Welcome to the Global Intelligence Knowledge Network Podcast, where real-world intelligence expertise meets insightful analysis. Join your host, Neil Bisson, a former Intelligence Officer with the Canadian Security Intelligence Service, for a weekly deep dive into the world of espionage, national security, foreign interference, terrorism, and all matters spy and intelligence related.
With over 25 years of experience in intelligence and law enforcement, both domestically and internationally, Neil Bisson brings a unique perspective to the table. From hunting spies and terrorists to recruiting and managing human sources, he's seen it all.
Each episode, Neil Bisson, Director of Global Intelligence Knowledge Network as he provides a comprehensive summary of the most intriguing international intelligence stories, dissecting the hottest media topics with professional analysis and insider knowledge. Whether you're a seasoned intelligence professional or simply fascinated by the world of spies, this podcast is your go-to source for accurate, insightful, and engaging content.
Tune in weekly to stay informed, enlightened, and entertained. Don't miss out on the latest from the frontlines of global intelligence. Subscribe now to the Global Intelligence Knowledge Network Podcast on Buzzsprout and never miss an episode. Stay sharp, stay informed, and stay ahead of the curve with the Global Intelligence Knowledge Network Podcast.
☣️ ISIS Planning Chemical Attack in Canada? | Global Intelligence Weekly Wrap-Up
A terrorism investigation in Quebec City has raised a disturbing question: Was an alleged ISIS supporter researching how to carry out a chemical attack in Canada?
This week, Neil Bisson — retired CSIS Intelligence Officer, former CBSA Officer, and Director of the Global Intelligence Knowledge Network — examines four stories demonstrating how foreign intelligence, cyber espionage, sabotage and terrorism are increasingly intersecting with domestic national security.
🇨🇦 CANADA — DOES CANADA NEED ITS OWN FOREIGN INTELLIGENCE SERVICE? Canada's renewed debate over developing a greater independent foreign-intelligence capability raises a fundamental question: Can Canada make truly independent strategic decisions if some of the intelligence informing those decisions must come from its allies? As the international security environment becomes increasingly uncertain, the debate over how Canada collects intelligence abroad is becoming more important.
🇳🇿 NEW ZEALAND — CHINA'S CYBER ESPIONAGE THREAT New Zealand has identified China as its most persistent and capable state-backed cyber threat. The warning reinforces a pattern GIWW has been following across the Five Eyes: Gain access. Maintain access. Collect intelligence. And potentially preserve that access for future operations. The distinction between cyber espionage and preparation for potential cyber disruption may be becoming increasingly difficult to define.
🇵🇱 POLAND — SABOTAGE, STARLINK & RUSSIAN HYBRID OPERATIONS Polish authorities are investigating a fire at a Starlink communications facility as suspected sabotage, while Denmark's intelligence service is warning of an escalating Russian hybrid campaign. The development comes only weeks after GIWW examined reports involving suspected Russian activity around critical undersea communications infrastructure near Svalbard. Infrastructure supporting Ukraine and NATO remains an important potential target — and sabotage may provide adversaries with a means of imposing costs while remaining below the threshold of conventional military conflict.
☣️ CANADA — ISIS & AN ALLEGED CHEMICAL ATTACK PLOT Our main story takes us to Quebec City. The RCMP has charged 24-year-old Louay Angoud with three terrorism-related offences following an investigation by the Integrated National Security Enforcement Team. Authorities allege Angoud communicated online with members of a terrorist organization and researched information related to constructing a chemical weapon that could potentially be used to poison people in Canada. Police have said there was no imminent threat to the public, and Angoud reportedly did not possess the materials necessary to carry out the alleged chemical attack when he was arrested. 2026 09 25 Global Intelligence … The case raises several important intelligence questions: • What originally brought Angoud to the attention of Canadian authorities? • What was the nature of his alleged online communications with ISIS? • How far had the alleged research progressed toward operational capability? • How do intelligence agencies distinguish extremist rhetoric and online research from genuine attack planning? • Has the internet fundamentally changed the pathway between radicalization and terrorist action? And there is another reason Quebec City is worth watching. GIWW previously examined a separate case involving a Quebec City-area teenager accused of promoting the Atomwaffen Division online. The two investigations involve very different extremist ideologies and should not be treated as part of the same phenomenon.
