
Lawfare Archive: The Violent Extremist Threat to Critical Infrastructure in the United States
About this episode
The Lawfare Podcast: Patreon Edition is made possible by:
Hosted on Acast. See acast.com/privacy for more information.
Get every episode summarized
Each time The Lawfare Podcast: Patreon Edition publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
431 searchable segments. Every word is indexed and playable.
Full transcript
The Lawfare Podcast: Patreon Edition — Lawfare Archive: The Violent Extremist Threat to Critical Infrastructure in the United States. Machine-transcribed; use the interactive transcript above to jump the player to any line.
I'm Sarah Wilrich, Internet Lawfare with an episode from the Lawfare Archive, the September 7, 2026. Over the past few weeks, numerous cyber attacks have been launched against water purification systems in over 12 states, which some have attributed to a wrong-linked hacking group. On August 26th, President Trump declared a national emergency related to the security of a different kind of critical infrastructure, the US Energy Grid. In his executive order, Trump warned of the potential for foreign actors to remotely disrupt the grid. For today's archive, I chose an episode from October 24, 2022, in which Tyler McBrion spoke with Llanah Krill and Sheamus Hughes of the George Washington University program on extremism about the threat to critical infrastructure posed by violent extremists. They discussed specific movements in their plans, how such plans spread, and what can be done to protect critical infrastructure going forward.
I'm Tyler McBrion, Managing Editor of Lawfare, and this is the Lawfare Podcast, October 24, 2022. Last month, the George Washington University program on extremism published a report called Mayhem Murder and Misdirection, Violent Extremist Attack Plots Against Critical Infrastructure in the United States. To talk through that report, and a recent Lawfare article on the topic, I sat down with Llanah Krill, a research fellow at the program on extremism, and Sheamus Hughes, the program's deputy director. We discussed the white supremacists and Salafi jihadists who make up these movements, the encrypted channels through which propaganda and plans are spread, and what's to be done to protect critical infrastructure in the United States. It's the Lawfare Podcast, October 24. The Violent Extremist Threat to Critical Infrastructure in the United States. So Sheamus and Llanah, you have just released this report and subsequent Lawfare article on the targeting of critical infrastructure by violent extremists. So to start things off, can you tell me a bit about who the actors are here?
Which violent extremists are we talking about? So the report looked at attacks and plots in the last six years. So since 2016, directed towards critical infrastructure. So what we tried to do was we took about 94 cases that we had, 55 white supremacists, 39 jihadists, and said, listen, what are they targeting? Are they looking at an energy sector? Are they looking at the internet? Are they looking at schools or things like that? And whether or less we can learn from those types of things, right? There's a giant talk about this need for critical infrastructure. But when we found out for the report is not a whole lot of people kind of dug into the data a bit. So when Alana and Bennett were working on this, they found some kind of interesting stuff. This is a niche area that no one really focuses entirely on. And these actors, whether they be white supremacist or jihadists, they share some levels of tactics, but there are also some differences that are interesting. And Alana, I know that there's this distinction in the report between homegrown violent extremists and domestic violent extremists. I think to a lay person's ear, these might sound like synonyms.
Could you describe sort of the distinction there? Yes. So homegrown violent extremists include actors that are motivated by foreign terrorizations such as al-Qaeda or Islamic state, but our residents that have grown up or are citizens of the United States. So domestic violent extremists are somewhat the actors we've seen at, say, the January 6th Capitol siege. They adhere to white supremacist doctrines that includes your average neo-Nazi actor within the United States, those who adhere to neo-fascist ideology. Great. And, and, and, and, you know, now that we've, we've gotten that's great away. We're talking about mostly so laughy jihadists and white supremacist movements, militias, et cetera. What do we mean by critical infrastructure here? Materially, you know, what does that look like? Yeah, no, it's, it's a catch-all phrase, right?
So if, if the terminology of homegrown violent extremism was confusing and versus domestic violent extremism, exactly that even further for critical infrastructure. So it's 16 different industries and it can range from energy industry, you can range from schools, military bases, a kind of everything you could think of that's critical infrastructure. Something that that keeps the lights on and the internet on is time of the folks or trains and airplanes and things like that. Things that we've seen traditionally that are kind of as focused on, you know, obviously 9-11, we have the attack on airplanes and other places like that, but we've also seen a rise of applauding an attacks towards rail states, systems and buses and things like that. And, you know, your, your original question about, you know, what is this difference between domestic violent extremism and homegrown violent extremism? Obviously, it's ideology, right? So it's one foreign base, which would be homegrown violent extremists, that's ISIS and al-Qaeda. And then domestic is, you know, the garden variety of white supremacists and neo-nazis. And it's really confusing for the public to understand those dynamics.
