/

The New Face of Terror: How States Are Outsourcing Chaos

Russia and Iran are increasingly turning to criminal networks, disposable operatives, and digital platforms to wage deniable campaigns across Europe, blurring the lines between terrorism, espionage, and great power rivalry.

4 mins read
A Representational Image

Europe is confronting a rapidly evolving security threat in which hostile states are increasingly relying on tactics once associated primarily with terrorist organizations and organized crime. According to analysis published by The Soufan Center, Russia and Iran have accelerated the use of proxy actors, criminal intermediaries, and online recruits to conduct destabilizing operations that remain below the threshold of conventional warfare while inflicting psychological and political damage across the continent.

The growing phenomenon reflects what analysts describe as a new phase of hybrid warfare, where state adversaries pursue geopolitical objectives through deniable, decentralized operations designed to exploit social fractures and undermine public confidence. Rather than deploying traditional intelligence operatives or uniformed forces, these states increasingly rely on loosely connected actors recruited online, often for relatively small sums of money, to carry out intimidation campaigns, sabotage, vandalism, and attacks against symbolic civilian targets.

The issue moved further into the spotlight this week after the United Kingdom announced sanctions against nine individuals and three entities allegedly linked to an Iran-backed destabilization network. British authorities accused members of the Zindashti criminal organization and the Zarringhalam family of laundering money and financing operations tied to attacks and destabilizing activities in Britain and abroad. The sanctions formed part of what London described as a broader “day of action” against Iranian and Russian hybrid activity, highlighting growing Western concern over the convergence of criminality, terrorism, and statecraft.

Across Europe, governments have repeatedly accused both Tehran and Moscow of orchestrating attacks through proxy networks intended to inflame existing social tensions. Recent incidents linked to Iranian-backed groups have reportedly targeted Jewish communities and synagogues in countries including the United Kingdom, France, Belgium, Germany, the Netherlands, and Norway. Authorities in several cases have classified the incidents as acts of terrorism due to their apparent intention to spread fear among civilian populations and destabilize targeted communities.

At the same time, Russia has been accused of using similar tactics as part of a broader campaign aimed at weakening European cohesion. Analysts say Moscow’s strategy frequently involves exploiting sensitive political and ethnic divisions, including tensions surrounding Jewish and Muslim communities, to deepen polarization and erode public trust in democratic institutions.

What distinguishes these operations is their ambiguity. The attacks are often small-scale and designed to avoid triggering a direct military response, yet they carry strategic implications far beyond their immediate damage. Arson attacks, threats against community centers, intimidation campaigns, and acts of sabotage can create an atmosphere of insecurity while allowing sponsoring states to deny direct involvement.

Security experts argue that this ambiguity is central to the effectiveness of modern hybrid warfare. By outsourcing operations to criminal groups, petty offenders, or online recruits, states gain plausible deniability while imposing disproportionate costs on their adversaries. European governments must devote extensive intelligence resources, security personnel, and public funding to defend vulnerable targets and investigate incidents that are often difficult to trace conclusively.

One of the clearest examples of this emerging strategy is the rise of Harakat Ashab al-Yamin al-Islamia, known as HAYI, a shadowy group that emerged earlier this year claiming responsibility for attacks on Jewish and Israeli-linked targets across Europe. Though the organization presents itself as an independent militant movement, several analysts believe it may function as a front for Iranian-linked operations.

Researchers at the International Centre for Counter-Terrorism have pointed to the group’s sudden appearance, coordinated messaging, and amplification through pro-Iranian Telegram channels as signs of possible state backing. Phillip Smyth, a leading expert on Shiite militias, has argued that HAYI may serve the interests of Iran’s Islamic Revolutionary Guard Corps by allowing Tehran to rely on expendable local actors rather than formal proxy organizations that could be more easily traced back to the Iranian state.

The strategic value of such operations lies not necessarily in physical destruction but in psychological impact. A graffiti attack on a synagogue, a firebombing of a community center, or threats circulated online may require relatively little coordination or investment, yet they can generate widespread fear and dominate public discourse. Analysts say the cost imbalance heavily favors the aggressor: while the perpetrators spend little money or effort, governments must invest enormous resources into prevention, investigation, and community protection.

This decentralized model has been made possible by technological changes that are reshaping modern conflict. Encrypted messaging platforms, social media, cryptocurrency payments, and artificial intelligence tools now allow hostile actors to identify, recruit, and direct individuals inside target countries without relying on traditional espionage networks.

Research by Bart Schuurman, an expert on Russian hybrid tactics, suggests that Russia has increasingly used encrypted platforms such as Telegram to recruit operatives for what resembles “gig economy” sabotage. According to his findings, recruiters often target Russian-speaking diasporas, refugee communities, and criminal circles, offering modest payments in exchange for carrying out acts ranging from vandalism to surveillance.

Investigations by CNN also uncovered accounts posing as Iranian intelligence operatives online, advertising payments for attacks against Israeli interests or for spreading inflammatory political content. The methods echo aspects of jihadist recruitment campaigns that inspired lone actors in previous decades, but with one critical difference: ideology is often secondary to financial incentive.

The implications of this shift extend beyond Europe. Security analysts warn that the same tactics could increasingly be directed at the United States or other Western nations. Although the United States possesses a more extensive counterterrorism infrastructure and greater experience dealing with online radicalization, experts caution that no society is immune to decentralized, low-cost operations that exploit social divisions and vulnerable individuals.

Iran has previously been accused by American authorities of cultivating surrogate networks inside the United States and using criminal associates to target dissidents. Russia, meanwhile, has long engaged in cyber operations and disinformation campaigns aimed at influencing American politics and public opinion.

So far, Europe has proven a more accessible operating environment for many of these activities due to cross-border mobility, diaspora networks, and varying national security frameworks. But analysts warn that if states such as Iran, Russia, or even China choose to intensify this model elsewhere, the results could be significant.

The broader concern, according to The Soufan Center, is that the world may be entering an era in which the boundaries between terrorism, espionage, criminality, and interstate competition are becoming increasingly indistinct. In this emerging landscape, warfare is no longer confined to battlefields or conducted solely by soldiers and intelligence officers. Instead, it is being carried out through anonymous online interactions, disposable operatives, and deniable acts of disruption that are cheap to execute but extraordinarily difficult to stop.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog