This September, the Centre for Finance and Security (CFS) at RUSI will publish the second special issue of the RUSI Journal, focusing on “Illicit Finance in a Fragmenting World.” Guest-edited by Kinga Redlowska, the issue will examine whether the global financial integrity system is equipped to respond to an era of growing geopolitical rivalry and disruption.
One of the articles, co-authored by Olivia Allison and Oksana Ihnatenko, explores “Combatting the Illicit Financing of Hybrid Threats: Lessons from Russia’s Destabilisation of Europe.”
Ahead of the publication, we spoke with Olivia about the financing behind hybrid threats, the challenges of identifying and disrupting these financial networks, and the lessons Europe can draw from Russia’s destabilisation activities.
I think one of the reasons is that this type of threat is less spectacular than terrorism, so the way it is prioritised is fundamentally different. Terrorism is often intended to create a spectacle—usually through a large, violent event. You have a particular moment in time when the threat becomes very visible, and it can therefore be easier to organise a response because everyone can clearly see what has happened.
Hybrid threats, on the other hand, are fundamentally designed to operate under the radar and destabilise society. If a hybrid operation is successful, it should be somewhat invisible. It plays on divisions that already exist within society, exacerbating existing problems and creating new ones that can appear organic rather than externally driven.
I think the second reason is that these activities are often carried out by states that deliberately try to conceal their involvement. This makes it very difficult to identify who is actually behind a hybrid threat. In many cases, it can look more like an intelligence operation, where attribution is difficult and it is harder to say definitively, “This is the threat, and this is what we need to do about it.”
It can also be difficult to prove responsibility to a criminal standard. As a result, building the case for a coordinated global political and geopolitical response becomes much more challenging.
It’s interesting because, in this respect, I think hybrid threats are somewhat similar to terrorism in terms of how the financing works. On the one hand, you have state-sponsored activity, which requires certain budgets and financial resources.
At the same time, we can see that even sabotage or some of the more kinetic hybrid threats taking place in Western European countries or the UK do not necessarily require very much money. The individuals carrying out these attacks are often not paid significant amounts.
Some of these activities can also generate their own funding. For example, on social media, if you post divisive content and gain more followers and engagement, you can generate advertising revenue.
There are also links to organised crime and economic crime. I think these connections represent a vulnerability for hybrid operations, but they also create important similarities with terrorism. In many ways, terrorism-financing typologies and hybrid-threat financing typologies can be quite similar, particularly when it comes to money laundering, links with organised crime, and the financial mechanisms used to support these activities.
I think, again, it is useful to break hybrid operations down into different components and consider which types of criminal legislation can be applied to each activity.
We talked about the intersection with organised crime. When we look at activities such as cyberattacks, many of them are already crimes in themselves. The revenue-generating part of a cyberattack, for example, may involve fraud or scams, which can already be prosecuted under existing criminal law.
If you have an effective approach to prosecution and can prioritise cases that are linked to state actors, you are inherently taking action against hybrid threats without necessarily having to change your entire security doctrine or create a completely new framework for hybrid threats.
So, simply having a stronger and more effective approach to cybercrime is something that can make a country more resilient to hybrid threats.
I think the first and most obvious lesson—and it is something we hear all the time, but it is important to repeat—is that Ukraine’s experience shows that hybrid attacks can be the beginning of a much broader campaign, which can ultimately include physical or kinetic attacks against a country and its sovereignty.
Hybrid attacks can be a relatively “light-touch” way of undermining sovereignty. But if a hostile actor wants to undermine your sovereignty through hybrid means, they may also be considering other forms of aggression against your territory. It is important to recognise that reality, place individual hybrid attacks within the broader strategic context, and prioritise the threat accordingly.
I think European countries sometimes underplay or downplay the significance of these attacks because we do not necessarily want to confront that bigger strategic picture. As a result, many hybrid attacks have received relatively limited public and media attention.
This also creates a difficult challenge for policymakers. Hybrid attacks are usually part of very long-term campaigns, so it can be difficult to know when and how to communicate the threat to the public. Responding effectively requires a degree of vigilance across society, but it is very difficult to keep the public vigilant for many years. People naturally become tired of hearing about the same threat over a long period of time.