And that's because we have this like, got-awful system in government where we try to confuse people as much as possible. It makes sense to the FBI agent talking to the DHS officer, but for the general public, this idea of domestic violent extremism and homegrown violent extremism being very different, it confuses people. But it's kind of just what we're stuck with now. And Shema started to hint at this at an earlier answer about the motivations behind this report. You mentioned that there's a lot of rich data out there, but no one is really comparing it and no one's quite talking about it. Alana, could you, could you speak to a bit about, you know, what motivated you to embark on this project with your colleagues, you know, what you were hoping to find and what you were looking for? Yes. So when we first entered this space and started thinking about critical infrastructure targeting, we had a wide range of actors to choose from when starting this comparative study. We elected white supremacists and Salafi Jihadists because they're known to government agencies
to be some of the most lethal actors out there that conduct some of the most lethal attacks. And from there, we noticed that there was a gap in the literature, especially comparative literature surrounding critical infrastructure targeting by all types of extremists, specifically whites from haemesis and Salafi Jihadists. So we wanted to compare over the last six years their actions, their what targets they tended towards and their successes, their failures, and what it all means for the state of critical infrastructure moving forward. And Shamus, I think a lot of listeners will be wondering at this point, you know, how bad could this be or how bad could it get critical infrastructure, as you said, is is definitely right there. It's critical. So what's this, what's the spectrum of severity that we're looking at, you know, from, from the low end to the high end, if some of these attacks were to be successful? Yeah, that's always the question. When you look at these kind of homegrown or domestic violence, extremist groups is like,
you know, how much capability do they actually have? And if you peel back the numbers, you know, we're talking about 94 different individuals, it's not that large of a sample size admittedly so you've got a population size of 330 million. So you're not talking about a large number of folks, but we have seen both in the propaganda, whether it be ISIS or increasingly white supremacists saying, listen, we got to take down the energy grid because for the ISIS guys, it's like, we take that down and then the system falls. And for domestic violence extremists, it's like, we got to start a civil war, right? This is, this is the way to do it. The most these guys, for lack of a better word, are knuckleheads, right? Dangerous knuckleheads hold really atrocious beliefs and all of those things, but some of them, you know, have a very hard time putting together a plot. They have the general idea of, man, we should, we should derail a train or we should take down a power grid, but the actions don't usually reach up to this, like, level of this mastermind, Hollywood idea of a terrorist. We've seen a number of cases where the FBI has interjected themselves in the process and
it may have been the white supremacist's idea to attack say an energy grid, but there was some some help along the way to get them to the point where they can have handcuffs on them. You know, we always think like, you know, are these kind of masterminds planning this out? And the short answer is usually not. The downside is, is if it's such a large sector, critical image structure, then the opportunities there are vast, right? And you know, because we rely on kind of a system of systems, there's not a huge level of backup on these things, right? You take down one spot and it has a ramification. You know, we saw that in COVID, right? So we shut down certain areas. Other things get affected. To go back to the two umbrella groups that we're talking about here, as you've been, you know, talking about they have their own motivations, which then will subsequently motivate different targets, different methods. So taking each group, you know, separately, how do their beliefs then motivate which sector that they target? So I think, you know, your report speaks well to the fact that the energy sector is well
targeted because it's so essential to every other sector, as you mentioned, it's a system of systems. But you know, what is the white supremacist more likely to target versus this Lofi jihadist likely to target? And why? So it's a Lofi jihadists. We've seen throughout the cases that they tend to target government infrastructure sectors, emergency services, and commercial facilities. Their belief is that they're in an entrenched conflict with the West and Western governments. So in fact, it's quite logical that they target government infrastructure, for say, compared to that white supremacists, they tend to target energy sector the most. How they also want to create mass chaos, they're hoping to, as I said earlier, kind of influence and edge on the downfall of the United States systems and governance. But that includes a long-winded scale of attacks.
