The Use of Drones by Terrorists

This is the paradox: states have never invested so heavily in military superiority, yet the threshold for causing disruption has never been so low. Defence budgets now fund complex systems — satellites, missiles, cyber capabilities and autonomous platforms — while non-state actors can repurpose low-cost civilian technologies to generate disproportionate tactical effects. The commercial drone embodies this shift, turning a capability once reserved for the military into a resource available to ordinary individuals.

This is not an intellectual posture or a staff-college digression, it is concrete. The Islamic State group illustrates this by encouraging its militants, through its propaganda channels, to use commercially available drones bought online (COTS) to carry out operations. Although weakened, the organization still retains enough disruptive capacity to closely monitor this kind of thinking surrounding consumer drones designed for immediate use.

From the 2020s onward, the dangerous nature of this phenomenon became clear. And precisely because this is not new, it is worrying. For years, security experts and professionals have warned about the normalization of drone use. Yet it must be acknowledged that neither European institutions nor (Europol), for now, efforts to raise awareness among public authorities and prepare them for such scenarios have truly kept pace. As a result, the level of risk is gradually rising. For now, these remain isolated cases. But we are refusing to face reality. On several occasions, disaster was narrowly avoided.

A few cases illustrate this trend. A 14-year-old teenager was arrested in Turkey while training to manufacture a bomb and pilot drones. A small drone was discovered in Indonesia, where aspiring terrorists aligned with ISIS planned to attack the Pope on an official visit. More recently, in March, Kuwaiti intelligence services dismantled a cell of individuals suspected of colluding with Hezbollah, who were planning attacks against the country's critical infrastructure.

Individual Terrorist Acts

An analysis of these individual cases reveals a major shift. In the 2000s, an activist was typically someone tied to a terrorist organization; the connection was clear. Today, we face individuals who become terrorists, people who identify with a cause and, without consulting anyone, launch a radical project. Another major shift: where the 'lone wolf' once might use a knife, today they arm themselves with drones—easily obtainable items—along with manuals and tutorials for making explosives.

The primary challenge for security services lies in the unpredictability of these individuals. There is no single profile. Potential perpetrators span a wide spectrum: a young cybersecurity professional who suddenly acts, three idealists plotting a drone attack on the Belgian Prime Minister, a PhD engineering student designing drones in an ideological environment linked to ISIS, or more predictable profiles, such as white supremacist Skyler Philippi, who planned to attack a Tennessee power plant.

These individuals do not share the same age, education level, or degree of social integration. Yet they are all drawn to the same tool: commercial drones, which are easily accessible and adaptable. The threat no longer depends on a network but on the ability of isolated individuals to turn civilian technology into an instrument of death. All countries are affected. There is no initial hotspot. It is no longer a matter of skin color, religion, or sociopolitical claims. No intelligence agency is surprised anymore that a terrorist does their shopping online and receives free training. Blogs explain how to modify the features of a COTS drone. Tutorials detail how to unlock no-fly zones (geofencing), how to alter the software restrictions on a controller using NLD-type software, or how to disable remote identification.

The aggravating factor is the attitude of criminal organizations, which are always lying in wait, ready to seize new technologies to expand their business. This is evidenced by one alarming figure: a U.S. Customs and Border Protection official revealed that 34,682 drone flights were detected within 500 meters of the U.S.-Mexico border in 2025. Drug trafficking alone does not explain this UAV activity. Some of these cross-border transports stem from bloody rivalries. In 2025, three drones loaded with explosives struck a government building in Tijuana, Mexico, housing the state attorney general’s office, just one kilometer from the California border.

Acceleration

Month after month, the commercial drone market is expanding at a pace now measured in months rather than years. For a long time, almost all UAVs were DJI models, the easiest to operate and the most widely available. In 2024, they accounted for 95% of drones detected worldwide. By early 2025, that share had fallen to 83%. This does not mean that drones are disappearing. It means that other types of platforms are emerging: other brands, modified drones, and even improvised or hand-assembled systems.

This phenomenon is extremely rare in the history of weaponry. Major innovations have usually followed a slow trajectory. Aircraft, tanks, and even military radios required heavy infrastructure, state budgets, and decades of industrial maturation. Drones break with this logic. The civilian market is innovating faster than defence industries and military doctrines, a trend that de facto benefits asymmetric terrorist violence. The Islamic State had to capture tanks by force in Syria in order to use them. Today, its remaining militants can learn online how to acquire an aerial capability that is no longer the monopoly of states.

Market growth is being driven by a feedback loop between pilots and manufacturers. A broader UAV culture is now taking shape. Knowledge-sharing on malicious manipulation has become increasingly common, including discussions of open-source systems based on MAVLink which may be vulnerable when communications are insufficiently authenticated. In such cases, hostile actors can send false commands to a drone and repurpose it as a lethal device. Although many terrorist plots remain incomplete or are disrupted, it would be mistaken to treat the threat as marginal. These failures are part of a learning curve. Lone actors test, adapt, observe current conflicts, and recycle knowledge available online. For security services, the challenge lies less in the immediate sophistication of individual plots than in the growing volume of attempts.

States do have access to military countermeasures, many of them highly effective. Yet these systems are costly and difficult to scale across the full range of vulnerable spaces. A military base or an airport can be protected. It is far harder to secure, permanently and simultaneously, a broad spectrum of exposed sites: stadiums, prisons, ports, railway stations, refineries, embassies, official convoys, or large public gatherings.

This evolution calls for a doctrinal shift. The threat no longer lies solely in the final act of violence, but in the chain of preparation that precedes it: acquiring a drone, consulting technical material, conducting repeated trials, or surveilling sensitive sites. Counter-terrorism must therefore focus on pathways of capability-building: identifying the point at which civilian use begins to turn into hostile preparation.

This requires monitoring weak signals not in isolation, but in combination. The threat is no longer only the decision to attack. It also lies in the gradual formation of operational capability.

More than ever, terrorism appears as a mutating force, adapting to the world in order to destroy it.

Submit Your Publication

Submit Your Publication

Submit Your Publication

Submit Your Publication

Submit Your Publication

Submit Your Publication

Submit Your Publication

Submit Your Publication

Submit Your Publication

Submit Your Publication

An error has occurred. This application may no longer respond until reloaded. Reload 🗙