Financing Across the Organised Crime–Terrorism Interface: Adaptive Portfolios, Displacement, and European Criminal Policy
This article proposes an adaptive financial-portfolio theory to evaluate counter-terrorist-financing effectiveness by analyzing the interface between organised crime and terrorism, arguing that policy must move beyond counting disrupted assets to assessing how criminal groups dynamically reconfigure diverse, complementary funding mechanisms across physical and digital domains.
Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
When a government agency tries to stop money from reaching a terrorist group, they usually look for a specific thing to shut down: a bank account, a digital wallet, or a person moving cash. The standard assumption has long been that if you cut off one of these paths, the flow stops. But money is rarely that simple. Terrorist groups, like many complex organizations, do not rely on a single pipeline. Instead, they build a network of different ways to get, hold, and move value, switching between them depending on where they are, what tools are available, and what risks they face. This is not just about hiding; it is about survival. If one path is blocked, they do not necessarily stop; they often find a different way to do the same job. Understanding how these groups adapt their financial habits is crucial because closing an account today might only force them to use a different method tomorrow, leaving the threat intact.
A new study by researchers at the University of Hong Kong and the University of Macau challenges the old way of thinking about this problem. Instead of counting how many bank accounts or crypto wallets have been frozen, the authors propose looking at the entire financial system of a group as a flexible portfolio. They argue that terrorist organizations treat their money like a toolkit, assigning different tasks to different tools. Some tools are good at gathering small donations from many people, others are better at moving large sums across borders, and some are best for spending money on supplies in a local conflict zone. The researchers suggest that when authorities shut down one tool, the group does not simply disappear. Instead, they reorganize. They might switch from a bank to a mobile money app, or from a digital currency to physical cash, depending on which option best fits the specific job they need to do next.
The researchers developed this idea by comparing two major global reports on terrorist financing, one from 2015 and a much more detailed update from 2025. They also looked at specific cases involving groups like the Islamic State, Hamas, and Al-Shabaab to see how these organizations actually handled their money over time. What they found was that the old idea of "new technology replacing old methods" is mostly wrong. The reports show that cash is still everywhere, often serving as the final step after money has moved through digital systems. A group might collect donations online, convert them into a digital asset, move them through a broker, and finally hand them over as physical cash to buy weapons. These different steps are not separate options; they are linked parts of a single chain. The researchers call this an "adaptive portfolio," meaning the group keeps a variety of methods ready and uses them in combination to ensure they can always get the job done.
One of the most important findings is that simply closing a channel does not prove the group has been stopped. If a bank account is frozen, the group might just move the same amount of money through a different bank, or switch to a less regulated system. The researchers argue that we need to measure success differently. Instead of counting closed accounts, we should look at how long it takes the group to get their money moving again, how much it costs them to find a new path, and whether they can still reach the places they need to. Sometimes, a group might find a new way to move money, but it is slower, more expensive, or less reliable. In that case, the intervention has weakened them, even if the money keeps flowing. Other times, they find a perfect replacement, and the intervention has done very little. The study suggests that the real danger lies in "shared dependencies." If many different parts of a group's financial network rely on the same person, the same computer, or the same identity, taking that one thing down can cause the whole system to collapse. But if they have spread their risks out, shutting down one part might just make them stronger by forcing them to use a better, more secure system.
The study also looks at how this plays out in the European Union, where laws and regulations are complex and spread across many countries. Because the rules are different in each nation, a group might start a transaction in one country, move it through a digital service in another, and end up with cash in a third. This makes it hard for any single agency to see the whole picture. The researchers propose that European authorities should stop looking at individual transactions and start mapping the entire financial architecture of a group. They need to ask not just "where is the money now?" but "what function is this money serving, and what else could do that job?" By understanding the specific role each part of the network plays, authorities can target the weak links that, if removed, would truly stop the flow of funds. This approach requires a careful balance, because the same tools used by terrorists—like digital wallets or international money transfers—are also used by ordinary people to send money to family or support charities. The goal is to disrupt the bad actors without accidentally cutting off the legitimate needs of innocent people.
The researchers are careful to say that their ideas are still hypotheses that need to be tested with more real-world data. Public records often show what went wrong for a group, like a seized account, but rarely show what worked, like a successful backup plan that was never caught. This means the true picture of how these groups adapt is likely even more complex than what we can see today. The study also draws a parallel with organized crime groups that deal in drugs. While their goals are different—one wants political change, the other wants profit—they both use similar tricks to move money. This suggests that the rules of adaptation are not unique to terrorism but are a general feature of any group that needs to move resources while avoiding detection. The key difference is that a drug trafficker might accept a loss if the profit is still high, whereas a terrorist group might accept a financial loss if it helps them achieve a political goal, or they might struggle more if they cannot get the money to a specific place in time.
Ultimately, this research offers a new way to think about the fight against terrorist financing. It moves the focus from counting the tools that have been broken to understanding how the group rebuilds its own system. It suggests that the most effective way to stop these groups is not to chase every new technology they use, but to understand the underlying structure of their financial needs. By identifying the critical connections that hold their network together, authorities can design interventions that cause real, lasting damage to the group's ability to operate, rather than just creating a temporary inconvenience. The study concludes that we must measure success by how much we degrade a group's ability to function over time, not just by how many accounts we close today. This shift in perspective is essential for building policies that are both effective and fair, ensuring that the tools used to stop violence do not harm the very people they are meant to protect.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.