But they share something important: The operational environment increasingly begins online. 2026 09 25 Global Intelligence … This week's stories may involve different countries, adversaries and threats. But the boundaries separating foreign intelligence, cyber espionage, sabotage and domestic national security are becoming increasingly difficult to define.
⏱️ CHAPTERS 00:00 Introduction 02:00 Canada: Does Canada Need a Foreign Intelligence Service? 07:30 New Zealand: China's Cyber Espionage Threat 12:45 Poland: Starlink Sabotage & Russian Hybrid Operations 18:00 ISIS Planning a Chemical Attack in Canada? 28:45 Final Thoughts & Outro
🎟️ PILLAR SOCIETY SPEAKER SERIES — OCTOBER 20 The Ottawa–Gatineau Chapter of the Pillar Society welcomes Canadian journalist Andrew Coyne to the Shenkman Arts Centre in Orléans on October 20 for a discussion examining Canada's national security, defence, productivity and geopolitical challenges.
www.pillarsociety.com
Tickets and information: Pillar Society 🌐 GLOBAL INTELLIGENCE KNOWLEDGE NETWORK Training, presentations and consulting on foreign interference, espionage, HUMINT, proxy operations, sabotage, research security and emerging national-security threats. 📧 globalintelligence@globalintelligenceknowledgenetwork.com ☕ SUPPORT GLOBAL INTELLIGENCE WEEKLY WRAP-UP Support Global Intelligence Weekly Wrap-Up Subscribe, share the episode and leave a review on your favourite podcast platform.
This week on Global Intelligence Weekly Wrap-Up, Neil Bissan, a retired intelligence officer with the Canadian Security Intelligence Service and the director of the Global Intelligence Knowledge Network, examines a series of developments showing how intelligence and national security threats are becoming increasingly difficult to contain within borders, whether those threats originate overseas, inside computer networks, or just online. We begin in Canada, where parliamentarians are examining whether the country needs greater independent foreign intelligence capabilities, reviving a debate that Canadian governments have wrestled with for nearly eight decades. From there, we travel to New Zealand, where the country's national cybersecurity center has identified China as its most persistent and capable state-backed cyber threat. This is part of a much broader pattern of Chinese-linked actors gaining and maintaining access to telecommunications, government networks, and critical infrastructure. Then to Europe, where Polish authorities are investigating a suspected sabotage attack against a Starlink communications facility supporting Ukraine, as Danish intelligence warns that Russia's hybrid campaign against NATO and the West could escalate in the months ahead. And finally, our main story brings us back to Canada, where the RCMP have charged a 24-year-old Quebec City man with terrorism offenses, alleging he communicated online with members of ISIS and gathered information about constructing a chemical weapon that could be used to poison Canadians. What connects Canada's foreign intelligence debate, Chinese cyber espionage, suspected sabotage in Europe, and an alleged ISIS terrorist plot in Quebec City. Each demonstrates how the national security environment is changing, and how events thousands of kilometers away can increasingly create intelligence. Economic and security consequences right here at home. So what are you waiting for? Let's get started.
