This Insight is part of GNET’s LatAm series, which looks at the crime-terror nexus in Latin America and the implications/risks for tech moderation.
The February 2025 United States Foreign Terrorist Organization (FTO) designation of international cartels covered eight entities: six Mexican cartels, one Central American street gang (MS-13), and one Venezuelan prison gang (Tren de Aragua). Prior to this, the primary distinction had always been that FTOs pursue political objectives while Transnational Criminal Organizations (TCOs) are profit-motivated. This line, however, has “blurred to the point of indistinction.” This raises a significant question: should cartels be categorised as terrorists?
Similarly, the FTO designations forced a major issue for tech platforms, one they had never had to answer directly: now that cartels were categorised as FTOs, should their online content be monitored like other FTOs such as ISIS or Hezbollah? This exposed further tensions: major tech platforms have long operated under the assumption that violent extremist groups and criminal organisations are categorically distinct, each in their own lane, governed by separate definitions, classifications, and enforcement frameworks. As Byman and McCaleb note, this means content “would be permissible under most companies’ terms of service as long as the organizations were not designated terrorist organizations.” Designation tells a platform which organisations to watch. It does not tell them what that organisation’s content looks like. Drawing upon Meta’s Dangerous Organizations and Individuals policy as a case study, this Insight explores how separating terrorist and criminal enforcement creates gaps that these groups can exploit and argues that platforms should place greater emphasis on behavioural and functional indicators of harm rather than designation-based enforcement.
Inside Meta’s Dangerous Organizations Policy
Meta’s ’Dangerous Organizations and Individuals’ policy divides entities into two tiers based on the harm they cause offline. Terrorist organisations, hate groups, and criminal organisations, including those designated as FTOs or Specially Designated Narcotics Trafficking Kingpins, all fall under Tier 1, the most extensive level of enforcement. This should mean that terrorist groups and cartels are treated equally. In practice, however, the underlying definitions for each category create very different enforcement realities. Meta defines terrorist organisations and individuals as non-state actors that engage in violence “with the intent to coerce, intimidate and/or influence a civilian population, government, or international organization, in order to achieve a political, religious, or ideological aim.” On the other hand, to be designated as a criminal organisation only requires three or more people unified under a shared name, colours, hand gesture, or identifying symbol, who engage in “criminal activity such as homicide, drug trafficking, or kidnapping”, without necessarily having political or ideological motivation. As the GIFCT-KAS report notes, tech companies rely on government designation lists as a key source for identifying which groups’ content to action [p.43].
The problem is that many groups now designated as FTOs do not fit cleanly into either category. Groups like the Jalisco New Generation Cartel, better known as CJNG, govern territory, use violence to intimidate civilian populations, and exert political influence, all characteristics that mirror terrorism, while remaining profit-driven criminal enterprises. When a group operates across both definitions simultaneously, it enters a grey area where neither enforcement framework captures it fully.
Coded Language and Emojis
FTO groups and organised crime groups also use the same encrypted messaging apps, which allow coordination with limited detection. Cartels also recruit through game chats. In late 2024, InSight Crime reported two Mexican minors approached through the online game Free Fire, one allegedly by the Sinaloa Cartel. Recruiters typically move these conversations to encrypted apps such as WhatsApp or Signal. A report by the United Nations Office on Drugs and Crime (UNODC) found criminal networks using Telegram to trade stolen data, launder money through unlicensed cryptocurrency exchanges, and sell fraud tools, with cybercrime-related messages on the platform rising from 27 million in 2019 to 1.4 billion in 2024. Similarly, Islamic State supporters share content across Telegram and smaller encrypted platforms such as Element and RocketChat, and Islamic State-linked recruiters have been documented moving minors from TikTok into Discord servers and Roblox games. Terrorist and criminal groups are thus operating in the same online spaces, even though platforms enforce against them separately.

Figure 1: TikTok posts using cartel-coded emojis and hashtags. Source: Colegio de México, Criminal Recruitment on TikTok, April 2025 [p. 9].
