FB-ISAO Current Threat Level
This threat level statement is current as of 21 August 2026.
Physical Threat Level Remains SEVERE
Cyber Threat Level Remains ELEVATED
Bottom Line Up Front (BLUF)
FB-ISAO assesses that the overall threat level remains Severe. The sustained and dynamic threat environment – shaped by election-related tensions, upcoming major faith-community observances, societal polarization, and ongoing cyber and physical security concerns – does not currently support an adjustment. Members should maintain appropriate protective, mitigation, response, and recovery measures based on local threat information, vulnerabilities, potential consequences, and available resources. FB-ISAO’s Operational Resilience and Cyber Threat Intelligence working groups will resume quarterly updates while maintaining regular monitoring and assessment. The next scheduled update is anticipated in mid-to-late December.
Important Note: The FB-ISAO threat level should be viewed as a strategic indicator, not a substitute for local assessment. Organizations should use it alongside local threat information, known vulnerabilities, potential consequences, and available resources to determine appropriate protective, mitigation, response, and recovery measures.
Executive Summary
FB-ISAO assesses that the current threat level (“Severe”) should remain unchanged. While no single new development presently warrants an increase to an imminent-threat (or “Critical”) level, the broader threat environment remains sustained, dynamic, and persistently concerning. Likewise, conditions that informed the prior assessment on 02 April 2026 (retained below) have not materially improved, and the available indicators do not support a downgrade (back to “Elevated”) at this time. Additionally, several near- and medium-term factors, including election-related tensions, major faith-community observances, heightened societal polarization, and continued cyber and physical security concerns support maintaining the current level.
FB-ISAO will continue to review the threat environment on a regular basis and may issue additional updates, bulletins, or alerts when specific developments, tactics, actors, or localized concerns require attention, even if the overarching threat level remains unchanged.
Sustained Increased Vigilance
The current environment is best framed as a sustained increased baseline, or “new normal,” requiring continued vigilance. In this context, “new normal” should be understood as normalization of increased risk, not normalization or cessation of vigilance. The threat environment continues to present credible, sustained concern for faith communities and related soft targets. Therefore, faith-based organizations should maintain heightened vigilance, including visible deterrence, disciplined access control, volunteer and security team readiness, incident reporting, law-enforcement coordination, phishing resistance, identity security, timely patching, and resilient backups.
Supporting Factors
The following factors support maintaining a severe threat level:
- Persistent elevated baseline: The threat environment remains sustained, dynamic, and elevated, with no clear indicator that underlying geopolitical, cyber, or physical security risks have materially diminished.
- Near- and medium-term risk factors: Election-related tensions, major faith-community observances, heightened societal polarization, and continued cyber and physical security concerns support maintaining the current level, such as:
- Persistent conflict with few prospects for sustained resolution of ongoing wars.
- Growing sectarian hostilities driving anti-Zionism, antisemitism, Islamaphobia, anti-Hindu and anti-Sikh sentiments, all of which have sparked actions against HOWs during 2026.
- Enduring occurrences of vandalism, arson, theft, and assaults at houses of worship throughout the country on pace or equal or exceed last year’s incident total.
Influencing Indicators
FB-ISAO continues to monitor indicators that could influence a shift in threat level, including, but not limited to:
- Elections and political tensions: Distrust, polarization, protest activity, extremist rhetoric, cyber activity, or disruption tied to election events or outcomes.
- Major faith-community observances: High Holidays, Christian holidays, end-of-year gatherings, and other large religious or community events that increase visibility and congregation density.
- Localized threats and grievances: Family disputes, targeted grievances, disruptive individuals, or community-specific tensions that may not be visible in national-level reporting.
- Societal volatility: Heightened polarization and social tensions may contribute to an increased likelihood of confrontational, disruptive, intimidating, near-violent conduct, or threatening behavior affecting faith communities, civic institutions, and public spaces.
- Cyber and critical infrastructure concerns: Ransomware, phishing, emerging tactics, member-specific vulnerabilities, and water-sector, industrial control system, or other critical infrastructure vulnerabilities that could indirectly affect communities and operations.
- Global instability: Geopolitical conflicts or tensions that may influence domestic threat narratives, grievances, or actor motivation.
Reminder: A SEVERE threat level is not intended to be sustained long-term. As such, FB-ISAO will continue its weekly internal assessments. However, as conditions are assessed to persist for the foreseeable future (through the end of the year), we are resuming a quarterly update cadence. The next published statement can be expected mid-December 2026, unless conditions warrant escalation, downgrade, or other interim communication.
