Skip to content
TrackPodcasts
societyOct 7, 202624:12

October 7th: The Enemy You Think You Know

Get every episode summarized

Each time The Watch Floor with Sarah Adams publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

About this episode

“I spent the last few years investigating October 7th from the terrorist side of the attack. And how a terrorist organization Israel had watched for decades was able to carry out an attack on that scale.”From the transcript

October 7th was not simply an intelligence failure. Israel had warning, surveillance, military power, and years of experience watching Hamas. What it lost was enough doubt about whether its own assumptions could be wrong.


In this episode of The Watch Floor, I look at the lessons from October 7th that go well beyond Israel. We examine how complacency shaped intelligence assessments, how Hamas studied and attacked Israel’s dependence on technology, why warning indicators were missed, and what happened when the national response became overwhelmed and the fight turned local.


I also look at the broader threat environment around Hamas, including training and relationships outside Gaza, and why intelligence services have to understand the enemy they actually have, not the enemy they remember. Most importantly, this episode is about what the United States can learn from those failures before someone tests the same weaknesses here.


Complacency does not always look like laziness. Sometimes complacency looks very sophisticated.

Hosts & guests

Transcript ready

208 searchable segments. Every word is indexed and playable.

October 7th: The Enemy You Think You Know

The Watch Floor with Sarah Adams

0:00
24:12

Full transcript

The Watch Floor with Sarah Adams — October 7th: The Enemy You Think You Know. Machine-transcribed; use the interactive transcript above to jump the player to any line.

Mmm. Mmm. Mmm. Welcome to the Watch for I'm Sarah Adams. I spent the last few years investigating October 7th from the terrorist side of the attack. Who planned it? How the attackers prepared? Who supported them? Where some of the training occurred? And how a terrorist organization Israel had watched for decades was able to carry out an attack on that scale. But the more I worked October 7th the harder it became to ignore another part of the story. How did Israel allow it to happen? I don't ask that to blame the people who were attacked. I ask it because

Israel had one of the most capable intelligence and security systems in the world. And there are lessons in what went wrong that could save lives somewhere else, including right here on US soil. And I don't think October 7th can be explained simply by saying Israel had an intelligence failure. It was so much bigger than that. Israel developed a set of assumptions about Hamas. And those assumptions began shaping everything else. They affected how intelligence was interpreted. How forces were positioned? What scenarios people trained for? How much confidence was placed in technology? And how seriously warning signs were taken? This is what worries me. Israel did not lack intelligence. It did not lack military power. It did not lack surveillance. It did not know nothing about Hamas.

It had all of those things. What it lost was enough doubt about whether its own assessment might be wrong. The central assumption was that Hamas was deterred. Israel knew Hamas remained but the belief had developed that Hamas did not want a major war. Hamas governed Gaza. It had major economic interests there. It had stayed out of some previous fighting involving the Palestinian Islamic jihad. The assessment became that Hamas understood one another major confrontation with Israel would cost and would therefore avoid one. The problem with an assessment like that is once it becomes accepted long enough, new information starts getting interpreted through it. Israel had the Hamas invasion concept that became known publicly as the Jericho

Wall Plan. It described a large attack across the border, assaults against military positions in Israeli communities, and many of the basic elements that appeared on October 7th. Israel also watched Hamas train. Personnel inside Israeli intelligence raised concerns that what they were seeing was beginning to look a lot less like something aspirational, a more like a plan that Hamas was actually preparing to do. But the larger assessment did not move enough. Later reviews found that information on the invasion concept existed but the possibility of Hamas actually executing it was discounted. The threat had essentially been identified without being fully accepted. Think about that for a moment. You have the enemy's plan but you still don't prepare for the enemy's plan. That happened when information has to compete with an assumption that has become stronger

