Definitional Frameworks for Nihilistic Violent Extremism

Definitional Frameworks for Nihilistic Violent Extremism
15 September 2026 GIFCT Team
In News

This insight was written by GIFCT Trust and Safety Solutions Associate Jessa Mellea and GIFCT Membership Engagement Associate Charley G. 

Introduction

Nihilistic Violent Extremism (NVE) is a hotly debated topic within counterterrorism, preventing and countering violent extremism (PCVE), and trust and safety spaces, in terms of both academic definitions and practical applications. As an emerging and evolving hybrid-threat area, there has been significant debate on whether and how counterterrorism frameworks should tackle NVE threats. 

As part of the Terrorism and Social Media (TASM) conference, convened by the Cyber Threats Research Centre at Swansea University in June 2026, GIFCT convened a multi-stakeholder workshop to better navigate applying definitional frameworks to NVE attacks. This blog post outlines key highlights and outcomes of the TASM workshop, presents some recommendations to consider when tackling NVE, and underscores GIFCT’s work to date on this issue. 

TASM Session and Outcomes

The session, hosted by GIFCT, was designed to help participants analyze, identify, and characterize signals and behavior with the goal of creating definitions that could be applied for counterterrorism or PCVE activities. To develop definitional frameworks, participants were guided through a three-part, progressive exercise. A selection of attack case studies, with publicly available details about the attacks, perpetrators, and any relevant online content, were presented to participants. These cases were chosen to include attacks that have been designated as NVE by various stakeholders, as well as attacks where categorization has been contentious. 

In small groups, participants discussed these case studies and were tasked with creating clusters of similar attackers. Groups considered grievances and goals expressed by the attackers, targets of the attack, and various definitions of “ideology” and “terrorism.” Next, groups identified the common themes of each cluster to delineate dividing lines. Finally, participants collaboratively worked to draft definitions for the clusters they had identified, including their core motivation or organizing principles, distinguishing characteristics of their activities, and key identifiers used by the group, such as symbols or other aesthetics.

Purpose of Definitional Frameworks

Across the board, participants stressed that creating definitional frameworks was key to a range of counterterrorism and PCVE activities. Having a clear understanding of how terrorists and violent extremists operate online aids in investigations, including those for governments monitoring potential attack perpetrators, researchers aiming to understand novel threats, and tech platforms that are enforcing content moderation strategies. While some cases may not fit within the legal frameworks used for counterterrorism investigations or prosecution, they may nevertheless benefit from primary prevention programs or rehabilitation services. Programs that allow individuals to channel grievances, regardless of whether they are sociopolitical, personal, or a mix thereof, into prosocial actions can benefit a wide swath of individuals. Many underlying needs, such as a need for community, purpose, or psychological support, that may push individuals to engage with violent extremist movements are shared by individuals involved in similar but less ideological communities online, such as the glorification of school shooters—and can be served by similar interventions.  Definitions must be both mutually intelligible, to enable cross-sector analysis and evaluation, and adapted to organizations’ scope of work. Legally applicable definitions should also reflect existing definitions, policy frameworks, as well as domestic and international legal obligations.

Similarly, participants noted that definitional frameworks were vital after an attack to aid in legal processes, prosecutions, and criminal convictions. Even when an act of violence has not yet occurred, however, participants noted that definitional frameworks can aid those working in prevention and rehabilitation to better understand new networks and threat areas and better tailor services to those considered “at risk” of committing violence.

Core Components of Nihilistic Violent Extremism – Participant Findings

When determining which perpetrators and groups fit their understanding of NVE, participants identified a range of features that made NVE unique compared to other terrorist and violent extremist (TVE) ideologies. Below is a non-exhaustive list of some core features of NVE, as identified by the session participants. Many of these overlap with other violent extremist movements, underscoring the difficulty of distinguishing between groups.

  • Content signals: Many of these signals overlapped with other violent extremist movements, underscoring the difficulty of distinguishing between groups. Participants emphasized the culture of glorification, particularly through trendy forms of idolization like fan cams, as central to the NVE milieu.
    • Glorification: Idolization of past attackers, TVE networks, and perpetrators across the ideological spectrum was identified as a core part of NVE content.
    • Livestreaming: NVE attackers, in emulating white supremacist attacks, have shown distinct interest in livestreaming acts of violence and encouraging other users in NVE spaces to film and/or livestream their own criminal activity. 
    • Manifestos: NVE attackers typically document their personal and group grievances in short manifestos. These typically pay homage to previous attackers whom they consider “inspirational.” 
  • Behavioral signals: Participants identified a notable behavioral signal of NVE attacks as target choice. They posited that the target is often a key feature in determining if an attack could be described as terrorist or violent extremist broadly, or NVE more specifically. 
    • Choice of targets: schools and education centers were identified as primary targets for NVE attackers. Attacks that took place at public gatherings or offered chances for indiscriminate violence were also more likely to be classified as NVE. In defining the target choice, there was a need to understand: 
      • if the attack sought to target people indiscriminately; 
        • if there was any demographic (no matter how broad) choice in targeting;
      • if the attacker was familiar with the target location; 
        • if they had been to the location aside from as part of attack reconnaissance; 
      • if the attack sought to emulate or imitate a high-profile attack, e.g., a school shooting.
    • Clothing: NVE attackers have worn similar styles of clothing, typically referencing past attacks, including t-shirts with specific slogans, writing of attackers’ names on weapons, and use of specific symbols. 
  • Network signals: The broader behavior of the network was one of the areas where NVE diverged from other TVE movements, with the milieu’s involvement in other online harm types and crimes. 
    • Other online harms: Notably distinct from other TVE networks online, NVE networks show an equal interest in other online criminal activity including cybercrimes, extortion (including sextortion), and commission and distribution of child sexual abuse material (CSAM).

Moving Towards a Framework

Participants proposed a solution to the false dichotomy of “ideological” vs “non-ideological” debate present throughout much of the literature on NVE. They suggested that TVE attackers across ideologies are rarely, if ever, motivated by a single belief, and that NVE attackers are no different. Inasmuch, the group considered a spectrum-based approach to better understanding individual motivations versus group motivations and how these various grievances have impacted attack perpetrators. 

At one end of the spectrum are attack perpetrators driven entirely by personal grievances; while these perpetrators may have been influenced by TVE networks, their core motivators are highly personal, targets are selected and typically well known to the individual, and attacks are limited in scope. At the other end of the spectrum are attack perpetrators driven by group grievances. These perpetrators seek to instill fear in a wide proportion of the public, target indiscriminately, and can conduct much larger-scale attacks. They may not be part of a TVE group, rather they aim with their attack to create sociopolitical change that affects more than just their individual self. