The September 2026 assault on Kohat Police Lines, involving complex militant coordination, underscores a serious and persistent security challenge that should command respect from policymakers and security officials.
Kohat offers a revealing case of how militant targeting intentions may persist even after an earlier plot has been disrupted, without necessarily implying continuity between the perpetrators.
📌 Inside this Assessment
The Kohat Attack: Event Overview
A Target already Identified in 2025
Investigative Findings and Suspected Militant Cooperation
Contested Attribution and AQIS Response
Intelligence Assessment and Early Warning Indicators
Related Intelligence & Analysis:
The Kohat Attack: Event Overview
On 18 September 2026, a coordinated suicide bombing and armed assault against the Old Police Lines compound in Kohat, Khyber Pakhtunkhwa, resulted in one of the deadliest attacks against Pakistan’s security infrastructure that month. The operation, which began during Friday prayers and continued into the following day, combined an explosives-laden vehicle with a sustained armed confrontation involving police and counterterrorism personnel. According to subsequent reporting based on Pakistani security officials, 23 people were killed, including 17 police personnel and six civilians, while more than 100 others were injured. The confrontation continued for approximately 21 hours before security forces declared the compound secured.
The initial explosion struck the mosque located within the Police Lines complex, causing extensive destruction and casualties among those gathered for Friday prayers. Armed militants subsequently engaged security personnel in a prolonged confrontation that extended into 19 September, requiring a substantial security response before the remaining attackers were neutralised. Although the mosque bombing accounted for a significant proportion of the immediate casualties, the broader operation involved an assault against an installation housing elements of Pakistan’s police and counterterrorism apparatus, including facilities associated with the Counter-Terrorism Department (CTD) and Special Branch.
The distinction between the location of the initial explosion and the wider target of the assault is central to understanding the incident. The destruction of the mosque cannot be treated simply as collateral damage, particularly given the subsequent statements concerning its targeting. However, the continuation of the operation against the security compound indicates that the attackers’ objectives were not necessarily confined to the religious facility. Kohat therefore presents a case in which the targeting of security institutions and the deliberate or foreseeable exposure of individuals attending communal prayers became intertwined within a single operation, producing consequences that extended beyond the immediate confrontation.
The attack also differed from an isolated suicide bombing in its duration and apparent coordination. The prolonged engagement required security forces to respond to an evolving incident inside a sensitive installation. At the same time, the combination of multiple attackers and successive phases of violence suggested a level of preparation extending beyond the initial detonation. Such methods are not unprecedented in Pakistan’s militant environment. Still, their application against a compound containing counterterrorism facilities is particularly significant given that the same installation had previously appeared in an investigation into a disrupted militant plot.
This earlier history is essential to the assessment. The central question raised by Kohat is not simply how militants were able to conduct a complex assault against a protected facility, but why an installation already identified as a potential target in an earlier counterterrorism investigation remained the focus of a subsequent, successful attack. The recurrence does not establish that the same network was responsible for both plots. However, it adds a dimension of persistent targeting largely absent from accounts that focus exclusively on the September 2026 operation.
A Target Already Identified in 2025
In August 2025, Pakistani authorities announced the disruption of a militant plot against security installations in Kohat, including the mosque within the Police Lines compound and facilities associated with the CTD. The investigation resulted in the arrest of two brothers, identified as Siraj and Faridoon, who were reportedly employed within the police and counterterrorism apparatus respectively and were accused of facilitating the planned attacks. Contemporary reporting also described alleged communications with militant handlers based in Afghanistan and the collection of information concerning the intended targets. The Express Tribune associated the suspects with a network linked to Tehrik-e-Taliban Pakistan (TTP), while Dawn reported the disruption of the plot and the alleged facilitation activities without conclusively establishing the same organisational attribution.
The importance of this earlier investigation lies in the specificity of the reported targeting. The militants were not merely considering attacks somewhere in Kohat or against Pakistani security personnel in general; the Police Lines mosque and CTD facilities were among the locations explicitly identified during the investigation, corresponding to installations subsequently affected by the September 2026 assault. This overlap provides a documented basis for examining the persistence of militant interest in the compound, even though the available evidence does not demonstrate that the perpetrators of the later attack had participated in, inherited or directly benefited from the earlier plan.
Three explanations remain plausible. The September assault may have involved individuals or facilitators who retained information developed during the 2025 preparations; a broader militant network may have survived the earlier arrests and continued to regard the installation as a priority target; or a separate group may have independently identified the same compound as an attractive objective because of its concentration of security personnel and counterterrorism facilities. These scenarios would have different implications for the effectiveness of the 2025 disruption, and none can presently be established as the definitive explanation.
