This Insight is part of GNET’s LatAm series, which looks at the crime-terror nexus in Latin America and the implications/risks for tech moderation.
For over three decades, the Tri-Border Area (TBA) between Argentina, Brazil and Paraguay has been at the centre of debates surrounding the crime-terror nexus, particularly over the extent to which terrorist organisations exploit the region’s illicit economies and cooperate with organised criminal networks. The TBA has become one of the most studied examples of how organised crime and terrorism interact within environments characterised by corruption, porous borders, weak governance and informal economies. Since the bombings of the Israeli Embassy in Buenos Aires in 1992 and the AMIA Jewish Community Centre in 1994, attention has focused on Hezbollah’s logistical and financial presence in Latin America. Although evidence linking the organisation directly to terrorist activity in the region remains limited, evidence of its involvement in illicit activities and criminal entrepreneurship is far stronger (p.219 – 226). Yet, as the global threat landscape evolves, so too do the mechanisms sustaining these operations.
This Insight argues that technological innovation is transforming the contemporary crime-terror nexus by enhancing the adaptability, resilience and transnational reach of Hezbollah’s illicit financial networks. In doing so, it argues that the existing crime-terror nexus theory should be expanded to account for the growing role of digital technologies. This expansion would shift analysis beyond traditional forms of criminal-terrorist interaction to consider how digital technologies enable new forms of financial, operational and transnational convergence.
Makarenko’s Crime-Terror Continuum
Tamara Makarenko’s crime-terror continuum remains one of the most influential frameworks for understanding the relationship between organised crime and terrorism. Rather than framing the two as distinct phenomena, Makarenko showed they exist along a continuum characterised by alliances, cooperation, convergence, and, in some cases, organisational hybridisation. This broader perspective is reinforced by Shelley and Picarelli, who similarly argued that globalisation blurred the distinction between ideological violence and profit-driven criminality as terrorist organisations increasingly adopted organised crime techniques to ensure their financial sustainability. In the contemporary security environment characterised by rapid technological change, globalisation and increasingly interconnected illicit economies, the ability of criminal and terrorist organisations to cooperate, share expertise, exploit emerging technologies, operate across interconnected physical and digital spaces, and challenge the rule of law requires a broader understanding of the crime-terror nexus than earlier conceptualisations allowed.
What has changed is the environment in which both organised crime and terrorism now operate. Much of the literature still focuses on cigarette smuggling, counterfeit goods, drug trafficking, hawala networks, and money laundering, reflecting the operational realities of the early 2000s rather than the twenty-first-century digital landscape. Today, illicit finance increasingly operates through digital payment platforms, cryptocurrencies, stablecoins, and blockchain technologies. Communications have shifted from physical meetings and conventional telecommunications to encrypted messaging applications, while artificial intelligence is creating fertile ground for sophisticated fraud, identity theft, and document forgery. While evidence of its systematic use by crime-terror networks remains limited, these capabilities are increasingly available to the same illicit actors already exploiting digital financial and communication systems. These developments are often seen as new tools for criminal actors, but that view fails to capture their importance. Technology is no longer simply facilitating criminal activity; rather, it has already reshaped the organisational architecture of the crime-terror nexus itself.
Finance, Communication and the Digital Crime-Terror Nexus
The Tri-Border Area provides a useful regional example of how established illicit economies are adapting to technological change. Criminal organisations operating across Brazil, Paraguay, and Argentina have long relied on cash, smuggling, and money-laundering networks to move illicit proceeds. Increasingly, however, these traditional mechanisms exist alongside digital ones. Brazil’s Primeiro Comando da Capital (PCC), which operates across regional trafficking routes, provides an important example of this adaptation. Since 2024, PCC-linked networks have used cryptocurrencies to move and conceal criminal proceeds, while organised criminal networks in Brazil are increasingly exploiting emerging technologies, including AI-enabled fraud and digital identity manipulation. These developments show how technological innovation is becoming embedded in the same illicit economies where crime-terror interactions have historically occurred.
The PCC is relevant to the crime–terror nexus because of its activities and alleged cooperation with Hezbollah-linked actors, rather than simply its presence in the region. A 2019 analysis in PRISM (p.64-65), drawing on Brazilian Federal Police investigations, reported cooperation between PCC members and Hezbollah-linked actors in drug trafficking and arms trafficking. The PCC’s more recent use of cryptocurrency raises a separate question about how criminal finance is changing. In June 2025, Paraguayan authorities uncovered a site combining cocaine processing with suspected illegal cryptocurrency mining, illustrating how traditional illicit activities can increasingly coexist with digital technologies. This is particularly relevant to the crime-terror nexus given reported links between the PCC and Hezbollah-linked actors, including through drug trafficking, arms trafficking and other illicit activities.
These examples show how organised criminal groups are integrating emerging technologies into established illicit economies, creating opportunities that terrorist organisations operating within or alongside these networks may also exploit. Technology therefore creates opportunities that criminal and terrorist networks can access without requiring formal technological cooperation between them.
Cryptocurrencies illustrate this point particularly well. Much of the existing literature frequently portrays them as alternatives to conventional banking that have revolutionised terrorist financing. Their value for organisations lies elsewhere: rather than replacing established money laundering mechanisms, cryptocurrencies complement cash smuggling, trade-based money laundering, informal value transfer systems, and shell companies, creating hybrid financial ecosystems that are more adaptable and resilient than any single mechanism alone. A 2026 report (p.18) by the Paris-based Financial Action Task Force (FATF) — an intergovernmental body comprising 38 member jurisdictions and two regional organisations — supports this argument, showing that terrorist financiers almost never rely on virtual assets alone but instead blend digital virtual assets with traditional terrorist-financing methods.
This pattern resembles Hezbollah’s wider organisational behaviour. As research argues (p. 220-227), Hezbollah’s engagement with organised crime is best understood as rational criminal entrepreneurship driven by necessity and opportunity. In the Tri-Border Area, a 2006 U.S. Treasury designation described how businesses at Ciudad del Este’s Galeria Page generated funds, while associates collected and transferred money to Hezbollah in Lebanon. This illustrates the importance of commercial activity and trusted intermediaries in its regional financing. The question is how digital tools might extend such established methods. Stablecoins provide a particularly useful example; tied to real cash, they keep their value steady like normal money while moving as fast as cryptocurrencies. This makes them highly attractive for cross-border transactions and, in some cases, sanctions evasion. Analysis in a recent GNET Insight similarly concludes that Hezbollah’s financial facilitators are operating within digital financial ecosystems that combine stablecoins with traditional smuggling networks. A separate, documented example comes from a 2024 U.S. Treasury designation of Tawfiq Muhammad Said al-Law, a Syrian hawala operator accused of facilitating money transfers for Hezbollah. According to the OFAC report, al-Law managed digital wallets used on behalf of the organisation, while analysis by TRM Labs found that tens of millions of dollars flowed through USDT on the Tron blockchain. This example shows how traditional hawala networks are increasingly integrated with blockchain-based value transfer rather than displaced by it. Digital assets therefore reinforce rather than replace Hezbollah’s established criminal infrastructure. This supports the basis of Makarenko’s continuum but also shows its limits, as technology increasingly allows crime and terrorism to converge across physical and digital spaces, with knock-on effects on their interaction. Together, these cases show Hezbollah’s continued reliance on financial intermediaries: the Barakat network used businesses and couriers in the Tri-Border Area, while al-Law provided access to digital wallets, which could move value through blockchain networks alongside established financial channels.
Finance, however, is only one dimension of this transformation. Encrypted communications reduce the importance of physical proximity, allowing facilitators operating across different jurisdictions to function as components of wider transnational networks. Geography still matters: indeed, the Tri-Border Area continues to provide permissive conditions for illicit activities. The TBA’s porous borders, high levels of cross-border trade, extensive informal economy and uneven state oversight have historically provided opportunities to move illicit goods and funds between jurisdictions. Digital connectivity (p.25), however, amplifies those geographical advantages, allowing communication, financial activity and criminal coordination to extend beyond physical borders.
These developments expose a key limitation in existing crime-terror nexus theory. Makarenko’s continuum explains how organised crime and terrorism converge organisationally, but it was developed before the emergence of cryptocurrencies, encrypted communications, artificial intelligence and decentralised finance. Contemporary technological change suggests that another stage has emerged. Therefore, rather than replacing Makarenko’s framework, this article proposes extending it through the concept of a Digital Crime-Terror Nexus, in which technologies function as cross-cutting enablers that simultaneously strengthen organised crime and terrorism. The critical transformation is therefore not organisational but technological. Blockchain technologies, digital financial platforms, encrypted communications, and artificial intelligence reshape how illicit actors generate revenue, communicate, launder money, and evade law enforcement, regardless of organisational identity.
Updating the Continuum
Makarenko’s continuum explains crime–terror convergence through alliances, cooperation and organisational hybridisation. These models remain useful, but digital tools also shape how illicit actors communicate and move funds. A 2024 UNICRI report examines how access to cybercrime services and encrypted platforms can lower barriers for extremist actors. Similar use of technological systems does not itself establish cooperation. It does, however, make the digital infrastructure available to criminal and terrorist networks an important part of the analysis.
