See the threat beyond the attacker
Understanding how fragmented threats develop and translate into physical action requires intelligence that connects activity across the wider threat environment.
Explore Physical Intelligence Services
Understanding how fragmented threats develop and translate into physical action requires intelligence that connects activity across the wider threat environment.
Explore Physical Intelligence ServicesNatasia Kalajdziovski, Senior Fusion Threat Intelligence Analyst at SecAlliance, examines the recruitment of teenagers as contract killers. The age of the perpetrator draws attention, she argues, but the system surrounding them is more consequential. Physical security, narrative intelligence and VIP monitoring teams working separately will each hold one part of the picture. Fusion analysis is what makes the pattern visible.
The recruitment of teenagers to conduct contract killings has, understandably, attracted attention because of the age of the perpetrators involved. The image is a particularly unsettling one: young people, sometimes still children in legal and developmental terms, travelling across borders with firearms, following instructions received through encrypted messaging platforms and preparing to kill individuals with whom they have no personal relationship and, in some cases, whose identities they may barely understand.
Yet, while the age of those involved is important, it is not necessarily the most analytically significant element of this emerging threat landscape.
The more consequential development resides in the system which surrounds them: an increasingly fragmented infrastructure through which violent intent can be separated from violent action, criminal capability can be procured at distance, and individuals with little experience or ideological commitment can be used as disposable instruments by those seeking to remain several steps removed from the consequences.
A recent BBC investigation into the use of teenage hitmen provides a particularly stark illustration of this problem. Its examination of cases connected to the Swedish-based Foxtrot Network demonstrates how young people can be recruited online, moved across national borders, supplied with weapons and directed towards targets by individuals they have never met. It also illustrates the difficulties involved in determining where responsibility for such violence ultimately begins and ends.
The person holding the firearm may be the most visible participant in an attempted killing. They are not necessarily the person who selected the target, developed the intent, arranged the logistics or stood to benefit from the outcome.
This distinction is central to understanding what Europol has termed violence-as-a-service. Although the outsourcing of criminal violence is not new, the accessibility, geographical reach and organisational fragmentation of the present model marks an important development in how that violence can be generated and deployed. It is a development which cannot be assessed adequately through the lens of organised crime alone, particularly where criminal networks, hostile states, online subcultures and publicly available information are increasingly capable of intersecting.
For organisations operating within complex threat environments, the issue is therefore best understood as a fusion intelligence problem, situated at the nexus of physical threat, narrative mobilisation and executive vulnerability.
Johannes Natland at the Briar Court Hotel in Huddersfield [source]

In July 2026, Norwegian national Johannes Natland was convicted of conspiracy to murder after travelling to the United Kingdom to conduct a contract killing. Natland, who was eighteen at the time of the plot, had been offered EUR 25,000 and was directed through messages sent to his telephone. After arriving in Manchester, he travelled to Huddersfield, where he was instructed to collect cash, a stolen vehicle and two firearms hidden in woodland.
The operation was disrupted before the intended killing could take place. However, the identity of the target has not been made public, while those situated further upstream in the operation remained physically removed from both the weapons and the scene of the proposed attack.
The details of the case are striking, but they should not be interpreted only as evidence of the susceptibility of young people to criminal recruitment. Rather, they demonstrate how the different components of serious violence can be divided amongst several actors, each of whom may possess only a partial understanding of the operation in which they are involved.
The instigator may identify the target and provide the financial incentive. A recruiter may locate somebody willing to conduct the attack. An enabler may arrange travel, accommodation, vehicles or weapons. The final perpetrator may then be provided with little more than a photograph, an address and a series of instructions.
Europol’s own analysis of this process distinguishes between the roles of instigator, recruiter, enabler and perpetrator. While these categories should not be understood as an inflexible framework applicable to every case, they provide a useful way of conceptualising the distribution of agency within violence-as-a-service.
Europol’s “violence-as-a-service” pathway [source]

The value of this distribution is readily apparent from the perspective of the person commissioning the act. By separating intent from execution, the model creates distance, complicates attribution and places the greatest degree of immediate exposure upon the individual who is most easily replaced.
The young perpetrator is valuable precisely because they are disposable.