The suspected involvement of serving security personnel in the earlier plot adds an important institutional dimension. If the allegations reported in 2025 were accurate, the case demonstrated that militants had attempted to exploit individuals positioned within the very institutions they intended to attack. Such access could potentially provide information unavailable through external observation, although there is no verified evidence that comparable insider assistance contributed to the September 2026 assault. The analytical relevance of the earlier arrests therefore concerns the existence of a previously identified insider-facilitation risk, rather than any presumed continuation of that specific arrangement.
The significance of the 2025 investigation increased following reporting published after the September attack. On 24 September, Dunya News, citing CTD investigators, indicated that the inquiry had also examined the earlier plan against the Kohat Police Lines, suggesting that the potential relationship between the two episodes had become relevant to the authorities’ reconstruction of the assault. This development strengthens the case for treating the recurrence as an investigative issue rather than a coincidence identified solely through retrospective analysis, while leaving unresolved whether any individuals, communications or logistical arrangements connected the two operations.
Kohat’s history also extends beyond these two episodes. In September 2010, a suicide bombing struck the Police Lines area, causing numerous casualties and demonstrating that the location had previously attracted militant attention. The 2010 attack, the disrupted 2025 plot and the September 2026 assault should not be interpreted as evidence of a continuous campaign conducted by the same organisation, since no such connection has been established. Their significance instead lies in the repeated selection of the same security environment across different periods of Pakistan’s insurgency.
Taken together, these developments raise a broader question concerning the durability of counterterrorism disruption. The arrest of suspects may prevent a particular operation while leaving unresolved the wider threat to the intended target, especially where information, local relationships or organisational interest extend beyond the individuals detained. In Kohat, the available evidence supports the conclusion that the installation remained a recurrent militant objective; whether this persistence reflected surviving operational relationships or independently renewed targeting remains an important unresolved issue.
Investigative Findings and Suspected Militant Cooperation
Investigative developments reported during the final week of September introduced further indications that the Kohat assault involved preparation and support extending beyond the militants who directly participated in the attack. On 24 September, Dunya News reported, citing CTD investigators, that two militant organisations were suspected of cooperating in the planning of the operation. The same reporting indicated that the attackers had remained in Kohat for several days before the assault and that investigators had identified a suspected accommodation site, detained individuals believed to have facilitated the operation and recovered material considered relevant to the inquiry.
These findings, while still dependent on information attributed to investigators, are significant because they suggest the possible involvement of a wider support network. The organisation of an extended armed assault against a sensitive security installation may require assistance from individuals who do not participate directly in the attack, and the reported identification of accommodation arrangements and local facilitators provides a basis for examining whether the operation relied on relationships already established within the area. The existence, composition and organisational affiliations of such a network remain matters for investigation, rather than independently verified conclusions.
A potentially more consequential detail concerns the attackers’ alleged intention to enter the CTD facility and release detained militants. According to the investigative account published on 24 September, the operation may have involved an objective directed at freeing associates held within the compound. If substantiated, this would alter the interpretation of Kohat by suggesting that the attack combined the infliction of casualties and the targeting of security infrastructure with an attempt to recover personnel from detention.
The distinction matters because an operation intended partly to release prisoners would have a different organisational significance from an attack designed exclusively to inflict casualties or produce a propaganda effect. It could indicate an effort to preserve or restore militant personnel resources while simultaneously challenging the authority of Pakistan’s counterterrorism institutions. The available reporting does not establish whether prisoner release was the principal objective, a secondary consideration or an investigative hypothesis subsequently revised by the authorities, making it necessary to retain this interpretation as provisional.
Further reporting published on 27 September indicated that investigators were examining repeated reconnaissance, the movements of suspected participants and individuals believed to have provided local assistance. These developments are consistent with an operation involving preparatory activity over an extended period. However, the precise duration of the planning process and the division of responsibilities among participants have not been independently established.
The reported involvement of two militant organisations introduces an additional layer of uncertainty. Pakistan’s militant environment includes organisations and factions that may retain separate leadership structures while sharing personnel, maintaining informal relationships or cooperating around specific objectives. Such arrangements can complicate attribution, particularly when an operation involves participants from more than one network or when public claims do not reflect the full range of actors involved in its preparation.
