New Research: Terrorist Use of Hybrid Threat Finance Networks
Written for RUSI's Centre for Finance and Security's Project CRAAFT
Hello, Insight Monitor subscribers, and a warm welcome to all the new faces around here who have joined over the last few weeks. Our community continues to grow thanks to all of you who are sharing this newsletter, which is so important to me — the more people who care about illicit finance, the better! Today, I’m sharing new research I just published with RUSI’s Centre for Finance and Security’s Project CRAAFT. This research builds on data I’ve been collecting for years now (and that you’ve all heard about in various forms). Happy reading, and be sure to let me know what you think in the comments!
Terrorist Use of Hybrid Threat Finance Networks
For years, discussions of terrorist financing have often treated traditional financial systems and digital assets as separate worlds; increasingly, these are not separate systems for illicit financing. Today, threat actors combine these systems deliberately to obfuscate the flow of funds, complicate investigations, and try to ensure operational success.
In a new paper published with the Royal United Services Institute’s Centre for Finance and Security (RUSI CFS), Terrorist Use of Hybrid Threat Finance Networks, I argue that terrorist financing has entered a new phase—one in which financial networks increasingly blend conventional financial services with digital assets, decentralized finance (DeFi), online payment platforms, and other financial tools. Rather than choosing between traditional and digital methods, terrorist actors are using both.
Our terrorist financing analysis course caters to researchers, intelligence, law enforcement, and compliance professionals to help them learn about terrorist financing, and analyze suspicious patterns and activities more effectively. Sign up today!
The paper introduces the concept of hybrid threat finance networks to describe this evolution. These networks combine the resilience, accessibility, and anonymity offered by different financial ecosystems, allowing terrorist groups and their supporters to move seamlessly between traditional banking, money service businesses, cash, cryptocurrencies and stable coins, DeFi platforms, and other emerging financial technologies. (I talk about “TradFi and DeFi” as shortform in the paper. I think it’s useful!)
The research examines this shift through three case studies focused on ISIL. These include a Canadian ISIL financing network, an examination of ISIL’s organizational financing, and the financing of the Crocus City Hall terrorist attack, all with an emphasis on digital assets and hybrid networks. While the case studies focus on ISIL(a deliberate choice driven by the project’s scope and NATO sponsorship), the broader findings extend well beyond a single organization. The same trends are increasingly evident across terrorist and violent extremist movements, regardless of ideology. I make some reference to neo-Nazis and accelerationist groups, but it applies equally to Hamas, the Houthis, other Iran-sponsored groups, and more.
One of the paper’s key contributions is new empirical evidence drawn from my original dataset of terrorist financing cases. The data demonstrate how financial behaviour has evolved over time, showing that digital assets are becoming integrated into broader financing networks rather than replacing traditional methods. Many contemporary terrorists and extremists are digital natives (and increasingly crypto natives) who view digital financial services as simply another component of their financial toolkit.
This has important implications for governments, financial institutions, regulators, blockchain analytics firms, and technology companies. Countering terrorist financing cannot focus exclusively on either traditional financial institutions or virtual asset ecosystems. Instead, practitioners need to understand how funds move across both environments and where vulnerabilities emerge as actors exploit the interfaces between them. Increasingly, every threat finance investigation has a digital asset component.
The paper identifies several key policy challenges, including:
Uneven regulation and supervision of digital assets across jurisdictions.
The growing complexity of monitoring transactions between the TradFi and DeFi ecosystems.
The need for stronger public-private partnerships capable of addressing hybrid financial threats rather than isolated financial sectors.
As terrorist financing continues to evolve, our analytical frameworks must keep pace. Hybrid threat finance networks as a concept better captures the operational reality facing investigators and policymakers today than approaches that artificially separate “traditional” and “digital” finance.
I hope the paper provides a useful framework for researchers, practitioners, and policymakers working to understand how terrorist financing is adapting to an increasingly digital financial ecosystem.
If you’re working on terrorist financing, digital assets, sanctions evasion, financial intelligence, or countering violent extremism, I’d be interested in hearing your thoughts and discussing future collaboration!
© 2026 Insight Threat Intelligence Ltd. All Rights Reserved.
This newsletter and its contents are protected by Canadian copyright law. Except as otherwise provided for under Canadian copyright law, this newsletter and its contents may not be copied, published, distributed, downloaded or otherwise stored in a retrieval system, transmitted or converted, in any form or by any means, electronic or otherwise, without the prior written permission of the copyright owner.