They may have no established connection to the target, no previous presence within the relevant threat environment and no substantial knowledge of the network for which they are acting. Their arrest may disrupt the immediate plot, but it does not necessarily reveal the full structure behind it. Nor does it remove the capacity of the instigator or recruiter to find somebody else.
This is one of the central difficulties presented by the model. The visible manifestation of the threat may be inexperienced and poorly organised, while the system which produced it remains capable, adaptive and deliberately obscured.
The activities attributed to the Foxtrot Network are also significant because they sit within a wider pattern in which the boundaries between criminal and state-directed violence have become increasingly difficult to distinguish.
Foxtrot is primarily understood as a transnational criminal organisation, associated with drug trafficking, shootings and contract killings. However, British and American authorities have also accused the network of acting on behalf of the Iranian state in connection with attacks against Jewish and Israeli targets in Europe. In April 2025, the United Kingdom sanctioned Foxtrot and its leader, Rawa Majid, while the United States Treasury similarly assessed that the network had conducted attacks at Iran’s direction.
Rawa Majid, pictured with Ali Shehad Ahmed, who is believed to be part of the network [source]

As SecAlliance has previously examined in relation to the outsourcing of sabotage and terror by Russia and Iran, the use of criminal intermediaries provides hostile states with capabilities which may be difficult to generate through conventional intelligence structures without creating unacceptable diplomatic or operational exposure.
This does not mean that all violence-as-a-service activity should be interpreted as state-directed, nor that every act undertaken by a network with state connections necessarily serves a geopolitical objective. Criminal organisations retain their own interests, rivalries and commercial motivations, while the evidence required to attribute particular incidents to state direction is frequently incomplete.
However, the relationship creates an environment in which criminal and geopolitical objectives can overlap.
A criminal network may possess access to weapons, fraudulent documentation, transport routes and individuals willing to carry out violence. A hostile state may possess the intelligence requirement, target interest and financial resources. Neither actor needs to relinquish its own objectives for a temporary relationship to become mutually useful.
The result is not always a neat hierarchy in which a state directs a criminal organisation in the manner of a conventional intelligence asset. It may instead involve shifting, transactional and sometimes opportunistic arrangements in which access to criminal capability becomes one instrument amongst several.
This ambiguity is not an incidental feature of the model. It is part of its utility.
Where intent, facilitation and action are divided across several jurisdictions and categories of actor, it becomes more difficult for governments and organisations to determine whether an incident is primarily criminal, political, ideological or strategic. In practice, it may be several of these things all at once.

From a Physical Threat Intelligence perspective, violence-as-a-service presents a challenge to assessments which assume that intention and capability will be located within the same actor.
The conventional process of identifying a physical threat frequently begins with an examination of those individuals or groups possessing a known grievance against a person, organisation or location. Previous threatening behaviour, ideological hostility, criminal history, fixation, operational capability and proximity to the target may all contribute to an assessment of whether hostile intent is likely to result in action.
The use of recruited intermediaries complicates this process because the individual who approaches the target may possess neither the original grievance nor any discernible historical interest in it.
A teenager sent to photograph an office entrance may have no ideological relationship with the organisation occupying the building. An individual tasked with collecting a vehicle may not know its intended use. A person instructed to leave a package or weapon at a particular location may have no knowledge of the perpetrator who will retrieve it.
The absence of a visible relationship between actor and target should not, therefore, be treated as evidence that no relationship exists further upstream.
This is particularly important when considering hostile reconnaissance. Organisations may reasonably expect surveillance to be conducted by the individual or group preparing to undertake an attack. Within a fragmented model, however, reconnaissance can itself be outsourced. The person gathering imagery of an entrance, identifying security personnel or confirming an executive’s vehicle may be providing information to somebody else rather than preparing to act personally.
The same is true of logistical indicators. Travel, accommodation, vehicle hire, weapons procurement and local facilitation may be distributed across individuals who do not know one another. Any one of these activities, examined in isolation, may appear insufficiently significant to justify escalation. Their value emerges when they are understood as parts of a broader operational process.
It would also be a mistake to assume that the relative inexperience of the final perpetrator diminishes the physical risk presented.
