Scope: This assessment examines the public official record concerning state-directed or state-associated targeted killing, assassination, murder-for-hire and lethal counterterrorism operations, with particular attention to the United States, Russia, China, the United Kingdom, France, Germany, Italy and the European Union, while using Iran and India as necessary comparators because recent official judicial records materially illuminate the phenomenon.
Executive Summary / BLUF
The available official record does not support a defensible narrative in which Russia uniquely employs extraterritorial lethal operations while other major powers merely respond to an exceptional Russian practice, but neither does it support the reverse proposition that the United States, China, Britain, France, Germany and Russia participate in an interchangeable system of politically motivated assassination; instead, the documentary record shows several legally and operationally distinct categories that are frequently collapsed into the same media vocabulary.
The United States possesses the most extensively documented public policy architecture among the states examined for deliberate lethal counterterrorism operations against individually identified or otherwise targetable persons abroad, including operations outside conventional battlefields, although no reliable official global database permits the conclusion that it is numerically the world’s largest practitioner across every category of targeted killing. In 2016 alone, the Office of the Director of National Intelligence reported 53 U.S. counterterrorism strikes outside areas then designated as active hostilities, assessing 431–441 combatant deaths and one non-combatant death, while explicitly acknowledging the inherent limitations of casualty assessment. Summary of 2016 Information Regarding United States Counterterrorism Strikes Outside Areas of Active Hostilities — ODNI
Washington has also publicly acknowledged particular individual killings, most conspicuously the 2 January 2020 killing of IRGC-Quds Force commander Qasem Soleimani in Iraq, which the Department of Defense described as a defensive action ordered by the President; the legality of that operation was subsequently disputed in the United Nations human-rights system, illustrating why the fact that a state publicly invokes self-defence does not itself settle the international-law question. Statement by the Department of Defense — 2 January 2020
Russia presents a materially different evidentiary pattern because European judgments, inquiries and current U.S. criminal proceedings concern alleged or established covert killings, poisoning operations and murder-for-hire activity inside states with which Russia was not in an acknowledged armed conflict, including the legally established 2019 Berlin Tiergarten killing, the British Litvinenko inquiry’s finding of probable FSB direction, the British government’s attribution of the Salisbury operation to GRU officers, and the newly unsealed September 2026 U.S. indictment alleging an intelligence-linked network engaged in murder-for-hire and preparations for targeted killings.
China is unquestionably documented in U.S. and European institutional records as conducting transnational repression, surveillance, coercion, intimidation and attempted forced repatriation abroad, but the official material examined for this assessment does not justify placing Beijing immediately behind Washington in a quantitative ranking of extraterritorial targeted killings; doing so would transform evidence of repression into evidence of homicide without the necessary documentary bridge.
The United Kingdom and France have acknowledged lethal operations against terrorist targets abroad and therefore cannot analytically be treated as states that categorically reject targeted lethal force, whereas Germany’s official record examined here is principally that of a host state confronting foreign targeted killing, and no comparable public evidence was identified establishing a German governmental assassination programme abroad; the same caution applies to Italy, for which no equivalent official record establishing a national programme of extraterritorial targeted killings was found during this review.
The principal analytical conclusion is therefore not that “everyone assassinates,” nor that Russian extraterritorial violence is sui generis, but that major powers operate across a spectrum running from acknowledged battlefield targeting and asserted self-defence, through secret counterterrorism operations, to clandestine state-directed murder, coercive rendition and transnational repression, and that these activities engage different bodies of law, different evidentiary standards and different degrees of state accountability.
Targeted Killing and the Politics of Selective Outrage
The argument over targeted killing is being distorted less by the absence of evidence than by the refusal to distinguish different kinds of evidence. On 15 September 2026, the U.S. Department of Justice charged five alleged members of a Russian intelligence network with financing terrorism, murder-for-hire activity and preparations for targeted killings in the United States and Europe. Those accusations matter, but they remain allegations. The wider record is more uncomfortable: the United States, United Kingdom and France have themselves acknowledged deliberate lethal operations against identified individuals abroad, while European courts have attributed clandestine killings to Russian state actors and U.S. courts have convicted or prosecuted individuals linked to Iranian, Chinese and Indian state activity. The relevant divide is therefore not between states that kill and states that do not, but between legal authority, operational method, evidentiary status and political accountability.
An indictment is not a judgment, and an intelligence assessment is not a conviction
The 15 September 2026 Russian case illustrates the first discipline required of governments and serious media alike. The Department of Justice alleges that five defendants associated with Russian intelligence services financed surveillance, murder-for-hire and attacks against infrastructure in countries supporting Ukraine, yet all remain defendants rather than convicted perpetrators. By contrast, the 2019 Tiergarten murder in Berlin crossed a different evidentiary threshold when the Kammergericht concluded in December 2021, after a 14-month trial, that Vadim K. had killed Tornike K. on behalf of Russian state authorities; the judgment became final on 27 December 2021.
The Alexander Litvinenko case moved still further into judicial attribution when the European Court of Human Rights ruled in Carter v. Russia, delivered on 21 September 2021 and final on 28 February 2022, that Russia was responsible under Article 2 of the European Convention on Human Rights. British investigators had examined more than 60 locations and sent more than 40 mutual-legal-assistance requests to 15 states. Salisbury, by contrast, remains in a different evidentiary category: in September 2018 the British government identified the suspects as GRU officers and assessed that the operation was almost certainly approved at a senior level of the Russian state, but no British criminal trial of those officers followed.
These distinctions are not legalistic decoration. They determine whether a reader is looking at a prosecutorial allegation, an intelligence conclusion, an executive attribution or an adjudicated fact. Collapsing them into a single headline category converts uncertainty into certainty and obscures the cases where attribution has actually survived judicial scrutiny.
Washington’s record is visible because Washington chose to institutionalise lethal reach
The United States is unusual among the states examined because its use of targeted lethal force has been repeatedly acknowledged by the government itself. In calendar year 2016, the Office of the Director of National Intelligence reported 53 counterterrorism strikes outside areas then designated as active hostilities, assessing 431–441 combatant deaths and one non-combatant death. Those figures were not a complete register of every operation, but they documented a standing capability rather than an exceptional improvisation.
That architecture remained visible in individual operations. On 31 July 2022, two Hellfire missiles killed al-Qaida leader Ayman al-Zawahiri in Kabul at 06:18 local time, according to the Department of Defense, nearly one year after the withdrawal of conventional U.S. forces from Afghanistan. In October 2019, U.S. special operations forces raided the compound of Islamic State leader Abu Bakr al-Baghdadi in Syria; U.S. Central Command reported that 11 children were removed from danger, two men were detained and five Islamic State members presenting a threat were killed before Baghdadi detonated a suicide device.
The same system also produced documented failure. On 29 August 2021, a U.S. drone strike in Kabul killed 10 civilians, including up to seven children, after intelligence had incorrectly identified the vehicle and its occupants as an imminent ISIS-K threat. U.S. Central Command later acknowledged error, confirmation bias and intelligence failure. In calendar year 2024, the Department of Defense assessed that U.S. military operations had killed two civilians and injured two others under its reporting methodology. The lesson is not that transparency resolves the legality of every strike, but that the U.S. record is unusually measurable because policy, operations and failures have all generated official documentation.
Britain and France sit inside the same operational universe, but with thinner public ledgers
On 21 August 2015, an RAF remotely piloted aircraft killed British national Reyaad Khan near Raqqa. Prime Minister David Cameron subsequently told Parliament that the National Security Council had considered Khan a direct threat, that the Attorney General had advised on the legal basis and that the Defence Secretary had authorised what Cameron explicitly called a “targeted strike”. The Intelligence and Security Committee later stated that there was “no doubt” Khan posed a very serious threat to the United Kingdom, while declining to substitute itself for a court on the legal question.
Britain’s current operational role remains visible. Operation SHADER recorded four publicly listed RAF strike dates in Iraq and Syria during 2025, while on 3 January 2026 British Typhoons and a Voyager tanker joined French aircraft in striking a Daesh underground facility north of Palmyra with Paveway IV precision-guided bombs. The United Kingdom therefore cannot be described as a state standing outside targeted lethal operations; the defensible distinction lies in the legal basis claimed, the theatre, the target and the degree of disclosure.
France presents a comparable but institutionally different pattern. Operation CHAMMAL currently deploys about 600 French military personnel in the Levant, while French Rafales flew between 18 and 21 sorties per week in several reporting periods during May and June 2026. Earlier Barkhane operations targeted senior jihadist leadership directly: Abdelmalek Droukdel, emir of al-Qaida in the Islamic Maghreb, was killed on 3 June 2020, while Adnan Abu Walid al-Sahraoui, leader of Islamic State in the Greater Sahara, was killed in an August 2021 operation involving armed drones and Mirage 2000D aircraft.
The comparative problem is therefore not whether Britain and France possess the capacity to identify and kill individuals abroad; official records show that they do. The problem is that neither publishes a comprehensive historical ledger comparable to the partial American record, making any numerical hierarchy between Washington, London and Paris methodologically unsound.
China’s documented coercion is extensive, but the lethal comparison is weaker than the rhetoric
China belongs in the record, but not where a simplistic ranking would place it. U.S. federal proceedings have established a substantial body of evidence concerning Chinese transnational repression, including surveillance, stalking, intelligence collection and coercive repatriation. In April 2025, former New York police officer Michael McMahon was sentenced to 18 months in prison and an $11,000 fine for conduct linked to Operation Fox Hunt; another defendant, Quanzhong An, received 20 months and approximately $5 million in financial penalties, including about $1.3 million in restitution, after pleading guilty to acting as an illegal PRC agent in a coercive repatriation campaign.
The intelligence dimension is equally concrete. Shujun Wang was convicted on all four counts in August 2024 after prosecutors established that he cultivated Chinese democracy activists while secretly reporting to Ministry of State Security officials. Tang Yuanjun separately pleaded guilty after acknowledging that between 2018 and June 2023 he passed names, photographs, recordings and other information concerning U.S.-based democracy activists to the MSS.
What those cases establish is systematic extraterritorial repression; what they do not establish is a public evidentiary basis for describing China as the world’s second-largest practitioner of overseas targeted killing. The distinction matters because surveillance, coercive return, attempted intimidation and assassination belong to the same continuum of state repression but are not interchangeable operational events.
Europe is no longer merely observing these methods; it has become operational terrain
Europe’s exposure is measurable because the continent is simultaneously projecting military power and protecting the infrastructure, communities and institutions that foreign states increasingly target. As of July 2026, the European Union reported 22 ongoing Common Security and Defence Policy missions and operations, involving more than 3,500 military personnel and 1,300 civilian personnel. By early 2026, more than 87,000 Ukrainian personnel had been trained under the EU Military Assistance Mission, while Operation ASPIDES had protected more than 2,390 merchant vessels and provided close protection to more than 720 ships in the Red Sea.
Italy illustrates the overlap between external commitments and internal exposure. Operation Prima Parthica maintains about 300 personnel in the land component and 400 in the air component, with Italian forces having trained approximately 50,000 Iraqi and Kurdish personnel. In June 2025, however, the Interior Ministry reported that more than 29,000 sensitive sites were under protection inside Italy, including more than 10,000 critical infrastructures and roughly 1,000 sites connected to American or Israeli interests. External policy is therefore transmitting directly into domestic security expenditure and policing requirements.
Germany’s position is even more structurally sensitive because the Bundeswehr’s August 2026 mandate ceilings included 500 personnel for Counter-Daesh and Capacity Building Iraq, 550 for NATO Sea Guardian, 350 for ASPIDES, 300 for IRINI, 300 for UNIFIL and 400 for KFOR, while the 2025 Federal Office for the Protection of the Constitution report identified Russia, China and Iran as the principal foreign intelligence threats and highlighted espionage, sabotage, transnational repression and cyber operations.
France has moved the same problem into counter-intelligence doctrine. On 6 January 2025, the Direction générale de la sécurité intérieure formally defined transnational repression as foreign-government activity intended to identify, locate, monitor, intimidate, forcibly repatriate or attack political opponents abroad. The definition matters because it places the surveillance of dissidents and potential lethal action inside the same national-security continuum rather than treating them as unrelated crimes.
Britain shows what happens when foreign-state coercion becomes a domestic security metric
The United Kingdom currently provides the clearest publicly quantified example of the internalisation of state threat. In March 2025, the Security Minister told Parliament that the number of MI5 state-threat investigations had increased by 48 per cent in one year and that Britain had responded since 2022 to 20 Iran-backed plots presenting potentially lethal threats to British citizens or residents. MI5 subsequently stated in its 2025 threat update that it had tracked more than 20 potentially lethal Iran-backed plots in the latest one-year reporting period.
The legal response followed the operational assessment. The National Security Act 2023 created modern offences concerning espionage, sabotage and foreign interference, while the Foreign Influence Registration Scheme, in force from 1 July 2025, imposed registration requirements on activity directed by foreign powers and created an enhanced tier initially focused on Russia and Iran. By May 2026, the Home Office was publicly defining transnational repression to include surveillance, stalking, coerced return, assassination and attempted assassination.
This development is more consequential than any single foiled plot because it signals the fusion of counterterrorism, counter-espionage and organised-crime methods. MI5 and Germany’s BfV have both warned that Russia and Iran increasingly use criminal or low-level proxies for surveillance, arson, sabotage and potentially violent tasks, allowing sponsoring states to lower cost, obscure attribution and exploit the lag between intelligence suspicion and judicial proof.
The next 12–24 months will be decided by attribution, not rhetoric
The European institutions have already shifted. In November 2025, the European Parliament adopted a resolution on transnational repression by 512 votes to 76, with 52 abstentions, stating that roughly 80 per cent of recorded cases were attributable to ten states including China, Russia and Iran. In June 2026, Parliament adopted a further resolution by 434 votes to 128, with 104 abstentions, calling for a common EU definition, stronger information sharing, law-enforcement training and an EU-level response architecture.
The cost of inaction over the next 12–24 months will therefore fall less on diplomatic communiqués than on intelligence services, police forces, ports, rail networks, energy operators, defence companies and diaspora communities. Italy is already protecting more than 29,000 sensitive sites; Britain is already recording double-digit potentially lethal foreign-state plots; Germany is already treating espionage, sabotage, cyber activity and transnational repression as one threat environment; France has already moved the issue into its counter-espionage doctrine.
The decisive contest will be over attribution speed. If European governments cannot connect criminal proxies, financial transfers, cyber reconnaissance and intelligence tasking quickly enough to establish state responsibility, adversaries will continue to exploit the space between suspicion and proof. If they can, the political argument will become harder to manipulate: not because targeted killing disappears from Western state practice, but because legal military action, covert murder, transnational repression and prosecutorial allegation will finally be judged on evidence rather than affiliation.
Navigational Index
Lawful targeting, contested targeting and assassination
The first pillar distinguishes killing permitted under the law of armed conflict in defined circumstances, lethal force claimed under Article 51 self-defence, counterterrorism operations outside traditional battlefields, extrajudicial killing, and clandestine assassination, because treating those categories as synonymous destroys both legal precision and geopolitical comparability.
The state record beyond the headline
The second pillar examines what official documents actually establish concerning the United States, Russia, China, Britain, France and other relevant states, distinguishing acknowledged state practice, final judicial findings, criminal allegations and unresolved intelligence assessments.
Europe as both operator and exposed territory
The third pillar assesses Italy, France, Germany, the United Kingdom and the European Union as jurisdictions simultaneously participating in collective counterterrorism and defence operations while becoming increasingly exposed to foreign transnational repression, sabotage, surveillance and potentially lethal action.
Master Abstract
The vocabulary problem is the beginning of the analytical problem
The term targeted killing possesses a broader analytical meaning than assassination, and the United Nations Special Rapporteur on extrajudicial, summary or arbitrary executions defined targeted killings in 2020 as the intentional, premeditated and deliberate use of lethal force against specific persons by states or organised armed actors, while emphasising that such killings can occur through drones, missiles, gunfire, poison and numerous other methods; critically, the same UN report stated that although targeted killings violate the right to life in most circumstances, they can under exceptional circumstances be lawful during armed conflict. Use of armed drones for targeted killings — Report A/HRC/44/38 — United Nations Human Rights Council
That distinction has immediate geopolitical consequences because a strike against a member of an organised armed group during an armed conflict, a lethal counterterrorism operation justified by a state as anticipatory or ongoing self-defence, and the poisoning of an exile living under another state’s peacetime jurisdiction involve fundamentally different questions of sovereignty, human rights law, international humanitarian law, domestic criminal law and state responsibility; grouping all three under a politically charged label such as “assassination” therefore produces an apparently symmetrical picture that the law and the official record do not sustain.
The same analytical discipline must be applied in the opposite direction, however, because states cannot convert every deliberate extraterritorial killing into an ordinary battlefield act merely by using military terminology, and the United Nations Special Rapporteur expressly identified the January 2020 Soleimani strike as a major development precisely because a state-operated armed drone had targeted a senior official of another state on the territory of a third country.
The United States has an unusually explicit lethal-force architecture
The United States is unusual not because every element of its targeted-killing system is transparent, which it is not, but because successive administrations have publicly articulated an institutional framework governing lethal counterterrorism action beyond ordinary battlefields; the Obama administration’s May 2013 policy framework stated that lethal force outside the United States and areas of active hostilities would be contemplated against terrorist targets posing a continuing and imminent threat to U.S. persons, while requiring, as policy standards, near certainty that the target was present, near certainty that non-combatants would not be injured or killed, assessment that capture was infeasible, assessment that relevant local authorities could not or would not effectively address the threat, and absence of reasonable alternatives. U.S. Policy Standards and Procedures for the Use of Force in Counterterrorism Operations — White House archive
The December 2016 White House legal-policy report subsequently described the domestic and international legal frameworks claimed by Washington for military operations in Afghanistan, Iraq, Syria, Somalia, Libya and Yemen, as well as its rules concerning targeting, detention and related national-security activity, thereby confirming that targeted lethal force was neither an improvised anomaly nor simply an intelligence practice but part of an articulated governmental system.
Its documented scale was also significant: ODNI reported that during calendar year 2016 the United States conducted 53 counterterrorism strikes outside Afghanistan, Iraq and Syria, which were then classified as areas of active hostilities, assessing 431–441 combatant deaths and one non-combatant death, while warning that precise casualty determination was inherently difficult in non-permissive environments.
Those figures cannot responsibly be converted into a current global ranking because states use different definitions, classification policies and reporting systems, and some disclose almost nothing; they nevertheless establish beyond reasonable documentary dispute that Washington developed and repeatedly exercised an institutional capability for deliberate lethal targeting far beyond its own national territory.
The later Trump administration revoked the particular executive-order requirement for annual public reporting of strikes outside active hostilities in March 2019, while explaining that Congress had separately imposed Department of Defense civilian-casualty reporting obligations; importantly, the revocation concerned the reporting mechanism rather than a prohibition on the operations themselves.
The Pentagon subsequently institutionalised broader civilian-harm mitigation processes through its 2022 Civilian Harm Mitigation and Response Action Plan and associated policies, demonstrating continued acceptance that military operations producing civilian risk remained an enduring operational problem requiring systematic governance.
Soleimani demonstrates why legality cannot be inferred from acknowledgement
The killing of Qasem Soleimani is particularly valuable analytically because attribution is not disputed: on 2 January 2020, the U.S. Department of Defense publicly stated that, at the President’s direction, U.S. forces killed Soleimani, describing the action as defensive and asserting that he was developing plans for attacks against American personnel and had been involved in previous attacks.
The United Nations Special Rapporteur later treated the operation as raising substantial questions concerning the use of force and the right to life, illustrating an essential principle for the broader report: an officially acknowledged killing can be evidentially certain as an event while its legality remains disputed, just as a clandestine assassination can be unlawful even where the sponsoring state denies responsibility entirely.
This distinction prevents two opposite analytical errors, because it neither sanitises U.S. lethal operations simply because Washington publishes legal rationales nor equates every American counterterrorism strike with clandestine peacetime murder.
Russia’s record contains cases with stronger judicial attribution than the current U.S. allegation
The newly announced U.S. case of 15 September 2026 should be represented exactly for what it presently is: the Department of Justice announced an indictment against five individuals allegedly working for Russian intelligence services, accusing the network of paying or attempting to pay people in the United States and elsewhere for pre-operational surveillance and targeted killings and of commissioning attacks against civilian and military infrastructure in European states supporting, or perceived to support, Ukraine; because the defendants remain at large and the allegations have not been adjudicated, they remain accusations rather than established facts. Members of Russian Intelligence Services Network Charged with Conspiring to Finance Terrorism and Commit Murder for Hire in the United States — U.S. Department of Justice — 15 September 2026
There are, however, older Russian cases for which the official evidentiary status is considerably stronger, most importantly the Berlin Tiergarten murder, where the Kammergericht convicted Vadim K. in December 2021 and concluded that he had killed Tornike K. in Berlin on the order of a Russian governmental state authority, with the judgment becoming final when no party appealed. Kammergericht judgment on the Tiergarten murder — Berlin judiciary
In Britain, the Litvinenko Inquiry concluded that Alexander Litvinenko’s killers were probably acting under FSB direction and that the operation was probably approved by then-FSB director Nikolai Patrushev and President Vladimir Putin, which is an official inquiry finding employing an explicit probability standard rather than a criminal conviction of the Russian leadership. Home Secretary statement on the Litvinenko Inquiry report — GOV.UK
The British government separately concluded in September 2018 that the two suspects identified in the Salisbury poisoning investigation were GRU officers and assessed that the operation was almost certainly approved beyond the GRU at a senior level of the Russian state, while acknowledging that the underlying intelligence supporting that governmental attribution could not all be made public.
Russia therefore presents a documented pattern in which clandestine lethal or potentially lethal activity has penetrated the domestic jurisdiction of European states, a characteristic that makes the cases analytically different from acknowledged coalition air operations against armed groups in recognised conflict theatres even when both categories involve deliberate targeting.
China presents a different evidentiary profile
Official U.S. criminal proceedings establish substantial evidence of Chinese transnational repression, including surveillance of dissidents, harassment, attempts to obtain sensitive information, coercive repatriation activity and operations undertaken or allegedly undertaken for the Ministry of State Security or Ministry of Public Security; the U.S. Department of Justice has brought repeated cases describing PRC-directed activity against people residing legally in the United States.
In one 2022 case, U.S. authorities alleged that individuals acting for the PRC targeted democracy advocates, conducted surveillance and sought to undermine political activity, while other proceedings concerning “Operation Fox Hunt” described coercive efforts to force persons back to China.
The European Parliament’s January 2026 study of transnational repression similarly treated Russia, Iran and China as three principal perpetrator-state case studies relevant to European security, confirming that Chinese extraterritorial coercion is not merely an American bilateral allegation but has become an identified European policy concern. Perpetrators and methods of transnational repression and possible counter strategies — European Parliament — January 2026
What those official records do not presently support is a clean assertion that China occupies second place in a worldwide league table of targeted assassinations, because surveillance, cyber harassment, intimidation, forced repatriation and extraterritorial killing are components of the broader phenomenon of transnational repression but cannot be counted as equivalent lethal events.
Britain openly crossed the threshold into individual lethal targeting
The United Kingdom publicly acknowledged the 21 August 2015 RAF drone strike that killed British national Reyaad Khan in Syria, and Prime Minister David Cameron told Parliament that the government considered the action lawful under the United Kingdom’s inherent right of self-defence because Khan was allegedly involved in planning armed attacks against Britain and no feasible alternative means of disruption existed.
The parliamentary Joint Committee on Human Rights subsequently accepted that the operation occurred within the broader armed conflict involving Daesh but carefully refused to pronounce on whether the particular strike itself satisfied the law of armed conflict, explaining that such an assessment would require access to the underlying intelligence; the Committee also criticised the government for not fully explaining its interpretation of the legal regime potentially governing lethal drone strikes outside armed conflict.
Britain therefore belongs among states with an acknowledged capacity and willingness to conduct deliberate lethal targeting abroad, but the official record does not support treating its documented practice as quantitatively equivalent to the much broader historical U.S. programme.
France has acknowledged targeted military strikes, but terminology matters
France likewise has publicly used force against identified terrorist infrastructure and leadership structures abroad, with President François Hollande announcing the first French airstrikes in Syria in September 2015 and grounding them politically and legally in France’s asserted right of self-defence against Daesh; he stated that reconnaissance missions had identified targets associated with terrorist training and that further strikes would follow where necessary. Déclaration sur les frappes aériennes françaises en Syrie — Présidence de la République — 27 September 2015
Following the November 2015 Paris attacks, Hollande explicitly declared that French and allied forces would intensify strikes in Iraq and Syria, strengthen intelligence exchanges and pursue Daesh leadership structures, placing deliberate targeting inside the larger military campaign against the organisation.
That evidence establishes French participation in targeted counterterrorism warfare, but the official documents examined here do not establish a transparent French equivalent of the former U.S. public policy system for identifying and lethally targeting named individuals outside areas of armed conflict; describing the French practice simply as an “assassination programme” would therefore go beyond the verified record.
Germany is more securely documented as a jurisdiction subjected to targeted killing than as its perpetrator
Germany provides an especially important corrective to any mechanically symmetrical comparison because the strongest official German evidence retrieved concerns not German assassinations overseas but the use of German territory for a Russian state-directed murder, established by the final Tiergarten judgment.
Germany has also confronted legally difficult questions arising from American drone operations because litigation challenged the alleged use of Ramstein Air Base in communications supporting U.S. drone strikes in Yemen, demonstrating the distinction between conducting a lethal operation, providing infrastructure potentially connected to it, hosting allied forces and bearing responsibility under international or constitutional law; those categories should not be collapsed into a claim that Germany itself maintains an extraterritorial assassination capability merely because relevant infrastructure exists on German territory.
No sufficiently authoritative official evidence located in this review establishes a German governmental programme comparable either to America’s acknowledged extraterritorial lethal counterterrorism system or to the Russian state-directed Tiergarten murder, and the proposition that Germany should automatically appear after Britain and France in a hierarchy of targeted killers is therefore unsupported.
Italy requires the same evidentiary restraint
Italy has participated extensively in NATO and coalition security operations and possesses sophisticated military and intelligence institutions, but the existence of those capabilities does not itself prove a national policy of extraterritorial targeted killing, while no official record located during this assessment establishes an Italian equivalent to the acknowledged U.S. and British individual lethal strikes or to the judicially established Russian Tiergarten operation.
Italy’s institutional significance is instead increasingly that of a European host jurisdiction, alliance member and potential target environment in which foreign intelligence services, diaspora-monitoring networks, coercive repatriation operations, sabotage structures and other manifestations of transnational repression must be detected before they develop into physical violence; the European Parliament now explicitly treats transnational repression as a European security phenomenon encompassing methods ranging from digital surveillance to extraterritorial killing.
Iran and India demonstrate why the problem cannot be reduced to a Russia–West contest
Any genuinely neutral assessment must include other states where official criminal proceedings provide highly material evidence, because excluding them would reproduce precisely the geopolitical selectivity the report is intended to avoid.
In the Iranian case, a U.S. federal jury convicted Asif Merchant in March 2026 of murder-for-hire and terrorism-related offences after prosecutors presented evidence that he had travelled to the United States and sought to arrange political assassinations; the Justice Department described him as an operative connected with Iran’s IRGC, while an earlier 2022 case separately accused IRGC member Shahram Poursafi of attempting to arrange the murder of former U.S. National Security Adviser John Bolton.
India presents another critical case because the U.S. Department of Justice alleged in 2023 and 2024 that Indian government employee Vikash Yadav directed a murder-for-hire plot against a Sikh separatist activist and U.S. citizen in New York, while co-defendant Nikhil Gupta was extradited to the United States and, critically, pleaded guilty to all three counts in February 2026; the guilty plea establishes Gupta’s criminal responsibility, whereas allegations concerning Yadav and wider governmental responsibility retain their separate procedural status.
These cases demonstrate why an analytically serious framework should examine state practice rather than geopolitical blocs, because transnational lethal coercion, assassination planning and repression are not phenomena confined to one ideological camp.
Key Evidence Table
| Indicator | Value/status | Reference date | Definition/scope | Issuer | Exact source |
|---|---|---|---|---|---|
| U.S. counterterrorism strikes outside areas of active hostilities | 53 strikes; 431–441 assessed combatant deaths; 1 assessed non-combatant death | 2016 | Excluded Afghanistan, Iraq and Syria under the then-operative U.S. definition | ODNI | |
| U.S. lethal-force policy threshold | Continuing/imminent threat; near-certainty standards; capture infeasible; local government unable/unwilling; no reasonable alternative | May 2013 | Policy rules for counterterrorism force outside U.S./areas of active hostilities | White House | |
| Soleimani killing | U.S. formally acknowledged killing IRGC-QF commander Qasem Soleimani | 2 Jan 2020 | U.S. described operation as defensive action | U.S. DoD | |
| Tiergarten killing | Final conviction; German court found killing commissioned by a Russian state authority | 23 Aug 2019 / judgment Dec 2021 | Murder on German territory | Kammergericht Berlin | |
| Litvinenko | Inquiry found strong probability killers acted under FSB direction and operation probably received senior approval | Inquiry report Jan 2016 | Poisoning in London | UK Litvinenko Inquiry / Home Office | |
| Salisbury | UK government concluded suspects were GRU officers and operation was almost certainly approved at senior Russian-state level | Sept 2018 | Novichok poisoning operation | UK Government | |
| 2026 Russian network case | Five defendants charged; murder-for-hire, targeted killing preparation and infrastructure attacks alleged | 15 Sep 2026 | Indictment, not conviction | U.S. DOJ/FBI | |
| Chinese overseas activity | Multiple indictments/prosecutions concerning surveillance, harassment, coercion and forced-repatriation operations | 2022–2025 | Transnational repression; not equivalent to proven killing programme | U.S. DOJ/FBI | |
| British Reyaad Khan strike | RAF deliberately killed identified British Daesh member in Syria | 21 Aug 2015 | Government invoked self-defence and armed-conflict framework | UK Government / Parliament | |
| French Syria strikes | France initiated strikes against Daesh targets identified through reconnaissance and coalition intelligence | 27 Sep 2015 onward | Counterterrorism military operation justified by France as self-defence | Élysée | |
| India-linked New York plot | Gupta pleaded guilty; Yadav charged as alleged directing Indian government employee | 2023–2026 | Murder-for-hire targeting U.S. Sikh activist | U.S. DOJ | |
| Iran-linked U.S. assassination plots | Federal conviction in Merchant case; separate IRGC-linked Bolton case charged | 2022–2026 | Murder-for-hire / terrorism cases | U.S. DOJ |
Competing Explanations or Pathways
The evidence does not satisfy the gate for a classical Analysis of Competing Hypotheses concerning a single hidden intention, because the observed phenomenon encompasses different states, legal regimes and operational purposes rather than one mutually exclusive causal question; a narrower alternatives assessment is therefore more defensible.
| Analytical interpretation | Supporting evidence | Limiting evidence | Current standing |
|---|---|---|---|
| Targeted killing is principally an exceptional practice of revisionist or authoritarian states | Russian judicial/inquiry cases, Iranian plots, Indian allegation, Chinese transnational repression | Publicly acknowledged U.S., British and French lethal targeting contradicts exclusivity | Not supported as a general proposition |
| Major powers broadly employ the same practice under different rhetoric | Multiple states use deliberate lethal force beyond their own territory | Armed-conflict strikes, self-defence operations, criminal assassination and coercive repression are legally and operationally different | Too undifferentiated to be analytically sound |
| The international system contains several overlapping regimes of targeted violence whose legality depends on context, authority and method | U.S./UK/French military practice; Russian Tiergarten/Litvinenko record; Iran/India criminal cases; Chinese repression record | Many intelligence operations remain classified, preventing complete comparison | Best supported by the verified public record |
Principal Gaps and Watch Indicators
The largest unresolved evidentiary problem is the absence of a common official international dataset recording state-attributable targeted killings, attempted assassinations and covert lethal operations according to uniform definitions, because national authorities report acknowledged military strikes, intelligence operations, criminal plots and transnational repression through entirely different institutional channels; consequently, any numerical ranking of the United States, Russia, China, Britain, France, Germany or other states would currently mix incomparable numerator and denominator definitions.
The September 2026 Russian case requires particular caution because the indictment contains serious allegations but remains untested at trial, and the assessment should change materially if defendants are arrested, documentary or communications evidence is produced publicly, cooperating witnesses testify, or a final judgment establishes—or rejects—the alleged intelligence relationship.
For China, the decisive missing evidence for any claim of a large-scale overseas assassination programme would consist of final judicial findings, officially authenticated operational documents, indictments directly alleging state-directed killings, or equivalent competent governmental records linking Chinese state organs to specific extraterritorial homicides; the existing verified record strongly supports a finding of systematic transnational repression but does not by itself establish the lethal ranking proposed in the original proposition.
For France, Germany and Italy, the decisive collection requirement is similarly specific: official operational doctrine, parliamentary findings, court decisions, acknowledged lethal operations or declassified governmental records capable of distinguishing national action from coalition participation, intelligence cooperation, logistical support and mere possession of strike-capable systems.
Within Europe, a major indicator will be whether the EU and national governments increasingly treat transnational repression as an integrated counter-intelligence, organised-crime and national-security problem, rather than as a series of isolated threats against diaspora communities, because the European Parliament’s 2025 and 2026 work already identifies a spectrum extending from surveillance and harassment to extraterritorial killing.
Net Assessment
The verified record produces a substantially more complex picture than the binary narrative in which Washington denounces Russian assassinations while standing outside the practice of targeted killing itself, because the United States has openly developed, legally rationalised and repeatedly exercised a system of deliberate lethal counterterrorism targeting abroad, including outside conventional battlefield environments, and therefore cannot credibly be analysed as a state unfamiliar with extraterritorial targeted force.
At the same time, analytical neutrality requires rejecting the opposite simplification, because the existence of American drone strikes does not erase the distinction between an acknowledged military operation against an asserted belligerent target and the clandestine murder of a political opponent living under another state’s peacetime protection; the Berlin Tiergarten judgment, for example, established that a Russian state authority commissioned a murder inside Germany, while the Litvinenko inquiry reached a strong probabilistic attribution to the FSB, and those cases therefore belong to a different legal and operational category from conventional coalition strikes against Daesh.
The same evidentiary discipline prevents unsupported claims about China, Germany or Italy, because the official record substantiates extensive Chinese transnational repression without presently supporting a worldwide numerical assassination ranking, establishes Germany principally as the jurisdiction of a proven Russian state-directed killing rather than as the operator of a comparable programme, and does not provide sufficient official evidence for placing Italy within such a hierarchy.
The deeper geopolitical development is therefore the normalisation of state power beyond territorial borders through increasingly precise combinations of intelligence collection, remote strike capability, covert action, proxies, criminal intermediaries, cyber surveillance and transnational coercion, while legal accountability remains fragmented among the law of armed conflict, Article 51 self-defence, international human-rights law, domestic homicide law and rules governing sovereignty; the European Parliament’s recent treatment of transnational repression as a distinct security problem and the continuing U.S. prosecutions involving Russia, Iran, India and China indicate that this phenomenon can no longer be understood solely through the traditional division between war and peace.
For decision-makers, the most important correction to the present information environment is accordingly methodological rather than rhetorical: every alleged targeted killing should be classified first by evidentiary status, territorial context, armed-conflict status, asserted legal authority, target status, responsible institution and degree of judicial or independent corroboration before any geopolitical comparison is attempted, because without those distinctions a criminal indictment becomes indistinguishable from a conviction, a drone strike becomes indistinguishable from an assassination, intelligence attribution becomes indistinguishable from judicial proof, and political messaging becomes indistinguishable from established fact.
Targeted Killing, Assassination and Transnational Repression: Separating State Practice from Strategic Narrative
EXECUTIVE BLUF: The official record does not support a binary narrative where Russia uniquely employs extraterritorial lethal operations while Western powers stand outside the practice; nor does it support an interchangeable equivalence of all assassinations. Major powers operate across a spectrum from acknowledged armed-conflict targeting and self-defence to clandestine murder and transnational repression.
U.S. Explicit Lethal Counterterrorism Architecture
The United States possesses the most extensively documented public policy architecture among states examined for deliberate lethal counterterrorism operations abroad. Successive administrations have articulated standards including continuing/imminent threat, near certainty of target presence, near certainty of zero non-combatant casualties, and infeasibility of capture.
| Indicator / Event | Value / Status | Reference Date | Issuer / Authority |
|---|---|---|---|
| U.S. 2016 Counterterrorism Strikes | 53 strikes; 431–441 combatant deaths | 2016 Report | Office of the Director of National Intelligence |
| Berlin Tiergarten Murder | Final conviction (commissioned by Russian state) | Dec 2021 Judgment | Kammergericht Berlin |
| Litvinenko Inquiry Poisoning | Probable FSB direction; senior approval | Jan 2016 Report | UK Official Inquiry |
| 2026 U.S. Russian Network Indictment | 5 defendants charged (murder-for-hire) | 15 Sept 2026 | U.S. Department of Justice |
| State | Primary Documented Record | Operational Category |
|---|---|---|
| United Kingdom | Acknowledged 2015 Reyaad Khan strike in Syria | Self-defence counterterrorism targeting |
| China | Extensive U.S./EU records of transnational repression & Fox Hunt | Surveillance, coercion & forced repatriation |
| India & Iran | U.S. federal indictments & guilty plea (Gupta/Merchant) | Murder-for-hire plots on foreign soil |
| Germany & Italy | Exposed host territories for foreign intelligence operations | Counter-intelligence and jurisdictional security |
Battlefield vs. Peacetime Murder
Grouping armed-conflict targeting, self-defence counterterrorism, and peacetime poisonings under “assassination” destroys legal precision and geopolitical comparability.
Judicial Convictions vs. Indictments
Distinguishing final judicial findings (Tiergarten murder conviction) and formal guilty pleas (Nikhil Gupta in 2026) from unadjudicated indictments and intelligence estimates.
Coercion vs. Homicide Ranking
Chinese transnational repression (surveillance, harassment, forced repatriation) is extensively documented, but cannot be equated without a documentary bridge to lethal assassination rankings.
- Unified Dataset: Absence of a common official international database recording state-attributable targeted killings.
- Trial Outcomes: Unadjudicated status of the September 2026 U.S. indictment against Russian intelligence network defendants.
- European Host Metrics: Comprehensive cross-border tracking of foreign surveillance and sabotage cells within EU jurisdictions.
- EU Security Integration: Evolution of EU and national responses treating transnational repression as unified counter-intelligence.
- Judicial Proceedings: Verdicts and evidentiary disclosures in pending murder-for-hire trials (Iran, India, Russia).
- Policy Frameworks: Updates to civilian-harm mitigation and legal reporting standards by major military powers.
Lawful targeting, contested targeting and assassination
Principal judgment: The decisive legal distinction is not whether a state intentionally selected an individual for death, because international humanitarian law expressly contemplates attacks directed against individual lawful targets during armed conflict, while international human-rights law permits intentional lethal force in narrowly defined life-protection circumstances; the controlling question is instead whether the operation survives four separate legal tests concerning authority to cross the territorial boundary, existence and classification of an armed conflict, lawful target status and conduct of the particular attack, because failure at any one of those levels can transform an otherwise militarily precise operation into an internationally wrongful use of force, an arbitrary deprivation of life, a war crime, an unlawful homicide, or—in the terminology of some domestic systems—an assassination.
This framework materially changes the geopolitical comparison developed in the opening assessment, because it shows why “targeted killing” cannot function as a single analytical category: an aircrew deliberately attacking an enemy commander during an international armed conflict, a special-operations unit using force in the territory of another state under an asserted Article 51 claim, an intelligence service poisoning a dissident living abroad, and police killing a dangerous suspect during an arrest can all involve intentional identification of a person before lethal force is used, while the legal rules governing those operations are radically different.
The four legal gates that determine whether an intentional killing is lawful
An intentional state killing outside the state’s own territory should be examined sequentially rather than rhetorically, because the legal authority permitting entry into another state’s territory, the law governing the conflict, the status of the individual and the execution of the attack answer different questions and are not substitutes for one another.
| Legal gate | Controlling question | Principal legal regime | What must ordinarily be established | Consequence if the gate fails |
|---|---|---|---|---|
| Territorial authority | Was the state entitled to use force on that territory at all? | UN Charter, consent, Security Council authority, self-defence | Valid consent, Security Council authority, or a sustainable self-defence basis | Potential violation of sovereignty and Article 2(4), even if the person was otherwise targetable |
| Conflict classification | Was an armed conflict legally in existence and was the operation sufficiently connected to it? | International humanitarian law | International or non-international armed conflict under the applicable factual tests | Ordinary human-rights/law-enforcement standards remain controlling rather than status-based battlefield targeting |
| Target status | Was this individual lawfully subject to direct attack? | IHL distinction rules or human-rights standards | Combatant/member of relevant armed forces or armed group, or civilian directly participating in hostilities; alternatively an imminent threat to life under law-enforcement rules | Intentional killing risks becoming unlawful attack or arbitrary deprivation of life |
| Attack execution | Was the particular attack carried out lawfully? | Distinction, proportionality, precautions, humanity; or necessity and strict proportionality under human-rights law | Target verification, lawful means, precautions, proportionality, cancellation where necessary | Even a lawful target can be unlawfully attacked |
| Domestic authority and criminal law | Did the acting institution possess domestic legal authority and avoid applicable homicide/assassination prohibitions? | Constitution, statute, executive authority, criminal law | Country-specific authorization | International legality does not automatically cure domestic illegality |
The United Nations Charter supplies the first gate rather than the last one, because Article 2(4) requires states to refrain from the threat or use of force against another state’s territorial integrity or political independence, while Article 51 preserves individual and collective self-defence when an armed attack occurs and requires measures taken in self-defence to be reported to the Security Council; consequently, the fact that an individual is a lawful military target under humanitarian law does not itself authorize another state to enter foreign territory and kill that person. United Nations Charter — United Nations
This distinction between the jus ad bellum, governing resort to interstate force, and the jus in bello, governing conduct after the armed-conflict rules apply, is indispensable because the two regimes deliberately ask different questions; an attack against an enemy combatant can comply with distinction, proportionality and precautions while the interstate use of force through which it was conducted remains unlawful, whereas an operation undertaken pursuant to a valid self-defence claim can still violate humanitarian law if civilians are intentionally targeted or expected civilian harm is excessive.
Territorial sovereignty remains the first constraint
Article 51 does not create an unrestricted licence to pursue designated enemies wherever intelligence locates them, because any operation conducted without the territorial state’s consent must independently satisfy the international legal conditions invoked by the attacking state for self-defence, including necessity and proportionality, while the treatment of operations against non-state armed groups located in third countries remains one of the most contested areas of contemporary jus ad bellum.
The United Kingdom’s Attorney General formally stated in January 2017 that British doctrine recognises anticipatory self-defence against an imminent armed attack and treats necessity and proportionality as indispensable conditions, while explaining that the assessment of imminence must respond to the characteristics of contemporary terrorist threats rather than mechanically require an attack to have physically begun. Attorney General’s speech at the International Institute for Strategic Studies — UK Attorney General’s Office — Jan 2017
The United States has articulated a broader and particularly consequential interpretation concerning non-state actors, because the Department of State’s Legal Adviser stated in 2016 that when a non-state armed group operates from another state’s territory, Washington considers force without territorial consent potentially lawful where the territorial state is “unable or unwilling” effectively to address the threat, while explicitly presenting that test as an application of necessity rather than as a general suspension of territorial sovereignty. International Law, Legal Diplomacy, and the Counter-ISIL Campaign — U.S. Department of State — Apr 2016
That doctrine is politically and legally significant precisely because it is not universally accepted as a settled rule in the breadth asserted by Washington, and the absence of a single authoritative international judgment establishing the full U.S. formulation means that an analytical report must describe it as a U.S. legal position supported by elements of state practice, rather than silently elevating it into uncontested universal law.
Territorial authority matrix
| Situation | Presumptive position | Additional legal question | Analytical classification |
|---|---|---|---|
| Territorial state expressly consents | No Article 2(4) problem vis-à-vis consenting state if consent is valid and operation remains within its scope | Was consent valid, attributable and not exceeded? | Potentially lawful territorial basis |
| UN Security Council authorises force | Charter basis may exist within mandate | Does the operation remain within geographic, temporal and substantive mandate? | Potentially lawful territorial basis |
| State acts against attacking state under Article 51 | Self-defence potentially available | Armed attack, necessity, proportionality, reporting | Contingent legality |
| State acts against non-state group with host-state consent | Sovereignty objection substantially reduced | Is there an armed conflict and is the target lawfully targetable? | Frequently strongest legal configuration |
| State acts against non-state group without host-state consent | Legally contested | Necessity, threat, host-state capacity/willingness, Article 51 basis | Highest jus ad bellum controversy |
| Covert killing of political opponent in peaceful third state | No ordinary battlefield basis | Consent, self-defence or other recognized authority usually absent | Strong presumption of unlawful interference and homicide |
The central implication is therefore that target status cannot cure a sovereignty defect, because the question “can this individual be attacked under humanitarian law?” logically follows rather than replaces the question “may this state employ military force at this location?”
Armed conflict is a factual legal condition, not a political label
International humanitarian law does not become applicable merely because a government labels an opponent a terrorist, enemy, threat or hostile actor, because the existence of an armed conflict depends on objective factual conditions rather than executive terminology; this matters especially for targeted killings because status-based targeting is considerably broader than the lethal-force authority ordinarily permitted under law-enforcement rules.
Common Article 3 of the 1949 Geneva Conventions protects persons taking no active part in hostilities, including armed-force members who have laid down their arms or otherwise become hors de combat, against violence to life and person, while customary humanitarian law distinguishes civilians from members of armed forces and provides that civilians lose protection from direct attack only while directly participating in hostilities. Customary IHL Rule 6 — Civilians’ Loss of Protection from Attack — ICRC
The legal significance is considerable because an individual who may be lawfully attacked during an armed conflict because of combatant status or qualifying participation cannot automatically be killed under an ordinary law-enforcement paradigm, where the Human Rights Committee’s authoritative interpretation of ICCPR Article 6 requires potentially lethal force to be an extreme measure directed to protecting life against an imminent threat and ordinarily treats intentional lethal force as permissible only where strictly necessary for that protective purpose. General Comment No. 36 on Article 6 of the ICCPR — UN Human Rights Committee — Sep 2019
Why conflict classification changes the result
| Question | Armed-conflict paradigm | Peacetime / law-enforcement paradigm |
|---|---|---|
| May force intentionally be directed at a person because of status? | Yes, against lawful military targets subject to IHL | Ordinarily no |
| Must the target pose an immediately lethal threat at the precise moment of attack? | Not necessarily for a lawful combatant or qualifying armed-group member | Normally lethal force requires an imminent threat to life or serious injury |
| Must arrest be attempted before lethal force? | No general IHL rule requiring capture instead of attack when a person is lawfully targetable, subject to surrender/hors-de-combat protections and other applicable law | Arrest and non-lethal alternatives become central to necessity |
| Can surprise attack itself be lawful? | Yes, provided perfidy and other prohibitions are respected | Deliberate pre-planned killing without arrest justification is highly problematic |
| Does civilian status provide immunity? | Generally yes, unless and for such time as direct participation removes protection | Yes, except lethal force strictly necessary to protect life |
| What governs incidental civilian deaths? | Proportionality and feasible precautions | Much narrower necessity/proportionality requirements apply |
This distinction explains why geographical distance and weapon type are legally secondary to the underlying regime, because a drone strike can be lawful or unlawful for the same reasons as a manned-aircraft strike, sniper attack or missile launch, while the remote character of the weapon does not itself create a separate law of targeted killing; the legal focus remains on authority, target status, proportionality and precautions.
The target must be lawful independently of how dangerous the state considers the person
The customary principle of distinction requires parties to distinguish civilians from combatants and civilian objects from military objectives, while the International Court of Justice has described distinction as one of the cardinal principles of humanitarian law; correspondingly, neither political importance, ideological hostility, inclusion on a domestic terrorism list, nor intelligence value alone converts an individual into a lawful military target. Customary IHL Rule 7 — Principle of Distinction — ICRC
For civilians, the central exception is direct participation in hostilities, under which protection against direct attack is lost for the legally relevant period of participation, while state practice and international jurisprudence have repeatedly distinguished genuinely direct participation from political sympathy, general economic support or other conduct that contributes to a war effort without satisfying the required operational nexus. Customary IHL Rule 6 — Civilians’ Loss of Protection from Attack — ICRC
Target-status decision table
| Individual category | Direct attack under IHL | Critical qualification |
|---|---|---|
| Member of regular armed forces of a party to an international armed conflict | Generally targetable | Protected once hors de combat, surrendered, detained or otherwise specially protected |
| Member of organised armed group performing continuous combat function in a NIAC | Treated by the ICRC framework as continuously targetable while membership/function persists | Membership and function require reliable factual determination |
| Civilian presently taking direct part in hostilities | Targetable during qualifying participation | Protection returns when qualifying participation ends under the prevailing civilian-participation framework |
| Civilian providing general political support | Not targetable merely for such support | Political affiliation is not equivalent to direct participation |
| Financier or propagandist | Not automatically targetable | Requires separate analysis of whether conduct crosses the direct-participation threshold |
| Intelligence collector transmitting tactical targeting data | Can constitute direct participation depending on immediacy and causal nexus | Strategic or remote intelligence support does not automatically qualify |
| Captured fighter | Not targetable as a battlefield target | Protected from murder and violence under Common Article 3 and other applicable rules |
| Wounded fighter incapable of fighting and abstaining from hostile action | Hors de combat and protected | Killing can constitute grave breach/war crime depending on conflict and facts |
| State political leader | Not targetable merely by virtue of political office | Must independently satisfy lawful-target criteria |
| Designated terrorist outside armed conflict | Designation alone does not create military target status | Human-rights/law-enforcement rules ordinarily control |
The distinction is especially important for political leadership because international humanitarian law does not contain a general category of “enemy political officials” who can automatically be killed; a civilian political leader becomes directly targetable only where the applicable law and facts establish a qualifying military role or direct participation, whereas the mere fact that a government considers that person strategically responsible for hostile policy does not erase civilian protection.
A lawful target can still be attacked unlawfully
The fourth gate concerns execution, because lawful target status does not permit unlimited means or collateral consequences, while the principal customary rules require distinction, proportionality, feasible precautions, target verification and cancellation or suspension when information acquired during the operation shows that the target is not a military objective or that expected civilian harm has become excessive.
The customary proportionality rule prohibits an attack expected to cause incidental civilian death, civilian injury or civilian-object damage excessive in relation to the concrete and direct military advantage anticipated, while this assessment is prospective and therefore must be judged according to the information reasonably available to those planning and deciding the attack rather than solely by the casualty count discovered afterward. Customary IHL Rule 14 — Proportionality in Attack — ICRC
The separate precautionary obligation requires continual attention during execution, including cancellation or suspension when it becomes apparent that the object is not a military objective or that expected incidental civilian harm would be excessive, meaning that intelligence updates occurring seconds before impact can have legal relevance rather than simply operational relevance. Customary IHL Rule 19 — Control During the Execution of Attacks — ICRC
France’s official 2022 Manual on the Law of Military Operations expressly identifies distinction, proportionality, precaution and the prohibition of superfluous injury and unnecessary suffering as cardinal principles governing conduct of hostilities, demonstrating that these obligations are incorporated into national operational doctrine rather than existing solely as abstract treaty provisions. Manuel de droit des opérations militaires — Ministère des Armées — 2022
Operational legality checklist
| Requirement | What commanders must determine | What does not satisfy the rule by itself |
|---|---|---|
| Identification | Reasonable basis that intended person is a lawful target | Name appearing on an intelligence list without adequate verification |
| Distinction | Attack directed at lawful military target | General association with hostile population or political movement |
| Proportionality | Expected incidental harm not excessive to concrete and direct military advantage | Argument that target is “important” without contextual assessment |
| Precautions | Feasible measures to reduce civilian harm | Precision-guided weapon alone |
| Weapon legality | Means and method permitted by applicable law | Technological sophistication |
| Dynamic reassessment | Cancel/suspend if target or proportionality assumptions materially change | Reliance on original intelligence after contrary information emerges |
| Hors-de-combat protection | Determine whether surrender, incapacitation or detention changes targetability | Prior combatant status |
| Accountability | Review credible indications of unlawful death | Mere internal assertion that operation complied with rules |
A precision weapon therefore does not make a strike legally precise, because weapon accuracy addresses only one part of the precautions analysis, while mistaken identity, defective intelligence, disproportionate expected civilian harm or unlawful target selection can render a technically perfect hit legally defective.
Human-rights law does not disappear when armed conflict begins
A second major source of conceptual confusion arises from the assumption that humanitarian law completely replaces human-rights law during hostilities, whereas the UN Human Rights Committee states that ICCPR Article 6 continues to apply during armed conflict and that humanitarian law and human-rights law are complementary rather than mutually exclusive, with humanitarian-law rules informing whether a deprivation of life in hostilities is arbitrary. General Comment No. 36 — Human Rights Committee — Sep 2019
The Committee further states that Article 6 is non-derogable, that arbitrary deprivation of life remains prohibited even during armed conflict, and that states should disclose criteria used for lethal targeting, including the legal basis for attacks, target-identification process and relevant means and methods where disclosure is compatible with legitimate security requirements. General Comment No. 36 — Human Rights Committee — Sep 2019
Within the European legal space, Article 2 of the European Convention on Human Rights imposes an especially demanding standard for intentional state force outside ordinary hostilities, permitting force resulting in death only where it is no more than absolutely necessary for specified protective purposes, while Strasbourg jurisprudence requires scrutiny not merely of the trigger-puller’s decision but also of operational planning and control. Guide on Article 2 of the European Convention on Human Rights — European Court of Human Rights — updated Aug 2025
In McCann and Others v. United Kingdom, the European Court held that “absolute necessity” demands a stricter test than the ordinary proportionality standard used elsewhere in the Convention and that lethal-force cases require examination of surrounding circumstances, including planning and control; this has major relevance to alleged assassination operations because a state cannot ordinarily satisfy Article 2 merely by arguing after the fact that the deceased was dangerous. McCann and Others v. United Kingdom — European Court of Human Rights
Extraterritorial human-rights obligations increasingly penetrate remote warfare
European jurisprudence also prevents governments from assuming that human-rights obligations end mechanically at the national frontier, because the Strasbourg system recognises exceptional circumstances in which state agents exercising authority or control abroad bring affected individuals within a state’s Convention jurisdiction, including detention and certain exercises of public power outside national territory. Al-Skeini and Others v. United Kingdom — European Court of Human Rights
Germany’s Federal Constitutional Court carried this reasoning into a particularly important contemporary technological context in its 15 July 2025 Ramstein judgment, holding that Germany’s Basic Law contains a general protective mandate capable, under appropriate circumstances, of generating obligations concerning threats to life suffered by non-German citizens abroad where a sufficiently close connection exists with German sovereign power; although the complaint was ultimately rejected, the Court accepted that German constitutional responsibility is not automatically confined to German citizens or German territory. Judgment of 15 July 2025 — 2 BvR 508/21 — Bundesverfassungsgericht
The case concerned U.S. armed-drone operations in Yemen involving technical infrastructure at Ramstein Air Base, and the Constitutional Court recorded findings that the satellite relay station played a central operational role in transmitting control and data signals; the judgment therefore has significance far beyond one historical strike because it demonstrates that territorial infrastructure, communications relays and enabling functions can generate legal scrutiny even when the lethal weapon and target are thousands of kilometres away. Judgment of 15 July 2025 — Bundesverfassungsgericht
European legal exposure created by remote targeting
| State role | Potential legal relevance | Example of legal mechanism |
|---|---|---|
| State launches strike | Direct responsibility for use of force and targeting | Charter, IHL, ECHR/ICCPR, domestic law |
| State supplies intelligence | Responsibility depends on knowledge, contribution and applicable attribution/assistance rules | International responsibility and domestic oversight |
| State hosts command infrastructure | Territorial nexus can create constitutional/human-rights questions | German Ramstein litigation |
| State permits foreign base use | Consent does not automatically eliminate own legal obligations | Status-of-forces arrangements plus domestic/international duties |
| State provides refuelling or communications | May become legally relevant where contribution is essential and risk is foreseeable | Fact-intensive inquiry |
| State receives intelligence derived from operation | Normally weaker causal connection | Depends on subsequent use and knowledge |
This infrastructure dimension is especially relevant to Italy, Germany, the United Kingdom and France because modern targeting systems depend upon distributed intelligence, communications, basing, surveillance, airborne refuelling and coalition command networks, meaning that legal responsibility cannot always be reduced to the nationality painted on the aircraft or the passport of the operator.
“Assassination” is a politically powerful term but an unusually unstable legal category
There is no comprehensive universal treaty definition converting every deliberate killing of a named person into the international crime of “assassination,” while international law instead regulates the conduct through other categories, including unlawful use of force, murder, arbitrary deprivation of life, war crimes, perfidy, prohibited attacks against civilians, and violations of sovereignty; consequently, a high-quality geopolitical analysis should resist treating the word as though it carried a single universal legal test.
The United States illustrates the problem particularly clearly because Executive Order 12333 expressly states that no person employed by or acting on behalf of the U.S. Government may engage in or conspire to engage in assassination, while the executive order itself does not supply a comprehensive definition of assassination. Executive Order 12333 — United States Intelligence Activities — National Archives
U.S. executive-branch legal interpretation has consequently distinguished prohibited assassination from what it regards as lawful targeting undertaken in armed conflict or self-defence, with the Department of Justice’s published legal analysis concerning Anwar al-Aulaqi concluding that, under the factual and legal assumptions described there, a lethal operation against the identified al-Qa’ida leader would constitute lawful conduct of war or self-defence rather than assassination prohibited by Executive Order 12333. Applicability of Federal Criminal Laws and the Constitution to Contemplated Lethal Operations Against Shaykh Anwar al-Aulaqi — U.S. Department of Justice Office of Legal Counsel — Jul 2010
That proposition should be understood precisely as a U.S. executive-branch legal conclusion applying specific assumptions, rather than as an international judicial ruling binding other states, because questions concerning whether the relevant conflict extended to the location, whether the target satisfied the necessary status criteria, whether the territorial state consented or was genuinely unable or unwilling to act, and whether the asserted concept of imminence was sufficiently restrictive remain independently reviewable under international law.
What the label “assassination” does—and does not—prove
| Proposition | Legal accuracy |
|---|---|
| “The person was deliberately selected, therefore this was an assassination.” | Insufficient: deliberate individual targeting can be lawful in armed conflict |
| “The target was a terrorist, therefore killing was lawful.” | Incorrect: designation alone does not establish territorial authority, armed conflict or targetability |
| “The strike was conducted by military forces, therefore it was lawful warfare.” | Incorrect: military personnel can commit unlawful killings and war crimes |
| “The operation was covert, therefore it was necessarily unlawful.” | Not automatically: secrecy does not itself determine legality, although it complicates accountability and evidentiary review |
| “The target was outside a battlefield, therefore IHL cannot apply.” | Too categorical: conflict nexus and applicable legal theory require factual analysis |
| “The state invoked self-defence, therefore the operation was legal.” | Incorrect: invocation is a legal claim, not adjudication |
| “Domestic law authorised the operation, therefore international law was satisfied.” | Incorrect: domestic and international authority are independent |
| “The state prohibits assassination, therefore it does not conduct targeted killings.” | Incorrect: domestic doctrine may distinguish assassination from lawful military targeting |
Imminence is one of the major fault lines between state doctrines
The concept of imminence illustrates the gap between seemingly shared legal vocabulary and materially different operational rules, because the UK has formally stated that Article 51 does not require a state to wait passively until an attack begins, while insisting that defensive force must remain necessary and proportionate, whereas U.S. counterterrorism doctrine developed a more elastic concept in which the absence of precise intelligence concerning the exact time and place of an anticipated terrorist attack did not necessarily defeat an imminence determination.
The DOJ white paper concerning lethal force against a U.S. citizen stated that, for senior operational al-Qa’ida figures continuously engaged in plotting attacks, imminence did not require clear evidence that a specific attack would occur in the immediate future and instead incorporated factors including the relevant operational window, ability to reduce civilian harm and consequences of delaying action. Lawfulness of a Lethal Operation Directed Against a U.S. Citizen Who Is a Senior Operational Leader of Al-Qa’ida or an Associated Force — U.S. Department of Justice
That approach substantially enlarges the temporal scope of defensive targeting compared with a literal interpretation requiring an attack to be immediately forthcoming, which is precisely why the term “imminent” should never appear in an institutional report without identifying whose legal definition is being applied, because the same word can conceal different practical thresholds.
Competing operational meanings of imminence
| Model | Core concept | Operational consequence |
|---|---|---|
| Classical Caroline formulation | Threat is instant and overwhelming, leaving no meaningful choice or time for deliberation | Extremely narrow anticipatory window |
| Modern UK formulation | State need not absorb first strike; imminence assessed contextually alongside necessity and proportionality | Broader than literal immediacy but still framed as exceptional |
| U.S. post-9/11 counterterrorism formulation | Specific time and place of attack need not always be known where operational leaders continuously plan attacks | Potentially substantially broader temporal targeting window |
| ICCPR law-enforcement model | Intentional lethal force ordinarily only to protect against imminent threat to life or serious injury | Narrowest outside armed conflict |
The legal significance is not semantic, because a state adopting a broad imminence concept gains a substantially larger operational window for pre-emptive lethal action, while another state applying a stricter interpretation would treat part of the same window as premature and therefore potentially unlawful.
Capture is legally central outside armed conflict but more complicated inside it
Public debate frequently assumes that a lawful targeted killing requires proof that capture was impossible, yet that proposition is not a universal rule of international humanitarian law for every lawful battlefield target, because a combatant or otherwise lawful military target is not ordinarily entitled to be offered arrest in place of attack so long as that person has not surrendered or become hors de combat; by contrast, in a law-enforcement framework, the availability of arrest and less-lethal measures is fundamental to whether lethal force is strictly necessary.
The Human Rights Committee states that potentially lethal law-enforcement force must represent a last resort after less harmful alternatives have been exhausted or deemed inadequate, while intentional lethal force is permissible only where strictly necessary to protect life against an imminent threat. General Comment No. 36 — Human Rights Committee
The operational importance is substantial because governments sometimes incorporate capture feasibility as a policy safeguard stricter than the minimum IHL rule, while analysts then mistakenly report that safeguard as if it were a universal treaty obligation; policy restraint and binding law should therefore be separated explicitly.
Current U.S. policy demonstrates how executive standards can change without changing the underlying claimed authority
The United States provides a particularly useful illustration of the distinction between law and policy, because the Biden administration’s October 2022 Presidential Policy Memorandum imposed a set of interagency standards governing direct action against terrorist targets outside areas of active hostilities while maintaining the 2001 AUMF and presidential constitutional authority as underlying domestic legal bases. Notification of a Change to the Legal and Policy Frameworks for the United States’ Use of Military Force and Related National Security Operations — White House — Nov 2022
The White House’s calendar-year 2025 report, published in February 2026, records that President Trump rescinded that October 2022 policy on 30 January 2025 and restored the first Trump administration’s Principles, Standards, and Procedures for U.S. Direct Action Against Terrorist Targets, while reporting that the underlying scope of the 2001 AUMF remained unchanged. Report on the Legal and Policy Frameworks for the United States’ Use of Military Force and Related National Security Operations — White House — Feb 2026
This development is analytically important because it demonstrates that executive safeguards surrounding direct action can be narrowed, broadened or procedurally reorganised without Congress necessarily changing the claimed statutory authority and without international law itself changing, meaning that any serious comparison of states must distinguish treaty obligation, customary rule, domestic authorization and discretionary executive policy.
U.S. authority stack as of 2026
| Layer | Instrument / doctrine | Legal character | Can executive branch alter it unilaterally? |
|---|---|---|---|
| UN Charter | Articles 2(4), 51 | International treaty obligation | No |
| Law of armed conflict | Treaty and customary IHL | International law | No |
| 2001 AUMF | Act of Congress | Federal statute | No, not by ordinary presidential memorandum |
| Article II authority | Constitutional claim | Domestic constitutional authority | Interpretation varies; text cannot simply be rewritten |
| Executive Order 12333 | Assassination prohibition | Executive order | President can amend/revoke subject to other law |
| Direct-action PSP/PPM | Executive targeting policy | Policy framework | Yes |
| Operational rules of engagement | Mission-specific executive/military rules | Operational policy, often classified | Generally yes within legal constraints |
This hierarchy explains why political statements that “the rules changed” can be simultaneously correct at the policy level and misleading at the legal level, because changing a presidential targeting memorandum does not remove Article 2(4), Article 51, IHL distinction or the ICCPR prohibition on arbitrary deprivation of life.
