Today's briefing:
Somali pirates seized a sixth ship off Yemen since April.
An Albany woman planned to bomb New York's Capitol.
A record 907 aid workers were killed, injured or kidnapped in 2025.
Welcome to your weekly briefing.
One of the problems with effective security is that, when it's working, it can start to look unnecessary. Nothing happens, the threat appears to have gone away and sooner or later someone begins to question why they're still paying for the cover. Somali piracy had been virtually wiped out for a decade, but now it's back, with six ships taken since April.
As protectors, this presents us with a familiar challenge. How do you prove the value of a security measure when its greatest success is that nothing happens? This week, On the Circuit, we look at what the return of Somali piracy can teach us about complacency, budget pressure and the danger of mistaking a controlled threat for one that no longer exists.
Don’t have time to read? Watch 👇
TOP STORY
Somali Piracy Is Back. The Defenses Aren't.

On August 20, six armed men came alongside the tanker Seamull about 136 nautical miles east of the Yemeni port of Al Mukalla, boarded her, and turned her toward the Somali coast. The crew got out a distress call before the boarders took control. She was the sixth commercial vessel seized off Somalia since April, and five others were still being held when she was taken. The Washington Post counted the run: the Honour 25 in April, the Sward and the Eureka within weeks, the Asana in July, the Lutuf three days before the Seamull.
For more than a decade this did not happen. Somali piracy peaked in 2011 and was beaten down to almost nothing by 2013, through two things working together: warships patrolling the basin, and merchant ships that hardened themselves with razor wire, safe rooms and embarked armed teams. The threat faded, and the measures faded with it. The naval coverage is now committed elsewhere, to the Red Sea and the Strait of Hormuz for the war with Iran, and merchant traffic steering clear of those waters is running closer to the Somali coast than it has in years. The analysis that saw this coming named the cause plainly: the escorts left, and the ships stopped carrying the defenses that used to stand in for them.
The stakes are not small water. The Gulf of Aden feeds the Red Sea and the Suez Canal, which carries somewhere between 12 and 15 percent of the world's trade by value every year. Yemen announced a new maritime security committee the same day the Seamull was taken. The full sequence, and the sanctions history that had already put the Seamull on a list, is in our Circuit Wire report.

Our Take
Good security has a habit of making itself look unnecessary. The longer it works, the harder it becomes to prove why it is still needed. Somali piracy wasn't defeated because the pirates lost the ability or desire to seize ships. It was suppressed by naval patrols and merchant vessels that made themselves much harder to board and control. Once those protections were withdrawn, the threat had room to return.
There is a lesson here for every protector. The absence of an incident is not, by itself, evidence that a security measure is no longer required. It may be the result of that measure being there. The real discipline is maintaining the right level of protection through the quiet periods, when budgets are under pressure and there is nothing visible to point to. Because when the protection goes, we often discover that the threat never really went anywhere.
Sound even smarter:
John Walker, a former Royal Navy counter-piracy officer now with EOS Risk Group, told NPR that the 2011 peak reached 237 attacks with more than 30 vessels held hostage at once, and that this year's tally has already climbed to about a dozen.
The World Bank's Pirate Trails study put Somali piracy between 2005 and 2012 at more than 1,000 attacks and roughly $400 million in ransom payments, before naval deployments and hardened ships all but ended hijackings in 2013.
READER POLL
A threat you'd written off comes back. What makes you re-add the countermeasure you cut?
*Skip to the end to see the results of last week’s poll ↓
TACTICAL MEDICINE — THE CIRCUIT SPECIALIST SERIES
Launch Price: 50% Off — ENDS MIDNIGHT
The Tactical Medicine is your field guide when something goes wrong on a detail. It covers what to carry, what to do in the first few minutes when a casualty cannot wait, and how to keep someone alive until the professionals take over.
MEANWHILE
An ISIS Plot to Bomb New York's Capitol

Federal agents arrested Jessica Bowie, 35, in Albany on August 19 as she took delivery of what she believed was a live bomb. Prosecutors charged her the next day with attempting to provide material support to ISIS. She had planned to walk into the New York State Capitol dressed as a food delivery driver, carry the device inside a delivery bag, and set it off while state senators were in session. In a message to a source she wrote that she wanted to destroy as much of the building as possible and kill the senators while they met.
The build-up was methodical. Bowie visited the Capitol grounds five times and photographed the building, and security cameras recorded every visit. She bought components at a Home Depot near her home, handed a source $200 toward a bomb maker, and had recorded a formal oath to ISIS in May. She was talking to FBI sources the whole time, one posing as an ISIS contact, and was carrying a firearm, ammunition and knives when agents took her in. She had also weighed attacking the White House and set it aside as too hard for now.
A Record Year for Attacks on Aid Workers