Indeed, inexperience may increase certain forms of risk. A poorly trained individual acting under time pressure may be less able to verify a target, control a weapon, adapt to changes in the environment or distinguish between the intended victim and those around them. The BBC investigation’s examination of the murder of Murad Abdelkader, who was killed after being mistaken for another person, demonstrates the potential consequences of this imprecision.
The physical risk may therefore extend beyond the intended target to colleagues, family members, security personnel, drivers and members of the public. The operational weakness of the perpetrator does not make the threat benign; it may instead make its effects less predictable.
For Physical Threat Intelligence, the analytical requirement is consequently not only to assess whether a known hostile actor possesses the capability to conduct violence, but whether that actor has access to an environment in which capability can be acquired, delegated or purchased.

The violence-as-a-service model is facilitated not only by criminal infrastructure, but by the narratives through which participation in violence is made conceivable.
A young person does not necessarily arrive at the decision to conduct a contract killing through the development of a settled ideological worldview. Recruitment may instead draw upon financial vulnerability, status, coercion, excitement, belonging or the desire to demonstrate value within an online community.
Europol’s Operational Taskforce GRIMM, established to address the recruitment of young people into serious, organised crime, has identified the importance of social media and encrypted communications within this process. The platforms themselves do not cause violent behaviour; however, they can create access between recruiters and individuals whose personal circumstances make them receptive to particular forms of manipulation.
The language used in this engagement is important because it can obscure the moral and physical reality of what is being requested.
The use of gaming references, coded terminology and descriptions of attacks as tasks or missions can reduce the target to an abstraction. Within the Natland case, the individual issuing instructions reportedly used the name “Agent 47”, a reference to the central character of the Hitman video-game franchise. Such language should not be overstated as a causal explanation, but neither is it without significance. It provides a vocabulary through which violence can be represented as performance, achievement or play.
Narrative Threat Intelligence can help to identify how these environments function, particularly by examining the transition between generalised content and purposeful mobilisation.
There is an important distinction between material which glorifies criminality and communication which begins to facilitate a specific act. Hostile or violent rhetoric is widespread across online spaces and, in most instances, will not produce physical action. The analytical problem resides in determining when grievance, fantasy or posturing begins to acquire operational characteristics.
This may occur when discussion becomes attached to a named person, organisation or location; when publicly available information is requested or circulated; when financial incentives are introduced; or when users begin to discuss access, timing, transport, weapons or methods.
In this way, narrative does not sit apart from the physical threat environment. It can help to identify the target, legitimise action against it, recruit the person willing to act and, after the event, frame the meaning of what has occurred.
The target-facing narrative is equally significant. Organisations and their leaders can become symbolically associated with conflicts, governments, sectors or policies in ways which may bear only a partial relationship to their actual role. A financial institution may be presented as responsible for the implementation of sanctions. A technology company may be characterised as an instrument of state surveillance. An executive within the defence sector may be framed as personally responsible for military action conducted elsewhere.
The accuracy of these claims may be secondary to their mobilising value.
Once an individual or organisation has been constructed as a legitimate object of punishment, publicly available information about them can acquire a different significance. An address is no longer merely personal data; it becomes a means of access. A conference announcement becomes an opportunity. A photograph of a vehicle becomes a tool of identification.
The narrative environment, therefore, helps to explain not only why an actor may wish to cause harm, but how the target becomes intelligible and reachable to others.

For VIP Monitoring, the central implication is that executive risk cannot be assessed solely through prominence.
An individual does not need to possess widespread public recognition to become significant within a particular threat context. Their relevance may be derived from the organisation they represent, the sector in which they operate, the event they are attending or the political meaning attached to a business decision. This relevance is often temporary and relational.
An executive may attract little hostile attention during the ordinary course of their work, but become more visible following a sanctions announcement, controversial contract, merger, public statement or appearance at a politically sensitive event. A regional director may acquire symbolic importance because they are the most accessible representative of a much larger organisation. A family member or colleague may become exposed because their online activity provides access to the intended target.
As SecAlliance has previously assessed, visibility can become a form of vulnerability when fragments of publicly available information are assembled into an intelligible pattern of life.
The person tasked with conducting violence does not need to possess sophisticated intelligence tradecraft if the collection and analysis have already been undertaken elsewhere. They may be provided with a photograph, a home or hotel address, details of a speaking engagement, a vehicle description and instructions about where the target is likely to appear.