Britain exposes the difference between political authorization and legal adjudication
The British parliamentary examination of targeted drone killing is particularly instructive because the Joint Committee on Human Rights accepted that the 2015 strike against Reyaad Khan occurred within the broader armed conflict against Daesh but expressly declined to determine whether the particular strike itself complied with the law of war, explaining that such a judgment required access to the underlying intelligence. The Government’s Policy on the Use of Drones for Targeted Killing — Joint Committee on Human Rights
That distinction is exceptionally important for intelligence analysis because classification of an operation within an armed conflict does not prove target identification, proportionality or precaution compliance, while a ministerial statement asserting that an operation was necessary and proportionate should therefore be recorded as the government’s legal position unless the underlying facts have been tested by a competent court or equivalent independent process.
The Committee also criticised the government’s refusal to explain fully its legal understanding of lethal drone strikes outside armed conflict, which leaves a persistent difference between the existence of a national capability and the transparency of the legal doctrine governing its most difficult potential uses. Government Response to the Joint Committee on Human Rights — UK Parliament
France codifies the battlefield rules more clearly than the political vocabulary suggests
French doctrine is valuable because its official military-law manual places targeting inside a structured humanitarian-law framework rather than treating “targeted killing” as an autonomous legal category, explicitly organising operations around distinction, military necessity, proportionality and precautions while recognising the balance between military necessity and humanity. Manuel de droit des opérations militaires — Ministère des Armées — 2022
French domestic law also separates general force structure and operational command from the international legal basis for particular deployments, with the Code de la défense establishing that French military missions outside the ordinary territorial framework are executed within France’s international commitments and operational command system, rather than creating an autonomous statutory power to kill named persons abroad merely because they have been designated threats. Code de la défense — Légifrance
The resulting French position is therefore better understood through ordinary law-of-war targeting and self-defence doctrine than through the politically loaded category of assassination, while any allegation of a covert peacetime killing would require a separate evidentiary and legal assessment rather than being inferred from France’s acknowledged military strike capability.
Germany’s criminal law illustrates how unlawful targeting becomes individual criminal responsibility
Germany’s Völkerstrafgesetzbuch, implementing core international-criminal-law offences, criminalises the intentional killing of persons protected under international humanitarian law and prohibits attacks directed against civilians, civilian objects and attacks undertaken with the certain expectation of civilian harm disproportionate to the anticipated concrete and direct overall military advantage; where intentional death results in specified circumstances, German law provides severe penalties reaching life imprisonment. Code of Crimes against International Law — Federal Ministry of Justice
This domestic implementation demonstrates the transition from abstract targeting rules to individual criminal exposure, because the state-level question “was this operation internationally wrongful?” and the individual question “did a commander or operator commit a prosecutable war crime?” overlap but do not automatically produce identical answers, particularly where criminal liability requires proof of mental elements beyond the objective unlawfulness of the attack.
State responsibility versus individual criminal responsibility
| Issue | State responsibility | Individual criminal responsibility |
|---|---|---|
| Wrongful use of force | State can breach Charter obligations | Not automatically an international crime for every individual involved |
| Attack on civilians | Engages state responsibility | Can constitute war crime if elements are proven |
| Disproportionate attack | State responsibility possible | Criminal liability requires applicable offence and mental element |
| Faulty intelligence | Can contribute to internationally wrongful act | Criminality depends on knowledge/recklessness standard under applicable law |
| Covert murder abroad | State responsibility for attributable act | Individual perpetrators can face ordinary murder or international-crime charges |
| Political authorization | Can attribute action to state | Does not immunize subordinate or superior where criminal elements exist |
This distinction is especially important in government reporting because an operation can be unlawful without every participant being a war criminal, while conversely a state’s refusal to acknowledge responsibility does not prevent identifiable individuals from being prosecuted where sufficient admissible evidence establishes their conduct and intent.
The legal treatment of political killing is therefore contextual, not ideological
No legal rule identified in the official record creates one targeting standard for democracies and another for authoritarian states, while the same fundamental questions concerning sovereignty, self-defence, armed-conflict classification, civilian protection, necessity, proportionality and precautions apply irrespective of alliance alignment; what varies sharply is the legal theory invoked, transparency provided, judicial accessibility and quality of evidence available for external review.
For analytical purposes, state conduct should therefore be placed into the following categories before geopolitical interpretation is attempted.
| Category | Defining feature | Primary law | Evidentiary threshold required for institutional reporting |
|---|---|---|---|
| Conventional battlefield targeting | Lawful military target within armed conflict | IHL | Reliable confirmation of conflict, status and attack circumstances |
| Named-person military strike | Individual intentionally selected during armed conflict | IHL plus jus ad bellum | Same rules as other attacks; individual selection does not itself make operation unlawful |
| Cross-border self-defence strike | Force used in another state against alleged threat | Article 51 + sovereignty + IHL where armed conflict exists | State legal claim plus facts supporting necessity, proportionality and territorial basis |
| Law-enforcement lethal action | Force used to protect life/arrest suspect outside hostilities | Human-rights and domestic policing law | Imminent threat and strict necessity |
| Extrajudicial execution | Intentional killing inconsistent with applicable right-to-life standards | ICCPR/ECHR/domestic law | Reliable attribution plus absence of lawful basis |
| Clandestine political murder | Covert killing of political opponent or dissident outside armed conflict | Domestic homicide law, sovereignty, human rights, state responsibility | Judicial findings or strong official evidentiary attribution |
| Assassination under U.S. domestic executive law | Conduct falling within EO 12333 prohibition | U.S. executive law | Requires application of U.S. interpretation distinguishing prohibited assassination from lawful military/self-defence action |
| War crime of unlawful attack or killing | Conduct satisfies applicable international criminal elements | IHL/ICC or national implementing law | Criminal standard appropriate to adjudicating forum |
Key judgments
The most important legal finding is that intentionality alone does not distinguish lawful targeting from assassination, because modern armed-conflict law permits intentional attack against lawful military targets while imposing strict protections on civilians, surrendered persons and others hors de combat; the analytical error begins when deliberate target selection is treated as proof either of legality or illegality without examining the applicable legal regime.
The second judgment is that Article 51 and humanitarian law perform different functions, because self-defence can provide an asserted justification for entering foreign territory but does not itself determine whether a particular person was lawfully targetable, while lawful target status cannot independently supply a territorial right to employ force.
The third judgment is that armed-conflict classification is the principal switch between status-based targeting and the far narrower law-enforcement model, meaning that governments have a powerful legal incentive to characterise transnational counterterrorism operations as components of continuing armed conflicts, while critics and courts must test that characterisation against factual rather than rhetorical criteria.
The fourth judgment is that European law increasingly creates legal exposure for states that enable lethal operations as well as states that execute them, because the Ramstein judgment confirms that territorial infrastructure and sovereign control can be sufficiently connected to threats abroad to engage constitutional protection analysis under defined circumstances. Judgment of 15 July 2025 — Bundesverfassungsgericht
The fifth judgment is that the United States’ assassination prohibition cannot be equated with a prohibition on targeted killing, because Executive Order 12333 forbids assassination while U.S. executive-branch doctrine expressly interprets lawful armed-conflict and self-defence targeting as conceptually distinct, a distinction that remains politically controversial but is firmly established within the published U.S. governmental legal framework. Executive Order 12333 — National Archives OLC Memorandum on Anwar al-Aulaqi — Department of Justice
What would change the assessment
The assessment would materially change if the International Court of Justice or another competent international tribunal produced authoritative jurisprudence resolving the contested scope of self-defence against non-state actors operating in unwilling or unable territorial states, because present state practice and legal positions do not eliminate significant disagreement concerning that doctrine.
It would also change if governments published sufficiently detailed targeting directives to establish whether claimed policy safeguards—particularly capture feasibility, standards of target identification and definitions of imminence—constitute binding operational requirements or merely internal discretionary guidance, while the 2025 restoration of the U.S. first-term direct-action framework illustrates how rapidly policy controls can change without alteration of underlying statutory authority. Report on the Legal and Policy Frameworks for the United States’ Use of Military Force — White House — Feb 2026
A third material change would follow from new European jurisprudence defining when intelligence sharing, basing, satellite relays, refuelling, targeting support or other enabling functions create sufficiently direct responsibility for unlawful lethal operations, because the technological architecture of contemporary targeting increasingly separates the state selecting the target, the state providing intelligence, the territory hosting communications infrastructure and the platform delivering the weapon.
Open official record
The principal unresolved official record concerns the precise operational content of current national targeting directives, because substantial portions of rules of engagement, intelligence-certainty thresholds, target-validation procedures, no-strike criteria and mission-specific legal advice remain classified in the United States, United Kingdom, France and other states, while absence of publication prevents independent comparison rather than proving that safeguards do or do not exist.
A second unresolved area concerns the breadth with which states other than the United States accept the “unable or unwilling” doctrine for unilateral force against non-state actors on foreign territory, because publicly articulated national positions are uneven and cannot responsibly be treated as universal consensus merely because several coalition partners have participated in operations justified partly through collective self-defence.
A third unresolved issue concerns the boundary between continuous membership in an organised armed group and episodic civilian direct participation, where different states and institutions use related but not perfectly identical operational tests; this uncertainty can materially alter whether an individual is continuously targetable or protected except during specific hostile acts, making it one of the most consequential unresolved questions in contemporary counterterrorism targeting.
A fourth unresolved record concerns the interaction between domestic assassination prohibitions and intelligence authorities outside the United States, because France, Germany, Italy and the United Kingdom do not reproduce Executive Order 12333 in an identical legal form, meaning that comparison must be conducted through each jurisdiction’s constitutional, criminal, intelligence and military authorities rather than through a misleading search for nominally identical statutes.
No decision-useful visualisation is supportable from the verified record, because the legal regimes operate through conditional tests rather than comparable numerical series, while the matrices above preserve the distinctions that a numerical chart would necessarily conceal.
Lawful Targeting, Contested Targeting and Assassination: The Four Legal Gates
EXECUTIVE BLUF: Intentional selection for death does not automatically constitute assassination. The decisive legal test is whether an operation successfully navigates four sequential gates: territorial authority (UN Charter/Article 51), armed-conflict classification (IHL vs. law enforcement), lawful target status (distinction rules), and attack execution (proportionality and precautions).
The Four Legal Gates Determining Intentional Lethal Force
An intentional state killing outside its own territory must survive four sequential legal tests: territorial authority (UN Charter/Article 51), armed-conflict existence (IHL vs. policing), lawful target status (distinction rules), and attack execution (proportionality and precautions). Failure at any gate transforms the operation into an unlawful use of force or arbitrary deprivation of life.
| Legal Gate | Controlling Question | Principal Legal Regime | Consequence if Gate Fails |
|---|---|---|---|
| Territorial Authority | Was the state entitled to use force on that territory? | UN Charter, consent, self-defence | Violation of sovereignty & Article 2(4) |
| Conflict Classification | Was an armed conflict legally in existence? | International humanitarian law (IHL) | Law-enforcement/human rights standards control |
| Target Status | Was this individual lawfully subject to direct attack? | IHL distinction rules or human rights | Unlawful attack or arbitrary deprivation of life |
| Attack Execution | Was the particular attack carried out lawfully? | Proportionality, precautions, necessity | War crime, unlawful homicide, or wrongful force |
| Operational Question | Armed-Conflict Paradigm | Peacetime / Law-Enforcement Paradigm |
|---|---|---|
| Force directed because of status? | Yes, against lawful military targets under IHL | Ordinarily no |
| Must target pose imminent threat? | Not necessarily for lawful combatants | Lethal force requires imminent threat to life |
| Must arrest be attempted? | No general IHL rule requiring capture | Arrest and non-lethal alternatives are central |
| Governing Incidental Deaths | Proportionality and feasible precautions | Much narrower necessity requirements apply |
Jus ad Bellum vs. Jus in Bello
Target status cannot cure a sovereignty defect. An attack can comply with IHL while the interstate use of force through which it was conducted remains an unlawful violation of Article 2(4).
Extraterritorial Human Rights
Germany’s July 2025 Ramstein judgment established that territorial infrastructure and communications relays can generate legal scrutiny for remote lethal operations abroad.
Law vs. Discretionary Policy
Distinguishing statutory authorization (2001 AUMF) and treaty obligations from shifting presidential targeting memorandums (restored in February 2026).
- Targeting Directives: Full operational rules of engagement and intelligence thresholds remain classified across Western states.
- Unable/Unwilling Consensus: Broad international acceptance of unilateral force against non-state actors remains unsettled.
- Enabler Responsibility: Precise legal boundaries where intelligence-sharing or relay infrastructure creates direct complicity.
- ICJ Jurisprudence: Authoritative international tribunal rulings clarifying self-defence against non-state groups.
- Executive Policy Shifts: Subsequent modifications to U.S. direct-action policy standards following the February 2026 report.
- European Court Rulings: Expanding ECHR extraterritorial jurisdiction rulings regarding remote warfare infrastructure.
The state record beyond the headline
Principal judgment: Once the legal categories examined in the preceding chapter are set aside and the record is reconstructed solely from official documents, the observable picture becomes markedly less symmetrical than political rhetoric often suggests, because the United States, United Kingdom and France have publicly acknowledged selected lethal operations against identified terrorist leaders or operational figures; Russia is associated with both final judicial findings of state attribution and newer criminal allegations concerning murder-for-hire and attacks abroad; China is documented through convictions, guilty pleas and indictments concerning surveillance, coercive repatriation and intelligence-directed transnational repression but, on the verified public record reviewed here, not through an equivalent series of adjudicated overseas political killings; Iran, India, Saudi Arabia and North Korea provide additional official cases demonstrating that extraterritorial lethal coercion cannot be reduced to a Russia-versus-West paradigm, while the evidentiary status of each case must remain visible because an intelligence assessment, governmental attribution, indictment, guilty plea and final judicial judgment do not establish the same proposition.
This chapter therefore does not attempt to decide which state is “worse,” nor does it construct an artificial league table of assassinations for which no internationally harmonised dataset exists; instead, it reconstructs the state record by asking a narrower question that can actually be audited: what precisely has a government acknowledged, what has a court established, what has prosecutors alleged, what has an intelligence service assessed, and what remains unproven in the public domain?
The evidentiary architecture matters more than the headline
Official records concerning targeted violence abroad fall into materially different evidentiary classes, and those distinctions should remain attached to every claim because a government announcing that it killed an individual establishes attribution to itself but not necessarily the legality of the operation, while an indictment establishes that prosecutors believe sufficient evidence exists to charge a defendant but does not establish guilt, and a final judgment following adversarial proceedings carries a different evidentiary meaning from either category.
| Evidentiary category | What the official record establishes | What it does not automatically establish | Representative cases in this chapter |
|---|---|---|---|
| First-party acknowledgement | State admits conducting or participating in lethal operation | International legality, accuracy of every intelligence claim, proportionality | U.S. al-Zawahiri operation; UK Reyaad Khan strike; French Barkhane leadership strikes |
| Final judicial finding | Court has adjudicated facts under defined legal standard | Every wider allegation about state strategy | Carter v. Russia; Berlin Tiergarten murder |
| Criminal conviction / guilty plea | Individual criminal liability established | Complete responsibility of every government official allegedly involved | Iranian operative Asif Merchant; Nikhil Gupta; PRC-linked Operation Fox Hunt defendants |
| Criminal indictment | Formal prosecutorial allegation supported sufficiently to charge | Guilt or final state attribution | September 2026 Russian intelligence-network case |
| Official intelligence assessment | Intelligence community has reached stated analytic conclusion | Judicially adjudicated proof | ODNI Khashoggi assessment |
| Executive attribution | Government has publicly attributed conduct on intelligence or security grounds | Independent judicial confirmation | UK Salisbury attribution |
| Official unresolved assessment | Government acknowledges uncertainty, error, or incomplete evidence | Definitive determination | U.S. Kabul 29 August 2021 strike investigation |
The methodological implication is substantial because political debate frequently flattens these categories into a single declarative vocabulary, whereas a government intelligence assessment that an operation was state-approved, a court judgment that particular individuals acted as agents of a state, and an indictment alleging a conspiracy to commit murder-for-hire occupy different procedural positions even when they point toward similar geopolitical conclusions.
United States: the clearest record of openly acknowledged individual lethal targeting
The United States differs from most states examined here because official records contain repeated public acknowledgements of individually focused lethal operations conducted by military or intelligence-supported counterterrorism capabilities, while annual civilian-casualty reporting and post-strike investigations provide at least a partial quantitative record that is simply unavailable for many other states.
A particularly clear contemporary example is the 31 July 2022 strike against Ayman al-Zawahiri in Kabul, which the Department of Defense publicly described as an “over-the-horizon” counterterrorism operation in which two Hellfire missiles struck the al-Qaida leader at 06:18 Kabul time, with the administration assessing that Zawahiri was the only casualty; the official account emphasised that multiple intelligence streams had been used to establish his presence and that the operation took place nearly one year after the withdrawal of U.S. military forces from Afghanistan, making it an unusually explicit example of lethal reach beyond a continuing conventional troop deployment. U.S. Drone Strike Kills al-Qaida Leader in Kabul — Department of Defense
The October 2019 operation against Abu Bakr al-Baghdadi illustrates a different operational model because U.S. Central Command described it as a special-operations raid developed once actionable intelligence located the ISIS leader, with the plan explicitly designed to capture or kill him; CENTCOM reported that eleven children were removed from danger, two men were detained, five ISIS members who presented a threat were killed, and Baghdadi detonated a suicide device when U.S. forces closed on him, killing himself and two children, while the Pentagon subsequently used DNA to confirm his identity. Central Command Chief Gives Details on Baghdadi Raid — Department of Defense
The significance of these operations is not that every U.S. counterterrorism action can therefore be presumed accurate, because the U.S. government’s own investigations demonstrate the opposite; the 29 August 2021 Kabul drone strike is the most important counterexample, since U.S. Central Command initially believed it had struck an imminent ISIS-K threat but later concluded that the vehicle and deceased individuals were unlikely to have been associated with ISIS-K, acknowledged that up to ten civilians, including as many as seven children, had been killed, and described the operation as a mistake resulting from erroneous interpretation of intelligence, confirmation bias and communication failures. CENTCOM briefing on the 29 August Kabul strike — Department of Defense
That episode is unusually valuable for institutional analysis because the same government that conducts targeted operations also generated an official record contradicting its own initial operational assessment, thereby providing a documented example of why first reports, battlefield intelligence and later investigations cannot be treated as evidentially interchangeable.
Selected acknowledged U.S. individual-target operations
| Date | Target | Location | Operational form | Officially reported immediate result | Evidentiary status |
|---|---|---|---|---|---|
| Oct 2019 | Abu Bakr al-Baghdadi | Idlib province, Syria | Special operations raid | Baghdadi died by suicide device as capture became imminent; five ISIS members killed; 11 children protected; 2 detainees extracted | Publicly acknowledged by DoD/CENTCOM |
| Jan 2020 | Qasem Soleimani | Baghdad, Iraq | Precision strike | Soleimani and accompanying personnel killed | Publicly acknowledged by DoD |
| Aug 2021 | Suspected ISIS-K target | Kabul, Afghanistan | UAV strike | 10 civilians later assessed killed; intended target assessment proved erroneous | Publicly acknowledged operational error |
| Jul 2022 | Ayman al-Zawahiri | Kabul, Afghanistan | Two Hellfire missiles | Zawahiri killed; U.S. assessed no additional casualties | Publicly acknowledged by DoD |
The U.S. documentary record is also comparatively rich because civilian-harm reporting creates a measurable, albeit incomplete, transparency layer; the Department of Defense’s report covering calendar year 2024 assessed that U.S. military operations had resulted in two civilians killed and two civilians injured, while stating that the report covers only civilian casualties attributed to U.S.-operated weapons and uses a “more likely than not” evidentiary threshold for confirmed civilian casualty assessments. Annual Report on Civilian Casualties in U.S. Military Operations in 2024 — Department of Defense
This reporting architecture should not be mistaken for a complete database of targeted killings because the casualty reports aggregate military operations rather than provide a global registry of named-person strikes, while intelligence operations, classified activities and foreign-partner actions can fall outside the publicly visible denominator; nevertheless, the Department of Defense now maintains annual civilian-casualty reports for successive years, producing a degree of official quantitative traceability absent from many comparable national systems. Civilian Harm Mitigation and Response reporting archive — Department of Defense
The current policy framework further confirms continuity rather than abandonment of direct-action capability, because the White House’s February 2026 report to Congress states that President Trump rescinded the October 2022 Biden Presidential Policy Memorandum on 30 January 2025 and reinstated the first Trump administration’s Principles, Standards, and Procedures for U.S. Direct Action Against Terrorist Targets, while reporting no change to the scope of the 2001 Authorization for Use of Military Force and no change to the categories for which force could legally be used under that statute. Report on the Legal and Policy Frameworks for the United States’ Use of Military Force — White House, February 2026
What the U.S. record actually supports
| Proposition | Status in official record |
|---|---|
| United States possesses a standing capability to identify and lethally strike individuals overseas | Established by repeated first-party acknowledgement |
| United States has used this capability after conventional troop withdrawals | Established, including al-Zawahiri strike in Afghanistan |
| Targeting intelligence is infallible | Contradicted by official U.S. investigations, notably Kabul 2021 |
| Every targeted strike is publicly disclosed | Not established |
| Official casualty numbers constitute a complete total of all U.S. targeted killings | Not established |
| U.S. lethal targeting can be quantitatively compared directly with every other major power | Not supportable from current official reporting systems |
Russia: from final European judicial attribution to a new U.S. murder-for-hire indictment
The Russian record differs fundamentally from the U.S. documentary pattern because the most consequential public cases concern covert or deniable operations uncovered by foreign police, courts, public inquiries or intelligence agencies rather than operations publicly acknowledged by Moscow as state policy.