Fraud, Scams, and Cryptocurrency
Further blurring the lines between the two, FTOs like Hamas and ISIS now use cryptocurrency to raise and launder money. In March 2025, the Justice Department seized roughly $201,400 from Hamas fundraising wallets, which had laundered more than $1.5 million since October 2024 through a rotating set of at least 17 addresses circulated in an encrypted group chat. An earlier DOJ action dismantled financing campaigns run by ISIS, Hamas’s al-Qassam Brigades, and al-Qaeda, seizing over 300 cryptocurrency accounts, four websites, and four Facebook pages. The FTO-designated cartels do the same. In May 2026, the US Treasury sanctioned a Sinaloa Cartel network that collected bulk cash from fentanyl sales in the United States and converted it into cryptocurrency for transfer to Mexico. The Office of Foreign Assets Control (OFAC) designated the network under both narcotics and counterterrorism authorities; the same counterterrorism authority used against Hamas and al-Qaeda financiers. When terrorist groups engage in fraud and the same encrypted platforms become routine for both terrorist groups and organised crime groups, the notion that platforms can draw a clean line between violent extremist groups and criminal organisations becomes increasingly difficult to defend.
In all three cases below, platforms do not flag the content because they fail to identify the group, since the frameworks built to detect terrorist content look for something else.
1. Mexican Cartels
The Mexican cartels highlight this issue most clearly. Cartel governance content resembles community-oriented content online, rather than having the hallmarks of terrorist content. Governance content refers to material portraying cartels as providers of social order in lieu of the state, regulating territory, markets, and access to justice in ways that displace formal government authority, reflecting organised crime’s ambition to become “de facto rulers“ of Mexican towns. Cartels deliberately craft a public image online, in what researchers call narco-culture, blending community service, cultural identity, and displays of power as a form of propaganda [p.11]. During COVID-19, both CJNG and the Sinaloa Cartel distributed food baskets across at least 10 Mexican states, and they documented and broadcast it on social media to boost their reputation. This content is functionally indistinguishable from legitimate NGO or government activity to an automated classifier. Differentiating cartel food distribution from a legitimate food bank is possible, but it requires contextual knowledge that automated systems lack and the kind of human oversight that platforms are currently cutting back. Terrorist organisations do the same. Hezbollah has long operated schools, hospitals, and social welfare programmes in Lebanon, using humanitarian efforts as a tool of political legitimacy, allowing content to go undetected by platform moderation despite originating from a designated FTO.

Figure 2: Food packages distributed by Mexican cartels during the COVID-19 pandemic. Source: InSight Crime, 2020.
2. Gangs
El Salvador’s Supreme Court declared MS-13 terrorists “regardless of whether such armed groups have political, criminal, economic, or other purposes”, explicitly collapsing the political motivation requirement. MS-13 “run bakeries, fuel distribution, public transport, and water sales“ in Las Margaritas, El Salvador [p.13], reinforcing their role as de facto service providers similar to cartel activity. MS-13’s online content does not resemble jihadist propaganda. As InSight Crime documented, during the COVID-19 pandemic, MS-13 circulated voice messages and videos of community curfew enforcement in El Salvador, content largely indistinguishable to a classifier from government public health messaging. Researchers at the Igarapé Institute tracking MS-13 on Facebook, Twitter, and Instagram found members posting in gang-specific slang and coded language that required specialist glossaries to interpret, appearing to automated systems as ordinary social media activity. This mirrors how jihadist groups use platforms, posting community and identity content in local dialects that classifiers are not trained to read. The difference is that MS-13’s designation is contested. El Salvador and the United States treat the gang as a terrorist organisation; most other countries do not. A platform that enforces on designation alone will therefore reach different conclusions about the same content depending on which government’s list it follows.
3. Terrorist Groups
Hezbollah is the clearest comparative example of how inconsistent government designations of terrorist entities break down platform enforcement. Hezbollah holds seats in Lebanon’s parliament, runs schools and healthcare facilities, and promotes its activities online as legitimate political and civic work. Simultaneously, Hezbollah-affiliated networks engage in drug trafficking, human smuggling, and money laundering in the tri-border area of Argentina, Brazil, and Paraguay. On social media, “Hezbollah uses proxies, such as charities and Al Manar, its ostensibly independent broadcaster, to post content that is widely available on social media channels” allowing non-violent propaganda to slip through moderation frameworks.