than the real information itself. This is one of the reasons I think intelligence organizations have to keep asking a very uncomfortable question. What would make us admit that our assessment is wrong paging CIA on a Hamza bin Laden because intent is difficult to know. An adversary can change his intent tonight. Capability is often easier to see developing over time. You can watch training. You can see new equipment. You can watch tactics change. You can see organizations experimenting, learning, and building relationships that they didn't have before. This is where another part of October 7 needs a lot more attention. The attack is often discussed as though Hamas developed this capability almost entirely inside of Gaza and then suddenly launched it against Israel. The work I've done

and many others on the actual plotting for this attack show it comes from a much broader terrorist environment. Heck, even the paraglider attack wasn't designed by Hamas. It was an old lashkari taiba plot. A couple years ago, we put out a report called October 7, where we traced different pieces of the plotting, the training, the facilitation, and the relationships that went on outside of Gaza to Iranian actors, to senior leaders in al-Qaeda, hacked to the Taliban and the Hakhani network to terrorists inside of Syria. I'm not going to turn this episode into another breakdown of that investigation. I've covered that separately. And some of those fighting go well beyond what Israel has told the public. To this day, they're still not discussing the foreign terrorists that were on the ground. I know Libyan terrorists were there. I know Syrian terrorists were there. There was members of ISIS there. Heck, there was members of the Taliban there. Al-Qaeda sent a senior

terrorist named Yossin al-Suri to be kind of their commander for Gaza. There was a lot of different layers when it comes to terrorists. And when you only focus on Hamas and then move on to Iran and ignore all these other actors, you're leaving a threat that other countries now also are going to feel and be affected by. So that should change a little bit how you look at Hamas. If somebody you've been watching for 20 years suddenly begins training with people who've spent decades fighting the United States and his allies, right? Like al-Qaeda, you should not continue evaluating him on what he did five years ago, right? Hamas has evolved. You need to evolve with this threat. You should be asking what Hamas has been learning now in this collaborative process. Maybe now they have better operational security. Maybe they know how to compartment

information better. You know, loose lips has been one of Hamas's problems. Well, it wasn't an issue in October 7th. These relationships gave ways to think like they haven't thought before. The fact that that relationship exists with different terrorist groups should make some uncurious. Israel was told months before October 7 that Hamas was training enough Gammist in with a number of other terrorist groups. So right there, you're focusing on yesterday's enemy when the current enemy is stinging their right in front of you and you don't want to hear this. And we heard ourselves again and again and again by putting terrorist organizations into these neat institutional boxes. Hamas is Hamas al-Qaeda is al-Qaeda. Hezbollah is a Hezbollah. Iran is a state. Sure, those distinctions matter, but they don't stop knowledge, weapons, money, training, and experiences from moving between networks. The adversary does not care which analyst, which agency,

or which portfolio owns their problem. Only we do. And sometimes that creates seams. They can, of course, exploit. None of that also changes the fact that Israel already had a warning much closer to her home. During the night before the attack, unusual indicators began accumulating. Israeli SIM cards associated with Hamas operatives were activated. Other anomalous activity was detected, senior officials held consultations. The warning was not perfect. It usually isn't. The problem was the unusual activity was still being interpreted against the existing belief that Hamas was not preparing for a major attack. The response was cautious. And ground readiness was not substantially increased. This is another lesson I think people misunderstand about intelligence. Warning does not usually arrive as someone hand in you the date, the time in the location of

attack. Most of the time you get pieces. Something changes that normally does not change. Then something else looks slightly wrong. A communication pattern shifts. A report comes in about something unusual from a source. An adversary moves people or equipment. Activity that has been routine suddenly increases. Individually, each one of those things may have an innocent explanation. The challenge is recognizing when everything is starting to come together. This is what leaders have to prepare for because if you're standard for changing posture as absolute certainty, you will often get certainty when an attack begins. That is far too late. And you have to consider, of course, than the consequences of that. Even if the probability of an attack is assessed as low, what happens if the consequence of being wrong is catastrophic? That doesn't mean putting a

country on maximum alert every time something looks unusual. It means having graduated responses. Maybe you move a few additional forces. Maybe you alert local security teams. Maybe you position medical resources differently. Maybe you tell people to keep their radios on and be ready. You buy yourself options. Intelligence reduces uncertainty. It does not eliminate it. If you're waiting for it to eliminate it, you're going to be in a very difficult spot. A resilient security system should be able to survive when an intelligence assessment is wrong. And that brings me to technology. Israel has built an extremely sophisticated defense system around Gaza. There's cameras, sensors, communications, observation posts, remote systems, and the physical barrier gave Israel an enormous amount of visibility. The problem was that Hamas was, of course, studying that

system too. Hamas attacked observation and communication systems while breaching the border at numerous locations. Drowns and other weapons were used against part of that defensive network while assault forces moved through the gaps. Research after the attack has highlighted how Hamas deliberately worked to degrade Israeli awareness as the assault began. That matters because Hamas was not simply attacking Israel. It was attacking Israel's ability to understand what was happening. Once cameras go down, communications become confused and several locations began reporting attacks at the same time. A highly sophisticated system can suddenly become very human again. People are trying to determine what is happening, where the main attack is, where forces are needed, and what report is accurate. Hamas created that confusion deliberately. The lesson for us

is not to stop using technology. That would be completely ridiculous. The lesson is to train for the moment when it's all gone. If a police department depends heavily on cellular communications, practice without cellular communications. If security depends on cameras, shut down the camera feed during an exercise. If everybody relies on GPS, see what happens when GPS is unavailable. That is how you learn whether technology is supporting your security plan or whether technology has quietly become the security plan. Human intelligence fits into the same problem. Of course, we can't say Israel had no human intelligence in Gaza. That's been proven wrong for years. The reality is a lot more complicated. There are indications that Israel's insight into Hamas' intentions had weakened while technical collection had become increasingly important.

They were relying a little more on technology than human collection. The same thing we're doing in places like Afghanistan. Syria, Iraq, the US government is making the exact same mistakes. And then at that same time, Hamas was working to reduce this signature's Israeli intelligence depended on, including through compartmentation and their new communications discipline. Technology can tell us an enormous amount. And partner reporting can be valuable, but neither completely replaces having trusted people who know what's happening inside of an organization. The further removed we become from a target, the more careful we have to be about believing that more technology means more understanding. Sometimes it means more data. They are not always the same thing. Then there's the concept of preparedness on the ground. And this is one of the clearest lessons for Americans because it does not require a national intelligence agency to fix it.

When Israel's larger response became overwhelmed, the fight became very local and very quickly. Communities near Gaza had local security swaths often made up of residents with military experience, but their readiness was incredibly uneven. At Naq al-Az, most of the local security teams' rifles were locked in an armory. When the power went down, the armory could not be opened normally, and the person able to open it manually was killed early in the fighting. Local defenders and police still fought, but substantial military help did not arrive for roughly seven more hours. Now look at Neeron. The outcome was very different. A locally station military force police and the community security squad were able to organize and keep a mosque attackers from penetrating the kaboots. The security squad opened its armory, distributed the rifles

that had ensuing the defense. The later investigations still found serious readiness problems, including faulty weapons and limited ammunition, but the fact that people were able to respond immediately mattered enormously. That is what community preparedness means in the real world. It means what happens before enough help gets there. There is always a gap in a crisis. What is your plan to fill that need? A large coordinated attack is specifically designed to overwhelm first responders. Police go to one location while another attack develops somewhere else. Roads become blocked. Communications fail. Hospitals begin receiving casualties. Rumors and bad information spread at the same time, leaving leaders to try to understand what is actually even real. You cannot eliminate that chaos. You can prepare people to function, though, inside of it. Israel had spent decades dealing with terrorism, but much of the system was prepared for threats

within a familiar or comfortable range. October 7th combined, a large rocket barrage with drones, border breaches, attacks against military positions, assaults on civilian communities and police stations hostage taking, and communications disruptions, and all this was occurring simultaneously. The attack exceeded the assumptions built into the response. We should learn from that. If we only train one problem at a time, the exercise may tell us whether a particular procedure works. It doesn't tell us whether the system holds together when several procedures fail at once. At some point, exercises need to become uncomfortable. Communications disappear while police are responding to more than one attack site. Hospitals begin getting casualties while information online is wrong. A second incident starts while resources are still committed to the