SPEAKER_01
Hello, and welcome back to the Global Intelligence Weekly Wrap-up. I'm your host, IlB Sonic. As a former intelligence officer with the Canadian Security Intelligence Service and the director of the Global Intelligence Knowledge Network, I take the latest headlines concerning international espionage, sabotage, national security, and terrorism, and provide you with the insights, analysis, and intelligence to help you with your career, your business, and your safety. Been another busy week, from a potential sabotage attack against a satellite manufacturing facility in Poland to the arrest of an ISIS-linked man in Quebec who is planning to build a chemical weapon. There's a lot to discuss, so let's get into it. We begin this week in Canada, where a debate that has been going on behind closed doors in Ottawa for decades is suddenly receiving some serious attention. Members of the National Security and Intelligence Committee of Parliamentarians, or ENSCOP, are examining the effectiveness of Canada's ability to collect foreign intelligence. And that raises a much bigger question. Have we decided that Canada finally needs its own foreign intelligence service? For listeners who aren't familiar with Canada's intelligence structure, we need to make an important distinction here. Canada does collect intelligence for overseas. The Communications Security Establishment collects foreign signals intelligence. Global Affairs produces diplomatic reporting. The Canadian Armed Forces collects defense intelligence. And CISES can operate outside Canada when investigating threats to the security of Canada, including terrorism and espionage. That's different from foreign intelligence in the traditional human sense. CESIS's foreign intelligence authority is very restricted. Under Section 16 of the CES Act, foreign intelligence collection concerns foreign states, organizations, or individuals, and is conducted within Canada under specific ministerial authority. It can collect foreign intelligence information abroad, but only with the sign off of different ministers for different reasons. And as such, this capability is not a regular or often used function of the service. What Canada definitely does not have is the equivalent to Britain's MI6, America's CIA, or Australia's ACES. The primary purpose of these organizations is to recruit human sources overseas for the purpose of influence and to collect political, military, and economic intelligence specifically in support of their own country's interests. And that distinction matters, because according to Global News, a CISES memorandum prepared last year acknowledged something particularly important. Canada can only learn to act so much through its existing authorities and has historically depended on Allied intelligence relationships for some foreign intelligence. That gets directly to the issue we've discussed before on this podcast. Intelligence sharing is enormously valuable, but intelligence sharing is not the same thing as possessing an independent intelligence capability. And this is where I want to take the listeners back to the March 13th, 2026 edition of the Global Intelligence Weekly Wrap-Up. Because we've discussed almost the exact same issue six months ago. This previous segment was prompted by research published in February by Alan Barnes of the Carleton University Norman Patterson School of International Affairs. Barnes examined newly available archival records covering Canadian government discussions about creating a foreign intelligence agency between 1945 and 2007. And what those records show was fascinating. Canada hasn't simply forgotten to create a foreign intelligence service. Successive governments have repeatedly considered it and then decided against it. The discussion goes all the way back to the aftermath of the Second World War. In 1951, British intelligence actually discussed with Canadian officials the possibility of Canada establishing such capability. Canadian officials subsequently developed proposals examining whether Canada should secretly recruit human sources overseas, but it never happened. The issue resurfaced reportedly during the Cold War and has surfaced again in the 1980s. Then in 1993, officials developed another substantial proposal arguing that Cobert Foreign Intelligence could provide information specifically targeted toward Canadian political and economic interests. The issue came up again following the attacks of 9-11, and then it became a political issue during the 2006 federal election when Stephen Harper's conservatives promised to establish a Canadian Foreign Intelligence Agency. Again, it didn't happen. So when we discussed this on the podcast in March, I pointed out two arguments that have repeatedly influenced Canadian governments. The first is cost. Running an international human service is expensive. You need trained intelligence officers overseas, you need secure infrastructure, you need diplomatic and potentially non-official cover, recruitment and training systems, you need analysts, technical support, and operational capabilities. And then you have to sustain those networks for years before some of them produce meaningful intelligence. But the other argument is Canada's relationship with its allies, particularly the Five Eyes intelligence partnership involving Canada, United States, United Kingdom, Australia, and New Zealand. Historically, the thinking has been that Canada receives enormous amounts