How to Identify Lone-Actor Terrorist Threats Using OSINT
Learn how to assess lone-actor terrorist threats with OSINT: research-backed warning behaviors, real cases, link analysis, and evidence preservation.

Lone actor terrorism has become more prominent in the West. In its 2025 report on lone wolf and youth terrorism, the Institute for Economics & Peace reported that lone actors carried out 93 percent of fatal terrorist attacks in Western countries during the five years through 2024. The report describes a shift toward individuals acting on their own initiative, sometimes influenced by extremist communities but without a group directing the attack.
That shift creates a difficult detection problem. MI5 explains that attacks initiated by individuals rather than directed by terrorist groups can be harder to identify. The UK's Lessons for Prevent review also warns that the online behavior of people who radicalize independently is growing harder to detect and interpret. Methods built around organized groups do not fully address this threat.
Yet public information can still give investigators a starting point.
In 2018, public social media posts helped draw investigators' attention to an Ohio man who later admitted planning an attack on a synagogue. According to the U.S. Department of Justice's account of the Damon Joseph case, the posts included weapons photographs and messages supporting ISIS. A subsequent FBI investigation established the attack plan, and Joseph was arrested before carrying it out. He received a 20-year prison sentence in 2021.
Public posts provided an investigative lead, while the undercover conversations and further investigation established facts that the public material alone could not.
That is the role of open source intelligence, or OSINT, in preventing lone-actor terrorism. It can reveal concerning communications, help establish who is behind them, and show how behavior changes over time. Those findings can support a decision to investigate or intervene.
It cannot reliably identify future terrorists from a list of beliefs, personality traits, or social media interests.
For security teams, the useful question is specific: what does the available evidence suggest about a person's movement toward violence, and who needs that information now?
What is lone-actor terrorism?
Lone-actor terrorism generally refers to ideologically motivated violence planned and carried out by an individual without direct command from a terrorist organization. Research definitions vary, particularly around outside assistance and pairs of offenders. The FBI's study of lone offender terrorism examined attacks committed independently of a group's direction.
The familiar term “lone wolf” can be misleading. Acting alone does not mean developing beliefs alone or having no social connections.
A systematic review by Jonathan Kenyon, Christopher Baker-Beall, and Jens Binder, covering 109 sources, identified ties to other extremists and wider movements as a recurring theme. It also found substantial differences between offenders and disagreement across the research about social isolation and motivation.
For OSINT investigators, this means relationships can matter even when there is no formal cell. Public interactions may help explain influence or encouragement. They do not, by themselves, establish shared intent or involvement in a crime.
What the research supports, and what it does not
The research supports examining behavior in context. It does not support a universal terrorist profile or an automatic prediction score.
Several studies help explain the distinction:
| Research | Evidence examined | Relevance to OSINT |
|---|---|---|
| Gill, Horgan, and Deckert, 2014 | 119 people who carried out or planned lone-actor terrorism in the United States and Europe | Examines behavior and social connections before attacks, extending the analysis beyond offender demographics. |
| Meloy and Gill, 2016 | 111 lone-actor terrorists, assessed retrospectively using TRAP-18 | Provides a structured framework for examining warning behaviors, with explicit limits arising from hindsight and source quality. |
| Gill and colleagues, 2017 | 223 convicted UK terrorists | Examines internet use across different activities and emphasizes behavior, intent, and capability in addition to beliefs. |
| FBI, 2019 | 52 lone offender attacks in the United States between 1972 and 2015 | Shows why bystander observations and reporting belong alongside digital research. |
| Kenyon, Binder, and Baker-Beall, 2022 | 437 convicted extremist offenders in England and Wales | Compares online, offline, and mixed radicalization pathways, showing why online involvement should not be equated with violent action. |
These are different populations. Some include disrupted plots, some completed attacks, and some broader extremist offending. Their percentages should not be combined into a single estimate of how many attackers can be detected online.
For example, the FBI found that, in 25 percent of its cases, another person knew about the offender's research, planning, or preparation. That suggests opportunities for reporting. It does not mean the same information was publicly posted or discoverable by an OSINT platform.
There is also a difference between reconstructing a case and recognizing it in advance. After an attack, researchers know whose history to examine. Before an attack, investigators must distinguish relevant information from a much larger volume of ambiguous material.
The systematic review highlights this evidence problem. Much of the literature is descriptive, relies on secondary sources, or draws on small samples. Such studies help identify questions for investigators. They cannot establish that everyone displaying a similar behavior is likely to attack.
Online radicalization is not the same as attack preparation
The 2022 Ministry of Justice research found that, within its convicted-offender sample, those who primarily radicalized online were most likely to have committed a nonviolent offense and offenses confined to the online environment.
That finding does not make online extremism harmless. It shows why an analyst needs to distinguish exposure, advocacy, intent, and preparation. The study concerns convicted offenders, so it also cannot tell us the probability that an ordinary internet user will become violent.
An account sharing hateful material and an account communicating a specific intention to harm someone raise different investigative questions. Treating them as equivalent can obscure the cases requiring urgent attention.
Why an accuracy percentage can mislead
Consider a hypothetical screening system reviewing 100,000 accounts, of which 10 represent genuine attack planners. Assume it identifies nine of those 10 but incorrectly flags 1 percent of the other accounts. It would generate about 1,000 false alerts alongside nine true ones.
Those figures are an illustration, not an estimate of terrorist prevalence or any product's performance. They show why rare events create a difficult screening problem. A claim of high accuracy needs a clear definition, a relevant test population, and information about missed cases and false alerts. None of those can be inferred simply from how often a behavior appeared among known attackers.
Which warning behaviors can OSINT help reveal?
Behavioral threat assessment examines what a person is doing, how the behavior is changing, and what it means in context.
The warning behavior framework developed by Meloy and colleagues describes patterns including fixation, identification with attackers, preparation for violence, leakage, and directly communicated threats. These concepts inform professional assessment. The examples below are questions for review, not a checklist that diagnoses a terrorist.
Communications suggesting an intention to harm
In threat assessment, leakage refers to communicating an intention to harm a target to someone other than the target. It may appear in writing, conversation, images, or other communications. It is distinct from a threat delivered directly to the intended victim.
An investigator should establish what was communicated, who authored it, its date, and whether the surrounding context supports the apparent meaning. A quotation, a report about someone else's threat, and an original statement of intent are different kinds of evidence.
A study by Menna Rose and John Morrison examined leakage in 31 ISIS-inspired lone-actor cases in the United States. Its narrow sample and retrospective court records limit how widely the findings can be applied. The authors also recognize a central problem: not everyone who leaks goes on to attack, and not every attacker leaks.
Case lesson: In the 2019 Poway synagogue attack, the perpetrator posted a manifesto shortly before killing Lori Gilbert-Kaye and injuring three others. This was a public communication, but its late timing limits what the case can demonstrate about early warning. Finding a document online after an attack does not prove there was a practical opportunity to respond before it.
Increasing preoccupation with a target or violent role
Fixation involves an increasingly intense preoccupation. Identification concerns a person's adoption of a violent role or alignment with previous attackers. The research on identification includes a desire to imitate or surpass earlier perpetrators among the behaviors considered.
OSINT can help an analyst examine whether a person's public communications have changed from general grievance toward persistent attention to a particular target, or toward presenting themselves as someone who should commit violence.
Context remains essential. Repeatedly discussing a political issue is not equivalent to violent fixation. Referencing an attacker in journalism, research, or criticism is not evidence of wanting to imitate one.
The analyst's task is to describe the observed change and its supporting evidence without turning interpretation into fact.
Evidence of movement toward violence
Preparation matters because it can connect hostile statements to action. A public statement claiming preparation is a lead to verify. It is not proof that the claimed action occurred.
The TRAP-18 research separates relatively immediate warning behaviors from more distant background characteristics. It is a structured professional judgment approach, not a public screening quiz. Its 2016 study used known outcomes and acknowledged hindsight bias, observational bias, and imperfect correspondence between some variables and their definitions.
