Daniele Garofalo Monitoring

Daniele Garofalo Monitoring

The Distributed Threat

What Changed in Global Security This Week? Weekly Threat Shift | Issue #17

Daniele Garofalo's avatar
Daniele Garofalo
Sep 11, 2026
∙ Paid

Executive Snapshot

The 2–8 September reporting period reinforced a security trend that is becoming increasingly difficult to treat as marginal: operational capability is spreading across smaller, less structured, and often geographically disconnected actors.

In Europe, three suspected jihadists detained in France illustrate how a small digital network can combine domestic attack intent, aspirations to join Islamic State abroad and contacts extending across the Atlantic. In Italy, the investigation of a 16-year-old exposed a different trajectory, in which Islamic State propaganda reportedly coexisted with neo-Nazi, white-supremacist and accelerationist material. Neither case resembles the structured European jihadist networks of the previous decade, yet both demonstrate pathways through which online environments can translate extremist consumption into operational interest.

A parallel development is visible in Russian activity against Europe. Denmark’s PET warned of concrete planning and preparation for sabotage against defence-related targets, including attempts to recruit ordinary individuals online. In Romania, the SRI announced the disruption of a suspected Russian intelligence operation involving reconnaissance of military facilities, critical infrastructure and Ukrainian cargo aircraft. These developments follow Germany’s attribution of the Leipzig/Halle explosive-drone operation and reinforce the assessment that Moscow is increasingly able to project disruptive capability through compartmentalised, expendable intermediaries rather than conventional intelligence infrastructure.

The common feature is not ideology or command structure. It is distributed capability, which shows why we need to understand evolving threats and should give the audience confidence to adapt strategies.


📌 Inside this Weekly Threat Shift

  1. The Shift of the Week #17

  2. Threat Signals

  3. The Information Battlefield

  4. Why It Matters

  5. Watchlist, Next 30 Days

  6. Strategic Consequence

  7. Final Analytical Line.


The Shift of the Week #17

From hybrid radicalisation and transnational jihadist micro-networks to disposable proxies and operational expertise

For intelligence services, organisational strength has traditionally provided one of the principal indicators of operational capability. Large networks offered recruitment pools, financing, training, logistical infrastructure and command structures. Disrupting those structures therefore reduced an adversary’s ability to act. That relationship is becoming less reliable.

This week’s cases show that capability can increasingly be assembled without a large organisation, so we need to stay vigilant about digital connectivity and online environments.

The French jihadist investigation is particularly illustrative. Three men aged between 20 and 26 were placed under investigation over an alleged violent project targeting the Jewish community. French authorities also suspect that they intended to travel to Africa to join the Islamic State. According to Le Monde, investigators identified them through a WhatsApp group called “Les soldats d’Allah.” One of the suspects was reportedly in contact with Jessica Bowie, the American woman arrested by the FBI on 19 August over an alleged Islamic State-inspired plot against the New York State Capitol.

No public evidence currently shows a formal transatlantic operational cell or centralised Islamic State direction, but this underscores the need for nuanced analysis of social networks linking prospective attackers across countries.

This is an important distinction. Online networks may be loose, unstable, and largely self-directed, which impacts operational security and challenges traditional counterterrorism measures by enabling contacts, ideological reinforcement, and operational encouragement in a decentralised manner.


Threat Signals

  • France: From Digital Networking to Attack Intent

The French case shows several indicators at once. The alleged domestic targeting of the Jewish community coexisted with an apparent desire to reach an Islamic State theatre in Africa. This challenges a rigid distinction between foreign-fighter mobilisation and domestic attack planning. Individuals may consider both options, shift between them or regard overseas affiliation as part of a longer trajectory toward violence.

It also underscores Africa’s importance in contemporary jihadist mobilisation. The aspiration allegedly expressed by the suspects was not centred exclusively on Syria or Iraq. Islamic State’s strongest operational environments are now concentrated heavily in Africa, and European counterterrorism agencies increasingly need to consider African theatres when assessing attempted extremist travel.

The reported contact with Bowie adds a further layer. Her arrest in the United States initially appeared consistent with a highly individualised Islamic State-inspired trajectory. The subsequent discovery of a connection to an individual under investigation in France does not establish organisational coordination. Still, it demonstrates why the category of “lone actor” should be applied cautiously. Digital radicalisation can produce individuals who act alone physically while remaining socially connected to a transnational extremist milieu.