of foreign intelligence from its allies. So why duplicate something we've already been receiving? But as I argued in March, there's a fundamental weakness in that reasoning. The CIA collects intelligence solely for the benefit of the United States. MI6 collects intelligence for the prosperity of the United Kingdom. ACES collects intelligence to ensure a sphere of political influence for Australia. Their intelligence requirements are established according to the political, military, and economic interests of their own governments. And those interests can and do frequently overlap with Canada's, but not always. Imagine Canada, the United States, and Britain competing for a multi-billion dollar infrastructure, defense, or technology contract with another country. All three countries may be Five Eyes intelligence partners, but economically, we are competitors. If an American intelligence source inside the foreign government provides Washington with information about the negotiations, America's intelligence community has an obligation to protect and advance their own interests. Canada cannot automatically assume that every piece of strategically valuable intelligence collected by an ally well be or is shared with Auto. That was an important distinction when we discussed this back in March. Given our current political, military, and economic challenges, it's even more important today. This is no longer simply an academic debate. NCCOP, which consists of MPs and senators who hold top secret security clearances and who examine classified material, is now reviewing the effectiveness of Canada's foreign intelligence collection capabilities. Records obtained from Public Safety Canada reportedly show that the cabinet ministers have been briefed on expanding Canada's ability to collect and act upon foreign intelligence. This review is taking place while the Carney government prepares Canada's first national security strategy in more than twenty years. That strategy is expected to place considerably greater emphasis on economic security, and that is extremely important because foreign intelligence isn't just about discovering whether another country is preparing for war. Modern strategic intelligence can involve understanding another government's negotiating position, its intentions regarding tariffs, or critical mining policy, energy security, emerging technology, foreign investment, supply chains, defense procurement, artificial intelligence, and the list goes on and on, including political decisions that could affect Canadian companies and Canadian jobs. A country's security and prosperity are tied to intelligence requirements. And this is where the why behind this debate has changed considerably. Canada is operating in a geopolitical environment where even close allies may simultaneously be security partners, but economic competitive. At the time, countries including China, Russia, India, Israel, and Iran are using intelligence capabilities to advance their economic, technological, political, and military interests. That makes independent Canadian intelligence increasingly relevant not simply to national security, but potentially to national prosperity. One of the people interviewed by Global News was Gorin Samuel Pesik, who worked on this issue in 2007 while advising then public safety minister Stockwell Day. Pesick argues that previous governments backed away partly because officials believed a separate service wasn't necessary and because of concerns over costs. His central argument now is that an independent country requires its own tools of statecraft and that events occurring overseas can have enormous consequences inside Canada. Something that's proved by the Global Intelligence Weekly wrap-up. There's also an interesting historical perspective from Alan Barnes' research. Barnes found that Canadian officials have considered versions of this question for approximately eight decades. Arguments against creating the service have included cost, diplomatic risk, political concerns, and Canada's extensive access to Allied intelligence. Arguments in favor have repeatedly returned to one fundamental issue. Canadian intelligence requirements are not necessarily the same as Allied intelligence requirements. And that's what this debate is really all about. So six months after we examined the issue on the podcast, we've gone from newly released historical records showing that Canada has debated a foreign intelligence service for decades to Canadian parliamentarians with top secret clearances examining whether existing foreign intelligence capabilities are actually sufficient. That doesn't mean Canada is about to create a CIA or MI6. We don't know what NSICOP will ultimately recommend. And there are legitimate questions about cost, mandate, ministerial control, accountability, oversight, and diplomatic consequences when overseas intelligence operations inevitably go wrong. But something has clearly changed. Canada is talking increasingly about strategic autonomy, economic security, and protecting Canadian interests and a much more competitive and hostile world. If Canada wants greater security autonomy, the intelligence question becomes unavoidable. Can you truly make independent strategic decisions if much of the intelligence informing those decisions comes from somebody else whose interests don't align with your own? For our next segment, retropolites, New Zealand, where the country's national cybersecurity center has released a remarkable direct assessment of the state-sponsored cyber threat facing the country. And the country at the top of that list is, to no one's surprise, China. According to New Zealand's newly released Cyber Threat Report 2026, state-sponsored cyber activity linked to China, Russia, Iran, and North Korea was detected during that past year. But New Zealand's assessment of China goes considerably further. The National Cybersecurity Center describes the People's Republic of China as the most persistent and capable state actor conducting cyber activity in New Zealand. That is a significant statement coming from the Cybersecurity Agency of a Five Eyes Country. And the numbers demonstrate why. During the reporting year running from July 2025 through June 2026, New Zealand's National Cybersecurity Center received 4,673 incident reports. Of those, 369 incidents were serious enough to be triage for specialistic technical support because of their potential national significance. And 86 of those incidents, approximately 23%, had suspected thanks to state-sponsored actors. Their targets included government agencies, health and education organizations, as well as information technology managed service providers. But there's an important intelligence distinction. These aren't necessarily cyber attacks designed to immediately shut something down. Many of these operations are about something we've discussed often on this podcast. Access. State-sponsored cyber espionage can involve conducting reconnaissance, quietly penetrating a network, establishing persistence, and then remaining inside that system for months or years. That access allows the hacking group or state to monitor the flow of information, acquire login credentials, and observe the evolution and tactics of an organization for an extended period of time. But depending upon the target and the circumstances, access to critical systems can potentially provide options for future disruptions as well. And the distinction between collecting information today and potentially disrupting the capacity of an organization tomorrow is something I previously identified as a growing concern in the intelligence community. Because for regular listeners of the Global Intelligence Weekly Wrap Up, there is something particularly important about this new assessment. We've seen this pattern before. In previous episodes of the Global Intelligence Weekly Wrap Up, I've examined the Chinese-linked cyber group Assault Typhoon and discussed reports that the group had penetrated American internet service providers, organizations sitting at the very heart of the communications infrastructure of the United States. But what made that story important wasn't simply the theft of information. The reporting indicated that the actors were attempting to establish persistent access, getting inside these networks and remaining there. During the same segment, we connected Seoul Typhoon to another Chinese-linked operation, Vault Typhoon. The FBI and other American security agencies had warned that Volt Typhoon was targeting critical infrastructure, including energy and transportation systems. What I mentioned at that time deserves repeating. These actors could gain persistent access, collect sensitive intelligence, and position themselves for potential future disruption. With the latest reporting, we are now hearing essentially the same warning from another five-eyed country on the other side of the globe. New Zealand's National Cybersecurity Center isn't describing one isolated hacking incident. It's describing persistent state-sponsored activity directed towards government agencies, health and education organizations, and information technology providers. And New Zealand has previously joined international partners in identifying Vault Typhoon, Flax Typhoon, and Sol Typhoon as part of this broader threat environment. In April of this year, New Zealand joined nine other countries in warning about large-scale covert networks of compromised devices, including home rotors, being used by China-linked cyber actors to conceal malicious activity. Two of the groups specifically identified were Volt Typhoon and Flax Typhoon. Then there's Salt Typhoon. In August 2025, New Zealand joined international partners in identifying a campaign associated with that group targeting telecommunications, transportations, and government networks globally. According to New Zealand's NCSC, the activity included efforts to harvest data, telephone communications, credentials, and information about the networks themselves. So consider the pattern we've been following here. In the United States, Chinese-linked actors were identified inside telecommunication networks and critical infrastructure. Now, in New Zealand, the country's national cybersecurity authority identifies China as the most persistent and capable state-backed cyber actor. Different countries, different networks, different operations. But a remarkably similar strategic objective. Get access, maintain access, collect intelligence, and potentially preserve the ability to use that access later for disruption operations. In August, the New Zealand Security Intelligence Service, or the NZSIS, released its security threat environment for the 2026 assessment period. That report stated that several countries conducted espionage against New Zealand, but it made a very specific distinction. The People's Republic of China was the only country New