Today's briefing:

  • Russia warns it could strike UK military targets over Ukraine missiles.

  • Nigeria: gunmen seize up to 600 worshippers from four village mosques.

  • US and FBI seize China-run hacking platforms behind federal breaches.

Welcome to your weekly briefing.

Geopolitics is often thought of as a background consideration to the job. It shapes the travel advisories and the threat briefs, but it happens somewhere else, to someone else's principal, in a country we fly into and back out of.

That line between the war over there and the work over here is getting thinner. A conflict our client has no part in can still put their business, their staff, or their supply chain on someone's target list, and the people sent to do the damage may be hired locally, for cash, with no obvious tie to a foreign state. That is a harder problem than a known adversary at a known address.

This week, On the Circuit, we look at how a war a country is not fighting can still land on its doorstep, and what that means for the sites and people we protect.

Don’t have time to read? Watch 👇

TOP STORY

Russia's War Reaches British Businesses

Russia warned on August 27 that it could strike British military targets inside and outside Ukraine if Kyiv keeps firing UK-made long-range cruise missiles into Russian territory. Foreign Ministry spokeswoman Maria Zakharova, at a Moscow briefing, called it the strongest such warning to date, and said London was close to being complicit in what she termed terrorism against Russian civilians. It came a day after Moscow accused Ukraine of hitting a shopping center in occupied Donetsk with a British Storm Shadow missile, and after London agreed to let Ukraine build those missiles locally.

The warning was the sharpest in a rising series. On August 18 the Russian embassy in London said Britain's support for Ukraine would carry consequences, after reports that drones from two British firms had been used in long-range strikes inside Russia. A former Russian deputy foreign minister told the BBC those consequences could include attacks, and that Moscow was betting NATO would not respond in force. British ministers said the support would continue.

For anyone responsible for security in Britain, the immediate risk is the campaign already under way, rather than a missile on London. Last October, five men were jailed for a combined 53 years over an arson attack on a Ukrainian-owned warehouse in Leyton, east London, that caused about a million pounds of damage in March 2024. The men were recruited through the Wagner Group, a private military organization acting for the Russian state, and they had also carried out surveillance on two businesses in Mayfair in preparation for further attacks. It was the first case prosecuted under Britain's National Security Act.

Counter Terrorism Policing described the use of British proxies as a new tactic favored by hostile states, and said counter-state-threat investigations have risen sharply. The same pattern runs across Europe, from an explosive drone found by a runway at Leipzig-Halle to a disrupted plot in Warsaw, with arson and sabotage repeatedly traced back to Russian intelligence. The targets are mostly commercial, from logistics depots to warehouses to companies tied, sometimes loosely, to Ukraine, rather than government buildings.

Our Take

For those who are protecting people and sites in the UK, this changes who and what you consider as the threat. We are used to planning around a motivated individual, or a criminal after money or goods. The Leyton case is different. Ordinary men were recruited online and paid to set fire to a specific building for a foreign government, with a second target already under surveillance.

Would you spot pre-attack surveillance on a commercial site that you’ve never once thought of as a target. The good news is that this is preventable with the basics we already train for, from access control to surveillance detection to knowing who holds the keys. The warning is that those basics now have to cover sites that felt, until recently, like nobody's target.

Sound even smarter:

  • Counter Terrorism Policing said Dylan Earl, who organized the plot, made contact with the Wagner Group on Telegram in 2023, and that officers pulled 56GB of data from his phone; he was jailed for 17 years on October 24.

  • The same Ukrainian company's warehouse was also hit by arson in Madrid, which is what led London's counter-terror command to take the case over from local officers, according to Counter Terrorism Policing.

READER POLL

*Skip to the end to see the results of last week’s poll ↓

SPECIAL NEWSLETTER ONLY OFFER

TACTICAL MEDICINE — THE CIRCUIT SPECIALIST SERIES

The Tactical Medicine is your field guide when something goes wrong on a detail. It covers what to carry, what to do in the first few minutes when a casualty cannot wait, and how to keep someone alive until the professionals take over.

MEANWHILE

Hundreds Taken From Their Mosques

Gunmen hit four villages in Niger State, in north-central Nigeria, at the same time on Friday, striking several mosques during prayers and leaving with an estimated 600 worshippers. The toll is unsettled: a district official put the dead at 30, a police spokesman told the BBC more than 40, and the head of the Borgu local government said the attackers took closer to 60. On Sunday the kidnappers released a video of captives held in a forest, and a local official said improvised explosive devices were planted as the group was moved, killing a teenage boy during an escape.

At least 2,000 residents fled across the border into Benin, and President Bola Tinubu ordered a rescue operation. Mass kidnappings for ransom have climbed across northern Nigeria this year; forces rescued 308 captives on August 5 and freed another 145 earlier this month in the same region. The fuller account is in our Circuit Wire report.

A Chinese Espionage Network, Seized

The US Justice Department and FBI seized three domains last week to shut down two hacking tools, QScan and QTRouter, run by a China-based group known as QTFY that had been breaking into US networks since 2018. Court documents named victims including NASA, the Federal Reserve, and the Departments of Energy, Justice and Health and Human Services. Prosecutors said the group worked out of a front company in Nanjing and sold access to buyers that included China's Ministry of State Security and the military.

The two tools worked as a pair. QScan carried more than 200 ready-made break-in methods and, on a single day in 2024, ran over two million scanning tasks; QTRouter then routed the attacks through infected devices so they appeared to come from outside China. The group used the setup to reach three Department of Energy national laboratories and a US medical-research network, and tried without success to get into a Senate network and an election system. The FBI and the National Security Agency published a list of warning signs dating back to 2018.

The CIA's Quiet Warning to Moscow

CIA Director John Ratcliffe made an unannounced trip to Moscow on August 25 to warn Russia against attacking NATO, particularly the Baltic states, after US intelligence assessments that Putin could launch a limited assault to test the alliance. The Wall Street Journal, which broke the story, cast it as an ultimatum: pull back the campaign of sabotage and hybrid attacks on NATO's eastern flank, or risk a direct allied response. Russia's foreign intelligence chief confirmed a working-level meeting; Ratcliffe did not meet Putin.

The message follows a long run of Russian pressure on the Baltics, from airspace violations to cyberattacks and sabotage. Three Baltic members of the European Commission, joined by Poland and Finland, wrote to Brussels on August 26 warning of a deteriorating security environment and rising drone incursions. Russia confirmed the meeting but dismissed the reports, and President Trump played the trip down as semi-routine.

SNAPSHOTS

🇨🇩 DR Congo. The Ebola outbreak has reached 5,515 cases and 2,642 deaths, a fatality rate near 48 percent. Travelers who were in the country within the past 21 days cannot board US-bound flights.

🇮🇩 Indonesia. Protests returned to Jakarta and other cities around August 27, a year after unrest that killed at least ten. The US embassy told Americans to avoid the parliament complex and protest sites; a police post in Slipi was set alight.

🇳🇵 Nepal. A Himalayan flood has killed more than 390 people and left over 1,500 missing across Nepal and Tibet. Nepal's tourism department said 668 trekkers from 34 countries, including 90 Americans and 33 Britons, were out of contact.

🇮🇷 Gulf. Iran's security chief warned that any Gulf state joining new US sanctions would be treated as a target, and said Iran would again go after tankers in the Persian Gulf.

EXTRA INSIGHT

REGULATION. The UK's Security Industry Authority has opened a consultation on the biggest change to licence training in years. An in-date first aid qualification and an English-language test would become conditions of a licence for close protection officers, door supervisors and guards, alongside new content on drones, spiking and Martyn's Law. It affects more than 510,000 licences, closes on October 23, with new qualifications due in 2027.

FRAUD. An eight-month Interpol operation against West African crime networks led to 58 arrests across 22 countries and identified 263 suspects. Most arrests came in Johannesburg, where a syndicate ran romance and investment scams on retirees in English-speaking countries; about 2.67 million dollars was seized and 257 bank accounts blocked. Investigators also flagged a rise in sextortion aimed at teenagers.

  • The ATF declared a major incident after the Qilin ransomware group claimed it breached a standalone system holding data on the agency's investigation targets.

  • Supermicro fired sales and support staff after a probe into the alleged diversion of 2.5 billion dollars of Nvidia servers to China, saying no senior manager knew.

  • CISA gave federal agencies three days to patch an actively exploited flaw in Citrix NetScaler remote-access gear used to guard networks.

NEW RESOURCE FOR PREMIUM SUBSCRIBERS

Getting Paid

You can close out a detail perfectly and still lose money on it, after the invoice goes out. Eighty-five percent of contractors are paid late, and a large part of what you are owed is recoverable, some of it a statutory entitlement almost nobody in this industry ever claims. There’s another less obvious loss too. The day rate that looks healthy on the booking email is not the money that reaches your account, and in April a tax change moved a liability back onto contractors without most of them noticing.

This week's premium piece is the admin half of the job nobody teaches on a course, written for a protection contractor rather than a generic freelancer: what your working status actually costs you, the rule change with your name on it, and how to collect what you are owed. It comes with two working tools, a status and true-cost calculator and a full invoicing and escalation pack, both built for how this industry actually invoices.

Before you go, help us build the benchmark. We are running an anonymous salary survey, open to every reader, to test how pay across this profession really holds up against the numbers. It takes a few minutes, your answers stay anonymous, and the full results go back to every subscriber later this year.

Most of what we do comes down to a promise we make to the client; that we have thought about the thing that has not happened yet. That promise is only as good as the last time we checked it against the current reality. For some of you, that reality shifted this month. So it is worth an hour this week with your own plans open in front of you, asking whether they still describe the threat your people face. If they were written for last year's version of the job, they are already behind.

See you next week,

– On The Circuit

If you found this useful, forward it to someone who needs to read it. If someone forwarded this to you, subscribe at circuit-magazine.com

To give or receive feedback, hit reply.

PREVIOUS POLL - RESULTS

Q: A threat you'd written off comes back. What makes you re-add the countermeasure you cut?

🟩🟩🟩⬜️⬜️⬜️ Your own read on the ground (50%)
🟨🟨⬜️⬜️⬜️⬜️ A confirmed incident nearby (31%)
🟧⬜️⬜️⬜️⬜️⬜️ The client finally asks for it (13%)
⬜️⬜️⬜️⬜️⬜️⬜️ Something else (6%)

Your Comments:

VSM: "Detecting changes in the environment reveals evolving risks before they impact operations. This shows that proactive situational awareness is essential, especially when adapting or restoring security measures in response to shifting global threats."

***

OTHER NEWSLETTERS YOU MIGHT LIKE
The Veteran Professional

The Veteran Professional

Helping veterans crush it in profesisonal careers, higher education, and entrepreneurship after the military.

The Overwatch

The Overwatch

War, Geopolitics, & Western Civilization — started by a Navy SEAL at Harvard University.

The Merge

The Merge

Military tech, trends, and happenings