first one. This is where you find the weaknesses an adversary will look for. Another lesson is listening to the people closest to the threat. Before October 7th, surveillance soldiers along the border were reporting concerning changes. Intelligence personnel challenged assumptions about Hamas' plans and training, and there were also concerns that existed about readiness. Those concerns did not change a larger system enough. That is important because seniority does not guarantee that you see the threat first. Sometimes a person watching the same target every day sees the change before everybody else. The challenge for leadership is building an organization where that warning can actually affect a real decision. There is no value in telling employees that the scent is welcome if every dissenting assessment is pushed upward until somebody explains why the old assessment

is still correct. We get that every day in the US when it comes to al-Qaeda and ISIS and the fact that they actually do work together and we're getting 10 and 15 year old assessments again and again. That is not red teaming. That is protecting the consensus. Israel's internal divisions also do belong in this discussion, but I think we need to be precise about the lesson. Political disagreements did not cause October 7th. Israel was however deeply divided in the months before the attack. In adversaries, we're watching. Hamas and others could see the protests, the arguments over military service, and the public political crisis. In adversaries, watches those things for the same reason we watch them in other countries. They can affect perceptions on cohesion, deterrence, and how a nation may respond under pressure. Just like Russia was watching the US during the fall

of Afghanistan, it made real decisions based on that regarding their invasion of Ukraine. These things don't happen in a vacuum. The lesson for America is not that disagreement is dangerous. The lessons that our enemy study our divisions and look for ways to use them. They study what anger us, what divides us, what Americans no longer trust, and what kinds of messages move quickly through our information environment. That becomes part of the battle space too. And finally, we cannot assume an adversary only gets one move. Has Balla, for example, did not launch a simultaneous large-scale ground infiltration from Lebanon on the morning of October 7th? Had Israel been dealing with major penetrations in both the North and the South, at the same time the response problem could have been dramatically worse. That matters even more when you look at October 7th inside of the broader terrorist network that I've been investigating.

The relationships around the attack extend beyond Gaza and involve actors across multiple countries and terrorist ecosystems. That does not mean every actor has the same role. It means we should stop expecting threats to respect organizational boundaries. A terrorist attack can create an opportunity for another group. A physical attack can coincide with a cyber activity. A hostile state can exploit the confusion through propaganda and disinformation. And another terrorist organization can simply watch what worked and copy it later. When I put all these thoughts together, I really come back to the concept of complacency. Because complacency doesn't always look like laziness. Sometimes complacency looks very sophisticated. It can look like an intelligence assessment supported by years of data. It can look like a billion dollar surveillance system. It can look like an exercise program built around years of experience.

It can look like a readiness report that says everything is fine. This is what makes it dangerous. Israel had developed a conception of Hamas and then built parts of its security posture around that conception. Hamas was deterred. A large invasion was unlikely. The border would provide a warning. Technology would expose preparations. Intelligence would give enough time to respond. Then Hamas attacked the assumption underneath that system. This is a lesson I think we need to take from October 7th. Know the enemy you actually have. Not the enemy you remember. Notice when capabilities are changing. Pay attention to who they're learning from. Keep human access even when technology makes attempting not to. Listen when people closest to the threat tell you something has changed. Train for your systems to fail. And make sure local communities can function

during the time before major help arrives. Most importantly, leave enough resilience in the system that one wrong intelligence assessment does not turn into a major catastrophe. We are never going to predict every attack. We are never going to eliminate surprise. But surprise does not mean defenseless. Hamas did not need Israel to know nothing. It needed Israel to believe the wrong thing for long enough. Other terrorist organizations in hostile states watch what happened on October 7th too. The question is whether we learn from it before someone tests the same weaknesses right here in the United States. Thanks for being here today on the watch floor.

More episodes

More from The Watch Floor with Sarah Adams

View all episodes →