TL;DR
- Terrorist financing has become more decentralized and difficult to interpret from transactions alone.
- Social media can support the journey from audience-building to payment.
- Cash, banks, money services businesses, and hawala still matter. Digital tools are being combined with them, not simply replacing them.
- FATF found major or structural investigative and prosecutorial deficiencies in 69% of assessed jurisdictions.
- Less than 30% of jurisdictions contributing to FATF’s 2026 work included social media, messaging, and streaming platform risks in their national risk assessments.
- Detection requires financial data, digital behavior, platform records, and investigative context.
In April 2021, members of an encrypted group chat discussed sharing fundraising links that appeared to support humanitarian causes. It was later discovered, the money had another destination: terrorist financing wallets.
The operation used services millions of people recognised. GoFundMe brought in donations, PayPal moved funds, Bitcoin crossed borders and Western Union handled transfers. Public platforms helped people connect, while encrypted messages carried instructions and warnings to delete conversations.
By October 2025, two defendants had been convicted in the United States. Together, the defendants and their co-conspirators moved about $35,000 to an ISIS facilitator and his associates.
That case captures the current terrorist financing problem. The financial rail may be old or new, but the campaign around it is increasingly digital.
How has terrorist financing changed?
Terrorist financing has never followed one model. Large organizations may control businesses, extort communities, receive state support, or use regional affiliates. Small cells may rely on salaries, savings, loans, or ordinary bank accounts.
That range makes global growth difficult to express as one reliable dollar figure. Much of the activity is concealed or mixed with legitimate funds. But the clearer trend is the combination of methods.
FATF’s 2025 global risk update found a marked increase in the interlinking of traditional financing methods with digital technologies. It also found that 69% of assessed jurisdictions had major or structural deficiencies in effectively investigating, prosecuting, and convicting terrorist financing cases.
The U.S. Treasury’s 2026 National Terrorist Financing Risk Assessment also adds an important point. Digital assets are not the primary way terrorist groups transfer funds abroad. Cash and money service businesses still matter, but supporters increasingly combine them with online fundraising, P2P payments, digital assets, and encrypted messaging to obfuscate their movement.
In fact, modern terrorist financing is not a clean move from cash to crypto. It is a layered model in which a social post, private chat, payment link, bank account, wallet, and cash withdrawal usually form one chain.
Why has social media become so useful?
Social media used to sit mostly at the communications end of terrorism: propaganda, recruitment, and coordination. Eventually, with evolution and upgrade, platforms started supporting much more.
A platform may offer public posts, private groups, live-streaming, tipping, merchant payments, or access to a virtual asset wallet. Even without processing payments, it can direct users to a bank account, crowdfunding page, QR code, or external wallet.
This gives terrorist actors four advantages.
First, reach. A fundraising appeal can reach a global audience almost instantly.
Second, trust. Repeated posts, peer approval, and emotional stories can make an account feel credible before it asks for money.
Third, privacy. A campaign can begin publicly and move into an encrypted group later.
Fourth, adaptability. If an account or wallet is blocked, organizers can share a replacement through the same network.
FATF’s June 2026 paper describes these platforms as trust-building infrastructure. That is one of its most important findings, hinting that a transaction is often the final step in a relationship that developed elsewhere.
What does terrorist financing through social media look like?
FATF identifies several recurring patterns.
Humanitarian-fronted fundraising
Conflict and disaster create urgency. An appeal may claim to support food, shelter, or families in a conflict zone. Some donors know the destination. Others may believe they are helping a legitimate cause.
The public-to-private handoff
A public post attracts attention. Users move to an encrypted group for payment instructions. Funds may leave through a bank transfer, P2P service, virtual asset wallet or card.
Creator and platform monetization
Livestream tips, subscriptions, virtual gifts, and creator payouts can turn attention into money. Aggregated payouts can obscure the original sources.
Coded and disposable communication
Requests can use emojis, numbers, religious references, or insider language. Ephemeral messages and rotating wallets reduce the time available for detection.
Ordinary-looking commerce
Funds may appear as payments for merchandise, event tickets, or digital products. The transaction looks commercial even when its purpose is not.
These patterns overall threat types. Jurisdictions contributing to the FATF June 2026 paper highlighted almost an equal distribution of terrorist threats abusing SMSPs for financing purposes: individual terrorists, including foreign terrorist fighters and small cells (30%), ethnically or racially motivated terrorist organisations and individuals (26%), large networked organisations relying on regional and domestic affiliates (25%) and non-affiliated regional and domestic terrorist groups (19%) were highlighted as abusing this ecosystem.
What should AML/CFT teams do differently?

FATF’s response begins with a simple fact: no single organization can see the entire terrorist financing journey.
Social media platforms see content and account behavior. Payment providers see transfers. VASPs see wallet activity. Banks see movement into and out of fiat. FIUs and law enforcement may hold investigative context that none of those companies can access independently.
Detecting terrorist financing through social media requires those different views to be connected lawfully and quickly.
1. Develop indicators that capture the wider activity
Risk indicators should extend beyond the transaction itself.
AML/CFT teams need triggers covering coded fundraising language, QR codes, rotating wallet addresses, humanitarian-fronted appeals, creator monetization, crowdfunding, and movement from public platforms into encrypted groups.
A single indicator should not be treated as proof of terrorist financing. Its purpose is to trigger deeper review when several connected signals appear together.
2. Coordinate operational teams from the beginning
Terrorist financing through social media may involve several platforms, payment methods, entities, and jurisdictions. Investigations cannot be divided into isolated stages.
FIUs, law enforcement, prosecutors, supervisors, cyber units, and intelligence teams need defined roles, escalation routes, and processes for working together. Early coordination also helps authorities preserve evidence and determine which organization has the legal power to obtain or act on specific information.
3. Connect digital and financial intelligence
Transaction monitoring shows how money moved. Digital intelligence can help explain why it moved.
Operational authorities should combine financial analysis with open-source intelligence, network analysis, platform information, and appropriate monitoring techniques. Account names, posts, group activity, QR codes, payment links, wallet addresses, and timestamps can reveal relationships that are not visible in the transaction record.
The objective is to connect online behavior, content, networks, and financial movement into one investigative view.
4. Treat the private sector as an early detection partner
Social media platforms, financial institutions, VASPs, payment providers, and technology companies often see the earliest signals of suspicious activity.
They hold the data and technical capabilities needed to detect unusual behavior, preserve records, and, where permitted by law and company policy, suspend suspicious transactions or accounts.
Authorities can improve this process by providing clear, case-specific context. That includes the suspected offense, relevant identifiers, known activity, and the information required. More precise requests help private-sector teams locate useful records and respond faster.
5. Establish information-sharing channels before a case becomes urgent
Secure communication should not begin only after suspicious activity has been discovered.
Authorities and private-sector organizations need bilateral channels and public-private partnerships for sharing case information, emerging typologies, and changes in terrorist financing methods.
Data-preservation procedures are equally important. Messages, posts, accounts, and wallet addresses may be deleted or replaced quickly. Delayed requests can mean losing the context needed to understand the financial activity.
All information sharing must follow applicable laws, data-protection requirements, privacy safeguards, and international humanitarian law.
6. Clarify responsibility and keep risk assessments current
The regulatory position of an SMSP depends on the financial function it performs.
A platform that only provides an interface for a regulated third-party payment provider may have different responsibilities from one that directly controls payments, custody, transfers, or virtual asset services.
Authorities should continue assessing which platform functions trigger AML/CFT obligations. Financial institutions and platforms should also update their risk assessments as payment features, monetization tools, encrypted communications, DeFi, and virtual asset integrations change.
Training, international cooperation, and access to electronic evidence must develop alongside those services.
The operational lesson is clear. Detecting terrorist financing through social media requires more than another set of transaction-monitoring rules. Teams need to connect platform signals, financial activity, and investigative context while there is still time to act.
Deconflict’s verified intelligence can add confirmed investigative context when an identifier has already surfaced through participating law enforcement agencies. It does not replace CDD, transaction monitoring, or institutional judgment. It helps teams understand which signals may warrant closer attention.
Read the full FATF paper to explore the findings and recommendations. To see how verified intelligence can add confirmed investigative context to your financial-crime workflows, request a demo or visit Deconflict.com