So they see the energy sector as one step in the process to influence all their energy sectors. And eventually, down the road, the downfall of our society, as we know, will occur. And a lot of touch on something that was very important, which is this idea of accelerationism. So if we're going to confuse the listeners even more, let's add another definition. Accelerationists are mostly of the domestic violence extremism mindset, but they're basically like, listen, we got to start a civil war. The system that we have is not working, and if we can cause as much chaos as humanly possible, then so be it. And the targeting gets a bit scatter shot on that. And it's also particularly hard for the US government to kind of wrap their head around, because it's ideologically focused, but not really. Meaning that, look at the gentleman who put a bomb at the DNC and the RNC on January 5th, right? If you put a bomb towards the DNC, you give it an ideological pack for the bomb in front of the RNC, you get an ideological back. You put them on both.
You're probably dealing with an accelerationist, right? Somebody's just trying to cause as much mayhem as possible. And we call it like the Joker effect, right? They just want to watch the world burn. Yeah, and kind of teasing at that thread a bit more, you know, and thinking about accelerationists, why is then critical infrastructure, almost the perfect target for their aims? So critical infrastructure is one piece of potential vast targets that accelerationists could target. It's a key target for them because overall, as I think Shemus mentioned earlier, critical infrastructure itself, its assets are spread widely across the United States, which creates opportunity for, say, actors as far as the Northwest in the United States to target an asset that's closer to them. Additionally, there's, as Shemus mentioned, there's so many different infrastructure sectors. There's an ability to, say, target one initially, and then what we've seen is these actors,
they attempt to evade law enforcement and evading consequences after what they hope would be after their first attack to target a different sector. So it creates a wide range of opportunities for these actors who are motivated to do more than just one attack. You know, it's this idea of a domino effect, right? You knock out the power grid and you move onto the trains, you move onto the buses, you go from there, and you cause as much mayhem as humanly possible. And that's what their end goal is, right? They think society is teetering on such an edge that if it just gives a little bit of a push, we'll be able to build back society into what we believe it should be. Now I want to go into some of these case studies or these cases rather that you looked at. Can you give us a sense of what some of these plots looked like when they were being planned? I understand that every person that you looked at here either was apprehended in the process of planning or attempting to carry out an attack. What did some of these attacks look like? Shema, so go back to you.
It runs with the spectrum, right? So in the Salafi Jihadist specter, you have two or three guys who are targeting the railway systems in the northeast. What I find the most interesting case would be one of Ohio, which is a bunch of domestic violent extremists who were targeting energy sector, right? So the idea was to target a substation and go from there. What I find most interesting about that case is those guys were charged from material sports terrorism, which is a very unique charge for a non-Jihadist case. Most of these guys get charged with some sort of attack on infrastructure or gun charges or drug charges or things like that. This is a part of a case where DOJ decided to put their finger on the scale and charge these guys from material support. Now they were lucky in some respects in that they pled out, right? Now if you take a domestic violent extremist case to trial under material support terrorism, it gets a little bit messy pretty quickly without a connection to a designated foreign terrorist organization. So I find those cases to be the most interesting.
And like I said, some of these guys, you look at the plots and you think to yourself, there's no way this is going to happen, right? It's never going to come to fruition. On the other hand, you only got to be lucky every once in a while on these type of things. And I think that's why the FBI was taking some of these cases so seriously. And Shame, it's just one more follow up on that. Are we talking here mostly kinetic plots or also attempted cyber attacks as well? Yes, cyber security is probably a different animal. I mean, listen, it falls on the critical infrastructure clearly, but we don't have the capability. We haven't seen the capabilities in the 94 cases. The low level DDoS attack is probably within their window, but widespread hacking of systems and things like that is not the skill set of these guys, right? The white supremacists tend to like to shoot guns in the woods and drink beer. They don't like to spend their time learning Python and R. So it's a little bit different in the way they're doing things. They're kind of like the caveman approach to an attack. They're less likely to do kind of cyber security type of attacks.
Those are much more state sponsored, right? The Iran, the Russia, the China of the world. We haven't seen that capability rise to a level four domestic violence extremists or even Johannes. Hopefully that comes some nerves among our listeners that white supremacists don't want to learn Python. Who does? Really honestly. Yeah, that's true. It's relatable, honestly. Alana, I want to go to you for this next one. I'm in thinking about how these terrorist groups and their dangerous knucklehead members learn about critical infrastructure. How do they disseminate the knowledge to plan attacks? Is a lot of personal research online or are there networks of information where both propaganda of radicalization and ideology are spread, but then also sort of the hard knowledge to know where the vulnerabilities are in these infrastructure systems? Yes. So a lot of these actors come across this knowledge through, I'd say, personal research, but also mostly over communication apps, including Telegram.
