Executive Snapshot
The 9–15 September reporting period highlighted a security problem that cuts across otherwise very different threat environments: the transition from hostile intent to usable operational capability.
In the United States, federal authorities arrested a 21-year-old Pennsylvania man after an investigation into his alleged support for Islamic State. Jonathan Hunter Kramer had reportedly presented himself online as an Islamic State supporter, offered to distribute explosives manuals and referred to preparations for a “mission”. What makes the case particularly significant, however, is what happened next. According to the Department of Justice, Kramer acquired a semiautomatic rifle, magazines and approximately 190 rounds of ammunition, purchased a disposable phone, travelled to a hotel and continued acquiring equipment before the FBI intervened. The threat had therefore moved beyond ideological identification and into material preparation. A different form of capability emerged in Germany and Austria. German federal prosecutors charged seven alleged Hamas members in connection with preparations for attacks against Israeli or Jewish targets. The investigation reportedly uncovered a weapons infrastructure that included a fully automatic rifle, 13 handguns and more than 700 rounds of ammunition, with part of the arsenal moved across borders. The significance of the case is not simply the weapons themselves, but the apparent logistical architecture behind them.
The same transition from intent to capability is visible in Russian activity against Western states. In the United Kingdom, a British man was charged after allegedly offering assistance to a structure British authorities link to Russian military intelligence. Near Svalbard, meanwhile, Britain, Norway and the United States reportedly disrupted a Russian deep-sea exercise involving technology designed to turn off critical undersea cables while making attribution difficult. The most complex case emerged on 15 September, when the US Department of Justice unveiled charges against five individuals allegedly working within a Russian intelligence services network. Prosecutors describe an architecture combining recruitment, surveillance, sabotage, terrorism financing and murder-for-hire, including attempts to recruit individuals inside the United States.
These cases should not be collapsed into a single threat category. Jihadist mobilisation, Hamas-linked clandestine logistics and Russian state-directed covert action remain fundamentally different phenomena. Their convergence lies elsewhere. Across each case, the decisive warning indicators appeared when intent began to acquire the means necessary for action: weapons, logistics, technical expertise, surveillance, access, intermediaries or infrastructure knowledge. That distinction matters. Ideology can identify a potential threat actor. Capability tells us how close that actor may be to producing harm.
📌 Inside this Weekly Threat Shift
The Shift of the Week #18
Threat Signals
The Information Battlefield
Why It Matters
Watchlist, Next 30 Days
Strategic Consequence
Final Analytical Line
The Shift of the Week #18
When intent becomes capability
Last week’s Weekly Threat Shift examined the growing distribution of operational capability across smaller networks, isolated individuals and expendable proxies. This week’s developments point to the next analytical problem: determining when those fragmented actors cross the threshold separating hostility, radicalisation, or recruitment from an increasingly credible capacity to act.
A single indicator rarely marks this threshold. An extremist acquiring a weapon does not necessarily mean an attack is imminent. A foreign intelligence service contacting a local individual does not demonstrate that sabotage will follow. Reconnaissance of critical infrastructure may have several explanations. Weapons stored by a clandestine network do not reveal when, where or even whether they will ultimately be used. The intelligence value emerges when these indicators begin to converge. The Pennsylvania case illustrates this progression particularly clearly. According to US prosecutors, Kramer had already displayed sustained Islamic State sympathies online. That behaviour was relevant, but it did not by itself determine attack proximity. The threat picture changed when ideological identification was accompanied by increasingly concrete behaviour.
On 12 September, investigators observed Kramer leave his residence, buy a disposable phone, obtain a long bag from another individual, travel to a hotel where he paid cash for a room, and then visit a sporting-goods store. Searches later recovered a semiautomatic rifle, magazines, a scope, a bipod and approximately 190 rounds of ammunition. Federal authorities allege that he had previously said he was preparing for his “mission” and lacked only a weapon. None of these elements is analytically decisive in isolation. Together they are different.
This is where the capability threshold becomes useful as an analytical concept. Intent identifies willingness. Networks can provide encouragement, instruction or access. Procurement introduces physical means. Operational security can indicate an attempt to conceal preparation. Reconnaissance can connect capability to a target. Only when several of these elements begin reinforcing one another does the distance between radicalisation and potential violence meaningfully contract. The German Hamas investigation demonstrates the same principle at network level. According to prosecutors and reporting on the indictment, the alleged network had accumulated firearms and ammunition and moved part of the arsenal across European borders. If the allegations are substantiated, this suggests something more consequential than ideological or financial support. Weapons procurement requires contacts, storage, transportation and individuals trusted to maintain access to the material.
The Russian cases extend the same problem into state-directed covert action. Here, capability does not necessarily depend on a conventional intelligence officer physically conducting an operation. It can be distributed between recruiters, local proxies, surveillance personnel, criminal facilitators and technical specialists. The individual ultimately conducting sabotage or violence may possess only one part of the operational picture. This makes capability harder to recognise because the warning indicators can appear fragmented across different institutions and jurisdictions.
A suspicious firearms acquisition may initially resemble ordinary crime. Photography of a military installation may appear to be isolated reconnaissance. Contact between a foreign recruiter and a local individual may not immediately reveal its purpose. Unusual activity around subsea infrastructure can remain ambiguous until combined with intelligence about adversary capabilities and intentions. The principal shift this week is therefore not that terrorism and state sabotage are becoming the same phenomenon. They are not. It is that increasingly different threat actors can build operational capability by combining relatively accessible components. For intelligence services, the challenge is identifying that convergence before the final component is assembled.
Threat Signals
From jihadist attack preparation and Hamas weapons networks to Russian sabotage and assassination infrastructure
United States: From ISIS Support to Material Preparation
The arrest of Jonathan Hunter Kramer provides perhaps the clearest example this week of how an apparently digital extremist trajectory can move toward physical capability. According to the Department of Justice, Kramer had used the online identity “Hamza Al Rashid”, claimed affiliation with Islamic State, offered to share explosives manuals and discussed preparing for a “mission”. The investigation also followed earlier concerns surrounding his extremist activity. After his release from juvenile detention in March 2026, the FBI received information suggesting that he had resumed contact with individuals from his previous network.


