A new Institute for Strategic Dialogue report warns that hostile states are increasingly adopting methods that overlap with those used by extremist and criminal networks, recruiting financially motivated young people online to carry out sabotage and violence while keeping their true sponsors at arm’s length.
The September 2026 study, authored by Milo Comerford, Emily Winterbotham, Jakob Guhl, and Melanie Smith, examines how states including Russia and Iran have exploited online recruitment, disposable intermediaries and criminal networks to conduct operations across Western countries.
The convergence is placing growing strain on security agencies already confronting rapidly changing terrorism threats. In Britain, people under 18 represented nearly 20% of terrorism-related arrests in 2023, roughly four times the proportion a decade earlier. Across the European Union, minors accounted for more than 29% of terrorism arrests in 2024.
Meanwhile, MI5 Director General Ken McCallum reported in October 2024 that state-threat investigations had increased 48% during the preceding year. UK Counter Terrorism Policing now devotes more than 20% of its casework to state threats, according to ISD.
The Gig Economy Goes to War
Russia has been particularly aggressive in recruiting low-level proxies who may have little or no ideological commitment to Moscow. The ISD study cites Ukrainian authorities as estimating that approximately 1,100 Ukrainians had been recruited for Russian-directed sabotage operations since February 2022, with around one in five being minors. Roughly half were unemployed.
A separate investigation into Russian recruitment networks documented Telegram advertisements disguised as easy work, including offers of thousands of dollars to damage NATO-linked vehicles or commit arson. Recruits were sometimes instructed to submit video proof before receiving cryptocurrency payments.
The model exploits people who can be recruited cheaply and discarded afterward.In one case cited by ISD, three suspects in a foiled Paris attack were minors. The principal suspect told investigators that an unknown individual contacted him through Snapchat and offered him €600 to attack Bank of America offices.
In Britain, 22-year-old Ukrainian construction worker Roman Lavrynovych was convicted in June 2026 for carrying out arson attacks in May 2025 against properties linked to Prime Minister Keir Starmer. He had communicated with an anonymous Russian-speaking handler through Telegram and received cryptocurrency payments.
Investigators linked the handler to pro-Kremlin networks, although British authorities said they had not established that the Russian state itself directed the attacks.
European law enforcement agency Europol launched a multinational violence-as-a-service task force in 2025 as authorities warned that criminal networks had increasingly “industrialised” the recruitment of children for violent acts.
Iran’s ‘Ghost Proxy’ Targets Jewish Communities
Iran presents a different version of the same broader problem. Between March and April 2026, a previously unknown organization calling itself Harakat Ashab al-Yamin al-Islamiya, or HAYI, claimed responsibility for a series of attacks in Europe, including arson, shootings and stabbings targeting Jewish institutions, Iranian dissidents and other targets. The group appeared online on March 9, 2026 with effectively no prior public footprint.
ISD described HAYI as a “ghost proxy,” a group apparently created to claim attacks while obscuring those directing them. Its visual branding echoed imagery associated with Iran’s Islamic Revolutionary Guard Corps and Kata’ib Hezbollah, while spelling mistakes and inconsistent designs suggested hastily produced or potentially AI-assisted material. The group became significantly more consequential after the arrest of Mohammad Baqer al-Saadi.
Al-Saadi was detained in Turkey in early May 2026 and subsequently transferred to U.S. custody. U.S. prosecutors describe him as a senior Kata’ib Hezbollah figure with close connections to Iran’s IRGC.
According to a federal complaint, al-Saadi and his associates planned, coordinated and claimed responsibility for approximately 18 attacks in Europe under the HAYI banner. Investigators also linked the network to two attacks in Canada.
The allegations offered unusually direct evidence connecting the supposed independent group to an Iranian-backed militia operative. Investigators said al-Saadi referred to HAYI attackers as “our people.” He also allegedly sent HAYI’s inaugural statement and imagery through Snapchat more than four hours before the group publicly released them.
U.S. prosecutors further allege that al-Saadi sought to recruit an undercover officer he believed was connected to a Mexican cartel to attack Jewish targets in the United States, including a synagogue in New York and Jewish institutions in Los Angeles and Scottsdale. The discussions included possible bombings or arson attacks.
Iran has previously used criminal intermediaries for attacks abroad. European investigations have tied Iranian operations to individuals associated with the Hells Angels in Germany and to criminal networks including Foxtrot and Rumba in Scandinavia and Belgium.
Security Services Under Growing Pressure
The changing threat has forced Western governments to devote greater resources to hostile-state activity. McCallum said in 2024 that British authorities had confronted more than 20 potentially lethal Iran-backed plots since 2022.
“We’re seeing the most complex and interconnected threat environment we’ve ever seen,” he said. McCallum also noted that more than 750 Russian diplomats had been expelled from Europe following Russia’s invasion of Ukraine, describing the majority as intelligence officers.
ISD’s Authoritarian Interference Tracker has documented 188 incidents linked to Russia targeting democracies in Europe and North America since February 2022. Germany responded to the growing threat in June 2026 by establishing a Joint Centre for the Defence Against Hybrid Threats intended to coordinate monitoring and government responses.
The Policy Blind Spot
The ISD report warns that governments still frequently treat violent extremism, organized crime and hostile-state activity as separate security problems even as adversaries increasingly exploit techniques spanning all three.

Drawing on a public-health model used in extremism prevention, the researchers call for stronger coordination between national and local governments, dedicated democracy-protection capabilities and closer integration between counter-extremism and hostile-state responses.
The report also argues that digital policy must address the entire lifecycle of online harm, from initial recruitment and algorithmic amplification to operational coordination and post-attack propaganda.
The Russian and Iranian cases are not identical. Moscow has heavily exploited financially vulnerable recruits for sabotage, while Iran has repeatedly relied on criminal intermediaries and deniable proxy networks for targeted violence. But both demonstrate the same strategic advantage.
States can recruit expendable operatives online, distance themselves from attacks and force Western authorities to determine whether an apparently isolated criminal act is really part of a foreign intelligence operation. By the time investigators identify the network behind the recruit, the individual giving the orders may already have disappeared.