For an OSINT team, the practical implication is to state the evidence precisely. “The account claims an intention to attack” is different from “the person has been independently confirmed to be preparing an attack.” Both may require action, but they are not interchangeable findings.
No one should wait for every element of a case to be confirmed before escalating a credible concern about immediate harm.
A timeline is more useful than a folder of alarming posts
A collection of screenshots can show that concerning material exists. A timeline helps reviewers understand sequence, change, and what was knowable at each stage.
For every relevant item, distinguish the apparent publication time from the time it was collected. Identify whether it is original content, a repost, a later account of an earlier event, or an unverified attribution. Keep contradictory evidence alongside supporting material.
These distinctions make a significant difference in the Christchurch case.
The 2020 Royal Commission's executive summary described an email sent to Parliamentary Service and others eight minutes before the attack as the only information directly referring to the attack that had been provided to public agencies. It concluded that detection would have been unlikely except by chance.
Later research challenged parts of that picture. In a June 2026 account of their research, University of Auckland researchers Chris Wilson and Michal Dziwulski reported attributing hundreds of previously undiscovered forum posts to the attacker, including earlier statements about violence. They argued that these created potential opportunities for detection, while acknowledging that their work relied on hindsight.
Those are distinct findings from different investigations. The later attribution should be presented as the researchers' finding, not silently treated as part of the Commission's original evidence.
The case demonstrates why an OSINT assessment should distinguish four things: when information existed, whether it was accessible, when it was linked to a person, and when someone capable of responding received it. Those events may be far apart.
Verify identity and relationships before drawing conclusions
An alarming account is not yet a verified identity. A graph connection is not yet evidence of a conspiracy.
Investigators should record why they believe two accounts belong to the same person and what could contradict that conclusion. A shared display name is weak evidence. Several independently corroborated details may support a stronger assessment. Copies of the same unverified claim are not independent corroboration.
Link analysis is useful when it makes the nature of a relationship explicit. An account may follow another, reply to it, share material from it, or have a documented connection outside the platform. Each relationship has a different meaning.
Keep those distinctions in the graph and in the report. Do not convert everyone in a follower network into an associate of a suspected offender.
Source criticism matters just as much as attribution. A 2025 study by Wilson and Dziwulski compared the Christchurch attacker's public narrative with forum posts attributed to him. The researchers found important inconsistencies and argued that the manifesto served a deliberate propaganda purpose.
For investigators, the lesson is to assess a perpetrator's statements as claims requiring corroboration. Their account of their motives, relationships, or history should not become the investigation's default explanation.
Preserve the evidence behind the assessment
Public material can change or disappear. A useful finding needs enough context for another analyst to review what was actually observed.
The Berkeley Protocol on Digital Open Source Investigations, developed by the UN Human Rights Office and UC Berkeley's Human Rights Center, provides a foundation for collecting, preserving, verifying, and analyzing digital information. Its original focus is international criminal, humanitarian, and human rights investigations. The underlying discipline is also useful here.
For a threat assessment record, preserve:
- The source URL and available account or post identifiers.
- The original content and relevant surrounding conversation.
- Publication and collection times, including the time zone where known.
- Available media and metadata, with the collection method recorded.
- The analyst's interpretation, confidence, and unresolved questions.
Keep observations separate from conclusions. If translation or AI helped interpret a post, retain the original and mark the assisted interpretation for review. A reviewer should be able to distinguish the source's words from the analyst's explanation.
Preservation supports scrutiny. It does not establish that a post is truthful, that an account attribution is correct, or that a conclusion follows from the material.
Turn OSINT findings into a response
An alert has limited value if nobody owns the next decision.
The U.S. Secret Service's guidance on behavioral threat assessment units places identification and intervention within a broader violence prevention process. The purpose is to help teams assess concerns and manage them over time.
For an organization receiving an OSINT finding, a useful handoff answers five questions:
| Question | What the reviewer needs |
|---|---|
| What happened? | The observed communication or behavior, in plain language. |
| Who is involved? | The account or person, with identity confidence stated. |
| Why does it matter now? | The evidence of urgency or meaningful change. |
| What remains unknown? | Gaps, competing explanations, and facts needing verification. |
| Who owns the response? | A named team or role, with a clear escalation route. |
Urgent threats should reach emergency services or the responsible security authority promptly. Less immediate concerns still need a designated reviewer and follow-up. Appropriate responses may involve protective measures, law enforcement, or qualified support services, depending on the facts and the team's role.
The Toledo case illustrates this division of work. Public information began the inquiry. The documented investigation then included undercover activity and an arrest. It would be inaccurate to describe the whole result as an OSINT detection success. Open sources supported a larger investigative process.
Where AI and OSINT platforms help
Software can help teams organize large volumes of material, develop leads, compare activity over time, and retain supporting evidence. Its value should be judged by the quality and reviewability of those outputs.
For this use case, assess whether a platform helps an analyst answer concrete questions:
- Can I return from a summary to the underlying source?
- Can I distinguish an asserted identity from a verified one?
- Can I see what changed over time?
- Can I explain what each relationship in a link chart represents?
- Can another reviewer inspect the evidence and challenge my conclusion?
AI-generated summaries and classifications should remain subject to those checks. A risk label without supporting evidence does little to explain a concern or guide a response.
How Intrace supports this work
Intrace's investigation suite connects Search, Graph, and Social Vault through shared entities and evidence. That supports the progression from an initial lead to relationship analysis, account review, and a report with source references.
Graph helps investigators examine links between people, accounts, locations, and records. Timeline views support review of how activity developed. Analysts can expand relevant entities and examine portions of a network while checking the meaning of each connection.
Social Vault supports review of account content, interactions, and activity over time. Its role in a threat inquiry is to help analysts inspect the history behind a concerning item and examine related material in context.
Intrace's evidence preservation capabilities retain collected posts, media, and metadata with timestamps and source attribution. Case organization and shared evidence help reviewers work from the same record, including after original content is removed.
These capabilities support investigation and documentation. Decisions about intent, urgency, and intervention remain with the responsible professionals. The research discussed in this article does not validate Intrace, or any other product, as a predictor of terrorism.
Common questions about OSINT and lone-actor threats
Can OSINT detect a lone-wolf terrorist before an attack?
It can reveal information that leads to assessment and intervention, as the Toledo investigation illustrates. It cannot guarantee early detection. Public evidence may be ambiguous, incorrectly attributed, unavailable, or discovered too late. A useful assessment makes those limits visible.
Does consuming extremist content mean someone will become violent?
No. Content consumption alone does not establish intent or preparation. The research on terrorist internet use supports examining what people do with online information and how that relates to their wider behavior. It does not provide a simple causal rule from viewing content to committing an attack.
Should investigators wait for an explicit threat?
No. The TRAP-18 study found that directly communicated threats were absent in many cases. A concerning pattern may warrant professional review even without a threat addressed to a target. Equally, an explicit threat needs context and verification. The task is to assess the available evidence and respond proportionately, rather than wait for a particular phrase.
Is there a demographic or mental health profile of a lone-actor terrorist?
The FBI emphasizes that there is no single demographic profile. Religion, ethnicity, political identity, and a mental health label cannot establish that a person intends violence. Assess the behavior and the specific circumstances. Support needs and threatening conduct are separate questions that may require different professionals.
What makes an OSINT report useful for prevention?
It identifies the concern, shows the supporting evidence, states uncertainty, and reaches someone responsible for responding. More collected data does not automatically produce a better assessment. The report needs to explain what the evidence means for the decision at hand.
Identify concerns early enough for people to act
The strongest use of OSINT in lone-actor threat assessment is a documented chain of reasoning: a concern, a carefully assessed identity, a timeline, corroborating sources, and a clear handoff.
That approach gives investigators something they can question, update, and act on. It also makes it easier to correct an initial suspicion when the evidence points elsewhere.
For teams evaluating how to support that process, explore Intrace's investigation capabilities for link analysis, social account research, and evidence preservation.