  • Italy: Hybrid Radicalisation and the Problem of Ideological Classification

On 2 September, Italian authorities placed a 16-year-old from Lombardy in a juvenile community as part of an investigation involving alleged self-training for terrorist purposes. According to Italian reporting, investigators identified Islamic State propaganda alongside neo-Nazi, white-supremacist and accelerationist material, as well as an increasing interest in weapons, explosives and incendiary substances.

The case’s significance lies less in ideological coherence than in its absence. Islamic State jihadism and neo-Nazism remain fundamentally incompatible ideological systems. Yet that contradiction may matter considerably less to some young individuals whose radicalisation is driven by violence, transgression, identity construction and fascination with extremist aesthetics rather than by adherence to a coherent political doctrine.

The resulting threat profile can be difficult to classify using conventional categories. A teenager can simultaneously consume jihadist propaganda, glorify far-right attackers and investigate methods of violence without progressing through the traditional stages associated with membership in an extremist movement.

In such cases, behavioural indicators become particularly important. Growing interest in weapons, target selection, operational security, attack methodologies or technical preparation may reveal more about movement toward violence than attempts to identify a single dominant ideology. The Italian case should not be generalised from a single investigation. But it fits a broader European concern over increasingly young individuals moving through fluid online extremist environments.

  • United States: When One Individual Adds Capability to a Network

A different model appeared in the United States. On 8 September, former Marine and former New Iberia police officer Micah James Legnon pleaded guilty to conspiracy to provide material support to terrorists. According to the U.S. Department of Justice, Legnon became involved with the Order of the Black Lotus, a faction associated with the Turtle Island Liberation Front, and discussed providing military knowledge to the network. The case involved discussions concerning explosives, urban combat, precision shooting and an alleged plan targeting a logistics facility in California.

The strategic significance lies in capability transfer. A small extremist network does not necessarily need to develop military expertise organically. One individual with previous professional training can significantly increase its competence.

This is a longstanding counterterrorism concern, but it becomes more consequential in decentralised environments. Network size may be a poor proxy for threat when one member has specialist knowledge of explosives, surveillance, weapons, communications, or military tactics.

  • Türkiye: Persistent Islamic State Attack Mobilisation

Türkiye provided another indicator of continued Islamic State-related operational activity. On 4 September, Turkish police and intelligence personnel attempted to arrest a 21-year-old suspected of Islamic State links and of preparing an attack. The suspect opened fire during the operation at Istanbul’s Sultanbeyli bus terminal and was killed when police returned fire. A civilian subsequently died from injuries sustained during the incident. Searches reportedly recovered material assessed as potentially usable for explosive production, while another person connected to the suspect was detained.

The incident should be understood within sustained Turkish pressure against Islamic State networks rather than as evidence of a broader resurgence by itself. Its importance is operational: authorities were dealing with an individual assessed to have moved beyond propaganda consumption toward potential attack preparation. It also illustrates the continuing coexistence of two realities. Islamic State has suffered sustained leadership and organisational pressure, yet individuals and small networks remain capable of progressing toward violence.

Immediately before this reporting period, Yemeni and coalition forces also announced the killing in Seiyun of Abu Hudhayfah al-Ansari, identified as Islamic State’s official spokesman. If the organisation ultimately confirms the identification, the loss would represent a significant disruption at the central media-leadership level. Yet developments in France, Italy, and Türkiye show why leadership attrition cannot be treated as an immediate measure of ideological reach or mobilisation potential. Organisational degradation and distributed mobilisation can occur simultaneously.


The Information Battlefield

The week’s cases reinforce a structural change in the relationship between online activity and physical violence. Digital platforms are no longer simply channels through which extremist organisations distribute propaganda to passive audiences. They increasingly become environments where individuals meet, compete, exchange material, construct identities, and occasionally establish operational relationships.

The French investigation illustrates the network dimension. The Italian case illustrates ideological fluidity. Together they demonstrate two different problems for intelligence collection. In the first, investigators must determine whether apparently autonomous individuals are connected to others and whether those relationships provide operational value. In the second, the problem is almost reversed. Analysts may encounter so many contradictory ideological signals that classification itself becomes misleading.

This matters particularly among younger subjects. Some contemporary extremist ecosystems reward violence more consistently than they reward ideological consistency. Islamic State imagery, neo-Nazi symbolism, previous mass killers, accelerationist literature and violent online subcultures can coexist inside the same digital consumption pattern.

This post is for paid subscribers

Already a paid subscriber? Sign in
© 2026 Daniele Garofalo Monitoring · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture