
THE TERRORIST WITHOUT AN ORGANIZATION
by Tobin Albanese
Volume 1 Tue Aug 18 2026
The next terrorist threat in Europe may not come from an organized cell in the traditional sense. It may come from someone operating largely on their own, but still connected to a much larger digital environment shaping how they think, what they believe, and eventually how they act.

For awhile now, terrorism has been easier to understand in the more organizational terms of entities. Not easy to stop, obviously, but easier to map out and correlate connections beyond statements. Groups like al-Qaeda and later ISIS had recognizable leadership structures, recruiters, financiers, propaganda networks, and people who were operating under some kind of command. A network of individuals all combined under some ideological or goal oriented purpose. If intelligence services could identify those relationships, follow some pattern of money or life, monitoring communications, or penetrate the organization itself, they would have something concrete to work against. That framework still exists, and still matters today in larger formatted networks across Africa, Middle East, and Europe. But what stands out to me is that the threat environment thats active in Europe is starting to become much harder to place into those same categories that we're all used to seeing today.
The numbers themselves show some of this change. Europol recorded 45 terrorist attacks across the European Union in 205 and 486 terrorism-related arrest, with Jihadist terrorism still accounting for the larger share of both attacks and arrests. An issue still instilling fear in the region for all these past years. So organized and ideological terrorism clearly has not disappeared. At the same time, Europol found that most terrorist attacks and plots involved lone actors or small, self-initiated cells, while also warning that ideological boundaries were becoming increasingly blurred and that digital environments were now playing a much larger role in radicalization, recruitment, and operation activity. The terrorism never left, the methodology only adapted to the new ways of life. A scary turn for a world where we saw terrorist organizations as men in caves, now plotting movements and radicalizing the minds of our youth behind the shadows of networks and services. To me, that creates an important distinction in our modern era. The traditional terrorist organization is still a major role in the problem, but it may no longer be enough to explain the whole threat itself.
The term "lone actor" can also make this seem simpler than it actually is. Someone may physically be carrying out an attack alone without ever truly developing their ideas alone either. Research on lone-actor terrorism has enlarged and repeatedly found that many of these individuals maintain some level of connection to extremist communities, social networks, online chatrooms, or other individuals who shape their motivation and behavior. Schuurman and his coauthors argue that the idea of the completely isolated "lone wolf" can actually become misleading because social ties often remain important even without formal organizational membership or direct command infrastructure. Gill, Horgan, and Deckert found something similar in their study of 119 lone actors, where other people often knew about an offenders grievances, extremist beliefs, or violent intentions before an attack ever occurred. A pattern of failed stoppages that we have seen before. So, when does intelligences responses dictate a call to action against lone actors or events. Where are the focal points of a response to human intelligence gathered prior to a specific event or a specific individual? In other words, acting alone does not necessarily mean being alone but at what point do we consider lone actors as more than a correlation or point of interests.
These questions become especially difficult when looking at newer environments like the Com Network and groups such as 764. These networks do not fit in the usual organizational model associated with al-Qaeda or ISIS. Argentino and Lindsay describe a decentralized online ecosystem where cybercrime, exploitation, self-harm, violent extremism, and offline violence can overlap, while status and belonging may be earned through increasingly extreme acts rather than through ideological commitment or rank inside a formal hierarchy. Europe is already beginning to see the consequences of that type of environment. In Italy authorities dealt with a series of violent incidents and alleged plots involving minors, some of whom moved between school-shooter culture, neo-nazi imagery, nihilistic ideas, personal grievances, and online communities without fitting neatly inside on established or pre-existing ideological framework.
This is where the larger counterterrorism problem starts to change. European counterterrorism has spent decades now learning how to identify organizations, members, recruiters, financiers, and chains of command. Those capabilities remain necessary and important. But what happens when the person preparing an attack has no formal membership, receives no direct order, finances themselves, pulls ideas from several different communities, and interacts primarily through a constantly shifting online environment? There may still be a network around that person, but it doesn't look like the kind of network intelligence agencies are originally built to penetrate. It's this new form of radicalization where a larger group may not be a direct correlation but also may be ploying smaller assets to control an lone asset. A new form of terrorist cell framework, taking to action like an intelligence agency would. So how do you stop a group that acts like the group hunting them? What cards are to be played, what legality routes can one take, and how might one stop the next attack.