FB-ISAO remains committed to an apolitical, intelligence-driven approach. During periods of heightened political and social tension, our assessments are grounded solely in observed threat indicators and operational risk considerations.
FB-ISAO’s Operational Resilience and Cyber Threat Intelligence working groups will continue to actively monitor a wide range of threat reporting and behavioral indicators affecting faith-based organizations. This includes evaluating both international and domestic developments and their localized impacts on people and places of faith.
OVERALL ASSESSMENT | 02 April 2026
We assess that, in light of all presently available indicators, the general threat of physical and cyber attacks against Houses of Worship in the United States is raised to SEVERE. We understand that individual Houses of Worship, given their faith, geographic location, socio-political/ethnic demographics, and degree of local tensions may not consider their threat as severe and should adjust their posture accordingly. Review our Threat Level Explainer.
-
- Physical threats are assessed as SEVERE, driven by credible indicators of hostile intent toward houses of worship, recent domestic attacks, and escalation linked to global conflicts involving Iran, Israel, and South Asia.
-
- Cyber threat levels remain ELEVATED, with increased hacktivist activity tied to geopolitical conflict; while no specific campaign against faith institutions is confirmed, symbolic and opportunistic targeting remains a concern.
-
- The threat environment is shaped by a convergence of global conflict, domestic polarization, and violent extremist rhetoric, increasing the likelihood of low‑warning, lone‑actor, or copycat incidents.
-
- FB‑ISAO strongly recommends sustained heightened vigilance and security measures, including coordination with law enforcement, updated emergency planning, access control, and proactive reporting of suspicious activity.
We recognize that the combination of global geopolitical tensions, combined with domestic unrest and persistent political polarization make it likely that the threat level will remain “Severe” for the foreseeable future. FB-ISAO will continue to closely monitor events and make appropriate revisions to this threat assessment as needed.
These assessments are supported by recent examples and documented threat reporting showing both direct risks to houses of worship and broader hostility toward religious communities, with confidence that continued physical events and incidents targeting houses of worship are highly likely.
- Confluence of domestic and global events.
- The current situation in the Middle East, Iran, Israel plus heightened tensions between Hindu and Sikh devotees in India.
- Normalization and violence surrounding antisemitism and Islamophobia.
- Polarization of U.S. politics, loss of center and mitosis toward fringe movements.
- Violent rhetoric on social media, on-line radicalization, rise of terrorist recruitment among radical left, right, accelerationist and nihilist organizations – all of which advocate violence as an acceptable tool of social, political and cultural change.
- Potential for cyber threat activity. The most concrete example is the suspected Iran‑linked attack of the Orthodox Jewish news site Yeshiva World News during the current Iran conflict, which temporarily took the site offline and aligns with U.S. DHS expectations that Iran‑aligned hacktivists would focus on low‑level web defacements and DDoS against symbolic targets such as religious and media outlets.
All member and partner organizations are advised to sustain enhanced security awareness and readiness measures, ensure incident response plans are current, and maintain close coordination with relevant law enforcement and information-sharing partners.
Regular updates are being shared in the Faith-Based Daily Awareness Post, shared via email and available on our blog.
Practical Security Recommendations for Houses of Worship
Houses of worship can reduce risk during the current threat environment and beyond by combining simple planning, trained people, and practical facility measures that preserve a welcoming atmosphere while making it harder for someone to do harm, easier for staff and volunteers to notice warning signs, and faster for the congregation to respond effectively if something happens.
- Appoint one person or a small team to coordinate safety and security decisions, training, and incident reporting.
- Coordinate with local law enforcement and emergency management, invite them for a site walk-through, and share basic facility information before a crisis.
- Complete a basic security self-assessment to identify gaps in access control, surveillance, children’s areas, opening and closing procedures, and special events.
- Build and practice a simple emergency plan that covers evacuation, lockdown, sheltering, medical emergencies, fire, severe weather, and hostile events.
- Train greeters and ushers to notice suspicious behavior, use non-confrontational techniques, and quickly escalate concerns.
- Strengthen entry control during services by limiting unlocked doors, monitoring main entrances, and keeping clear sightlines with lighting and trimmed landscaping.
- Report suspicious activity promptly so authorities can identify patterns and respond early.