The Alexander Litvinenko case has moved well beyond the level of political accusation because the European Court of Human Rights’ judgment in Carter v. Russia, delivered on 21 September 2021 and final on 28 February 2022, held by six votes to one that Russia had violated Article 2 of the European Convention on Human Rights in both its substantive and procedural dimensions; the Court found a strong prima facie case that Andrey Lugovoy and Dmitriy Kovtun had been acting as agents of the Russian state in poisoning Litvinenko with polonium-210 and concluded that the Russian government had failed to provide a satisfactory alternative explanation capable of rebutting that case. Carter v. Russia — European Court of Human Rights
The case file itself documents an unusually extensive forensic chain, including radioactive contamination detected across hotels, aircraft, offices and the teapot from which Litvinenko drank, while the post-mortem attributed death to acute radiation syndrome caused by ingestion of polonium-210; British investigators had examined more than 60 locations and issued more than 40 requests for mutual legal assistance to 15 states, demonstrating that the eventual state-attribution judgment rested on an evidentiary process far more developed than an initial intelligence allegation.
Russia did not simply remain absent from the proceedings, because the ECHR judgment records Russian investigative activity, Russian arguments and the refusal to extradite Lugovoy on constitutional grounds; the Court nevertheless found that the authorities had failed to conduct an effective investigation capable of meeting Russia’s Article 2 procedural obligations.
The Berlin Tiergarten murder supplies a separate and independent judicial strand because the Kammergericht convicted Vadim K. in December 2021 for the 23 August 2019 murder of Tornike K. in Berlin and concluded after a 14-month trial that the killing had been carried out on behalf of Russian state authorities; the judgment became final on 27 December 2021 because none of the parties appealed. Urteil zum „Tiergartenmord“ rechtskräftig — Berlin judiciary
The Salisbury poisoning occupies a different evidentiary tier because the British government publicly concluded in September 2018 that the two men charged by British prosecutors were officers of the GRU and assessed, on the basis of intelligence that could not be fully disclosed, that the operation was almost certainly approved outside the GRU at a senior level of the Russian state; this is therefore a high-level executive and intelligence attribution accompanied by criminal charges, but not a final criminal judgment against the alleged Russian operatives because they did not stand trial in Britain. Prime Minister’s statement on the Salisbury investigation — GOV.UK
The newly unsealed 15 September 2026 U.S. indictment represents a fourth category because the Department of Justice alleges that five individuals working for Russian intelligence services participated in a network that paid or attempted to pay persons in the United States and elsewhere to conduct surveillance and targeted killings and commissioned attacks against civilian and military infrastructure in European countries associated with support for Ukraine; crucially, the DOJ explicitly states that the defendants remain at large and that the indictment contains accusations that have not yet been proved beyond a reasonable doubt. Members of Russian Intelligence Services Network Charged with Conspiring to Finance Terrorism and Commit Murder for Hire — Department of Justice, 15 September 2026
Russia-related official record by evidentiary status
| Case | Event date | Official institution | What is established | What remains unresolved |
|---|---|---|---|---|
| Litvinenko | 2006 | European Court of Human Rights | Agents responsible for poisoning attributable to Russian state; Article 2 violation | Full internal Russian command chain beyond findings in public record |
| Tiergarten | 2019 | Kammergericht Berlin | Defendant committed murder on behalf of Russian state authorities | Complete sponsoring hierarchy remains non-public |
| Salisbury | 2018 | UK government / CPS / intelligence agencies | Suspects charged; UK concluded they were GRU officers and assessed senior state approval | No British criminal trial of accused officers |
| 2026 Russian network | Alleged activity through 2026 | U.S. DOJ/FBI | Formal indictment alleging intelligence-linked murder-for-hire and terrorism conspiracy | All substantive criminal allegations await adjudication |
This distinction is critical because the Litvinenko and Tiergarten records cannot properly be described merely as Western allegations, whereas the September 2026 indictment cannot properly be described as established proof simply because the underlying allegations are grave; neutral analysis requires preserving both propositions simultaneously.
China: a substantial transnational-repression record, but a different public lethal profile
The available Chinese record is extensive in relation to surveillance, intimidation, infiltration and coercive repatriation, and several elements have moved beyond indictment into conviction and sentencing, but the official material examined does not presently establish a directly comparable pattern of adjudicated overseas killings attributable to Chinese state organs.
The clearest trial-tested example is Operation Fox Hunt, where a federal jury convicted former New York police officer Michael McMahon and co-defendants in June 2023 in connection with a scheme to locate, monitor, harass and coerce a U.S. resident to return to China, after which McMahon was sentenced in April 2025 to 18 months’ imprisonment and an $11,000 fine, Zhu Yong had earlier received 24 months, and Congying Zheng 16 months; the Justice Department states that trial evidence proved that the campaign operated on behalf of PRC officials as part of China’s international repatriation programme. Private Investigator Sentenced for Operation Fox Hunt Activities — Department of Justice
A separate Operation Fox Hunt proceeding resulted in Quanzhong An receiving a 20-month prison sentence in March 2025, together with approximately $5 million in financial penalties, including roughly $1.3 million in restitution, after pleading guilty to acting as an illegal PRC agent in a campaign intended to coerce a U.S. resident’s repatriation. Leader of Multi-Year Operation Fox Hunt Campaign Sentenced — Department of Justice
The espionage and dissident-monitoring dimension is equally well documented because Shujun Wang was convicted on all four counts in August 2024 after prosecutors showed that he had cultivated relationships with Chinese democracy activists while secretly reporting to officials of the Ministry of State Security; the case therefore moved beyond a general assertion that Chinese security services monitor diaspora communities and into a federal jury verdict against an identified covert agent. Queens Resident Convicted of Acting as a Covert Chinese Agent — Department of Justice
Another defendant, Tang Yuanjun, pleaded guilty after acknowledging activity from at least 2018 to June 2023 in which he collected information on U.S.-based democracy activists and other persons regarded as adverse to PRC interests and transmitted names, photographs, recordings and other information to the Ministry of State Security. Man Pleads Guilty to Conspiring to Act as Illegal Agent of the Chinese Government — Department of Justice
The network remains operationally relevant rather than purely historical, because in July 2025 U.S. authorities arrested Yuance Chen and Liren Lai on allegations that they had overseen clandestine intelligence tasking in the United States on behalf of the MSS, although those allegations must remain procedurally distinct from the convictions described above. Justice Department Charges Two Individuals with Acting as Agents of the PRC Government — July 2025
China-related cases: what the official record proves
| Case / programme | Conduct established or alleged | Procedural status | State nexus described by U.S. authorities |
|---|---|---|---|
| Operation Fox Hunt — McMahon/Zhu/Zheng | Surveillance, stalking, harassment, coercive repatriation | Jury convictions and sentences | Conduct undertaken at direction of PRC officials |
| Operation Fox Hunt — Quanzhong An | Coercive repatriation campaign | Guilty plea and sentence | PRC-directed extralegal repatriation effort |
| Shujun Wang | Collection on democracy activists | Jury conviction | MSS officials identified as handlers/co-defendants |
| Tang Yuanjun | Reporting on dissidents, demonstrations and activists | Guilty plea | MSS direction acknowledged |
| Chen/Lai network | Alleged clandestine intelligence activity | Criminal charges | Alleged MSS network |
The evidentiary conclusion is therefore narrower than either pole of contemporary political rhetoric, because it would be inaccurate to dismiss concerns about Chinese transnational repression as merely unverified intelligence messaging when federal convictions and guilty pleas exist, yet it would be equally inaccurate to transform proven surveillance, stalking and coercion cases into an unsupported assertion that China maintains the world’s second-largest programme of extraterritorial targeted killings.
United Kingdom: public acknowledgement, ministerial authorization and classified intelligence review
The British official record contains one of the clearest examples of a democratic government acknowledging an intentionally selected overseas target outside its then-existing participation in coalition air operations over Syria, because Prime Minister David Cameron informed Parliament that Reyaad Khan was killed on 21 August 2015 by an RAF remotely piloted aircraft near Raqqa, while two additional ISIL associates, including British national Ruhul Amin, were also killed. Syria: refugees and counter-terrorism — Prime Minister’s statement, 7 September 2015
The British government did not present this merely as an incidental battlefield casualty because the Prime Minister stated that the intelligence agencies had identified Khan as a direct threat, that senior members of the National Security Council had decided the military should act when an opportunity arose, that the Attorney General had confirmed a legal basis, and that the Defence Secretary had authorised the operation; notably, Cameron explicitly described it as a “targeted strike” rather than part of the coalition air campaign then being conducted against ISIL in Syria.
Subsequent parliamentary intelligence oversight added an evidentiary layer not normally available in public debate because the Intelligence and Security Committee reviewed classified reporting and concluded that there was “no doubt” that Khan posed a very serious threat to the United Kingdom, while the Committee deliberately refrained from reaching its own legal conclusion on the strike; this separation between intelligence assessment and legal adjudication is precisely the type of distinction necessary for a government-grade evidentiary record. Government response concerning Intelligence and Security Committee review of the Khan strike — UK Parliament
Britain also participated in the intelligence effort surrounding Mohammed Emwazi, whom Prime Minister Cameron publicly stated had been targeted by a U.S. airstrike in Raqqa on 12 November 2015, although at the time of his initial statement the government had not yet confirmed whether the strike had succeeded; the record therefore shows British involvement in targeting-related intelligence without falsely reclassifying a U.S. strike as a British kinetic operation. PM statement on United States air strike in Syria — GOV.UK
British official record
| Event | British role | What is publicly established | What remains classified or unresolved |
|---|---|---|---|
| Reyaad Khan, Aug 2015 | RAF executed strike | Target selected; NSC involvement; Attorney General legal advice; Defence Secretary authorization | Detailed intelligence and full legal advice remain classified |
| Junaid Hussain, Aug 2015 | U.S. executed strike | UK publicly confirmed U.S. operation against British national | Full intelligence-sharing architecture |
| Mohammed Emwazi, Nov 2015 | U.S. executed strike with British pursuit/intelligence involvement | Cameron acknowledged UK effort to locate him and U.S. kinetic action | Complete intelligence contribution |
The British record therefore establishes a capacity for deliberate individual targeting and multinational intelligence support, but it remains much thinner quantitatively than the U.S. record and should not be converted into speculative totals.
France: leadership decapitation documented through operational communiqués
France’s official military record demonstrates sustained efforts against the leadership structures of jihadist organisations in the Sahel, with the Ministry of the Armed Forces regularly using the term “neutralisation” to describe killing or incapacitating targeted armed-group members, while operational communiqués identify particular leaders and describe the intelligence and strike architecture used against them.
On 3 June 2020, French forces in Operation Barkhane killed Abdelmalek Droukdel, emir of al-Qaida in the Islamic Maghreb, near Tessalit in Mali after what the Ministry described as a multi-day operation concluding in an assault by French forces; the communiqué states that no French soldiers were wounded. Point de situation des opérations du 05 au 11 juin 2020 — Ministère des Armées
The operation against Adnan Abu Walid al-Sahraoui, leader of Islamic State in the Greater Sahara, provides even greater operational detail because France states that the August 2021 action followed an extended intelligence process, combined air and ground components, armed drones and Mirage 2000D aircraft, while airstrikes were released only after targets had been identified as EIGS elements; French authorities subsequently confirmed that al-Sahraoui was among those killed. Neutralisation d’Abou Walid Al-Sahraoui — Ministère des Armées
French official material subsequently identified additional leadership removals during 2021, including Almahmoud ag Baye (“Ikaray”), Issa al-Sahraoui, Abou Abderahmane al-Sahraoui and Soumana Boura, while differentiating captured individuals such as Dadi Ould Chaib from those described as neutralised; that distinction is useful because it confirms that French operational reporting does not mechanically use “neutralisation” as a synonym for arrest. French Armed Forces operational summary — March 2022
Selected named French counterterrorism targets in the official record
| Individual | Organisation / role stated by France | Date / period | Outcome recorded by French authorities |
|---|---|---|---|
| Abdelmalek Droukdel | AQIM emir | 3 Jun 2020 | Killed during French assault |
| Almahmoud ag Baye (“Ikaray”) | Senior EIGS figure | Jun 2021 | Neutralised |
| Issa al-Sahraoui | EIGS logistics/finance coordinator and senior Mali leader | Jul 2021 | Neutralised |
| Abou Abderahmane al-Sahraoui | Senior EIGS judicial figure | Jul 2021 | Neutralised |
| Adnan Abu Walid al-Sahraoui | EIGS emir | Aug 2021 | Neutralised in Barkhane operation |
| Soumana Boura | EIGS group leader | Dec 2021 | Neutralised in coordination with Niger |
The French record therefore substantiates a strategy that included systematic pressure on high-level armed-group leadership rather than merely anonymous battlefield attrition, while the Ministry’s own operational documents describe the process as intelligence-led and integrated with drones, aircraft, ground forces and partner armies.
What the public record does not establish is a comprehensive French register of all deliberately targeted individuals, because operational communiqués are selective, terminology varies and classified special-operations activity remains outside ordinary public documentation; a total count would therefore create false precision.
Germany: primarily a jurisdiction of attribution, prosecution and enabling-infrastructure scrutiny
Germany’s official record is markedly different because the most consequential cases reviewed here concern foreign killings on German territory and Germany’s relationship to allied targeting infrastructure rather than publicly acknowledged German targeted-killing operations abroad.
The Tiergarten judgment establishes the first dimension, while the Federal Constitutional Court’s 15 July 2025 Ramstein decision establishes the second by recording that technical facilities at Ramstein played a central role in transmitting signals for U.S. armed-drone operations in Yemen; the Court ultimately rejected the constitutional complaint but held that Germany’s fundamental-rights protective mandate can under certain circumstances extend to foreign nationals abroad where threats have a sufficient nexus to German sovereign power. Judgment of 15 July 2025 — Federal Constitutional Court of Germany
The underlying German judicial findings described in that judgment are unusually detailed because the Higher Administrative Court had concluded that the Ramstein satellite relay constituted the necessary link between U.S.-based operators and drones operating in relevant theatres and had identified indications of possible international-law concerns in earlier operations, although the Constitutional Court ultimately held that the federal government’s protective response remained within constitutionally permissible bounds.
Germany therefore should not be inserted mechanically into a list of states conducting assassinations simply because its territory has formed part of allied communications architecture, since the official record supports a more precise conclusion: Germany has simultaneously been a victim jurisdiction of a judicially established Russian state-directed killing and a host jurisdiction whose infrastructure has supported U.S. remote-strike operations, two facts carrying distinct forms of state responsibility and strategic exposure.
Iran: the record has moved from allegation to conviction
Iran is particularly important because several U.S. cases no longer rest solely on intelligence attribution, and the March 2026 conviction of Asif Merchant provides a trial-tested example of a political assassination plot with a documented Iranian-state nexus.
A federal jury convicted Merchant of murder-for-hire and attempting to commit terrorism transcending national boundaries after evidence established that he travelled to the United States in April 2024, met people he believed to be hired assassins in June, and was arrested before leaving the country in July; according to the Department of Justice, Merchant acknowledged at trial that the Islamic Revolutionary Guard Corps had sent him to the United States to arrange political assassinations and steal documents. Iranian Intelligence Agent Convicted of Terrorism and Murder for Hire — Department of Justice, March 2026
That conviction sits alongside the 2022 case against Shahram Poursafi, an alleged IRGC member whom U.S. prosecutors accused of attempting to arrange the murder of former National Security Adviser John Bolton, with the complaint alleging that he sought to pay individuals in the United States to execute the killing, reportedly in retaliation for the January 2020 killing of Qasem Soleimani. IRGC Member Charged with Plot to Murder Former National Security Adviser — Department of Justice
Iran-linked U.S. cases
| Defendant | Target category | Status | State nexus in official record |
|---|---|---|---|
| Asif Merchant | U.S. politicians / officials | Federal jury conviction, Mar 2026 | DOJ states he was an Iranian intelligence operative and acknowledged IRGC direction |
| Shahram Poursafi | Former U.S. National Security Adviser John Bolton | Charged, remains allegation unless adjudicated | DOJ identifies defendant as IRGC member |
This distinction matters because Merchant’s conviction establishes individual criminal responsibility through trial, whereas Poursafi’s alleged conduct remains an accusation despite the official attribution.
India: guilty plea confirms the murder-for-hire conspiracy while broader state responsibility remains procedurally separate
The India-linked New York case is another important example of why evidentiary status has to be disaggregated, because Nikhil Gupta pleaded guilty on 13 February 2026 to all three counts—murder-for-hire, conspiracy to commit murder-for-hire and conspiracy to commit money laundering—in connection with a plan to kill a U.S.-based Sikh separatist leader. Indian National Pleads Guilty to Plotting to Assassinate U.S. Citizen in New York City — Department of Justice
The Justice Department states that Gupta acted at the direction of an Indian government employee, a proposition that remains connected to the separate prosecution and allegations surrounding that official rather than being transformed by Gupta’s guilty plea into an adjudication of every level of Indian governmental responsibility; the case therefore establishes the existence of the criminal conspiracy and Gupta’s participation while leaving the wider command chain subject to its own evidentiary process.
This case is analytically significant because it demonstrates that alleged state-linked assassination activity cannot be mapped cleanly onto familiar geopolitical antagonisms, while its procedural development from indictment to guilty plea materially increases the amount of conduct that can now be stated as established fact rather than prosecutorial allegation.
Saudi Arabia: a declassified intelligence assessment rather than a judicial finding
The killing of Jamal Khashoggi in Istanbul on 2 October 2018 occupies a separate evidentiary category because the United States released a declassified intelligence-community assessment rather than a judicial judgment establishing responsibility.
The Office of the Director of National Intelligence assessed in 2021 that Saudi Crown Prince Mohammed bin Salman approved an operation to capture or kill Khashoggi, basing the conclusion on his control over Saudi security and intelligence institutions, participation by a close adviser and members of his protective detail, and previous support for coercive measures against dissidents abroad; the assessment identified a 15-member Saudi team, including seven members of the Rapid Intervention Force, as part of the operation. Assessing the Saudi Government’s Role in the Killing of Jamal Khashoggi — Office of the Director of National Intelligence
ODNI also explicitly preserved uncertainty by stating that the U.S. intelligence community did not know how far in advance Saudi officials decided that Khashoggi would be harmed and could not establish that every participant knew beforehand that the operation would end in his death, an important qualification that prevents the assessment from being rewritten into a more precise command-order narrative than the intelligence record actually supports.
Khashoggi assessment: what is and is not established by the ODNI document
| Proposition | ODNI position |
|---|---|
| Crown Prince approved an operation concerning Khashoggi | Assessed yes |
| Intended operational options included capture or killing | Assessed yes |
| 15-member Saudi team involved | Documented in assessment |
| Seven members belonged to Crown Prince’s protective detail | Documented in assessment |
| Every participant knew beforehand Khashoggi would be killed | Not established |
| Exact timing of decision to inflict lethal harm | Not established |
| Equivalent of a judicial conviction of Crown Prince | No |
North Korea: formal U.S. state attribution to chemical assassination
North Korea supplies one of the clearest examples of an official state attribution involving a prohibited toxic agent because the U.S. Department of State formally determined under the Chemical and Biological Weapons Control and Warfare Elimination Act that the North Korean government used the chemical warfare agent VX to assassinate Kim Jong Nam at Kuala Lumpur International Airport, with the determination made on 22 February 2018 and sanctions taking effect following Federal Register publication on 5 March. Imposition of Chemical and Biological Weapons Control and Warfare Elimination Act Sanctions on North Korea — U.S. Department of State
The evidentiary category remains an executive governmental determination rather than an international judicial ruling, but it is considerably more specific than an anonymous intelligence allegation because it constituted the statutory basis for formal U.S. sanctions action.
Cross-state evidentiary comparison
The cases can now be compared without pretending that their legal or procedural status is identical.
| State associated with conduct | Representative case | Host jurisdiction | Conduct | Highest public evidentiary status identified | Date of latest decisive official record used here |
|---|---|---|---|---|---|
| United States | al-Zawahiri | Afghanistan | Direct lethal counterterrorism strike | First-party acknowledgement | 2022 |
| United States | Kabul mistaken strike | Afghanistan | Erroneous UAV strike | First-party acknowledgement + official investigation | 2021 |
| Russia | Litvinenko | UK | Poisoning with polonium-210 | Final ECHR judgment attributing conduct to Russian agents | Final 2022 |
| Russia | Tiergarten | Germany | Firearm assassination | Final German criminal judgment finding Russian-state commission | 2021 |
| Russia | 2026 intelligence network | U.S./Europe | Alleged murder-for-hire / sabotage | Federal indictment | 2026 |
| China | Operation Fox Hunt | United States | Surveillance, coercion, stalking, forced repatriation | Jury convictions / guilty pleas | 2023–2025 |
| China | Shujun Wang | United States | Covert collection against dissidents | Jury conviction | 2024 |
| United Kingdom | Reyaad Khan | Syria | RAF targeted drone strike | First-party acknowledgement + classified parliamentary review | 2015–2017 |
| France | Droukdel / al-Sahraoui | Mali/Sahel | Targeted counterterrorism operations | First-party military acknowledgement | 2020–2022 |
| Iran | Asif Merchant | United States | Political murder-for-hire plot | Federal jury conviction | 2026 |
| India-linked | Nikhil Gupta | United States | Murder-for-hire conspiracy | Guilty plea | 2026 |
| Saudi Arabia | Khashoggi | Turkey | Capture-or-kill operation | Declassified U.S. intelligence assessment | 2021 |
| North Korea | Kim Jong Nam | Malaysia | VX assassination | Formal U.S. statutory state attribution | 2018 |
The table demonstrates why a single numerical ranking would be analytically defective, because the underlying universe contains battlefield counterterrorism strikes, clandestine murders, attempted assassinations, coercive repatriation campaigns and intelligence-community assessments, while different governments disclose dramatically different fractions of their activities.
