The Rise of Proxy Crime: When States Use Criminal Networks

The The distinction between organized crime and state-sponsored activity is becoming blurred as governments increasingly use criminal networks and other non-state actors alongside traditional intelligence, military, and diplomatic capabilities to pursue strategic objectives overseas. Rising geopolitical turmoil, improved digital connectivity, and increased scrutiny of foreign intelligence operations are creating greater incentives for states to use these entities as proxies.

  • The U.K. National Crime Agency’s 2026 assessment found foreign states are using criminals as proxies for illegal activity, citing activities such as cybercrime, fraud, money laundering, and violent crime. The agency assessed plausible deniability is likely to be a main reason for states harnessing organized crime to pursue strategic objectives, while also highlighting the use of criminal networks to support state finances, evade sanctions, intimidate dissidents, and conduct sabotage. 
  • This trend extends beyond the U.K. as governments and security agencies across Europe and North America have identified criminal groups or individuals recruited to conduct activities aligned with foreign state interests. This creates a complex security environment for businesses, as incidents which initially appear to be conventional criminal activity may have a wider geopolitical dimension.

Russia has leveraged criminal groups for state activity. European security researchers documented the use of recruited individuals and criminal networks to conduct sabotage, arson, and other disruptive activities across Europe:

  • An assessment by GLOBSEC and the International Center for Counter-Terrorism identified 151 incidents between February 2022 and February 2026 involving Russia’s “crime-terror nexus” in Europe. The incidents included sabotage and other forms of kinetic activity, with Poland, France, Germany, Lithuania, and the U.K. among the countries recording significant numbers of cases.
  • In July 2026, the U.K. and EU imposed sanctions on Russian cyber networks, attributed a cyberattack against Poland to Russia, and targeted what the U.K. government described as Russian state and cybercriminal proxies involved in malicious activity across Europe.
  • The International Institute for Strategic Studies (IISS) described an emerging “intelligence-operative gig economy,” in which hostile intelligence services recruit individuals through online platforms to conduct surveillance, arson, and sabotage. The IISS noted Russia and Iran have relied on remotely recruited proxies, ranging from criminal gangs to vulnerable individuals, as traditional intelligence operations have become more difficult and costly.

Western governments have accused Iran of using criminal networks and proxy groups to conduct operations outside the Middle East:

  • The United States, U.K., Canada, Australia, and several European countries issued a joint statement condemning alleged Iranian state-linked activity across Europe, North America, and Australia. The statement highlighted the longstanding relationship between Iranian security services and international and local criminal groups.
  • In March 2026, a U.S. federal jury convicted Asif Merchant of murder-for-hire and terrorism-related offenses. Prosecutors said Iran’s Islamic Revolutionary Guard Corps (IRGC) sent him to the United States to arrange the assassination of U.S. politicians or government officials.
  • In March 2025, two leaders of an Eastern European organized-crime group were convicted of murder-for-hire offenses. The U.S. Department of Justice said the Iranian government hired them to target Iranian-American journalist and activist Masih Alinejad. The two men coordinated with an individual living in Yonkers, New York, to surveil Alinejad and prepare for her murder. He received payment for the plot and obtained an AK-47-style rifle and ammunition before the operation was disrupted by U.S. authorities.

Western governments have also accused China of utilizing an ecosystem of private cybersecurity companies, contractors, and freelance hackers to conduct operations on behalf of Chinese intelligence and security agencies.

  • The FBI has warned of Chinese state-sponsored actors targeting global telecommunications, government, transportation, lodging, and military infrastructure, with compromised networks potentially providing persistent access to additional systems.
  • In March 2025, U.S. authorities charged Chinese nationals with ties to the Chinese government and the hacking group APT27 for targeting U.S. companies, municipalities, and other organizations. According to U.S. prosecutors, Chinese intelligence and security agencies, including the Ministry of State Security and Ministry of Public Security, directed or financed hackers to steal information from technology companies, think tanks, defense contractors, universities and government entities.
  • In 2025, the U.S. Department of Justice charged individuals associated with i-Soon, a Chinese hacker-for-hire company, alleging the company conducted intrusions at the request of Chinese intelligence and law-enforcement bodies and sold stolen information to Chinese government agencies.

These cases depict how state-directed activity can utilize locally based criminal associates, organized-crime networks, and other intermediaries, creating a layer of separation between the sponsoring state and the individuals carrying out an operation. This can complicate attribution while bringing geopolitical risks into commercial and urban environments.

The continued deterioration of relations between Western governments and Russia, Iran, and China is likely to sustain the use of proxy networks, particularly where direct state action would carry greater diplomatic or political costs. Concentric assesses these threats could affect businesses and executives, through the use of:

  • Recruitment or coercion of employees and contractors to act as insiders.
  • Surveillance and targeting of executives and other high-profile personnel.
  • Cyber intrusions and theft of sensitive corporate or personal information.
  • Sabotage, arson, or other physical attacks against corporate facilities and infrastructure.
  • Harassment, intimidation, or violence targeting employees with links to dissident or politically sensitive communities.
  • Criminal networks or other intermediaries being used to conduct operations on behalf of state actors.
  • State-backed cybercrime, including ransomware, espionage, and disruptive attacks.

As state actors increasingly operate through criminal networks, cybercriminals, and remotely recruited individuals, businesses may need to consider geopolitical intelligence alongside traditional physical security, cyber risk and travel-risk assessments. Understanding who may be behind an incident, why a company or individual might be of interest, and how geopolitical tensions could translate into localized criminal activity will become increasingly important for organizations operating across Western markets.

HOW CONCENTRIC CAN HELP

Active Monitoring

Concentric continuously monitors geopolitical developments, state-linked activity, organized crime, cyber threats, concerning online activity, and other developments that could affect executives, employees, facilities, travel, events, or business operations. Our analysts identify emerging threats, assess their potential impact, and provide timely alerts and escalation where appropriate.

Corporate Security & Threat Assessments

Concentric assesses how geopolitical developments and state-linked criminal activity could translate into risks for businesses, such as  espionage, cyber intrusion, surveillance, intimidation, sabotage, and targeting of personnel or facilities. These assessments help organizations identify vulnerabilities and strengthen security measures before threats materialize.

Executive Risk Assessments

Our analysts assess an executive’s exposure to state-linked and non-state threats, considering factors such as public visibility, decision-making authority, government relationships, sensitive information, international travel, personal accessibility, and links to politically sensitive issues or regions.

Executive Protection

Concentric provides residential security assessments, advance planning, secure transportation, travel security, counter-surveillance support, and scalable protective services for executives and other high-risk personnel. Support can be deployed during periods of heightened geopolitical tension or incorporated into ongoing executive security planning.

Protecting Personal Information

Eclipse by Concentric™ removes unwanted personal information which may expose executives, family members, residences, staff, personal accounts, or travel patterns.

Related Posts