The United Nations reported that a record 907 aid workers were killed, injured or kidnapped in 2025, up from 833 the year before, with 350 killed outright. Gaza was the deadliest place for a third straight year, with 186 humanitarians killed there, and Sudan came next. The figures come from the Aid Worker Security Database, which has tracked violence against humanitarian staff for two decades and has never logged a higher toll.
UN aid chief Tom Fletcher tied the rise to the spread of cheap, adaptable armed drones in conflict zones. Drone strikes hit Goma in eastern Democratic Republic of the Congo in March, killing three people including a French aid worker, and convoys in Sudan and Ukraine have been struck repeatedly. The record arrives as funding for humanitarian operations is being cut, and the 2026 count will not be published until next year.
SNAPSHOTS

🇦🇪 UAE. Emirati air defenses tracked two Iranian ballistic missiles on August 18, one falling inside territorial waters, and the government suspended all trade with Iran the next day. Dubai and Abu Dhabi stay major transit hubs.
🇭🇰 Hong Kong. Two organizers of the city's annual Tiananmen vigil, Lee Cheuk-yan and Chow Hang-tung, were convicted of inciting subversion on August 21 and face up to 10 years. The law reaches foreign nationals too.
🇷🇺 Russia. More than 620 Ukrainian drones hit Moscow and its region overnight into August 18, the largest such attack on the capital in two years. Moscow canceled a Red Square festival and pulled hardware from a parade over the threat.
🇱🇧 Lebanon. The US Level 4 Do Not Travel advisory for Lebanon remains in force, reaffirmed August 21 with no change, citing terrorism, kidnapping and unexploded ordnance. Government help to citizens on the ground stays sharply limited.
EXTRA INSIGHT

REGULATION. The Justice Department finalized a rule reviving an individual review that lets people barred from owning firearms apply to have their federal rights restored, a route effectively closed for three decades. Attorney General Todd Blanche framed it as a path for roughly 30 million Americans, though it restores only federal rights and leaves state bans, and strong presumptions against violent felons, in place.
CYBER. The FBI, CISA and Health and Human Services updated their advisory on Medusa, a criminal group that rents out ransomware, past 500 confirmed victims across hospitals, defense suppliers, manufacturing and finance, up from 300 last year. The group buys its way in and hides inside the same remote-management software companies already run, so the exposure is a tool the target already trusts.
Comcast turned millions of Xfinity routers into camera-free motion sensors, and a support page says it may hand that motion data to law enforcement or other third parties.
SafePal exposed the names, home addresses and phone numbers of 39,798 crypto-wallet buyers through an order-lookup flaw, now offered for sale on a forum.
Ransom Busters, a rogue affiliate, is emailing ransomware victims before their breaches surface, posing as a recovery firm and undercutting the gangs it works for.
NEW RESOURCE FOR PREMIUM SUBSCRIBERS
What the New Drone Rule Lets Private Teams Do
Drones present private protection teams with an uncomfortable problem. You may be expected to detect and respond to the threat, while the law prevents you from operating many of the systems marketed as the solution. The new US counter-drone rule makes that division clearer than ever, and expressly closes the door on contractors operating mitigation systems for certified police agencies.
So, what can a private detail actually do? Our latest Premium article explains the lawful detection options, the four questions to ask before purchasing any counter-drone product and how to build an effective relationship with the agency that holds the response authority. It covers the US and UK position, real-world costs and includes two practical resources to help you prepare.
Before you go, help us build the benchmark. We are running an anonymous salary survey, open to every reader, to test how pay across this profession really holds up against the numbers. It takes a few minutes, your answers stay anonymous, and the full results go back to every subscriber later this year.
Whether you're protecting a principal, a property or an event, sooner or later someone will question a measure that hasn't been "needed" lately. That pressure is understandable. Security has to remain proportionate and budgets are not unlimited. But before you scale back the cover, be sure you understand why the threat has been quiet. If the risk has genuinely changed, then the protection should change with it. If the quiet has been created by the measure itself, removing it may simply give the threat room to return. Review what you do, challenge old assumptions and avoid maintaining security for its own sake. But don't dismantle a successful defense simply because it has been successful.
See you next week,
– On The Circuit
If you found this useful, forward it to someone who needs to read it. If someone forwarded this to you, subscribe at circuit-magazine.com
To give or receive feedback, hit reply.
PREVIOUS POLL - RESULTS
Q: You have to move a client through a compromised route. What do you lean on?
🟩🟩🟩🟩🟩🟩 Deception and misdirection (56%)
🟨🟨⬜⬜⬜⬜ Changing the timing (19%)
🟧🟧⬜⬜⬜⬜ Hardening the movement (19%)
⬜⬜⬜⬜⬜⬜ More bodies on the ground (0%)
🟧⬜⬜⬜⬜⬜ Something else (6%)
Your Comments:
AG: "All of the above, if possible."
***