The numbers that can safely be used
The official record does contain quantitative information, but only in tightly defined contexts where the denominator and issuing institution remain explicit.
| Indicator | Verified value | Period / event | Issuing authority | Limitation |
|---|---|---|---|---|
| U.S. civilian casualties assessed from U.S. military operations | 2 killed; 2 injured | Calendar year 2024 | Department of Defense | Covers U.S.-operated weapons under DoD reporting methodology, not all covert activity |
| Baghdadi raid | 11 children protected; 2 detainees extracted; 5 threatening ISIS members killed; Baghdadi + 2 children died in his explosion | Oct 2019 | CENTCOM / DoD | Single operation |
| Kabul mistaken strike | 10 civilians killed, including up to 7 children | 29 Aug 2021 | CENTCOM / Air Force investigation | Revised assessment after initial misidentification |
| Litvinenko investigation | 60+ scenes examined; 40+ mutual legal-assistance requests; 15 states contacted | 2006 onward | ECHR record of UK investigation | Investigative workload, not assassination frequency |
| Operation Fox Hunt McMahon sentence | 18 months + $11,000 fine | Apr 2025 | U.S. DOJ | One defendant |
| Operation Fox Hunt An sentence | 20 months; ≈$5m financial penalty; ≈$1.3m restitution | Mar 2025 | U.S. DOJ | One defendant |
| Khashoggi Saudi team | 15 members; 7 from Rapid Intervention Force | Oct 2018 | ODNI | Intelligence assessment |
| Russian 2026 indictment | 5 defendants | Sep 2026 | DOJ/FBI | Charges only |
| French Barkhane force during 2020 operations | approximately 5,100 personnel | 2020 | French Armed Forces | Theatre force size, not targeting unit size |
These data are decision-useful precisely because they are not mixed into a false global total, while any attempt to calculate a worldwide “share of targeted killings by country” from such inputs would violate basic quantitative integrity because the units of observation, disclosure practices, legal categories and time horizons are incompatible.
What the official record says about operational methods
A second cross-country distinction emerges from method and institutional architecture rather than legal doctrine, because the publicly documented mechanisms range from openly acknowledged military platforms to covert agents, criminal intermediaries and toxic substances.
| State / case | Instrument or method | Intermediary structure | Degree of public acknowledgement |
|---|---|---|---|
| United States — al-Zawahiri | UAV + Hellfire missiles | Military/intelligence targeting architecture | Direct acknowledgement |
| United States — Baghdadi | Special operations assault | CENTCOM/interagency intelligence | Direct acknowledgement |
| United Kingdom — Khan | RAF Reaper + Hellfire missile | Intelligence agencies, NSC, military command | Direct acknowledgement |
| France — Barkhane leaders | Aircraft, armed drones, ground commandos | French forces + partner-state forces | Direct acknowledgement |
| Russia — Litvinenko | Polonium-210 | Two identified operatives attributed by ECHR to Russian state | Denied by Russia; attribution judicially established by ECHR |
| Russia — Tiergarten | Firearm assassination | Individual operative acting for Russian state authorities | State role established by German court |
| Russia — 2026 indictment | Alleged hired killers / surveillance / sabotage intermediaries | Alleged intelligence network | Russian state not acknowledging; U.S. prosecution pending |
| China — Operation Fox Hunt | Surveillance, stalking, coercive family pressure | Private investigators, intermediaries, PRC officials | State-directed conduct established in U.S. prosecutions |
| Iran — Merchant | Intended hired killers | Operative engaging purported hitmen | Criminal conviction |
| India-linked Gupta case | Murder-for-hire arrangement | Criminal intermediary | Gupta guilt established; broader state responsibility separately alleged |
| Saudi Arabia — Khashoggi | Consular operation | 15-person team, including protective-detail personnel | ODNI intelligence assessment |
| North Korea — Kim Jong Nam | VX nerve agent | Operatives acting abroad | U.S. formal state attribution |
The operational picture therefore shows two partially overlapping systems of state violence: highly institutionalised military targeting, where governments often possess command structures, rules of engagement and formal targeting processes, and deniable extraterritorial coercion, where intelligence services or government-linked actors rely on covert operatives, proxies, private investigators or criminal intermediaries, thereby creating different evidentiary and counter-intelligence challenges even when the strategic objective is similarly focused on a named individual.
Denial, acknowledgement and evidentiary asymmetry
The degree of disclosure is itself strategically significant because acknowledged military operations generate a paper trail containing command statements, parliamentary oversight, casualty reviews and sometimes operational statistics, whereas clandestine intelligence operations are designed specifically to defeat attribution and therefore become visible disproportionately when they fail, when perpetrators are arrested, when defectors provide evidence, when forensic traces survive, or when courts compel disclosure.
This asymmetry means that the state with the largest visible record is not necessarily the state with the largest hidden record, while the reverse inference is equally invalid; the United States’ comparatively extensive acknowledged targeting archive cannot automatically prove numerical predominance over states whose operations remain classified, and the scarcity of publicly adjudicated Chinese or other cases cannot establish absence of clandestine activity.
The correct intelligence conclusion is therefore one of denominator uncertainty rather than agnosticism about everything: individual operations can be established with high confidence while global comparative frequencies remain fundamentally underdetermined.
The September 2026 Russian case should therefore be read precisely, not theatrically
The immediate case that triggered this assessment is significant because it alleges an operational model extending beyond surveillance into murder-for-hire, terrorist attacks and infrastructure targeting, while the Department of Justice states that five individuals connected to Russian intelligence services sought to pay people inside the United States and elsewhere for pre-operational surveillance and targeted killings and commissioned attacks against infrastructure in European countries supporting or perceived to support Ukraine. Members of Russian Intelligence Services Network Charged — Department of Justice, 15 September 2026
That case deserves close scrutiny because it is consistent in general character with previously established Russian extraterritorial activity, yet consistency with a historical pattern is not a substitute for proof of the present charges, while the defendants’ status as fugitives means that the evidentiary record available to the public is currently dominated by the indictment and prosecutorial account rather than by adversarial trial evidence.
The analytically disciplined formulation is therefore neither “the FBI has exposed another proven Russian assassination network” nor “this is merely American propaganda,” because the verified public record presently establishes a formal federal indictment containing serious intelligence-linked murder allegations, while guilt remains legally unresolved and must remain described as such until additional evidence emerges or a court adjudicates the charges.
Cross-national net assessment
The state record does not support the proposition that targeted overseas violence is a uniquely Russian practice, because the United States, United Kingdom and France openly acknowledge selected lethal operations directed at individually identified adversaries, while other governments—including Iran-linked actors and Indian-linked conspirators—appear in criminal proceedings involving political murder-for-hire, and Saudi Arabia and North Korea have been formally attributed by U.S. official institutions to high-profile extraterritorial killings.
It equally does not support the proposition that all such state conduct is operationally interchangeable, because the record contains sharply different mechanisms ranging from armed forces striking recognised terrorist leaders during military campaigns to intelligence-linked poisoning, coercive repatriation, clandestine shooting, consular killing and murder-for-hire conspiracies, while the evidentiary status ranges from voluntary governmental acknowledgement to final judicial attribution and untested indictment.
The United States therefore occupies a distinctive position in the public record not because an official dataset proves that Washington conducts more targeted killings than every other government combined, which no verified dataset establishes, but because the United States maintains one of the world’s most visible and formally articulated architectures for acknowledged extraterritorial counterterrorism lethality, supported by persistent military capability, interagency intelligence, direct-action policy frameworks and post-operation reporting.
Russia occupies a different position because two of the most important European cases—Litvinenko and Tiergarten—have crossed the threshold from intelligence or governmental accusation into judicially established state attribution, while the September 2026 American prosecution adds a new alleged network that remains unadjudicated and should therefore be tracked separately rather than fused into the older judgments.
China presents an extensive and demonstrable system of transnational coercive state activity, including covert intelligence collection, stalking and forced-repatriation schemes that have resulted in federal convictions and sentences in the United States, but the verified official record reviewed here does not support a quantitative claim placing Beijing immediately behind Washington or Moscow in extraterritorial political killings.
Britain and France openly document selected named-person lethal operations but provide much less comprehensive quantitative disclosure than the United States, while Germany’s principal significance in the examined record concerns exposure to Russian state-directed murder and legal responsibility associated with allied targeting infrastructure rather than an acknowledged German programme of individual overseas killing.
The wider comparison with Iran, India, Saudi Arabia and North Korea demonstrates why the phenomenon should be understood not as a simple conflict between “Western” and “non-Western” state behaviour but as a broader feature of contemporary statecraft in which military power, intelligence agencies, covert networks and criminal intermediaries increasingly overlap across borders.
Key judgments
The first decision-relevant judgment is that official attribution must be disaggregated by evidentiary status, because Carter v. Russia and the Tiergarten judgment permit substantially firmer factual language than the September 2026 Russian indictment, while the Khashoggi document remains an intelligence assessment and Chinese Operation Fox Hunt cases contain actual jury convictions and guilty pleas rather than merely executive assertions.
The second judgment is that acknowledgement and attribution are different analytical problems, because the United States, Britain and France openly acknowledge selected lethal military operations whereas the Russian cases primarily become visible through foreign investigation and adjudication, creating fundamentally different transparency profiles even before legality is considered.
The third judgment is that China’s documented transnational repression is extensive but should not be converted into an unsupported lethal ranking, since the available trial record establishes surveillance, intelligence direction, stalking, intimidation and coerced-repatriation activity but does not provide a comparable adjudicated body of overseas assassination cases.
The fourth judgment is that operational failure creates some of the most valuable official evidence, because the U.S. investigation of the August 2021 Kabul strike, failed or disrupted murder-for-hire plots in the United States, arrested Chinese-linked operatives and judicially reconstructed Russian cases provide visibility that successful clandestine operations deliberately attempt to prevent.
The fifth judgment is that no credible official-source methodology presently permits a defensible numerical ordering of the major powers by total targeted killings, because disclosure regimes, time horizons, operational definitions and institutional coverage differ too sharply for those numbers to be combined without manufacturing precision.
What would change the assessment
The assessment would materially change if the defendants in the September 2026 Russian case were arrested and evidence became available through motions, trial testimony, communications records or authenticated intelligence material capable of independently establishing the alleged command relationships, payment channels and operational tasking.
The assessment of China’s lethal overseas activity would change if courts, prosecutors or competent official investigations established specific cases in which PRC institutions directed or authorised homicide or attempted homicide abroad, rather than surveillance, coercion or repatriation alone.
The comparative assessment of Britain and France would change if either government released comprehensive historical targeting data comparable to the U.S. civilian-harm and direct-action record, because present French and British disclosures remain event-driven and do not permit robust frequency comparisons.
The U.S. assessment would change if current or future administrations substantially narrowed or expanded disclosure requirements surrounding direct action, while the 2025 restoration of the earlier Trump-era direct-action framework already demonstrates that policy transparency can change without eliminating the underlying operational capability.
Open official record
The principal unresolved record remains the absence of comparable national inventories documenting how many named individuals were deliberately targeted, how many operations were attempted, what institutions conducted them, what proportion occurred inside recognised armed conflicts, and how many operations failed, because no multinational official reporting architecture presently collects those data under common definitions.
For Russia, the command structure behind established historical cases remains only partially public even where state attribution itself has been judicially determined, while for the September 2026 network the full evidentiary record remains sealed or unavailable pending further proceedings.
For China, the principal gap is the boundary between proven transnational repression and alleged or suspected lethal activity, which cannot be bridged analytically without new competent official evidence.
For Britain and France, the major gap is systematic historical disclosure, because named cases and operational communiqués establish capability and practice without revealing the complete universe of targeting decisions.
For the United States, significant classified intelligence, CIA activity, partner-force operations and sensitive targeting criteria remain outside public reporting even though the visible record is substantially more extensive than for most comparator states.
For Saudi Arabia, India, Iran and North Korea, substantial uncertainty remains concerning internal decision chains beyond the specific official findings, convictions or assessments reviewed above, and those wider structures should not be reconstructed from inference where the documentary record stops.
The State Record Beyond the Headline: Evidentiary Audit and Architecture
EXECUTIVE BLUF: Reconstructing the state record solely from official documents reveals that the observable picture is markedly less symmetrical than political rhetoric suggests. Official records fall into materially different evidentiary classes—ranging from first-party acknowledgements and final judicial judgments to unadjudicated indictments and intelligence assessments.
Evidentiary Categories: From Acknowledgement to Indictment
Official records concerning targeted violence abroad fall into materially different evidentiary classes. A first-party acknowledgement establishes self-attribution but not legality; a criminal indictment establishes prosecutorial charges but not guilt; and a final judicial judgment following adversarial proceedings carries distinct evidentiary weight.
| Evidentiary Category | What the Official Record Establishes | What it Does Not Automatically Establish | Representative Cases |
|---|---|---|---|
| First-Party Acknowledgement | State admits conducting or participating in lethal operation | International legality, accuracy of every intelligence claim | U.S. al-Zawahiri operation; UK Reyaad Khan strike |
| Final Judicial Finding | Court has adjudicated facts under defined legal standard | Every wider allegation about state strategy | Carter v. Russia; Berlin Tiergarten murder |
| Criminal Conviction / Plea | Individual criminal liability established | Complete responsibility of every government official | Asif Merchant; Nikhil Gupta; Operation Fox Hunt |
| Criminal Indictment | Formal prosecutorial allegation supported sufficiently to charge | Guilt or final state attribution | September 2026 Russian intelligence-network case |
| State Associated | Representative Case | Host Jurisdiction | Highest Public Evidentiary Status Identified |
|---|---|---|---|
| United States | al-Zawahiri | Afghanistan | First-party acknowledgement (2022) |
| Russia | Tiergarten / Litvinenko | Germany / UK | Final ECHR judgment & German criminal judgment |
| China | Operation Fox Hunt | United States | Federal jury convictions and guilty pleas |
| Iran & India | Asif Merchant / Nikhil Gupta | United States | Federal conviction and formal guilty plea (2026) |
Acknowledged Lethal Targeting
The U.S. record is rich with public acknowledgements (Zawahiri, Baghdadi, Soleimani) and annual civilian-casualty reporting, while also recording operational errors (Kabul August 2021).
Judicial State Attribution
Unlike unilateral acknowledgements, Russian covert actions have been unmasked by European judicial findings (Tiergarten murder conviction) and ECHR rulings (Carter v. Russia).
China, Iran & India Trials
Operation Fox Hunt convictions, Merchant’s Iranian conviction, and Gupta’s 2026 guilty plea establish concrete conspiracies without equating coercion to proven mass assassination rankings.
- Universal Dataset: Absence of a common official international database recording state-attributable targeted killings.
- Command Chains: Unresolved internal decision hierarchies behind historical Russian and Saudi intelligence operations.
- Systemic Inventories: Complete classified universe of British, French, and partner-force kinetic actions.
- Trial Adjudications: Verdicts and evidentiary disclosures in pending federal cases (e.g. September 2026 Russian network).
- Policy Continuity: Administration updates regarding U.S. direct-action standards following the February 2026 report.
- Counter-Repression Measures: European intelligence and judicial crackdowns on cross-border surveillance and hit squads.
Europe as both operator and exposed territory
Principal judgment: Europe now occupies a structurally dual position in the security system, because the same states that contribute combat aircraft, remotely piloted systems, intelligence, training missions, maritime forces, special operations support and alliance infrastructure to counterterrorism and collective defence are simultaneously becoming targets of foreign intelligence penetration, transnational repression, sabotage, cyber operations, proxy violence and information manipulation; this is not a contradiction but a defining feature of the post-2022 European security environment, in which external power projection and internal resilience have become operationally inseparable.
The central European problem is therefore no longer simply whether a government possesses the legal authority and military capability to act beyond its borders, but whether the same government can prevent adversarial states from exploiting its own territory, infrastructure, diaspora communities, logistics networks, digital systems and political openness as operational terrain; official European records increasingly describe these threats as a continuum linking espionage, foreign interference, sabotage, cyber operations, coercion of dissidents, organised-crime proxies and, at the most severe end, kidnapping or assassination.
Europe projects security abroad while absorbing coercion at home
As of July 2026, the European Union reported 22 ongoing Common Security and Defence Policy missions and operations, with more than 3,500 military personnel and 1,300 civilian personnel deployed abroad, while the Union had conducted more than forty missions since 2003; these operations encompass crisis management, military assistance, maritime security, policing, border management, rule of law, security-sector reform and resilience against cyber and foreign information manipulation threats. Missions and Operations — European External Action Service — Jul 2026
The outward-facing military dimension is quantitatively substantial even before national operations are added, because the EU Military Staff reported in early 2026 that more than 87,000 Ukrainian personnel had received training under the EU Military Assistance Mission for Ukraine since October 2022, while Operation ASPIDES had protected more than 2,390 merchant vessels and provided close protection to more than 720 ships against threats in the Red Sea since 2024. The European Union Military Staff Marks 25 Years — EEAS — 2026 EU Foreign Policy in Action in 2026 — EEAS
At the same time, the Council of the European Union states that hybrid campaigns against the Union and its member states have intensified and now include sabotage against critical infrastructure, arson, cyberattacks, election interference, foreign information manipulation and interference, and the instrumentalisation of migration, while explicitly noting that sabotage against critical infrastructure increased particularly during 2024 and affected numerous member states. Council Conclusions on Resilience Against Hybrid Threats and Other Hostile Acts — Council of the European Union — 2025
The March 2026 Council conclusions hardened this diagnosis by describing persistent state and non-state hybrid campaigns as a direct security problem and expressly condemning Russia and its proxies for coordinated activity against the EU, its member states and partners, including sabotage, malicious cyber activity, information interference and election interference. Council adopts conclusions on advancing the EU’s capacity to counter hybrid threats — Council of the EU — 16 Mar 2026
Europe’s dual strategic posture
| Function | External European role | Internal European exposure | Principal institutions |
|---|---|---|---|
| Counterterrorism | Air operations, ISR, training, partner-force support | Foreign-directed plots, violent proxies, returning threat networks | National militaries, intelligence services, Europol, NATO |
| Collective defence | Forward deployments, air policing, maritime patrols | Espionage, infrastructure reconnaissance, sabotage preparation | NATO, national defence ministries |
| Maritime security | ASPIDES, IRINI, Sea Guardian, national deployments | Port disruption, cable attacks, shipping interference | EU, NATO, navies, coastguards |
| Intelligence | Target acquisition, strategic warning, counterterrorism support | Foreign intelligence collection and penetration | National services, EU INTCEN |
| Cyber defence | Defensive assistance and attribution | Cyber espionage, destructive cyber operations, DDoS, data theft | ENISA, national cyber agencies |
| Information security | FIMI monitoring and strategic communications | Disinformation, covert influence, proxy networks | EEAS, national governments |
| Diaspora protection | Asylum and human-rights protection | Surveillance, intimidation, coercive repatriation, assassination attempts | Police, security services, courts |
| Critical infrastructure | Host bases, transport hubs, energy networks | Sabotage, reconnaissance, cyber disruption | Ministries, private operators, NATO/EU |
The practical effect is that Europe is no longer protected by a clear distinction between “operations abroad” and “security at home,” because logistical nodes in Germany, air bases in Italy and Britain, French deployments in the Levant, maritime traffic through European ports and diaspora populations residing across major European cities all form parts of a single security ecosystem.