The Tri-Border Area shows both the relevance and the limits of this approach. Hezbollah-linked facilitators have historically used commercial and informal financial networks there. Separately, PCC-linked networks have used cryptocurrency to move proceeds from the United States to Brazil, while a Hezbollah-linked facilitator elsewhere has provided digital wallets. These cases show how digital methods can complement established channels. A digital extension of the continuum should therefore examine how technology interacts with identifiable networks and transactions, rather than treat use of the same technology as proof of a crime–terror nexus.
Approaches focused mainly on identifying relationships between criminal and terrorist organisations risk overlooking the technological infrastructure that enables them both. Countering the contemporary nexus therefore requires attention to financial and digital ecosystems, including stronger regulation of virtual asset service providers, improved transnational information sharing and better capacity to trace transactions that move between traditional and digital financial systems. In practice, FATF’s recommendations help identify parties to virtual-asset transfers, while the Egmont Group supports cross-border exchange between financial intelligence units. For practitioners, this is more than a theoretical distinction. How authorities understand the crime-terror nexus shapes what they look for. If convergence is viewed primarily through direct cooperation between criminal and terrorist organisations, authorities may overlook important connections within the wider digital ecosystem.
This has implications beyond financial regulation. For technology companies and online platforms, it means considering how legitimate digital services can be exploited across wider illicit networks. For those working in preventing and countering violent extremism (PCVE), it means looking beyond individual terrorist actors towards the digital environments that can facilitate their activities; GIFCT’s hash-sharing database is one practical platform response. For law enforcement, it requires closer cooperation between financial intelligence, cybercrime, counterterrorism and organised crime investigations. The challenge is not simply identifying a particular technology as criminal or terrorist, but understanding how otherwise legitimate technologies are combined with existing illicit networks and financial mechanisms.
Geography remains important, but it is no longer the primary determinant of criminal opportunity. Actors no longer need to be physically present in the same environment to access its networks, markets or financial opportunities. The significance of places such as the TBA therefore lies in how their established criminal infrastructure connects with wider transnational digital networks, extending their reach well beyond the geographical space itself. Armed with blockchain tools, encrypted messaging, and artificial intelligence, actors across the globe can now exploit international markets with a speed and flexibility earlier frameworks simply did not account for.
Conclusion
The defining feature of today’s crime-terror nexus is no longer purely organisational convergence, but a convergence of technological capabilities. Regardless of ideology, structure or motivation, criminal syndicates and terrorist groups now rely on the same digital infrastructure to collect funds, launder criminal proceeds, evade the rule of law, and coordinate across borders. Technology therefore acts as a force multiplier, stripping away traditional operational limits while boosting adaptability and transnational reach. Extending Makarenko’s continuum to account for this does not undermine its core principles; rather, it updates them by regarding technological innovation as a structural engine of convergence. The digital crime-terror nexus points towards an evolution of the continuum in which digital technologies do not simply facilitate existing relationships, but create an additional environment through which criminal and terrorist activities can intersect.
For practitioners, this distinction matters because how the nexus is understood shapes what law enforcement looks for. Understanding the nexus means looking beyond direct crime-terror cooperation to the wider financial, communication and digital infrastructure that can enable both, without assuming that shared use of technology necessarily demonstrates a direct relationship. Recognising this shift has important policy implications. Counter-terrorism financing remains heavily focused on disrupting physical financial flows and anti-money laundering (AML) frameworks, yet contemporary illicit networks increasingly operate across hybrid physical and digital ecosystems, creating more challenges for law enforcement agencies. Future responses must therefore integrate financial intelligence, cybercrime investigations, counterterrorism and counter-organised crime initiatives into a more coherent framework. Hezbollah’s activities in the Tri-Border Area suggest that the future of terrorist financing will be neither exclusively physical nor exclusively digital. It will be hybrid, leveraging both local safe havens and borderless online platforms. Thus, understanding that hybridisation is essential if scholarship and policy are to keep pace with the evolving crime-terror nexus.
–
Dr Adriana Marin is a Lecturer in International Relations at Coventry University, specialising in transnational security, organised crime, and the crime–terror nexus. Her research focuses on drug trafficking, criminal governance, and illicit economies across Latin America and the Middle East. She has published work on cartel dynamics, terrorist financing, and the evolving convergence of criminal and extremist networks.
–
Are you a tech company interested in strengthening your capacity to counter terrorist and violent extremist activity online? Apply for GIFCT membership to join over 30 other tech platforms working together to prevent terrorists and violent extremists from exploiting online platforms by leveraging technology, expertise, and cross-sector partnerships.
The views and opinions expressed in this Insight are the authors’ own and do not necessarily reflect those of GNET or any of its partners.