Individually, each disclosure may appear relatively innocuous. Their combined value is greater than the sum of their parts.
This is why effective VIP Monitoring must extend beyond the direct observation of threatening references to an executive’s name. It requires attention to the broader exposure environment surrounding them: family members, close colleagues, public schedules, corporate announcements, residential information, travel patterns and the narratives through which they are being interpreted.
It must also distinguish between visibility and significance. An increase in online mentions may reflect nothing more than publicity around a corporate event. However, where that visibility is accompanied by hostile framing, the circulation of personal information, practical discussion of access or evidence of financial incentivisation, the threat picture begins to change.
No single indicator necessarily establishes intent. Yet intelligence assessment has rarely been the simple accumulation of definitive indicators. It is the process of determining how partial, uneven and sometimes ambiguous pieces of information relate to one another, and whether their convergence alters the probability or potential impact of harm.
Within the violence-as-a-service model, this convergence is particularly important because different stages of the operation may be visible within different information environments. The narrative identifying the target may appear in one space, the personal information enabling access in another, and the recruitment or tasking of a perpetrator somewhere else entirely.
The central security challenge presented by violence-as-a-service is not that organisations lack access to relevant information. In many cases, at least some of the constituent indicators may already be visible.
The difficulty resides in their fragmentation.
A physical security team may identify unexplained surveillance near a site without understanding the online hostility surrounding the organisation. A narrative intelligence function may observe increasingly aggressive rhetoric without knowing that an executive’s travel itinerary has been exposed. A VIP Monitoring team may identify the circulation of personal information without visibility of local criminal facilitation or weapons availability.
Each function may therefore possess one part of the threat picture while remaining unable to interpret its full significance.
Consider, for example, an executive working for a European company involved in a politically contentious government programme. Online narratives begin to portray the company as directly responsible for violence overseas. The executive’s name and image are circulated alongside these claims. An upcoming conference appearance is announced publicly, while separate accounts identify the hotel commonly used by delegates.
Elsewhere, an individual offers payment for an attack. A young person in another jurisdiction responds. A local intermediary arranges transport or leaves a weapon near the venue.
Viewed separately, the hostile rhetoric may appear expressive rather than operational. The exposed itinerary may appear to be a privacy concern rather than a security issue. The presence of an unfamiliar young person near the event may appear suspicious but inexplicable.
Viewed together, they describe movement from narrative construction to target identification, from target identification to recruitment, and from recruitment towards physical action.
The role of fusion intelligence is not to impose coherence where none exists. Nor should every hostile narrative, personal-data exposure or unusual physical observation be interpreted as evidence of an organised plot. Such an approach would risk converting possibility into probability and generating more noise than warning.
Rather, the purpose is to create an analytical environment in which information collected through different disciplines can be assessed in relation to one another, while retaining appropriate caution regarding the strength and limitations of the available evidence.
{{standout}}
The figure of the teenage hitman is likely to remain central to public discussion of violence-as-a-service because it represents such a profound inversion of assumptions about age, vulnerability and violent capability.
However, the focus on the perpetrator should not obscure the structures which made their participation possible.
Behind the teenager may sit a recruiter who understands how to exploit financial need or social aspiration; an enabler with access to weapons and transport; a criminal network able to operate across jurisdictions; an online environment which reduces violence to status or performance; and, in some cases, a hostile state seeking to extend its reach while retaining distance from the act itself.
Not every case will contain all of these elements. The relationships between them will vary, and the evidence required to establish state direction, or wider organisational responsibility will frequently remain incomplete. Nevertheless, the cases examined by the BBC demonstrate that serious violence can no longer be understood solely through the motivations or capabilities of the person who ultimately attempts to conduct it.
The attacker may be young, inexperienced and operationally expendable. The threat which placed them at the target is considerably more complex.
For organisations, the question is therefore not merely whether an identifiable adversary possesses the capability to cause harm. It is whether hostile intent can be translated into action through a wider market of recruiters, facilitators and disposable perpetrators, and whether the organisation is able to recognise that translation as it occurs across its physical, narrative and executive threat environments.
Violence-as-a-service exists within the spaces between these disciplines – and it is within those same spaces that it must be understood.