DISCUSSION
Due to conflicts in the Middle East, Iran, and India, and increased polarization reflected in U.S. politics and social media for both religious and sectarian tensions, the potential exists to trigger a physical or cyber incident with little or no advance warning. Therefore, FB-ISAO assesses the current threat environment warrants an overall posture of SEVERE. This assessment is driven primarily by an increase in physical security concerns, including elevated reports of hostile activity and credible threats targeting houses of worship. While no direct cyber threats have been identified against the faith-based community, the rise in cyber activity across multiple sectors underscores a heightened risk landscape that could spillover, thus requiring increased vigilance.
ANALYSIS OF THE CURRENT PHYSICAL THREAT ENVIRONMENT
In light of all presently available indicators, we assess that the current physical threat level for the community of faith is SEVERE, indicating a high likelihood of targeted violence, disruptive activity, or hostile acts against religious facilities, gatherings, and affiliated individuals, including easily identifiable members of targeted religious faiths. This assessment reflects credible indicators of a high threat environment that is likely to continue for an extended period to include hostile intent, a sustained pattern of extremist interest in houses of worship, and a heightened security environment shaped by recent geopolitical escalation involving U.S. strikes on Iran.
While the current U.S.-Iran War is a significant driver in the recent increase in threats at home and abroad, recurring attacks in the U.S. and Canada on Hindu Temples and Sikh Gurdwaras reflect ongoing sectarian conflict in South Asia that has escalated from graffiti and vandalism to kidnap and murder.
Currently, the highest profile domestic incident is likely the March 12 ramming attack targeting Temple Israel in West Bloomfield Township, Michigan while dozens of children were learning inside the complex. The attack involved a truck laden with improved explosives and a gunman who exchanged fire with security personnel before dying of a self-inflicted wound. There were no other deaths. The attacker’s primary motivation appears to have been the death of multiple family members in a March 5 Israeli airstrike in Lebanon. Other attacks and potential attacks targeting synagogues have explicitly been linked to the war and threats to the Jewish community as a whole have increased dramatically since the start of the war.
Abroad, the group Harakat Ashab al Yamin al Islamia, which only began activities after the initial strikes on Iran, has claimed credit for six terror attacks across Europe, including a fire attack targeting four ambulances outside a Jewish community rescue service in London. Based on patterns of behavior from prior terror groups, it is likely some or all of the attacks were lone wolf incidents the group later took credit for.
ANALYSIS OF THE CURRENT CYBER THREAT ENVIRONMENT
Additionally, we assess that the current cyber threat level of the community of faith remains ELEVATED. While there is cyber activity associated with the conflict, reporting so far does not show a clear pattern of Iran‑attributed cyber attacks specifically targeting U.S. houses of worship or faith‑based organizations. Rather, reporting documents a surge in pro‑Iran and pro‑regime hacktivist operations – including DDoS (distributed denial of service), website defacements, and hack‑and‑leak activity – against Israeli and Western organizations framed in religious, symbolic, and ideological terms.
We continue to encourage preparedness and vigilance against routine threats and ongoing challenges such as ransomware, business email compromise, and scams. An organization’s public stance on various social and political topics could see it the target of hacktivists. Basic security measures including robust, unique passwords, and implementing multi-factor authentication (to include online meeting passcodes) significantly reduce the likelihood of a successful attack.
The TIG will continue to assess the Cyber Threat Level and provide updates accordingly. Likewise, the cyber threat landscape will be continuously monitored, but this Cyber Threat Level determination is valid until further notice.
Refer to the FB-ISAO Resource Library for resources related to:
- Securing Facilities and People
- Securing School Facilities and Students
- Protecting Digital Assets
- Protecting from Health Threats and Natural Hazards
- Informing Preparedness Activities
Additional Resilience Resource
Eight Recommendations for Jewish Communities (this resource is written by SCN for the Jewish Community, but the practices are appropriate for all communities of faith)
- Ensure awareness and coordination with law enforcement and/or security professionals servicing your community or region
- Extend the protections or security of your event’s/facility’s perimeter as far as possible
- Open events only to identifiable individuals and pre-screened invitation lists (e.g., no mass emails to the broad public)
- Require registration and verification of registrants for events open to the public
- Provide details of location, time, and other information only upon confirmed registration
- Allow access control (locks and entrance procedures) to known, confirmed registrants/attendees into the facility/event
- Remain vigilant and report suspicious activity
- Add armed on-duty or off-duty law enforcement, private security, and/or volunteer teams as additional layers of protection wherever possible