That is also one of the reasons hybrid attacks can be so effective. Each individual action may appear relatively small in isolation, but when you put them together, they can form part of a much larger coordinated campaign.
For example, bribing politicians while simultaneously building up investments in critical infrastructure and exploiting divisions within society may look like separate activities. But together, they can form part of a broader effort to undermine a country. It is very difficult to combat all of these activities simultaneously without explaining the bigger picture to the public and building public understanding and support for the response.
I think, in some ways, it is partly about bringing together issues that FATF has already been considering. There is already guidance on areas such as the money-laundering risks associated with crowdfunding, terrorist financing, and a range of other financial-crime threats. The question is how these existing approaches can be brought together and applied to the financing of hybrid threats.
The whole point of a FATF evaluation is to ask questions about what data a country collects, what controls it has in place, and how it makes decisions. We could start asking similar questions about hostile-state threats: How does a country identify potential state threats? How many related cases are investigated or prosecuted? How are those cases classified?
Simply encouraging states to think about how they collect and classify this data could be valuable. It might also help focus investigations more systematically on these types of threats. Including questions in evaluations that encourage the collection of relevant data would therefore be an important first step.
Of course, this is a sensitive area because investigations into hostile-state activity are often conducted by intelligence services, which can make it difficult to obtain or publish data. But even looking at indicators such as prosecutions or account closures, if they are classified appropriately, could help us begin to understand the scale of the problem.
I think there are two fundamental challenges. First, some states are simply not thinking about these threats in this way. Second, we still do not have a reliable understanding of the scale of the problem. There is not yet enough consistent data or a sufficiently developed narrative to show what is actually happening.
I think developing more detailed typologies and risk indicators would be particularly important for the private sector, especially banks.
There are sources of publicly available or identifiable information that could potentially be incorporated into customer due diligence and KYC processes to identify links between individuals and hostile-state activity. For example, if an individual has previously been registered at the address of a Russian military barracks, this could indicate that they have undergone military training or have current or previous links to the Russian military. This is something that has appeared repeatedly in investigations into different types of state threats, and information of this kind can sometimes be identified through open-source investigations.
This is therefore one area where governments could provide more guidance to the private sector on what information to consider and how to incorporate relevant indicators into due diligence and ongoing monitoring.
More broadly, it is important to give the private sector clear red flags: what should financial institutions be looking for, and what should they do when they identify it? There also needs to be clarity about the legal grounds for taking action. The legal framework must be sufficiently robust to allow financial institutions to respond appropriately—for example, by closing accounts or filing suspicious activity reports when relevant indicators of hostile-state activity are identified.
One important step is to strengthen the narrative around hybrid threats, because this is still something we do not hear enough about. Ukraine is fighting a full-scale war, but when Ukrainian authorities identify connections between Russian activities in Ukraine and networks operating in Eastern Europe, the UK, the US or other allied countries, communicating those connections is extremely important.
It helps demonstrate that these activities are not simply something happening to Ukraine. They may also represent a direct threat to other societies, and making those links visible can help governments and the public understand the broader nature of the threat.
Another priority is to trace the money and networks that support these activities. What we often see is that activities that initially appear to be ordinary financial or organised crime can have connections to much broader hostile-state operations. Operation Destabilise in the UK is a good example: the networks involved had links to money laundering as well as weapons procurement connected to Russia. UK authorities have appropriately treated these connections as relevant to the wider threat posed by Russian hostile-state activity.
Making these connections visible and building a clearer narrative around them is therefore extremely important. It allows individual cases of money laundering, organised crime or other criminal activity to be understood as potential components of a much broader hybrid campaign.
I would recommend Shaun Walker’s The Illegals: Russia’s Most Audacious Spies and the Plot to Infiltrate the West. It explores Russia’s secret programme of deep-cover spies, known as “illegals,” and provides useful insight into the history and evolution of Russian intelligence operations.
There are also a number of very good books on Russian money laundering—how these financial networks operate, how complex they can become, and how they intersect with broader Russian influence and hostile-state activity. I think that literature is particularly useful for understanding the financial dimension of the threat.