The Kohat investigation has not yet provided sufficient publicly verifiable information to identify the two organisations reportedly suspected of cooperation or to establish their respective roles. Consequently, the allegation should not be treated as confirmation of a joint IMP–TTP operation, nor as evidence of direct involvement by al-Qaeda in the Indian Subcontinent (AQIS). Its principal significance is that investigators have raised the possibility of an operation involving more than one militant network, a finding that requires careful differentiation between temporary cooperation, overlapping facilitation structures and formal organisational integration.
This uncertainty is especially relevant when considered alongside the August 2025 investigation. The earlier case demonstrated that the Police Lines compound had already been subjected to militant planning, while the September 2026 inquiry identified possible local facilitation and cooperation between militant actors. These findings do not establish a continuous network connecting the two episodes. Still, they provide complementary reasons to examine whether the security threat surrounding the installation was more persistent and organisationally complex than the disruption of an individual plot might initially suggest.
Contested Attribution and AQIS Response
Responsibility for the Kohat assault has remained complicated by competing statements and inconsistencies between militant communications and subsequent media reporting. TTP denied involvement shortly after the attack, while several Pakistani outlets attributed responsibility to Ittihad-ul-Mujahideen Pakistan (IMP), the coalition associated with Hafiz Gul Bahadur. The initial First Information Report (FIR) was registered against unidentified attackers, reflecting the absence of a formally established organisational attribution at that stage of the investigation.
The distinction between reported responsibility and independently authenticated organisational claims is important in this case. Pakistani reporting has repeatedly identified IMP as the organisation responsible for the assault, and its association with Hafiz Gul Bahadur makes that attribution relevant to the broader militant landscape of northwestern Pakistan. Nevertheless, the material examined for this assessment does not establish the provenance of a primary IMP statement sufficient to resolve the attribution independently. The reported involvement of two cooperating organisations further complicates any interpretation that assigns the entire operation to a single group without clarifying the roles of other participants.
An additional development occurred on 19 September, when AQIS issued a statement through As-Sahab Media, The Subcontinent, addressing the destruction of the mosque during the assault. The statement, distributed in Urdu and English under the title Regarding the Martyrdom of a Mosque in the Kohat Attack, expressed regret that a mosque had been targeted during an operation directed against the CTD and Police Lines compound. AQIS criticised attacks against mosques and other public locations, arguing that such actions were religiously impermissible and harmful to the objectives and public legitimacy of the militants involved.
The language of the statement is significant because AQIS distinguished the broader attack against Pakistan’s security institutions from the targeting of the mosque, rather than rejecting the operation in its entirety. It referred to the perpetrators as militants within the wider jihadist environment and framed its criticism around the consequences of their target selection. This indicates an attempt to influence the conduct and legitimacy of militant violence, although it does not establish that AQIS exercised authority over the attackers or possessed a direct role in the operation.
The statement also illustrates the reputational consequences that attacks involving Muslim civilian casualties can generate within jihadist circles. Militant organisations may present operations against police or counterterrorism facilities as attacks against state institutions, but the destruction of a mosque and the killing of individuals attending Friday prayers introduce a separate controversy over the legitimacy of the methods employed. AQIS’s intervention demonstrates that such controversies can produce criticism from actors ideologically sympathetic to anti-state militancy, even when those actors do not publicly identify the perpetrators or claim organisational responsibility.
No direct operational relationship between AQIS and the Kohat attackers can be inferred from this statement alone. The group’s description of the attack could have relied on publicly available information or communications circulating within militant environments, and the available material does not establish which sources informed its position. The statement is therefore best understood as evidence of AQIS’s public response to the operation and its attempt to shape the interpretation of the mosque’s destruction, rather than as proof of involvement in planning or command.
Taken together, TTP’s denial, the reported IMP attribution, the investigative references to cooperation between two organisations and AQIS’s subsequent intervention demonstrate the limitations of relying exclusively on public claims to reconstruct responsibility for complex attacks. The organisations involved in Pakistan’s militant environment may share ideological reference points or maintain relationships without operating under a single command structure. In co-responsibility for an individual operation may involve distinctions between planning, facilitation and direct participation that are not reflected in media attribution.
For Kohat, IMP remains the principal organisation identified in subsequent Pakistani reporting, although the evidence available in the public domain does not yet permit a definitive reconstruction of the wider network responsible for the assault.
Intelligence Assessment and Early Warning Indicators
The Kohat Police Lines assault illustrates the interaction between persistent militant targeting, possible local facilitation and the increasing complexity of organisational attribution in Pakistan’s insurgent environment. Its significance does not rest exclusively on the number of casualties or the duration of the confrontation, but on the fact that the attacked installation had already appeared in a disrupted militant plot approximately thirteen months earlier. This recurrence provides a concrete basis for examining whether counterterrorism disruption adequately addresses the wider threat surrounding a target after the immediate operational cell has been neutralised.