Zealand said it had detected conducting espionage at scale, and that espionage isn't restricted to cyberspace. NZSIS says foreign states are targeting intellectual property, innovative technology, government information, and other non-public information that could provide them with a strategic advantage. It also warned about attempts to recruit people with government connections and insider knowledge. Put those assessments together, and the picture becomes much broader than cybersecurity. We're looking at intelligence collections through people, networks, technology, government, information, intellectual property, and critical infrastructure. Different collection mechanisms potentially serving a broader strategic objective. NCSC's assessment is particularly important because this isn't coming from an outside cybersecurity company speculating about who might be responsible. It's the formal threat assessment of New Zealand's National Cybersecurity Authority, and its conclusion is explicit. State-sponsored espionage poses a significant risk to New Zealand's economy, long-term security, and international interests. The agency also warns that geography provides little protection. New Zealand may be geographically distant from many of the world's major conflicts, but its telecommunications, supply chains, businesses, and infrastructure are interconnected with the rest of the world. And increasingly, geopolitical competition is extended into the South Pacific. New Zealand's intelligence agencies say state-backed cyber espionage is targeting governments and infrastructure through the region. As usual, China is rejecting the allegations against them. Responding to the new report, a Chinese foreign ministry spokesperson called on New Zealand institutions to stop spreading what Beijing has described as false information and creating conflict. China maintains that it opposes hacking and acts against cyber attacks under Chinese law. However, it's important to recognize that New Zealand's latest assessment isn't occurring in isolation. It joins a much broader series of public warnings and attributions involving five eyes governments and Chinese state-linked actors. And I think that's the real significance of this story. If we look at these incidents individually, they can seem like separate cybersecurity stories. Salt Typhoon is targeting telecommunications, Vault Typhoon is targeting critical infrastructure, and Flax Typhoon is using compromised devices. Chinese intelligence services allegedly use professional networking sites to identify potential human sources. And now New Zealand identifying China as its most persistent and capable state-backed cyber actor. But put them together and a much clearer intelligence picture begins to emerge. The common denominator is what I referred to earlier, access. And this is access that can potentially remain hidden until geographical circumstances make that access particularly valuable. That's why cyber espionage shouldn't simply be viewed as just an IT security problem. It is also an intelligence collection issue and a military issue. When an advisory establishes persistent access inside telecommunication networks or critical infrastructure, the lines separating espionage and potential sabotage become very thin. New Zealand is now publicly warning that it is seeing this activity inside its own networks. And when another member of the Five Eyes Intelligence Alliance identifies the same actors, the same methods, and many of the same targets we've already discussed elsewhere, it becomes increasingly difficult to view these incidents as isolated events. We are seeing a global pattern here. A pattern we've been following for some time and will likely continue to follow for some time to come. Our next segment takes us to Europe, where two developments this week are raising new concerns about Russia's continued hybrid campaign against NATO. The first comes from Poland. The fire broke out Wednesday night at a ground-based Starlink satellite communication station in Wolo Kobrozka in central Poland. Polish Deputy Prime Minister and Digital Affairs Minister Christoph Gaukowski said the fire was a deliberate act of sabotage, and the target is particularly significant. The station transmits internet traffic through Poland to other countries, including Ukraine, and uses SpaceX systems providing connectivity through Starlink terminals. According to Kakowski, the fire affected the station's power system generator and appeared deliberately designed to disable the facility, potentially disrupting internet connectivity to several institutions, including Ukrainian military. The station remained operational following the incident, but there's an important distinction we need to make here. At the time of this recording, Poland has not yet established if it was Russia that carried out the attack. Gakowski said there were many indications to suggest that this incident fits what he described as a new Russian doctrine of attack. Polish Prime Minister Dalom Tusk was even more cautious, saying he did not want to label something sabotage rather than an accident without complete certainty, although he acknowledged that the circumstances appeared suspicious. At this stage we have a suspected act of sabotage against infrastructure supporting Ukraine, but not a publicly established Russian perpetrator. This is an important distinction, because as I teach in my online course, Sabotage and Proxy Operations