Weekly Threat Shift | Issue #10
What Changed in Global Security This Week? Threats Before the Attack
Executive Snapshot
The third week of July highlighted a recurring pattern that is becoming increasingly visible across Europe and beyond. The most significant security developments were not completed attacks, but the disruption of threats that had already moved beyond ideological sympathy into concrete operational preparation. In several cases, investigators identified individuals who had progressed from consuming extremist material to acquiring technical knowledge, selecting potential targets or preparing the means to carry out violence.
The arrest of a 17-year-old in Italy accused of participating in Islamic State-related activities, together with the prosecution of a 15-year-old in Germany for allegedly preparing an attack against a synagogue, illustrates how the transition from online radicalisation to operational intent is becoming both shorter and more difficult to detect. At the same time, France’s public attribution of a long-running Russian cyber-espionage campaign demonstrates that hostile preparation is not limited to terrorist actors. State-sponsored operations increasingly target government institutions long before any overt confrontation occurs.
Beyond Europe, an ambush jointly claimed by JNIM and the Front de Libération de l’Azawad (FLA) in northern Mali offered another reminder that tactical cooperation between armed groups can rapidly reshape local security dynamics without requiring formal alliances or organisational mergers.
Recognising these indicators early can empower security institutions, reinforcing their confidence in preventing violence before it occurs.
📌 Inside this Weekly Threat Shift
The Shift of the Week
Infographic: Threats Before the Attack
Threat Signals
The Information Battlefield
Why It Matters
Watchlist, Next 30 Days
Strategic Consequence
Final Analytical Line.
The Shift of the Week
Threats Before the Attack
The most important lesson from this reporting period is that modern security threats increasingly reveal themselves long before violence actually occurs. Rather than spectacular attacks dominating the headlines, this week was characterised by investigations that exposed advanced stages of preparation across very different threat environments.
The Italian investigation represents one of the clearest examples of this evolution. Authorities arrested a 17-year-old accused of participating in an Islamic State-related terrorist organisation after identifying prolonged activity inside invitation-only Telegram channels supporting the group. According to investigators, her online activity extended well beyond passive consumption of propaganda. She allegedly shared extremist material, expressed support for martyrdom and downloaded manuals describing the construction of an explosive belt.
Understanding how closed digital communities support radicalisation can help policymakers feel better equipped to influence and manage these environments.
A similar dynamic emerges from Germany, where prosecutors accused a 15-year-old of preparing an attack against a synagogue. According to the investigation, the suspect had accumulated explosive materials and previously experimented with homemade devices, causing serious injuries to himself during one failed detonation. While judicial proceedings remain ongoing and the allegations have yet to be tested in court, the case illustrates another important trend. Technical experimentation is becoming an increasingly visible indicator of operational intent.