Hezbollah’s online presence rarely appears under its own name. Al Manar, the group’s broadcaster, was designated by the US Treasury and banned outright in the United States, Canada, and France. Al Manar’s content, however, is largely news bulletins, religious programming, and general broadcast content, material that reads as ordinary state news rather than terrorist propaganda. As such, platform responses have been inconsistent and reversible. Facebook removed Hezbollah and Al Manar pages entirely. Apple and Google pulled the Al Manar news app from their stores. X banned Al Manar in November 2019 after the Treasury designation, and then later reinstated its X account. Four platforms reached four different conclusions about the same entity, despite operating from the same designation. The EU designated only Hezbollah’s military wing in 2013, while the US, UK, Germany, Canada, and Australia designated the organisation in full. For a moderator, this means the same broadcast is terrorist content or lawful media depending on where it is judged. Hezbollah’s own leadership denied that separate military and political wings exist, so platforms are sorting content into categories the organisation itself does not use. Assessing what the content does would remove the need to make that call.
The Structural Problem
These cases point to a structural problem rather than individual failures. Terrorism classifiers are trained on ideological markers, such as insignia, flags, martyrdom language, and known propaganda matched against shared hash databases. Hybrid actors produce none of these. A cartel food distribution video and a gang lifestyle post do not fail detection; they fall outside what detection is designed to look for. When designation is the trigger, enforcement follows political decisions rather than harmful behaviours. When the United States designated six cartels, MS-13, and Tren de Aragua as FTOs in February 2025, nothing about those groups’ online output changed. The same content became subject to terrorism enforcement overnight because a government label changed, and it would stop if a future administration reversed the decision. The result is enforcement that is unstable across time and inconsistent across borders, and that responds to what a group has been called rather than what its content does.
Recommendations
Platforms need an enforcement framework that does not depend on government labelling to identify harmful actors. Meta already runs one. Its Coordinated Inauthentic Behaviour (CIB) policy targets how networks of accounts behave rather than who is behind them, and Meta says these standards apply “agnostic of content, political or otherwise.” Applying this approach to dangerous organisations could help address FTOs that portray themselves as governance actors. TikTok, for instance, also has specific policies for handling content by dangerous or extremist actors, including “Violent Criminal Organizations.”
The Global Internet Forum to Counter Terrorism (GIFCT) ran technical trials combining behavioural and linguistic signals to find terrorist content. Layering signals, combining several weak indicators such as posting patterns, language, and network connections so that no single one has to be conclusive on its own, detected more content while flagging fewer false positives. GIFCT’s Global Definitions of Terrorism Map already records which behavioural signals governments most often use to proscribe groups. A shared behavioural layer gives platforms something: a designation list. A shared behavioural layer gives platforms something a designation list cannot: a reference point that does not shift when an administration changes or a jurisdiction disagrees.
For hybrid actors, three signals matter most: recruitment that moves people from open platforms into encrypted channels, coded emojis and hashtags used to signal membership, and governance content combined with threats or violence. Researchers already document all three. What is missing is not detection capability but the integration of that research into moderation policy. Behavioural signals will likely produce false positives, since legitimate organisations and ordinary users share some of these patterns. However, designation-based enforcement already fails in both directions: it misses groups that have not been designated, and it removes harmless content from groups that have, purely because of the label. The trade-off is between a system that makes errors and one that does not look until it is told to. Tech Against Terrorism has argued that governments, not companies, should fix the inconsistency in designation systems. But hybrid actors show the problem is not that the lists are messy; it is that lists are the wrong tool. Platforms can already observe all three without waiting to be told who to watch, and layering them reduces the false positives any one of them would produce alone.
—
Rebecca Fainberg is a graduate student in the Center for Global Affairs at New York University, where she specialises in transnational security. Her research focuses on the intersection of trust and safety, threat intelligence, online extremism, and transnational organised crime, with particular interest in how digital platforms can identify and disrupt harmful actor networks. She has conducted research with the United Nations Interregional Crime and Justice Research Institute (UNICRI) and the Institute for Peace and Security Studies (IPSS), and previously spent nearly a decade leading intellectual property enforcement operations in the private sector.
–
Are you a tech company interested in strengthening your capacity to counter terrorist and violent extremist activity online? Apply for GIFCT membership to join over 30 other tech platforms working together to prevent terrorists and violent extremists from exploiting online platforms by leveraging technology, expertise, and cross-sector partnerships.
The views and opinions expressed in this Insight are the authors’ own and do not necessarily reflect those of GNET or any of its partners.