This post argues that Europe is not moving beyond terrorist organizations entirely. Instead, the threat is now only becoming more organizationally ambiguous. Individuals and smaller cells can now remain operationally independent while still being socially connected, ideologically influenced, and digitally embedded within much larger environments. The organizations are still there in many of these cases. But increasingly, it may only be a smaller factor of a much broader system of participation, imitation, criminal overlap, and decentralized influence. Understanding that shift matters because counterterrorism cannot depend only on finding the organization behind an attacker when, in some cases, there may no longer be one clear organization to find. To me, amateur hour theory is no longer at play. To me, I see larger networks deploying smaller cells to gather intelligence and assets that can be controlled whether physically or digitally. Lone actors are the puppet, while the unbeknownst hands pulling the strings are the larger terrorist cells. That's the key to all of this.
From Organization to Ecosystem

The shift away from traditional terrorist organizations did not happen all at once, and it definitely did not start with social media. That is important to recognize because it would be easy to look at Telegram, TikTok, Discord, or other online platforms today and assume that decentralized terrorism is strictly a modern digital problem. But it isn't. Terrorist organizations had already been moving towards a more flexible structure for years. Adapting to the new lay of the land. Technology. What technology opened up for these organizations was make that flexibility easier, faster, and much harder to control once it left the hands of the organization itself. A network of terrorist turning into a network of proxy channels of information and communications.
Al Qaeda is a good place to start. Even before ISIS, jihadist movements were already encouraging violence without always needing a direct chain of command structure behind them. Bright, Whelan, and Harris-Hogan said that Ayman al-Zawahiiri encouraged individual attacks as early as 2001, while al-Qaeda in the Arabian Peninsula later promoted solo terrorism through inspire magazine. ISIS took this concept even further. In 2014, Islamic State messaging directly called on supporters in Western countries to carry out attacks with whatever means were available to them. This is where I think the older organizational model started to change in a really important way. The organization was still active and still there, but now the individual no longer had to be fully inside of it.
This is what creates the differentiated relationship between the group and the attacker. Under the more traditional framework, intelligence services could look for formal recruitment, money transfers, travel, training, communications, or any other physical connections that tie back to the larger organization. Those kinds of relationships created risk for terrorist groups because every interaction opened another possible point of detection. The pager issue all over again, or sending "birds" of individual assets to European countries to take information and fly back. The human source taking into affect. Paralleling information back and forth without ever making any contact physically or electronically with lone actors. The more people involved however, the more information that exists. The more information that exists, the more opportunities intelligence services have to understand what is happening. Just like the internet, the highways of information only leaks bits of intelligence that can be gathered and acted upon.
An individual does not necessarily need to meet a recruiter or a handler. They do not have to travel abroad. They may never even receive money or weapons from the organization itself or be aware that they are a pond in that organizations chess game. In some cases, they may never communicate directly with anyone inside of it in the first place. A facade of actors controlling an individual unaware to the ideology that they are actively supporting. Regardless of self-interest or devotion to ones own cause, their actions will ultimately be recognized by someone else after the fact. They can consume the ideology nonetheless, accept the larger message, and make final operational decisions themselves. I'm not counting lone actors as the blind mule either. They still play the role regardless of who might tell them to do it in the first place. That evil still stems inside them regardless of the larger actors around them or not. I just see it as an organization still influencing the act, but the direct chain between leadership and attacker becomes the weaker focus point.
To me, that distinction between command and influence is one of the most important parts of understanding the modern threat. Someone does not have to be commanded in order to be influenced and act upon a terrorist activity.
This is also where the idea of the completely isolated lone actor starts to fall apart. Schuurman and his coauthors also argued that social ties to online and offline radical environments are often important in both developing the motivation for terrorism and maintaining the capability to actually carry the act out. Their research pushes back against the image of the "lone wolf" as some completely invisible individual who suddenly appears without warning. A separate analysis of 55 lone actors came to a similar conclusion, finding that many of these individuals leaked information about their intentions, maintained social connections, and showed observable behavior well before their attacks. So even when the final attack is carried out by one person, the roads leading back to the attack can still involve a much larger social environment. The internet itself changed the size of that environment.
Before these digital spaces became so embedded in everyday life, extremist social networks were more limited by geography. People often needed some kind of physical connection, whether through friends, family, religious circles, political groups, or other local networks. Research on terrorist networks has consistently shown how important these relationships were. Bright and his coauthors point out that many people historically became involved in terrorist groups through friendship and kinship rather than through some perfect top-down recruitment process. However, the social side was always there. Now geography is much more of a less restrictive issue. Someone sitting in Italy can communicate with someone in Britain, Germany, the United States, or somewhere completely different without ever physically meeting them. They can move freely through multiple online communities at once, leave one, join another, consume material from several different ideological environments, and build relationships with people whose real identities they may not even know. Some of these connections are temporary. Some are weak. Others can become deeply influential though. But together they create a much larger environment around the individual than the term "lone actor" really suggests.
Europol's 2026 report gives a pretty clear picture of this shift. The report found that most terrorist attacks and plots in European Union during 2025 involved lone actors or small self-initiated cells. At the same time, Europol described the online environments as an important space for radicalization, recruitment, communication, and operational activity across different ideologies. What stood out to me even more was how propaganda itself is changing. Europol notes that users are increasingly editing and reproducing extremist material themselves rather than simply consuming official propaganda made by terrorist organizations. That changes who actually controls the message. A terrorist organization can produce the original propaganda but once that material enters the broader digital environment, it can be copied, edited, mixed with other ideas, and redistributed by people who hold no actual formal connection to the organization at all. The audience is no longer just another audience. They can become part of the production and distribution system themselves.
This is the larger transition thats actively taking place in our modern technological world. Terrorist organizations have not disappeared, and in many cases they still remain the central threat. But the environments around them are becoming much more independent. Ideas move without leadership. Propaganda moves without permission. Individuals can participate without membership. Social relationships can form without geography, and violence can be inspired without a direct order ever being given. The organization still matters. It just may not sit at the center of everything anymore.

When Ideology Stops Being Clean
If the organizational structure itself is becoming harder and harder to identify, then ideology is starting to create the same kind of problem. For years, terrorism was usually placed into much cleaner categories. Jihadist terrorism, right-wing terrorism, left-wing terrorism, separatist movements, and so on. Those categories still matter, and Europol makes it much more clear that the older ideological movements have not just disappeared. But what seems to be changing is how cleanly some newer actors fit into them. We are starting to see individuals move between different beliefs, personal grievances, nihilism, misogyny, violent subcultures, and online communities without ever fully committing themselves to one consistent ideological framework.
If someone follows a clear ideology, intelligence services at least have something to compare their behavior against. You can look at what propaganda they are consuming, what groups they may be following, what symbols they use, what they are saying publicly, and what kind of political or religious goals they keep coming back to. There is still some form of pattern there though. But what happens when someone starts pulling pieces from several different spaces at the same time? Someone can use neo-Nazi imagery, consume jihadist material, admire previous school shooters, interact with nihilistic communities, and still not really belong to any of those categories specifically. That does not mean ideology no longer matters however. I think it means that ideology can become much more fragmented and much more personal when looking at terrorist actors who act upon themselves to carry out attacks.
Peter Neumann describes this as part of a broader "gray zone" in European terrorism, where ideological hybridization can mix together with personal grievance, online influence, younger participants, and much faster paths toward violence. However, what stands out to me here is that the violence does not always begin with someone reading a complete ideology, accepting it, and then deciding to act on it. In some cases, it seems almost reversed. The person may already be angry, isolated, fascinated with violence, or looking for some kind of status or belonging, and then they begin pulling ideological pieces from whatever communities seem to validate what they already feel. Taking into account, the nihilism factor as well, of individuals already craze for the thirst of terrorism or harming individuals by justifying it with another cause.

The Counterterrorism Problem
What terrorism looks like and starts becoming what counterterrorism is supposed to do with cases like "lone wolf"s or smaller cell groups. If the organization is unclear, the ideology is mixed, and the individual may not even belong to anything in the traditional sense, then intelligence services are left dealing with a lot less bread crumbs and a much less predictable target. The information might still be there. In some cases, there may actually be more information than ever before. The problem is figuring out what actually matters.
That distinction is important. They often leaked intentions, maintained social relationships, and showed observable behaviors well before an attack. Gill, Horgan, and Deckert found something similar in their study of 119 lone actors, where people around the offender often knew about grievances, extremist beliefs, or even some level of violent intent. So the issue is not always going to be that intelligence is absent. Sometimes the harder issue at play is deciding when scattered information becomes enough to justify a response. Like I mentioned before, when does a significant amount of evidence on a character call for action against them. What is truly significant in modern legal terms. That is where I believe the real intelligence dilemma begins.
Someone posting extremist material online is not automatically a terrorist. Someone expressing anger is not automatically planning an attack. Even someone spending time inside an violent online community may never actually move towards violence. A behavioral aspect to ones curiosity might just be another loose factor in a larger game at play. Intelligence services cannot treat every offensive post, disturbing search, or radical opinion as if it is an operational threat. That would create some obvious legal and civil liberty problems, while also overwhelming analysts with far more information than they could realistically act upon. At the same time, ignoring these smaller indicators entirely creates the opposite problem. A person can sit inside that gray area until the warning signs finally become an official attack. So where is the line?
Europol itself points directly at this issue. Its 2026 report says that blurred ideological boundaries and fluid worldviews are creating legal, analytical, and operational challenges for authorities trying to understand and respond to terrorism in Europe. The older framework gave agencies more identifiable indicators. Membership mattered. Financing mattered. Direct contact mattered. Training mattered. Travel mattered. Those things all still matter, especially now, but they are no longer always going to be present or used in every cases. The Com Network makes this even harder because the same individual can move between behavior that looks like cybercrime, child exploitation, violent extremism, self-harm coercion, or terrorism. The environments alone cannot come from counterterrorism by itself. They call for a broader system involving counterterrorism, child protection, online harm reduction, and cross-jurisdictional cooperation because the threat itself crosses those boundaries. In other words, one agency may see a cybercrime case, another may see an exploited minor, another may see an extremist propaganda, and another may see a terrorism concern. The problem is that they may all be looking at the same exact network but from different angles and never even see it. That is dangerous when information stays separated.
A long history of failed intelligence comes directly from information not being shared. Not that I want every intelligence agency to collaborate or work together, I mean in a perfect world where everyone fought against extremism and terrorism sounds ideal. However, a world of shared information only awaits more secrets that ultimately fall back on everyone. But this is where intelligence sharing and human judgment can become just as important as the collection of information itself. You can collect thousands of posts, messages, reports, and suspicious behaviors, but that does not automatically give you who is actually going to act or is the true perpetrator. Collection creates the volume. Analysis creates the meaning. And sometimes that meaning may come from something much smaller than a direct order from a terrorist organization. It could be a change in behavior, a sudden interest in attack planning, contact with a violent community, repeated leakage, or a combination of indicators that only becomes important once they are viewed together.
The counterterrorism problem, then, is no longer just about finding the top dog or the organization behind the attacker. It has become about understanding when a person moves from participation to intent, and from intent to capability. That is a much harder thing to measure. It also means intelligence services may have to become far more comfortable looking for patterns without always having a clean organizational label attached to them. The risk is obvious. Move too early, and governmental risk treating speech or association as if they are crimes. Move too late, and the same warning signs become evidence that everyone wishes they had taken more seriously. That trade-off is not going away. If anything, it is becoming the central problem of this new environment. The threat is not completely hidden, but it is spread across different platforms, agencies, ideologies, behaviors, and communities. So the real question I am looking for may no longer be whether intelligence services can find the information. It is whether they can recognize the moment when all of those scattered pieces finally becomes a threat. How will they prevent it, how do you fight against it, and when will it ever stop.

Conclusion

At the end of the day, terrorist organizations are not disappearing or going away anytime soon. Al-Qaeda still exists. ISIS still exists. Organized extremist networks will continue operating, recruiting, financing operations, spreading propaganda, and attempting to carry out violence. It has become the world in which we sadly have reside in. Not so much sunshine and rainbows anymore. Nor was it ever. I don't think Europe is suddenly entering some completely new age where those threats no longer matter. If anything, ignoring those organizations would create an entirely different security problem. But what has changed is the environment around them and the amount of control an organization actually needs to influence someone towards violence. That is really what stands out to me throughout all of this.
The organization does not always need the individual anymore. At least not in the traditional sense. Someone does not necessarily have to become a member of anything, receive funding, meet a recruiter, travel to another country, or take direct orders from some larger command structure. They can sit behind a screen thousands of miles away, consume pieces of an ideology, communicate with people they may never physically meet, move between different violent communities, and eventually make their own decision to act. The organization might influence them. A digital community might reinforce them. Another individual might encourage them. Or the violence itself might become the motivation. That is where the clean lines we have traditionally placed around terrorism begin to fall apart.
The same goes for ideology as well. A jihadist is not always going to look exactly like the jihadist framework intelligence services that have been studied for decades now. A right-wing extremist may not belong to any recognizable right-wing organization. Someone involved in nihilistic violent extremism may pull from several ideological spaces without actually caring about any of them enough to build a political movement around it either. Sometimes the ideology is the motive. Sometimes it is the justification. Sometimes it is simply the identity someone attaches onto an already violent mindset. That does not make ideology by itself useless, but it does make the threat much harder to predict when the person themselves don't normally fit cleanly into one box.
There is no perfect formula telling an intelligence analyst when an offensive post becomes intent, when curiosity becomes preparation, or when communication inside a violent community becomes evidence of an incoming attack. Move too early and you risk treating thoughts, associations, and speech like crimes. Move too late and those same warning signs become the pieces everyone looks back on asking why nobody acted sooner.. That is the trade-off. I don't think there is some simple policy or technology that suddenly fixes it either. The future of European counterterrorism is going to depend less on simply collecting more information and more on understanding what the information actually means when it is placed together. The warning signs might already exist. They may just be sitting across different platforms, agencies, reports, communities, and ideological categories that nobody has yet connected. Collection creates volume, but volume alone does not stop an attack. Someone still has to understand the pattern.
To me, if given the opportunity to take charge against these patterns, I would deploy controlled identities across these online spaces, using facade believers to observe existing networks and identify the real handlers, recruiters, and individuals already moving toward violence. I would pair that with human intelligence on the ground, especially when digital activity starts pointing toward actual cells, meetings, or support networks operating inside European countries. The goal would not be to manufacture threats, but to separate the people simply talking online from the ones who are actually building the capabilities and intentions. At the same time, I would focus heavily on connecting information across agencies. One strange posts means very little by itself, but repeated contact with known extremists, movements across violent channels, changes in behaviors, and signs of attack preparation together create a much clearer picture. That is where modern counterterrorism has to move: less dependence on obvious organizational membership, and more attention towards the patterns that show when someone is actually becoming dangerous. It's an online world now, and terrorists are adapting to the changes around them. After decades, it is only time til they find a loophole that we miss, and when we miss in cases like these, it results in the death of many lives. Something that we can't have, and actions that must be prevented.
Focusing on three major factors, controlled digital access, stronger human-source collection, and faster integration of information across agencies in the European Union. But all three would have to operate under clear legal thresholds and oversight. A new branch in the field of intelligence operations with a clear distinction between someone expressing a disturbing belief and someone preparing to harm people. Otherwise counterterrorism becomes so broad that it starts undermining the rights it is supposed to protect. That is ultimately the operational side of the argument I keep coming back to. If terrorist networks are becoming less visible, then intelligence services may have to become more patient and adaptive in how they find them. They cannot wait for every actor to openly identify themselves as a member of ISIS, al-Qaeda, 764, or some future organization before paying attention. But they also cannot treat every angry person online as the next attacker. The job now becomes finding the pattern between everything.
Bringing me back to my original problem. For decades, counterterrorism became extremely good at hunting organizations. Find the leadership. Follow the money. Track the communications. Identify the network. Break the structure apart. That framework still matters. But the next threat may not give intelligence services something that clean or easy to hunt and prevent. It may be one individual, surrounded by hundreds of weak connections, fragments of different ideologies, personal grievances, violent content, and a digital community that never formally told them to do anything at all. They may be acting alone in the final moments, but everything leading up to that moment may tell a completely different story.
That is the part counterterroism cannot afford to miss. If intelligence services keep waiting for the enemy to identify itself first, then by the time the pattern becomes obvious, the attack may have already happened. The organization may be harder to see now, but the threat is still there. We just have to get better at recognizing what it looks like before it decides to show us. The next terrorist organization may never organize at all. That does not make it any the less dangerous.
There's a thin line between heaven and here, only we have the opportunity to fight and defend the heaven in which we share.

Resources & Archival References
Current European Threat Environment
- European Union Terrorism Situation and Trend Report 2026 (EU TE-SAT)
- The New Grey Zone: How Terrorism in Europe Has Changed
- Remotely Coerced Violence: 764, The Com Network, and the Hybridization of Threats
- A Domestic Mimetic Chain: Nihilistic Violent Extremism, Youth Radicalization, and School Violence in Italy
Lone-Actor & Network Research
- End of the Lone Wolf: The Typology that Should Not Have Been
- Bombing Alone: Tracing the Motivations and Antecedent Behaviors of Lone-Actor Terrorists
- Lone Actor Terrorist Attack Planning and Preparation: A Data-Driven Analysis
- Exploring the Hidden Social Networks of ‘Lone Actor’ Terrorists
- Scattered Attacks: The Collective Dynamics of Lone-Actor Terrorism
Digital Radicalization, Ideology & Counterterrorism
- Determining the Role of the Internet in Violent Extremism and Terrorism: Six Suggestions for Progressing Research
- Exposure to Extremist Online Content Could Lead to Violent Radicalization: A Systematic Review of Empirical Evidence
- The Contagion and Copycat Effect in Transnational Far-Right Terrorism: An Analysis of Language Evidence
- Countering Salafi Networks in Southeastern Europe: Leveraging Travel Intelligence for Effective Counterterrorism Strategies