drugs, along with fraud tools, stolen credit cards, login credentials, malware, and counterfeit documents, and markets itself specifically to Canadian buyers and sellers with bilingual support.
The name references the Toronto Raptors' "We The North" slogan, the rallying cry of Canada's NBA team. The administrators used the national branding to present the market as built for and protective of Canadian users, though the branding is marketing, not any indication of legitimacy or safety.
Its largest category is drugs, mainly cannabis, cocaine, and party drugs. It also sells fraud tools, stolen payment card data, account credentials, malware and hacking services, counterfeit documents, and digital how-to guides. The stolen-data and malware listings are what make it a cybersecurity concern, not just a drug market.
WeTheNorth launched in 2021, filling the gap left when The Canadian HeadQuarters, the previous dominant Canadian market, shut down in July 2021. Recorded Future's Insikt Group discovered it that same year and judged it was likely created to replace its predecessor.
No. CanadianHQ was an earlier Canada-focused darknet marketplace that shut down in July 2021. Recorded Future's Insikt Group assessed with moderate confidence that WeTheNorth was likely created to replace it and serve the same regional audience.
As of this writing, there is no credible confirmation that WeTheNorth itself has been taken down, and it is reported to remain active. However, its vendors are being pursued: in September 2025 the RCMP dismantled a major Canadian darknet drug network and charged seven people, an investigation that began with a tip from German authorities.
The market is real, but engaging with it is dangerous and illegal. More practically, most of the "mirror," "login," and "verified link" pages that appear in search results are phishing clones built to scam or infect visitors. Darknet markets also exit-scam and vendors defraud buyers, so there is no safe version to find.
Using the market to buy illegal drugs, stolen data, malware, or fraud services can violate Canadian law. Merely viewing a site is a different legal question and depends on the circumstances, but interacting with criminal marketplaces also creates substantial security, fraud, and law-enforcement risk.
Monitor dark web and stealer-log sources for your brand and customer credentials, enforce phishing-resistant MFA so leaked passwords are not enough to log in, run fraud and endpoint monitoring, verify identities strongly, and penetration test your authentication and payment flows. A tested incident response plan limits damage when data does leak.

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us