They could include encrypted apps where a lot of propaganda is being spread. For example, we saw a lot of accelerationist focused groups emerge out of what was called the Iron March Forum, which was an online forum that where a lot of different domestic violent extremists were able to speak to their ideas, share information, targeting information, and where a lot of these groups, including the Adam Loth division or the base, congealed and started to branch off into their own like-minded groups. A lot of the propaganda being shared over these communication apps is how actors, especially lone individuals, that hope to target critical infrastructures. It's where they find their information, their resources. You've seen this in multiple cases. Furthermore, we have seen actors who are arrested for plotting to target critical infrastructure
that have used resources such as books that understand more thoroughly how nuclear reactors work. So they use a wide range of materials, but I'd say most focus should be on the communication apps that they use, the information that they share. This also we've seen includes publications such as Terragram. It is known to be a collection of telegram channels that discuss accelerationist plots and domestic extremist plots. They have published propaganda resources, including large-scale documents that explain critical infrastructure, the weaknesses, how to circumvent such security within the infrastructure, and that's definitely something that's most concerning. I would also mention the labor intensiveness of these investigations. It's one thing these guys are organizing on open platforms like Twitter and Facebook
and things like that, relatively open platforms. It's a little bit of a different animal when they go to telegram or other encrypted apps. The FBI has always been complaining of this idea of going dark. We don't have a window into encryption and things like that. There is some truth to that. I think what the real truth is, it just means a little bit more work on the front end, meaning that you got to run sources against it. You got to rely on online covert employees. It's a whole thing. You got to begin the channels all the time, and those channels get knocked down on a daily basis. You got to add it to the next one. You got to have somebody to vouch for you. It's just a little bit more work on the front end for law enforcement, but that's where these guys are heading now. They're basically just trading their lessons learned online. To add to that, a lot of these actors also take information and notes from past attacks that have occurred. There's propaganda books out there that discuss attacking critical infrastructure sectors. Their fiction, let me be clear on that. They are fiction, but a lot of these actors and current day learn how or emulate this
with their plots, with what they want to achieve. That's something to be wary as well, because we can't control as a society, the flow of media, but it's something that's really, really important to understand. These materials being spread around are influencing new radicalized actors. To begin to shift the conversation toward solutions, what law enforcement can do, I'm curious the sharing of blueprints, for example, are some of those classified in the mere sharing of it illegal, or is it perfectly legal to share information about how a power good works? If so, what challenges does that pose to law enforcement trying to root out these networks? You have an open flow of information on the internet, right? That's the best part about the internet. You can get the Taylor Swift CD, and you can get a power plant grid, and both those things are fascinating to me, right? There's very little that law enforcement you can restrict it. You've seen some level of an attempt to basically not put some of this stuff online, or
air drop some of the plans, so they're not on the online space. For the most part, the horse is out of the barn. The question then becomes, how do you harden what's already out there? Then how do you, I mean, some of this is going to be good old fashioned law enforcement, how do you infiltrate your network so that you know what's up? If you look at solutions, there's a variety of them. One is, I think one of the takeaways from the report is, yes, it's concerning, but it's not the be all end all. And so, if they're not targeting energy, they're going to be targeting the public, if they're not attacking a power grid, they're going to be attacking the mall. And so, at the end of the day, the target matters a little bit, but not as much as the individual itself. And getting yourself into the system where you can stop that individual from doing something horrible. Sheamus, I was waiting for you to work in your Taylor Swift reference. I will. Well, you have a drop today. So, like, this is an important thing. I don't really know why we're talking about critical drug extractor. I mean, there is nothing more critical than Taylor Swift's new CD. Her album is fantastic. So I'm going to ask a bit of a cynical question pivoting away from Taylor Swift, unfortunately,
for the moment. You know, your report focused on cases in which individuals were apprehended, as I mentioned, in the process of planning or attempting to attack, which may lead, like I said, a cynic to ask, why pay closer attention to this if it seems like law enforcement's got this? They've been catching the bad guys and the plots have been foiled. So, a lot to go to you. Why still raise the alarm on this by publishing a report? Well, it's important to raise an alarm for this because actually, in this scope of critical infrastructure across the United States, the government works closely with private sector partners to make sure that their critical infrastructure assets are protected or up today are hardened against the most recent of threats. It's very important to understand that it's not just the government's job to protect such critical infrastructure and the assets around the country, but we need to be building more partnerships and stronger partnerships so that when threats arise, law enforcement, as
well as the private companies, can be prepared and update their securities accordingly. I couldn't agree with a lot more on that, right? So, you know, it's one thing to add another guard base to Fort Bragg because you're worried about a threat. That's not something that you can do at a power plant. You can't demand that they do things. You can add standards, you can add regulations, you can do all the variety of things you want to do. That takes time, right? At the end of the day, you need to have a partnership. The FBI needs to say, listen, these are the cases we saw. This is what we think they're targeting. And here's the information to the local power plant or other critical infrastructure and saying, this is what we're seeing, right? And this is where we think you should think about doing things. And that's where groups like InfraGuard, the FBI runs that works with private sector to alert them to emerging threats and things like that. It's going to rely a lot on private sector to do this. And then we have to figure out incentives for it, right? If you're worried about the bottom line, which you are as a private company, what is the incentive to stop these type of attacks or harden your stuff?