in Modern Intelligence, attribution and plausible deniability are one of the most fundamental challenges of hybrid warfare. It's a recognizable pattern because only two weeks ago in our September 11th episode, we discussed another suspected Russian operation involving European critical infrastructure. That case involved Leipzig Hal Airport in Germany, where German authorities blame Russia for an attempted drone attack against the airport, prompting German Interior Minister Alexander Dobrandt to discuss increased protection for critical infrastructure. And now this week we have what is potentially another sabotage incident in Poland, a ground-based starling facility supporting communications into Ukraine catches fire, where Polish authorities believe it was deliberately sabotaged. We add to that Poland's deputy prime minister saying that the objective appears to have been disrupting internet connectivity, including communications used by the Ukrainian military. Again, Russian responsibility has not been established. But look at the broader targeting pattern we've been following airports, electrical grids, infrastructure, and now satellite communications infrastructure supporting Ukraine. These may all be different targets in different countries. Different methods, but they all involve infrastructure that supports either NATO countries, Ukraine, or Europe's ability to continue supporting Ukraine. And this is precisely why an announcement this week from Denmark is so important. On Thursday, Denmark's Defense Intelligence Service released a new assessment of the threat from Russia. Danish intelligence assesses that Russia will further escalate its hybrid war or gray zone tactics against NATO and the West during the coming months. It also assesses a low but growing risk that Russia could conduct a limited military attack against NATO country, even while the war in Ukraine continues. And while Danish intelligence considers an actual Russian invasion of a NATO country unlikely, it says that possibility can no longer be completely excluded. Rutgers reported that Danish intelligence chief Thomas Arekian said a limited attack could potentially include isolated strikes using drones or missiles against infrastructure supporting Ukraine. It could even involve false plague operations using Ukrainian-made drones. And the latest assessment builds upon something Danish intelligence was already warning about. In its earlier assessment of Russian hybrid activity, Denmark concluded that Russia was conducting hybrid warfare against NATO in the West and had orchestrated sabotage operations against targets across Europe since 2023. The Danish assessment also made an observation particularly relevant to what we've been discussing here on the podcast about proxy operations. Russia doesn't necessarily need to send Russian intelligence officers into NATO countries to physically carry out sabotage themselves. Danish intelligence says Russia has used individuals not directly connected to Russian intelligence services to conduct sabotage operations. This is what proxy agent operations are all about. Providing Moscow with another layer of separation from this operation. Not until the intelligence services began connecting communications, financial institutions, recruitment activity, and operational patterns can the larger picture sometimes be visible. And Russia can continually reject that bigger picture. Moscow has repeatedly denied conducting sabotage and hybrid operations against their own country. Following Denmark's latest assessment, the Russian Embassy in Copenhagen rejected the allegations as unsupported by credible evidence and accused Western countries of escalating tensions over Ukraine. And this is where this week's story becomes particularly important. Because the Poland incident doesn't need to be definitively attributed to Russia for us to recognize the security environment in which it occurred. Over the past several months, I've discussed suspected sabotage involving airports, electrical infrastructure, telecommunication cables, undersea infrastructure, and other critical systems across Europe. Now we have a suspected sabotage attack against infrastructure helping provide satellite communications to Ukraine. At almost the same time, one of NATO's intelligence services is publicly warning that it expects Russian hybrid operations against the West to increase in frequency and consequence. Now we're discussing a suspected sabotage attack against a Starlink communications station in Poland supporting Ukraine, and Denmark's intelligence services warning that the hybrid campaign may be entering another period of escalation. And if the Danish intelligence assessment is correct, we should expect to see more of it. Not just in Europe, but for any country that continues to support Ukraine in their conflict with Russia. I'm looking at you, Canada. Our final story this week is our main story and takes us to Quebec City, where the RCMP arrested and charged a 24-year-old man of what police allege was a plot to carry out at least one terrorist attack in Canada on behalf of ISIS. Police alleged the suspect was gathering information about how to construct a chemical weapon that could potentially be used to poison Canadians. The accused has been identified as the way Engold. According to the RCMP, the investigation began in April of this year and was conducted by the Integrated National Security Enforcement Team or NSET. Police allege Angold communicated online with members of a terrorist group and collected information related to the construction of a chemical weapon. According to the RCMP, the objective was to conduct at least one terrorist attack in Canada on behalf of the Islamic State or ISIS. Angold initially faced several charges, including a weapons charge connected to a knife. However, following his first court appearance Thursday, reporting indicates that the weapons charge was dropped. He now faces three terrorism-related charges using or possessing property for terrorist purposes, committing an offense for a terrorist group, and participating in the activity of a terrorist group. The Crown opposed his release, and Engold remains in custody. He is expected to be back in court on Monday, September 28th, for the next stage of the proceedings. Police say there was no imminent threat to the public. According to the RCMP, Engold did not possess any of the material required to carry out the alleged chemical attack when he was arrested. From an intelligence and national security perspective, there are several aspects of this case that deserve closer attention. And perhaps the most important is how this alleged plot appears to have developed. The RCMP says its investigation began in April. That means Canadian National Security Authorities appear to have been investigating Engold for approximately five months before his arrest. One of the biggest questions that I have right now is what initially brought him to the attention of authorities? The second major question concerns Engold's alleged communication with ISIS. As previously referenced, police have said he communicated online with members of a terrorist organization. According to police, Engold allegedly gathered information about the construction of a chemical weapon that could be used to poison people in Canada. Successfully producing a toxic substance can be a considerably technical and difficult undertaking. Developing an effective method of dispersing it is another challenge altogether. At this point, police have publicly said that Engold did not possess the necessary materials to conduct the alleged chemical attack. But there is another element of this case that is going to receive considerable attention. According to reporting, Engold is not a Canadian citizen and currently has no legal status in Canada. We've seen a lot of terrorist investigations come out of Quebec as of late. In February, the RCMP charged a Quebec City area teenager with allegedly participating in the activity of a terrorist group. Police allege that the youth use social media to promote the Ottawa division, a violent neo-Nazi organization, including producing and distributing material intended to inspire and recruit others. Although these cases should not be treated as one network or one phenomena, given the fact that one is an ISIS-inspired violent extremism, and the other is accelerationless neo Nazi extremism, there still remains the common factor of an operational environment that increasingly appears to be the Internet. And cases like this can be an enormous challenge for intelligence and law enforcement agencies as they demonstrate that communication with terrorist organizations have fundamentally changed the radicalization environment. This is where Angold investigation could become particularly informative. For intelligence professionals, one of the critical questions in terrorist investigations is determining when extremist rhetoric begins moving towards operational capacity. Someone expressing extremist beliefs is not necessarily prepared to conduct violence. Someone consuming propaganda is not necessarily a terrorist. Even researching disturbing material doesn't automatically mean someone intends to conduct an attack. However, the progression from radicalization to action is one of the most difficult things intelligence and law enforcement agencies have to assess. And based on what the RCNP have publicly alleged so far, that appears to be exactly what investigators will be concerned about in this case. As the story continues to develop, I suspect we're going to learn considerably more about Leo Engel in this investigation in the coming days and weeks. Well, that'll do it for this week's wrap-up. I want to remind my listeners that on October 20th, the Pillar Society will be hosting Andrew Coyne at the Shankman Center in Orleans for a discussion on how Canada faces an unprecedented national security and productivity crisis, driven by psychological unpreparedness, a weak and underequipped military, insufficient independent foreign intelligence collection capability, and rising geopolitical coercion from a shifting U.S. foreign policy. I highly recommend you attend this event if you can. Tickets are on sale from the Pillar Society website, and I'll leave a link in the show notes in the transcript. If you enjoy this content and you find it worthwhile, I suggest you support the channel by going to Buzzspro. A one-time contribution or continued support goes a long way to ensure that we can continue to keep you aware, informed, and potentially prepared for what's coming next. As well, please feel free to leave a comment, like, share, and subscribe to the channel, either on Buzzpro or on YouTube. I'll leave a link to the channel in the show notes and the transcript. Until next week, stay curious, stay informed, and stay safe.
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.