Italy: an operational Mediterranean state with a widening internal protection burden
Italy’s military posture reflects its geography and alliance role more than a narrow expeditionary doctrine, because Rome simultaneously contributes to NATO, EU and coalition missions in the Balkans, Iraq and the Middle East, the Mediterranean, Lebanon, the Red Sea, North Africa and other theatres; Parliament’s 2025 mission authorization expressly included military deployments in the Western Balkans, support to Ukraine, Lebanon and the eastern Mediterranean, Iraq and the Middle East, Operation Levante, North Africa and West Africa. Authorization of international missions for 2025 — Camera dei Deputati
The Iraqi deployment remains one of the clearest measurable components of Italy’s counterterrorism architecture, because the Ministry of Defence states that Operation Prima Parthica currently comprises approximately 300 personnel in the land component and 400 in the air component, while Italian personnel have trained approximately 50,000 members of Kurdish Ministry of Peshmerga Affairs and Interior Ministry forces; Italy also maintains command and staff personnel in Iraq and Kuwait and operates training, advising and intelligence-support capabilities. Contributo nazionale — Operazione Prima Parthica — Ministero della Difesa
The air component demonstrates that Italy’s role is not limited to classroom training, because the Air Force reports approximately 400 personnel in the air contingent operating from Kuwait with MQ-9A Predator remotely piloted aircraft and F-2000A Typhoons, conducting surveillance, reconnaissance and intelligence-gathering missions in support of coalition activities and the security of forces and populations in Iraq. Aeronautica Militare Report 2025 — Task Force Air Kuwait
That external posture is increasingly mirrored by a large domestic protection requirement, because the Interior Ministry stated in June 2025 that more than 29,000 sensitive sites were under security surveillance in Italy, including more than 10,000 critical infrastructures, with approximately 1,000 sites connected to American or Israeli interests; the decision to reinforce protection followed worsening Middle Eastern tensions and involved police, intelligence agencies and national cybersecurity structures. Comitato nazionale per l’ordine e la sicurezza pubblica — Ministero dell’Interno — 22 Jun 2025
Italy: outward activity and internal exposure
| Indicator | Verified status / value | Operational meaning |
|---|---|---|
| Prima Parthica land component | ~300 personnel | Training, advising, command support in Iraq |
| Prima Parthica air component | ~400 personnel | ISR, air operations, coalition support |
| Iraqi/Kurdish forces trained by Italian personnel | ~50,000 cumulative | Long-term partner-force capacity building |
| Sensitive sites under surveillance in Italy | 29,000+ | Scale of domestic protective-security burden |
| Critical infrastructure among monitored sites | 10,000+ | Exposure of energy, transport and state systems |
| U.S./Israeli-linked protected sites | ~1,000 | Direct transmission of geopolitical crises into Italian domestic protection requirements |
| FIMI cases recorded in Italy in 2025 | 11 | Foreign information manipulation exposure |
| Total FIMI cases recorded by EEAS in 2025 | 540 | Italy forms part of broader European information battlespace |
The Senate recorded in March 2026 that the EEAS had documented 540 foreign information manipulation and interference cases during 2025, identifying Ukraine, France, Moldova and Germany as principal targets while recording 11 cases involving Italy; the same parliamentary account identifies Russia and China as among the principal actors employing covert networks and proxies to complicate attribution. 4th Permanent Committee, Senate of the Republic — 17 Mar 2026
Italy’s intelligence community has meanwhile framed the threat increasingly in multidomain terms rather than as conventional espionage alone, with the 2026 annual intelligence report describing threats as pervasive, technologically enabled, multidimensional and often deliberately difficult to detect; a parallel Senate inquiry into foreign interference explicitly identifies China, Russia, Iran and North Korea as states associated with organised interference and propaganda strategies. Relazione sulla politica dell’informazione per la sicurezza — Senate of the Republic — Mar 2026 Senate Foreign Affairs and EU Policies Committees — 15 Oct 2025
The domestic resilience architecture is expanding accordingly, because Italy established an interministerial civil-defence table in April 2025 whose remit expressly includes cyberattacks, foreign information manipulation, sabotage of critical infrastructure and geopolitical crises, demonstrating that hybrid threats are being incorporated into civil contingency planning rather than being confined to intelligence-service analysis. Tavolo Interministeriale per la Difesa Civile — Ministero dell’Interno — 2 Apr 2025
Italy’s strategic vulnerability is therefore not principally that it has already become the central European theatre for documented targeted killings, because the public record does not support such a conclusion; its vulnerability lies instead in the intersection of dense critical infrastructure, American and NATO facilities, Middle Eastern exposure, Mediterranean logistics, politically active diaspora communities and coalition military participation, all of which enlarge the number of potential foreign intelligence and sabotage targets.
France: a high-capability operator facing an explicit counter-intelligence threat
France represents the clearest continental European example of a state that combines independent expeditionary capability, nuclear status, overseas basing, intelligence reach and active coalition operations with a formal recognition that foreign governments are conducting repression against persons living on French territory.
Operation CHAMMAL currently deploys approximately 600 French military personnel in the Levant, with France integrated at strategic, operational and tactical levels into the multinational anti-Daesh coalition; French officers participate in coalition planning, while French forces contribute air and maritime support and maintain an independent national chain of command through the Centre de planification et de conduite des opérations. Opération CHAMMAL — Ministère des Armées
Operational tempo remained significant in 2026, because French Rafales flew 18 sorties and nearly 70 flight hours between 14 and 21 May, 21 sorties and nearly 76 hours between 28 May and 4 June, 21 sorties and nearly 80 hours between 4 and 11 June, and 19 sorties and nearly 80 hours between 18 and 25 June, repeatedly supported by coalition aerial refuelling; these are operational missions rather than a direct measure of lethal strikes, but they demonstrate that French counterterrorism and force-protection activity in the Levant remains active and persistent. Point de situation des opérations — 21–28 May 2026 — Ministère des Armées Point de situation — 4–11 Jun 2026 Point de situation — 11–18 Jun 2026 Point de situation — 25 Jun–2 Jul 2026
France also completed a one-year command of the NATO Mission Iraq in May 2026, after which command transferred to Spain, illustrating Paris’s simultaneous role in direct operational activity and institutional capacity-building. Point de situation — 14–21 May 2026 — Ministère des Armées
Yet the domestic counter-intelligence picture is becoming equally explicit, because the Direction générale de la sécurité intérieure formally defines transnational repression as activity by foreign governments intended to identify, locate, monitor, intimidate, censor, forcibly repatriate or attack the lives of opponents and political rivals abroad, and classifies such behaviour as foreign interference that receives priority attention within DGSI counter-espionage operations. La lutte contre la répression transnationale — DGSI — 6 Jan 2025
France: operational and counter-intelligence picture
| Dimension | Official evidence | Strategic consequence |
|---|---|---|
| CHAMMAL personnel | ~600 | Persistent expeditionary counterterrorism capability |
| Weekly Rafale activity, May–Jun 2026 | 18–21 sorties/week in several reported weeks | Sustained operational presence |
| NATO Mission Iraq | French command until 19 May 2026 | Institutional influence within allied security architecture |
| Transnational repression | DGSI designates as priority counter-espionage issue | Domestic security now directly linked to foreign regime activity |
| Russian cyber activity | APT28 operations against French entities documented for 2021–2024 | Long-duration cyber intelligence pressure |
| FIMI exposure | France identified among main European targets in 2025 | High strategic-information vulnerability |
France’s exposure is not restricted to physical repression, because the DGSI reported in May 2025 that French cyber authorities had observed attacks between 2021 and 2024 conducted with the APT28 operational mode, which French official sources associate publicly with Russia; this reinforces the picture of long-duration pressure combining intelligence collection, cyber penetration and information manipulation rather than isolated hostile incidents. Ciblage et compromission d’entités françaises au moyen du mode opératoire APT28 — DGSI — 13 May 2025
The EEAS’s 2025 FIMI dataset further identified France among the principal targets of documented foreign information manipulation operations, placing it alongside Ukraine, Moldova and Germany rather than in the lower-exposure category recorded for Italy. Senate of the Republic summary of EEAS Fourth FIMI Report — Mar 2026
France is therefore exposed not despite its status as a major security actor but partly because of it, since its military interventions, nuclear status, permanent UN Security Council seat, African and Middle Eastern footprint, intelligence partnerships and large dissident and diaspora communities increase both its strategic value as a target and the range of foreign actors with incentives to operate on French territory.
Germany: alliance infrastructure, substantial deployments and a high sabotage-intelligence threat
Germany’s security posture has moved significantly beyond its earlier post-Cold War image of limited expeditionary engagement, because as of 17 August 2026 the Bundeswehr officially listed deployments including Kosovo, Bosnia and Herzegovina, Operation IRINI, NATO Sea Guardian, UNIFIL, Counter-Daesh/Capacity Building Iraq, ASPIDES, South Sudan and Western Sahara. Die Bundeswehr in Auslandseinsätzen — Bundeswehr — 17 Aug 2026
The authorized force ceilings reveal the breadth of this footprint, including up to 500 personnel for Counter-Daesh/Capacity Building Iraq, 550 for NATO Sea Guardian, 350 for ASPIDES, 300 for IRINI, 300 for UNIFIL, 400 for KFOR, and 50 for EUFOR Althea, although these are mandate ceilings rather than evidence that every authorized billet is continuously filled. Die Bundeswehr in Auslandseinsätzen — Bundeswehr
Germany’s role in Iraq combines training, advising, air transport, surveillance and situational awareness, with the Bundestag describing a mandate of up to 500 Bundeswehr personnel intended to stabilize Iraq and prevent the resurgence of Islamic State. Fortsetzung des Bundeswehreinsatzes gegen den „Islamischen Staat“ — Deutscher Bundestag — Dec 2025
At home, however, the 2025 Federal Office for the Protection of the Constitution report states that the threat from espionage, sabotage, transnational repression and cyberattacks remains high and identifies Russia, China and Iran as the principal sources of foreign intelligence activity affecting Germany. Verfassungsschutzbericht 2025 — Bundesregierung — 30 Jun 2026
Germany: deployed capability and internal state-threat exposure
| Category | Official figure / assessment | Reference date |
|---|---|---|
| Counter-Daesh / Capacity Building Iraq ceiling | 500 personnel | Aug 2026 |
| NATO Sea Guardian ceiling | 550 | Aug 2026 |
| ASPIDES ceiling | 350 | Aug 2026 |
| IRINI ceiling | 300 | Aug 2026 |
| UNIFIL ceiling | 300 | Aug 2026 |
| KFOR ceiling | 400 | Aug 2026 |
| Main foreign intelligence threats | Russia, China, Iran | 2025 BfV report |
| Threat categories formally highlighted | Espionage, sabotage, transnational repression, cyber | 2025 BfV report |
The BfV’s preceding 2024 report had already warned that Russia was adapting to the reduction of traditional diplomatic intelligence capacity by expanding the use of “low-level agents” for espionage and sabotage, combining cyber operations, disinformation and physical intelligence activity, while specifically assessing an increased risk of sabotage and possible harm to life in Germany. Verfassungsschutzbericht 2024 — Bundesamt für Verfassungsschutz
Iran constitutes a separate counter-intelligence vector, because the German government stated in March 2026 that Iranian intelligence services continued to focus on members of the Iranian opposition in Germany, including surveillance of demonstrations and attempts to identify opposition activists, while the BfV had established a reporting point for victims of such transnational repression. Regierungspressekonferenz — Bundesregierung — 2 Mar 2026
Germany’s particular structural exposure lies in the density of military and logistical infrastructure on its territory, because American, NATO and German facilities form essential nodes for European defence, while the Ramstein litigation examined in the preceding chapter demonstrated how communications and relay infrastructure located inside Germany can be operationally linked to remote military action abroad; those characteristics make Germany simultaneously a rear-area enabling state and a high-value intelligence and sabotage target.
United Kingdom: the most explicit European warning of potentially lethal state plots
The United Kingdom’s dual role is especially visible because it continues to conduct offensive and surveillance missions against Daesh while MI5 publicly describes foreign-state threats inside Britain in terminology approaching the intensity traditionally reserved for terrorism.
Operation SHADER remains active, and the Ministry of Defence reported four publicly listed RAF strike events in Iraq and Syria during 2025, including strikes on 25 February, 10 June, 4 September and 28 September; the September operations included remotely piloted aircraft that positively identified individual Daesh members and killed them after surveillance determined that an engagement could occur without risk to civilians. RAF air strikes in Iraq and Syria: January to December 2025 — UK Ministry of Defence
The operational campaign continued into 2026, when RAF Typhoons and a Voyager tanker joined French aircraft on 3 January 2026 in striking a Daesh underground facility north of Palmyra using Paveway IV precision-guided bombs. Update: air strikes against Daesh — UK Ministry of Defence — updated 13 Jan 2026
The internal state-threat picture is substantially more alarming than in most publicly available European official records, because the UK Security Minister told Parliament in March 2025 that the number of MI5 state-threat investigations had risen by 48% in the preceding year, while stating that Britain had responded since 2022 to 20 Iran-backed plots presenting potentially lethal threats to British citizens or residents. Protecting national security — Home Office — 4 Mar 2025
MI5 subsequently stated in its 2025 threat update that it had tracked more than twenty potentially lethal Iran-backed plots in the single year since its previous annual speech, while separately referring to convictions involving individuals acting as Russian proxies, including five men convicted in connection with an arson attack on a London warehouse containing supplies destined for Ukraine. Director General Sir Ken McCallum gives threat update — MI5 — 2025
United Kingdom: unusually quantified state-threat environment
| Indicator | Official figure / status |
|---|---|
| MI5 state-threat investigation increase reported Mar 2025 | +48% year-on-year |
| Iran-backed potentially lethal plots responded to since Jan 2022, as reported in 2025 | 20 |
| Potentially lethal Iran-backed plots tracked in latest one-year period cited by MI5 | 20+ |
| Terrorist late-stage plots disrupted since 2020, according to MI5 2025 threat update | 19 |
| RAF publicly listed strike events in Iraq/Syria during 2025 | 4 dates |
| Foreign Influence Registration Scheme launch | 1 Jul 2025 |
The British government has responded by widening the statutory framework rather than treating each incident as an isolated counterterrorism case, because the National Security Act 2023 created modern offences addressing espionage, sabotage and foreign interference, while the government explicitly stated that the legislation was intended to make Britain a harder target for hostile acts including assassination. National Security Act 2023 — GOV.UK
The Foreign Influence Registration Scheme, which entered into force on 1 July 2025, added mandatory transparency requirements concerning activity undertaken at the direction of foreign powers and created an enhanced tier directed initially at Russia and Iran. UK launches Foreign Influence Registration Scheme — Home Office — 1 Jul 2025
The Home Office now formally defines transnational repression as foreign-state-directed activity including harassment, online disinformation, surveillance, stalking, physical violence, coerced return, assassination and attempted assassination, demonstrating that assassination is no longer being treated in UK policy solely as an exceptional intelligence scenario but as part of an explicit domestic protective-security framework. What to do if you think you are the victim of transnational repression — Home Office — updated 11 May 2026
The British case therefore provides perhaps the clearest current European example of the convergence between counterterrorism and counter-state-threat missions, because the same security institutions are now confronting terrorist plots, foreign intelligence operations, organised-crime proxies, assassination threats, hostile cyber activity and sabotage through increasingly integrated legal and operational structures.
The European Union: recognition has moved from human-rights language into security doctrine
The European Union’s institutional treatment of transnational repression changed significantly during 2025–2026, because the issue moved from a comparatively specialised human-rights concern into mainstream foreign-interference and security policy.
In November 2025, the European Parliament adopted a resolution on transnational repression of human-rights defenders by 512 votes to 76, with 52 abstentions, stating that approximately 80% of recorded cases were attributable to ten countries, including China, Türkiye, Tajikistan, Russia, Egypt, Cambodia, Turkmenistan, Uzbekistan, Iran and Belarus; the Parliament explicitly included targeted killings, abductions and harassment within the phenomenon. Addressing transnational repression of human rights defenders — European Parliament — 13 Nov 2025 European Parliament press release — 13 Nov 2025
In January 2026, a European Parliament study specifically examined Russia, Iran and China as perpetrator-state case studies active inside the EU, linking transnational repression to foreign interference, disinformation, abuse of migration mechanisms and broader hybrid threats. Perpetrators and methods of transnational repression and possible counter strategies — European Parliament — 22 Jan 2026
The institutional response moved another stage in June 2026 when the European Parliament adopted its resolution on an EU strategy against transnational repression by 434 votes to 128, with 104 abstentions, calling for a common EU definition, stronger data sharing, law-enforcement and judicial training, countermeasures against abusive Interpol notices and consular coercion, and consideration of an EU-level coordinator. MEPs demand EU action to fight transnational repression — European Parliament — 16 Jun 2026
EU institutional evolution, 2025–2026
| Date | Institution | Measure / finding | Quantitative element |
|---|---|---|---|
| Nov 2025 | European Parliament | Resolution on repression of human-rights defenders abroad | 512–76–52 vote |
| Nov 2025 | European Parliament | Ten perpetrator states account for nearly 80% of recorded TNR cases | ≈80% |
| Jan 2026 | European Parliament study | Russia, Iran and China used as EU perpetrator-state case studies | 3 principal case studies |
| Mar 2026 | Council of EU | Updated framework for countering hybrid campaigns | EU-wide |
| Jun 2026 | European Parliament | Calls for common EU strategy and definition | 434–128–104 vote |
| Jul 2026 | EEAS | Ongoing CSDP missions and operations | 22 |
| Jul 2026 | EEAS | Military personnel deployed | 3,500+ |
| Jul 2026 | EEAS | Civilian personnel deployed | 1,300+ |
These figures should not be read as proof that all member states face the same threat level, because threat intensity varies sharply by diaspora composition, political profile, military role, geography and bilateral relationships; they instead demonstrate that the Union has moved from recognising isolated incidents to treating transnational repression and hybrid threats as system-level European problems.
Russia, Iran and China present distinct European threat models
The official European record increasingly differentiates among major perpetrator states rather than describing a single generic category of hostile foreign activity.
Russia’s most prominent European threat model combines intelligence collection, cyber operations, information manipulation, sabotage and use of low-level proxies, while the Council explicitly characterises Russian activity as a coordinated and long-standing hybrid campaign. Hybrid threats — Council of the European Union
Iran’s European profile is disproportionately concentrated on dissidents, journalists, Jewish and Israeli targets and regime opponents, with the G7 Rapid Response Mechanism—comprising France, Germany, Italy, the United Kingdom, the United States, Canada, Japan and the EU—stating in September 2025 that Iranian intelligence services had increasingly attempted to kill, kidnap and harass political opponents abroad. G7 Rapid Response Mechanism Statement on Iranian Transnational Repression — 12 Sep 2025
China’s officially documented European threat model is more heavily concentrated on intelligence collection, monitoring of diaspora and dissident networks, cyber espionage, political influence and coercive activity, although European institutions include Beijing among the major state actors associated with transnational repression and foreign interference rather than limiting the concern to economic espionage. Perpetrators and methods of transnational repression — European Parliament
Principal European state-threat patterns
| Perpetrator-state model | Physical coercion | Cyber/espionage | FIMI | Proxy/criminal use | Main exposed populations/assets |
|---|---|---|---|---|---|
| Russia | Documented lethal cases and sabotage concerns | High | High | Increasingly documented | Defence logistics, Ukraine support infrastructure, officials, dissidents |
| Iran | Kill/kidnap plots explicitly identified | Significant | Present | Strong reliance on proxies/criminal actors documented by UK authorities | Dissidents, journalists, Jewish/Israeli interests |
| China | Coercion and repatriation documented; lethal record in EU less established | High | Significant | Intermediary networks documented internationally | Dissidents, diaspora, researchers, technology, political institutions |
| Other authoritarian states | Case-specific | Variable | Variable | Variable | Exiles, minorities, political opponents |
This differentiated model matters operationally because the countermeasure appropriate to an attempted murder-for-hire network is not necessarily the same as that required against an advanced persistent cyber actor, abusive diplomatic pressure or covert social-media influence operation, even when all four are instruments of state power.
European critical infrastructure is now part of the conflict geometry
The threat to European critical infrastructure has become strategically important because the continent’s military support to Ukraine, energy diversification, maritime trade and NATO reinforcement all depend on transport networks, ports, energy systems, undersea cables, satellites, logistics hubs and data infrastructure whose disruption can generate military and economic effects without a conventional attack.
The Council stated in 2025 that sabotage activity against critical infrastructure had increased particularly during 2024, affecting numerous member states, and specifically identified energy interconnectors, cross-border communications cables and transport infrastructure as areas requiring stronger resilience. Resilience against hybrid threats and other hostile acts — Council of the EU
The strategic mechanism is straightforward because an adversary does not need to destroy a military formation to reduce European military effectiveness if it can instead disrupt the railway, port, communications, energy or digital systems on which force movement and command depend, while comparatively low-cost proxy sabotage offers the additional advantage of ambiguity regarding attribution and escalation.
Critical-infrastructure exposure by function
| Infrastructure | Civilian function | Security / military function | Principal hybrid vulnerability |
|---|---|---|---|
| Ports | Trade and container flows | Reception of allied forces and military materiel | Sabotage, cyber disruption, surveillance |
| Rail | Passenger/freight transport | Reinforcement and heavy-equipment movement | Physical sabotage, signalling attacks |
| Airports | Commercial aviation | Strategic lift and military mobility | Cyber intrusion, drone disruption |
| Energy grids | Civil electricity supply | Bases, command nodes, industry | Cyber and physical attacks |
| Pipelines/LNG | Energy security | Defence-industrial continuity | Physical sabotage |
| Undersea cables | Financial/data connectivity | Military communications and intelligence | Seabed interference |
| Satellite ground stations | Communications | ISR and command support | Cyber penetration, physical surveillance |
| Defence manufacturers | Industrial production | Weapons and ammunition supply | Espionage, sabotage, supply-chain compromise |
| Data centres | Commercial/government services | Operational planning and government continuity | Cyberattack and insider threat |
The policy response is increasingly integrated, because the EU’s Critical Entities Resilience Directive and NIS2 framework are explicitly treated by the Council as central instruments for strengthening resilience against hybrid and cyber threats rather than merely as commercial compliance measures. Council Conclusions — Hybrid Threats — 2025
Diaspora communities have become a national-security perimeter
Perhaps the most consequential conceptual change concerns the treatment of diaspora and exile communities, because official European institutions increasingly recognise that foreign surveillance or intimidation of dissidents is not simply a human-rights issue affecting particular migrant communities but a violation of the host state’s sovereignty and security.
The UK Home Office expressly states that transnational repression is foreign-state-directed crime, while France’s DGSI identifies the phenomenon as foreign interference and Germany’s BfV treats it within the same national-security threat spectrum as espionage, sabotage and cyber operations. Transnational repression — GOV.UK La lutte contre la répression transnationale — DGSI Verfassungsschutzbericht 2025 — Bundesregierung
This shift alters the strategic calculus because surveillance of an exile, coercion of relatives abroad, infiltration of diaspora organisations or pressure through consular channels can generate intelligence useful for later kidnapping or physical attack, meaning that the distinction between “harassment” and “assassination threat” is often a progression of capability rather than a set of entirely separate phenomena.