And the answer is, you know, if it goes down, it's going to affect your bottom line. And so the more the FBI and law enforcement can hammer home that place, with the understanding that we're not talking about a massive wave of people that are interested in this, but still something that's concerning nonetheless. So while critical infrastructure targeting, we've seen a lot of cases that have been unsuccessful. Actors have unsuccessfully carried out their plots. There have been a small subsection of plots that have occurred that people were injured. Let's say in the 2016 attacks within Charl Cine, York and New Jersey, an actor who adhered to al-Qaeda's ideology named Ahmad Khan Rahimi, he targeted a 5K race and other transportation systems using explosives and it injured over 30 people. And this was only in 2016. There's been other attacks that have been successful, but it's really clear that while we hope
these actors won't carry out their plans, we need to be diligent working with law enforcement and our private partnerships to prevent further attacks from happening. So as much as there are a lot of cases that have not come to fruition, it's still a possibility and we should all be wary of that. I would add that we learned the lessons from the past, successful attacks, right? So think of the Oklahoma City bombing that killed hundreds of people. And then a number of security measures are put in place post that to try to harden federal buildings from that. I hope that this report can provide some level of nuance and understanding of the threats so that we can prevent future attacks that occur. This is not a Tom Plancing novel, right? These are not these guys that are planning to poison the entire water system. They don't have the capability of those things, but they're still dangerous nonetheless. And so we set ourselves up for failure if we don't try to figure out what happened in the past so we can learn and prevent the future.
In addition to that, there are other actors out there that we did not focus on for this report. Many other actors adhering to different ideologies that do target critical infrastructure. And we hope to dig into this and to further research. But this is just a small subsection of the actors that are willing to target the United say system of governance and our society through critical infrastructure. I think we can leave it there. Stay tuned for more research from the program on extremism. Alana Krill and Shaman Seuss, thank you so much for speaking with me. Thanks for having us. The Lawfare Podcast is produced in cooperation with the Brookings Institution. You can get out of three versions of this and other Lawfare Podcasts by becoming a Law fare Material Supporter at patreon.com slash lawfare. You'll get access to special events and other content available only to our supporters. Please rate and review us wherever you get your podcasts. Look out for other offerings including rational security, chatter, and our latest Lawfare Presents Podcast series on the government's response to January 6th via Aftermath.
Check out our written work at lawfareblog.com. You can also buy Lawfare swag at the lawfarestore.com. The podcast is edited by Jen Pate-Howell and your audio engineer this episode was Ian and Wright of Goat Roadio. Our music is performed by Sophia Yann. As always, thanks for listening.
More episodes
More from The Lawfare Podcast: Patreon Edition

Lawfare Archive: An Election in Germany
The Lawfare Podcast: Patreon Edition

Lawfare Archive: Juliette Kayyem on Dealing with Disasters
The Lawfare Podcast: Patreon Edition

Lawfare Daily: Mike Schmidt Talks CHIPS and U.S. Industrial Policy
The Lawfare Podcast: Patreon Edition

Rational Security: The "Whale of a Tale" Edition
The Lawfare Podcast: Patreon Edition