The evidence currently supports a distinction between the persistence of a target and the persistence of a specific network. The first is documented by the overlap between the August 2025 investigation and the September 2026 attack; the second remains unproven because the publicly available information does not establish shared planners, facilitators or communications between the two episodes. The subsequent CTD investigation may eventually clarify this relationship, particularly if evidence emerges connecting the suspected support network identified after the September assault with individuals or arrangements associated with the earlier plot.
The reported presence of local facilitators and the possibility of cooperation between two militant organisations also suggest that the operational environment surrounding Kohat may have been more complex than an attack conducted by a single, self-contained cell. If confirmed, these findings would reinforce the importance of examining the relationships between direct perpetrators and supporting networks, rather than treating organisational attribution as sufficient to explain the preparation and execution of the assault. The alleged prisoner-release objective is similarly relevant, since its confirmation would indicate that the attackers sought outcomes extending beyond immediate casualties and damage to security infrastructure.
From an intelligence perspective, several developments would materially affect the assessment. Evidence linking the 2025 and 2026 investigations through common personnel, communications or facilitation relationships would support the hypothesis that elements of the earlier network survived the disruption. Confirmation of the identities and respective contributions of the two organisations reportedly suspected by CTD investigators would help determine whether Kohat reflected temporary cooperation or a more established relationship. Further findings concerning the alleged prisoner-release objective would clarify the operation’s intended outcomes, while an authenticated organisational claim containing independently verifiable information could strengthen the attribution currently reported in Pakistani media.
The absence of such evidence should not be interpreted as proof of deliberate concealment by the perpetrators, just as the lack of a verified connection between the two plots does not establish that they were independently organised. The available information supports a narrower conclusion: the same security installation was repeatedly identified as a militant target, and the September 2026 operation appears to have involved preparatory activity and possible support relationships that remain incompletely understood.
Kohat therefore raises an important distinction between preventing a planned attack and reducing the longer-term threat to the intended target. The disruption of a cell may remove immediate perpetrators without necessarily eliminating the information, relationships or organisational interest that contributed to the original planning. Whether this occurred in Kohat remains to be established, but the recurrence of the target and the investigative findings reported after the assault make it a relevant case for assessing the durability of counterterrorism disruption.
The principal warning emerging from the incident is that the successful disruption of a militant plot does not necessarily mean that the threat to its intended target has been neutralised. Establishing whether the September assault reflected surviving elements of the earlier plan, cooperation among distinct militant networks or a separately organised operation against a repeatedly identified installation will be essential to understanding both the attack and the wider vulnerabilities it exposed.
Sources and primary material
Dawn, 19 August 2025 — Reporting on the disrupted Kohat plot and alleged facilitation by police and CTD personnel.
The Express Tribune, August 2025 — Investigation into the earlier plot and reported TTP-linked network.
Reuters, 18 September 2026 — Initial attack reporting and attribution uncertainty.
Associated Press, September 2026 — Attack developments and TTP denial.
Dawn, 20 September 2026 — Casualty updates, operational developments and reported attribution.
Dunya News, 24 and 27 September 2026 — CTD investigative findings, suspected cooperation, local facilitation and reported prisoner-release objective.
AQIS / As-Sahab Media, The Subcontinent, Regarding the Martyrdom of a Mosque in the Kohat Attack, statement AQS 12_003, 19 September 2026 — Primary-source English statement supplied by the author.
🔒Executive Intelligence Cycle
This assessment is part of a broader analytical cycle.
Founding subscribers receive the Executive Intelligence Briefing, which integrates all threat assessments, cognitive domain analysis, and a rolling 30–90-day forecast into a single monthly strategic synthesis.
© Daniele Garofalo Monitoring - All rights reserved.
ISSN (International Standard Serial Number): 3103-3520
NATO NCAGE: AX664 (NATO Commercial and Governmental Entity)
UNITED NATIONS Global Marketplace ID: 1210727
ORCID Code: 0009-0006-5289-2874Daniele Garofalo is an independent researcher and analyst specialising in Intelligence, Jihadist Terrorism, Islamist insurgencies, Non-State Armed Groups (NSAG), Cognitive Warfare, and Hybrid Warfare.
His work focuses on continuous intelligence monitoring, threat assessment, and analysis of propaganda and cognitive/information dynamics, with an emphasis on decision-oriented outputs, early warning, and strategic trend evaluation.