Escalation ladder in transnational repression
| Stage | Typical activity | Security significance |
|---|---|---|
| Identification | Mapping dissidents, activists, journalists | Establishes targeting universe |
| Surveillance | Physical or digital monitoring | Develops pattern-of-life intelligence |
| Social coercion | Threats to relatives, employment pressure | Suppresses political activity |
| Legal/administrative coercion | Passport pressure, abusive notices, consular leverage | Creates mobility and detention risk |
| Proxy recruitment | Criminals/private investigators/intermediaries | Provides deniability |
| Physical intimidation | Assault, arson, property damage | Tests security response |
| Kidnapping / rendition | Forced return | Removes target from host-state protection |
| Assassination attempt | Direct lethal action | Maximum sovereignty violation short of broader armed attack |
This progression explains why European counter-intelligence services increasingly intervene at earlier stages, because waiting for a plot to become overtly lethal forfeits opportunities to disrupt surveillance, financing, proxy recruitment and reconnaissance before operational execution.
Proxy actors are changing the counter-intelligence problem
The increased use of criminals and low-level intermediaries is one of the most consequential developments in European state-threat activity because it lowers the operational cost for sponsoring governments while complicating attribution.
MI5 has explicitly warned that both Russia and Iran use criminal proxies, including low-level offenders and organised-crime actors, to conduct surveillance, arson or potentially violent tasks, while Germany’s BfV similarly reports Russian adaptation toward the use of low-level agents after diplomatic expulsions reduced traditional intelligence capacity. Director General Sir Ken McCallum gives threat update — MI5 Verfassungsschutzbericht 2024 — BfV
The operational consequence is that traditional counter-espionage indicators become less reliable, because the person conducting reconnaissance outside a military warehouse, diaspora organisation or journalist’s home may possess no diplomatic status, intelligence-service training or obvious ideological connection to the sponsoring government; recruitment through messaging platforms or criminal networks can create disposable operational layers that separate the state from the act.
Classical intelligence model versus proxy model
| Variable | Classical intelligence officer | Criminal / low-level proxy |
|---|---|---|
| Training | High | Often low |
| Diplomatic cover | Common historically | Usually absent |
| State connection | Direct or institutional | Indirect and deniable |
| Cost to sponsor | High | Low |
| Operational sophistication | High | Variable |
| Arrest impact on sponsor | Potential diplomatic crisis | More easily disavowed |
| Attribution difficulty | Moderate | Often higher initially |
| Missions | Espionage, recruitment, covert action | Surveillance, arson, sabotage, intimidation, violence |
| Counter-intelligence requirement | Surveillance of known networks | Fusion of police, organised-crime and intelligence data |
This convergence between organised crime and state activity is particularly important for Italy, France, Germany and the United Kingdom because traditional institutional boundaries between intelligence services, counterterrorism police, organised-crime investigators and infrastructure security agencies become increasingly artificial when a foreign service can outsource tasks across those categories.
National responses remain uneven
Europe’s strategic vulnerability is reinforced by differences in domestic legislation, institutional cultures and disclosure practices, because the United Kingdom has created an explicit foreign-interference offence and registration regime, France treats transnational repression as a DGSI counter-espionage priority, Germany has established victim-reporting mechanisms through the BfV, and Italy is integrating hybrid threats into intelligence, civil-defence and parliamentary frameworks without yet possessing a directly comparable standalone transnational-repression regime.
| Jurisdiction | Dedicated TNR recognition | Foreign-interference legislation/tool | Protective-security framework | Public quantitative reporting |
|---|---|---|---|---|
| United Kingdom | Explicit government definition | National Security Act + FIRS | MI5/NPSA/Home Office | Relatively extensive |
| France | Explicit DGSI definition | Counter-espionage and criminal-law framework | DGSI-led | Moderate |
| Germany | Explicit BfV recognition | Constitutional/criminal/intelligence tools | BfV + federal/state police | Extensive annual intelligence reporting |
| Italy | Threat increasingly framed through hybrid/interference architecture | Intelligence, cyber, criminal and public-order instruments | DIS/AISE/AISI, Interior Ministry, ACN | Moderate, less TNR-specific |
| EU | Explicit parliamentary and policy recognition | Sanctions, FIMI tools, CSDP, CER/NIS2 | Commission/Council/EEAS/Europol cooperation | Increasing but fragmented |
The principal institutional weakness is therefore fragmentation rather than absence of authority, because individual member states may recognise and prosecute espionage, stalking, threats, unlawful intelligence activity, cyber offences or attempted murder without recording them under a common transnational-repression category; this makes the phenomenon systematically under-comparable across the Union.
NATO and EU membership simultaneously reduce and create exposure
Alliance membership increases deterrence and intelligence-sharing capacity, yet it also makes national territory operationally valuable to adversaries because bases, ammunition depots, ports, railways and defence industries contribute directly to NATO reinforcement and support to Ukraine.
Italy’s bases and Mediterranean position, Germany’s logistics and command infrastructure, Britain’s intelligence and military capabilities and France’s expeditionary assets all create targets whose disruption can produce alliance-level effects rather than merely bilateral consequences.
This produces a security paradox in which stronger integration generates greater collective resilience but also enlarges the number of interconnected nodes through which disruption can propagate, meaning that a port closure, cable disruption, cyberattack or targeted assassination of a strategically important official in one member state can have consequences for operations elsewhere.
Alliance integration and threat transmission
| European asset | Alliance value | Adversary incentive |
|---|---|---|
| Italian Mediterranean bases | Southern-flank logistics, ISR, Middle East access | Surveillance and disruption |
| German logistics network | Reinforcement, basing and U.S./NATO infrastructure | Sabotage and espionage |
| French air/naval capability | Independent and coalition expeditionary power | Cyber and intelligence targeting |
| UK intelligence / RAF network | Intelligence integration and long-range operations | State-threat and cyber targeting |
| EU ports and transport corridors | Military mobility and trade | Physical/cyber sabotage |
| European defence industry | Ukraine support and rearmament | Espionage, disruption, supply-chain attacks |
The implication is that European counter-hybrid policy cannot be separated from defence planning, because the ability to deploy forces abroad depends directly on protecting civilian infrastructure at home.
Comparative national exposure matrix
The following matrix does not rank countries by “danger” and should not be interpreted as a predictive score; it records only the principal exposure categories explicitly documented in current official sources.
| Exposure category | Italy | France | Germany | United Kingdom | EU-wide relevance |
|---|---|---|---|---|---|
| Expeditionary military role | Yes | High | Yes | High | CSDP |
| Counter-Daesh involvement | Yes | Yes | Yes | Yes | Coalition coordination |
| NATO strategic infrastructure | High | High | Very high | Very high | Alliance-wide |
| Foreign intelligence activity | Documented concern | Documented | High | High | EU-wide |
| Russian hybrid activity | Documented | Documented | High | High | Explicit Council concern |
| Iranian TNR threat | G7 recognition | Recognised | Surveillance documented | 20+ potentially lethal plots reported | Explicit G7/EU concern |
| Chinese influence/espionage concern | Documented institutionally | Documented | Documented | Documented | EP case study |
| Sabotage concern | Critical-infrastructure planning | Security concern | Explicit BfV warning | Proxy cases documented | Explicit Council concern |
| FIMI targeting | 11 cases in 2025 | Among major 2025 targets | Among major 2025 targets | Material threat | 540 cases in 2025 |
| Dedicated public TNR framework | Developing | DGSI | BfV | Most explicit | Parliament pushing common strategy |
The decisive policy problem is attribution speed
Europe has substantial capacity to prosecute overt crime and substantial intelligence capability to identify strategic adversaries, but hybrid operations exploit the interval between an incident and authoritative attribution, because sanctions, diplomatic expulsions, criminal prosecution and collective political response become more difficult when evidence is distributed among national police, intelligence, cyber agencies, private companies and allied governments.
Proxy operations deepen this problem because technical attribution of a cyber intrusion, financial attribution of payments, intelligence attribution of tasking and judicial attribution of individual criminal responsibility may develop on different timelines.
The result is a recurring gap in which governments may possess high-confidence classified intelligence before they possess evidence that can be released publicly or presented in court, while adversaries can exploit that interval to deny responsibility and frame accusations as political narratives.
Attribution chain
| Layer | Question | Typical evidence |
|---|---|---|
| Tactical | Who physically executed the act? | CCTV, forensics, arrest evidence |
| Operational | Who tasked or financed the actor? | Communications, financial transfers |
| Organisational | Which service or proxy structure was involved? | Intelligence reporting, human sources, digital infrastructure |
| State | Was the conduct attributable to a government? | Command links, official tasking, institutional control |
| Strategic | Was the act part of a broader campaign? | Pattern analysis across incidents and jurisdictions |
| Judicial | Can the attribution survive evidentiary rules in court? | Admissible evidence and witness testimony |
A mature European response therefore requires not merely better intelligence collection but mechanisms that permit evidence to move efficiently from classified intelligence to law-enforcement action, sanctions, diplomatic attribution and infrastructure protection without compromising sources and methods.
The EU’s principal structural weakness remains data fragmentation
Despite the rapid policy evolution, there is still no authoritative EU-wide statistical registry that records all cases of transnational repression, foreign-directed intimidation, sabotage, assassination plotting and foreign intelligence coercion according to common definitions.
The European Parliament’s repeated calls during 2025–2026 for a common definition and improved information exchange are themselves evidence of that institutional gap, because quantitative comparison remains dependent on heterogeneous national police files, security-service reporting, court proceedings and civil-society documentation. Countering transnational repression — European Parliament — Jun 2026
This means that the number of publicly known incidents is necessarily a floor rather than a complete measure, while it also prevents responsible analysts from converting individual national data—such as Britain’s twenty-plus Iranian lethal plots—into an EU-wide incidence rate without comparable reporting from Paris, Berlin, Rome and other capitals.
Key European data dashboard
| Metric | Latest official value used | Date / period | Institution |
|---|---|---|---|
| Ongoing EU CSDP missions and operations | 22 | Jul 2026 | EEAS |
| EU military personnel deployed | 3,500+ | Jul 2026 | EEAS |
| EU civilian personnel deployed | 1,300+ | Jul 2026 | EEAS |
| Ukrainian personnel trained under EUMAM | 87,000+ | By early 2026 | EU Military Staff |
| Merchant vessels protected by ASPIDES | 2,390+ | Since 2024 | EEAS |
| Ships receiving close ASPIDES protection | 720+ | Since 2024 | EEAS |
| FIMI cases documented in 2025 | 540 | 2025 | EEAS, cited by Italian Senate |
| FIMI cases concerning Italy | 11 | 2025 | EEAS, cited by Italian Senate |
| UK MI5 state-threat investigation increase | 48% | Previous 12 months reported Mar 2025 | UK Home Office |
| Iran-linked potentially lethal UK plots | 20+ | Recent one-year period reported 2025 | MI5 |
| Sensitive sites under protection in Italy | 29,000+ | Jun 2025 | Italian Interior Ministry |
| Critical infrastructures among them | 10,000+ | Jun 2025 | Italian Interior Ministry |
| Italy Prima Parthica personnel | ~700 | Current official page | Italian Defence Ministry |
| France CHAMMAL personnel | ~600 | Current official page | French Armed Forces |
| Germany Counter-Daesh ceiling | 500 | Aug 2026 | Bundeswehr |
| Germany Sea Guardian ceiling | 550 | Aug 2026 | Bundeswehr |
These figures describe different operational categories and therefore should not be aggregated into a single European threat score, but together they demonstrate the scale of the dual system: thousands of European personnel are deployed outside the Union while tens of thousands of domestic sites, strategic institutions and vulnerable individuals require protection against the consequences of the same geopolitical confrontation.
Indicators of escalation
Several observable developments would indicate that Europe’s security environment is moving from persistent hybrid competition toward a more dangerous phase of coercive state action.
A first threshold would be a sustained increase in state-directed sabotage causing deaths, rather than material damage alone, because such incidents would materially change both the political pressure for collective response and the legal debate over whether hybrid activity had crossed into armed-attack territory.
A second would be successful or repeatedly attempted assassinations of dissidents, defence executives, military personnel or government officials inside EU or UK territory, particularly where attribution to a foreign intelligence service becomes publicly demonstrable.
A third would be coordinated attacks against multiple infrastructure nodes—ports, railways, communications systems and defence-industry facilities—within a short period, because synchronisation would indicate campaign-level planning rather than isolated proxy activity.
A fourth would be evidence that criminal proxies are receiving increasingly sophisticated training, weapons or targeting information from state services, since that would represent an evolution from disposable low-level sabotage toward deniable paramilitary action.
A fifth would be a significant increase in foreign surveillance and intimidation of diaspora communities following crises or regime instability in perpetrator states, because history suggests that political shocks can produce pressure on governments to silence opposition networks abroad.
What Europe can currently do
The available institutional toolbox is broader than it appears when examined across rather than within bureaucratic boundaries, because European governments can combine prosecution, intelligence disruption, diplomatic expulsions, sanctions, cyber countermeasures, visa restrictions, asset freezes, foreign-agent transparency regimes, protective security, infrastructure hardening and multilateral attribution.
| Instrument | Authority level | Immediate effect | Principal limitation |
|---|---|---|---|
| Criminal prosecution | National | Incapacitates proxies | Requires admissible evidence |
| Intelligence disruption | National/allied | Can stop plots early | Often non-public |
| Diplomatic expulsion | National | Reduces official intelligence footprint | Encourages shift to proxies |
| Financial sanctions | EU/national | Raises cost and restricts networks | Can be circumvented |
| FIRS / transparency regimes | National | Exposes directed influence | Not all covert activity requires registration |
| Critical-infrastructure regulation | EU/national | Improves resilience | High implementation burden |
| Cyber attribution and sanctions | EU/national | Political and economic cost | Attribution delays |
| Protective security | National/private | Reduces vulnerability | Resource intensive |
| Diaspora victim reporting | National | Improves intelligence picture | Trust and awareness challenges |
| Joint EU coordination | EU | Reduces cross-border seams | Competence remains fragmented |
The central institutional requirement is not necessarily the creation of an entirely new security architecture but the closing of seams between systems that already exist, because intelligence services may detect foreign tasking, police may identify criminal proxies, cybersecurity agencies may observe infrastructure reconnaissance, financial-intelligence units may trace payments and asylum authorities may encounter threatened dissidents without any single actor initially possessing the entire operational picture.
Key judgments
Europe should be understood as a security exporter and security battlespace simultaneously, because Italy, France, Germany and the United Kingdom contribute materially to external counterterrorism, defence and maritime-security operations while their territories increasingly serve as targets for espionage, coercion, sabotage, cyber activity and foreign-state repression.
Italy’s principal vulnerability derives from its strategic geography, dense infrastructure, alliance basing and Mediterranean role rather than from an already demonstrated volume of assassination plots, while the scale of domestic security protection—more than 29,000 monitored sensitive sites—illustrates how external crises directly translate into internal security costs. Ministero dell’Interno — 22 Jun 2025
France combines the strongest autonomous continental expeditionary capability examined here with an explicit DGSI recognition that foreign regimes conduct transnational repression potentially extending to attacks on life, while its exposure to Russian cyber operations and information manipulation demonstrates that the threat spectrum extends well beyond physical violence. DGSI — Transnational repression
Germany’s role is uniquely sensitive because it combines major NATO logistics and operational infrastructure with a federal intelligence assessment that Russia, China and Iran constitute the principal foreign intelligence threats and that espionage, sabotage, transnational repression and cyber activity all remain at elevated levels. Verfassungsschutzbericht 2025 — Bundesregierung
The United Kingdom currently presents the most explicit publicly quantified lethal state-threat picture among the four states, because MI5 has described more than twenty potentially lethal Iran-backed plots and a rapidly expanding volume of state-threat investigations while the government has responded with legislation and registration mechanisms specifically intended to address foreign interference, sabotage and assassination. Protecting national security — Home Office
At EU level, the major development is institutional recognition that transnational repression belongs within the wider security concept of foreign interference and hybrid threats rather than solely within human-rights diplomacy, while the Parliament’s 2025 and 2026 votes demonstrate a substantial political majority in favour of a more coordinated response. MEPs demand EU action to fight transnational repression — European Parliament
The most consequential operational trend is the expanding use of criminal and low-level proxies, because this reduces the cost and diplomatic risk for sponsoring states while forcing European counter-intelligence systems to integrate information traditionally divided among espionage, organised crime, counterterrorism, cyber security and ordinary criminal policing.
What would change the assessment
The assessment would become materially more severe if European courts or governments establish additional cases of foreign-state-directed lethal action comparable in evidentiary strength to the Tiergarten or Litvinenko records, especially if such cases involve multiple jurisdictions or reveal persistent operational networks rather than isolated teams.
It would also change if EU institutions establish a harmonised reporting mechanism capable of producing reliable member-state comparisons, because current public data remain too fragmented to determine whether apparently higher activity in Britain, Germany or France reflects genuinely higher incidence, stronger detection capability, or simply greater transparency.
A third change would follow from evidence that sabotage campaigns are shifting systematically from property damage and disruption toward actions expected to cause casualties, because that would narrow the conceptual distance between hybrid coercion and overt armed violence.
A fourth would follow from large-scale reduction of Russian, Iranian or Chinese intelligence capacity in Europe through arrests, expulsions and network disruption, although the British and German records suggest that adversaries may compensate by expanding criminal-proxy recruitment rather than simply abandoning operations.
A fifth would arise if European governments begin treating attacks on major infrastructure or assassination plots as collective-security events under NATO or EU mechanisms rather than exclusively as national criminal matters, because such a shift would materially alter deterrence calculations.
Open official record
The most important remaining gap is the absence of harmonised statistics on foreign-state-directed threats to individuals, because Britain publishes unusually specific plot numbers while France, Germany and Italy generally disclose threat descriptions rather than directly comparable totals.
The second gap concerns the actual scale of proxy recruitment, since official services acknowledge the trend but do not publish comprehensive numbers identifying how many sabotage, surveillance or intimidation operations have been linked to criminal intermediaries.
The third concerns infrastructure reconnaissance, because governments rarely publish detailed information on attempted penetration or surveillance of ports, bases, telecommunications nodes and defence manufacturers for obvious security reasons, making the public record necessarily incomplete.
The fourth concerns the transition from information manipulation to operational activity, because the EEAS can document hundreds of FIMI incidents while only a subset can be connected publicly to espionage, sabotage or physical coercion networks.
The fifth concerns Italy specifically, where the intelligence and parliamentary record clearly recognises Russia, China, Iran and other states as sources of hybrid pressure, but there is not yet a publicly accessible statistical framework comparable to Britain’s MI5 reporting for quantifying transnational repression or lethal plotting.
The sixth concerns how national and EU institutions would respond to a demonstrably state-directed assassination or major sabotage event affecting several member states simultaneously, because the available legal and political tools are extensive but the threshold for escalating from criminal prosecution and sanctions to collective deterrence remains deliberately undefined.
Europe as Both Operator and Exposed Territory: The Dual Posture Matrix
EXECUTIVE BLUF: Europe occupies a structurally dual position. The same states projecting military power abroad (22 CSDP missions, 87,000+ Ukrainian troops trained, ASPIDES maritime defense) are simultaneously targeted by foreign intelligence penetration, transnational repression, sabotage, cyber operations, and proxy violence at home.
CSDP Missions & External Security Projection
As of July 2026, the European Union operates 22 ongoing CSDP missions with over 3,500 military and 1,300 civilian personnel deployed abroad. These include training 87,000+ Ukrainian troops under EUMAM and protecting 2,390+ merchant vessels via Operation ASPIDES in the Red Sea.
| Domain | External European Role | Internal European Exposure | Key Institutions |
|---|---|---|---|
| Counterterrorism | Air operations, ISR, training, partner-force support | Foreign-directed plots, proxy violence, threat networks | Militaries, Europol, NATO |
| Maritime Security | ASPIDES, IRINI, Sea Guardian, naval patrols | Port disruption, cable attacks, shipping interference | EU, NATO, Navies, Coastguards |
| Critical Infrastructure | Host bases, transport hubs, energy networks | Sabotage, reconnaissance, cyber disruption | Ministries, Private Operators |
| Diaspora Protection | Asylum and human-rights protection | Surveillance, intimidation, coercive repatriation | Police, Security Services, Courts |
| Metric / Indicator | Official Value / Status | Period / Date | Issuing Institution |
|---|---|---|---|
| Ongoing CSDP Missions | 22 missions (>3.5k military, 1.3k civilian) | July 2026 | European External Action Service (EEAS) |
| Ukrainian Personnel Trained (EUMAM) | 87,000+ personnel | Since Oct 2022 | EU Military Staff |
| UK MI5 State-Threat Investigations | +48% increase year-on-year | Reported Mar 2025 | UK Home Office / MI5 |
| Sensitive Sites Under Surveillance (Italy) | 29,000+ sites (10k+ critical infrastructure) | June 2025 | Italian Interior Ministry |
Italy, France & Germany Exposure
Italy monitors 29k sensitive sites; France (CHAMMAL/DGSI) combats active transnational repression; Germany (BfV) confronts escalating Russian, Chinese, and Iranian espionage/sabotage.
MI5 & State-Threat Operations
The UK documents 20+ potentially lethal Iran-backed plots since 2022, a 48% rise in state-threat cases, and has deployed the National Security Act 2023 and FIRS.
Criminal Intermediaries & Sabotage
Adversaries increasingly outsource surveillance, arson, and sabotage to criminal proxies, blurring traditional counter-espionage indicators and police boundaries.
- Harmonized Statistics: Lack of uniform cross-border metrics for transnational repression across EU member states.
- Proxy Scale: Unquantified actual volume of criminal intermediaries utilized for state sabotage.
- Infrastructure Surveillance: Classified specifics of attempted penetrations against European ports and defense nodes.
- Lethal Sabotage Incidents: Shift from material property damage to attacks intentionally causing casualties.
- Synchronized Node Attacks: Coordinated multi-node infrastructure disruptions across transport or energy corridors.
- EU Registry Adoption: Implementation of proposed common definitions and EU-wide coordinator mechanisms.

















