Today's briefing:
Five men arrested on the approach to RAF Fairford.
An ISIS financier extradited to Brooklyn after a decade.
Forensic tools bought by US agencies were secretly Russian-owned.
As security professionals, we tend to build our threat picture around what a site is and where it sits. A quiet air base in Gloucestershire can feel a long way from the conflict with Iran, even when American bombers are flying missions from inside its gates. But the threat to a site can change long before anything about the site itself does.
Five men were arrested on the approach to RAF Fairford this week, with counter-terrorism police now investigating whether the incident was connected to Tehran. The first visible warning did not come from intelligence systems or an alarm on the perimeter. It came from a local woman who found masked men outside her home and called for help.
So, how far beyond the fence does your own awareness extend?
This week, On the Circuit, we look at what happens when a familiar site takes on new strategic importance, and why the approach may tell you more than the perimeter.
Don’t have time to read? Watch 👇
TOP STORY
Five Arrested on the Approach to RAF Fairford

At about 12:45 a.m. on Sunday, police took calls from residents about three white vans that appeared to be heading toward RAF Fairford in Gloucestershire, England. About an hour later, a farmer returning home to the village of Whelford found her driveway and the road blocked by the vans, parked in what she called a "strange formation" about 100 meters from the base fence, and a group of hooded, masked men she believes numbered more than five. Some ran into the fields. She rang the Ministry of Defence police at the base and got no answer, then called emergency services at about 1:40 a.m. Armed officers arrived within 10 to 15 minutes, and five men were arrested, first under the Explosives Act and then on suspicion of preparing a terrorist act.
By Monday afternoon all five were out on bail under "stringent conditions on their movement and contact with others," still under investigation and uncharged. Police say they are British nationals from the London area, aged 23 to 25. The Army's bomb-disposal team spent Sunday working around the vans, and CNN heard what sounded like two controlled detonations, but police have not said what the vans contained. The 85 evacuated households were allowed home on Monday evening.

RAF Fairford is British-owned but run by the US Air Force, and US bombers have flown strike missions against Iran from it since March. In July, Iran's Revolutionary Guard warned that any base used against Iran was a legitimate target, and Iranian media later published video of self-described Iranian patriots filming at the Fairford perimeter fence. President Trump said the men were "looking to do big damage" and that "we had them under view for a long time," and on Monday said he was "surprised" they had been released. British officials have not confirmed that, and the BBC, the Guardian and the Telegraph reported, citing sources, that the operation was not intelligence-led. Laurence Taylor, head of UK Counter Terrorism Policing, said officers are considering whether the men were proxies working for a foreign state, "knowingly or unknowingly." Iran denied any role, and armored vehicles now guard the gates at RAF Lakenheath, another base used by US forces.
Our Take
Whatever these men intended, the most important fact is that they were stopped on the approach. RAF Fairford's physical defenses were never tested. A local woman found masked men and three vans outside her home, tried the base police and got no answer, then called the emergency services. Armed officers were in the village within ten minutes.
President Trump says the men had been under observation, so there may have been an intelligence operation running in the background. But the intervention we can see began with a member of the public noticing something wrong and refusing to ignore it. That is not evidence of a perimeter failure. It is evidence that a plot against a hardened site is often most exposed before it reaches the boundary.
If the Tehran connection is confirmed, the wider significance is serious. A conflict being fought overseas has reached the British infrastructure supporting it, potentially through people recruited to operate locally.
Sound even smarter:
UK officials said in March 2026 that national security cases involving hostile states such as Iran had risen 50% in the six months to December 2025, as our Circuit Wire report on the arrests sets out alongside the full police timeline.
Iran's Islamic Revolutionary Guard Corps had already declared RAF Fairford a legitimate target after US bombers flew missions against Iranian sites from the base.
READER POLL
Your site becomes linked to an active, high-profile and politically divisive situation. What's your primary concern?
*Skip to the end to see the results of last week’s poll ↓
THE SPECIALIST SERIES - VOL 2
NEW: SURVEILLANCE & COUNTER-SURVEILLANCE
The Circuit Specialist Series, Vol. 2
Most threats give themselves away before they act. A car that turns up on three legs of the same route. Someone who lingers a little too long outside the school gates. The operators who catch these things aren't lucky. They know what to look for.
Our second Specialist Series volume brings together 25 of the best surveillance and counter-surveillance articles from the Circuit archive, in one 180-page training volume. It's written by a retired CIA security officer, former special forces soldiers, government surveillance operators, investigators and close protection specialists.
Inside:
A red team's account of penetrating a close protection team
The complete Hostile Surveillance Detection series
Covert cameras, TSCM sweeps and mobile stakeouts
The four-part Countering the Effects of Surveillance series
For a limited time it's $9.99 (normally $18.99)
MEANWHILE
An ISIS Financier, Extradited After a Decade

Davud Ansariy, 41, was extradited from Georgia to New York on September 23 to face charges that he ran a Brooklyn network raising money for ISIS and the al-Nusrah Front. Prosecutors say the group, which called itself chayxona, an Uzbek word for tea house, collected funds to send fighters to Syria and to support the families they left behind. It paid the travel of at least three men who went to Syria in 2013, all of whom are believed to have been killed there.
Ansariy, an Uzbek national and naturalized US citizen, left for Turkey in May 2016 on a one-way ticket bought the day before, five days after one of his co-conspirators was arrested. A federal grand jury indicted him in 2021, and he stayed out of reach until this week. He faces up to 35 years, and the charges are allegations he has not yet answered in court.
The Soldier Who Hacked the Phone Companies
Cameron Wagenius, a 22-year-old former Army soldier, was sentenced to 70 months on September 25 for breaking into telecom companies and trying to extort them, much of it while he was on active duty. Operating as kiberphant0m, he and others stole network logins from at least ten organizations, traded them in group chats, and threatened to dump the data unless they were paid, in attempts that topped a million dollars.
In late 2024 he posted stolen call records belonging to a government official and to relatives of another, and, according to a researcher cited by CyberScoop, those records included calls of President Trump, used in a failed attempt to squeeze $500,000 out of AT&T. Investigators said he had also tried to sell stolen data to a foreign intelligence service and had searched online about defecting to Russia. His case ties back to the 2024 Snowflake breaches, one of the largest data thefts of that year.
SNAPSHOTS

🇿🇦 South Africa. Gunmen killed at least 27 people in two township attacks over the weekend, at a tavern near Johannesburg and a venue near Cape Town. Eight opened fire with rifles in the first, and no arrests had been made by Sunday.
🇪🇹 Ethiopia. Tigrayan forces seized the airport in Mekelle on September 23, and Ethiopian Airlines suspended all flights to the region with no restart date, closing the main way out as a rebel alliance moves against the government.
🇸🇦 Saudi Arabia. France is sending troops and air defenses to guard the Yanbu oil hub after Saudi forces intercepted six Houthi missiles aimed at Yanbu and Taif, with emergency warnings issued across Jeddah and Mecca before the all-clear.
🇵🇰 Pakistan. Karachi banned gatherings of more than five people through September 30, and Islamabad was sealed with thousands of shipping containers, ahead of a national opposition march demanding the release of Imran Khan.
EXTRA INSIGHT
SUPPLY-CHAIN RISK. US prosecutors charged the chief executive of Oxygen Forensics and a Moscow co-owner with hiding that the company was Russian-owned, while its phone-cracking software was bought by the Secret Service and two parts of Homeland Security and its code was written in Russia. The buyers were told none of this. Agencies came to rely on tools built and controlled by the country they most guard against.
CYBER FRAUD. Microsoft and London police shut down EvilTokens, a paid service that had broken into more than 12,000 email accounts at over 10,000 organizations. It slipped past passwords and second-step logins using a sign-in feature meant for televisions, then used AI to read the inbox, find unpaid invoices, and write convincing emails posing as trusted contacts. Work that took crooks days now takes minutes.
Kiteworks told customers worldwide to switch off their file-transfer servers for several hours after a federal warning of a possible attack on an unknown flaw.
ShinyHunters claimed it had breached the FBI and stolen agent and applicant records, the latest in a run of extortion claims by the group.
INTERPOL said a three-week border operation across five Middle Eastern and North African countries produced 48 arrests, including eight people wanted under Red Notices.
PARTNER PROMOTION
Forget Elon's Gadget. Buy the Companies Behind Its Tech.
Every breakthrough device runs on chips, parts, and materials from other companies — most of them public and overlooked. Our analyst named 3 positioned to profit from Elon's July 22 launch, plus the most undervalued name in the supply chain.
How Corporate Security Contracts Are Actually Won and Lost
The cheaper bid had no weaknesses and still lost. Here is what the scoring sheet saw that the bidder did not.

Losing a contract because your price is too high is easy to understand. Losing when you're cheaper and the evaluator has found no weaknesses in your proposal is much harder. Yet that is exactly what happened when America's largest contract security company bid for a $105 million federal contract. The buyer paid more for the firm that made the changeover feel safer.
That decision reveals how major security contracts are really won. In this week's Premium article, we look at what buyers score, why bids are often rejected before the technical response is read, how incumbents are displaced and where smaller firms can compete. The accompanying Corporate RFP Response Template and Bid Self-Scoring Model help you build the case, test the numbers and see the bid as the buyer will see it.
The threat to a site is not fixed simply because the site is. Its importance can change with the work happening inside, the people using it or a conflict taking place thousands of miles away. That means our view of the operation cannot stop at the gate. The roads, homes and businesses around a location may provide the first indication that somebody is moving towards it. We do not control all of those places, but we should never underestimate the people watching from them.
See you next week,
– On The Circuit
If you found this useful, forward it to someone who needs to read it. If someone forwarded this to you, subscribe at circuit-magazine.com
To give or receive feedback, hit reply.
PREVIOUS POLL - RESULTS
Q: How much of your threat planning actually accounts for hostile states, not just criminals?
🟨⬜️⬜️⬜️⬜️ It's central to how we plan (13%)
🟩🟩🟩🟩🟩 We factor it in for some principals (50%)
🟨🟨⬜️⬜️⬜️ Rarely, unless a client raises it (38%)
⬜️⬜️⬜️⬜️⬜️ Something else. Let us know → (0%)
***







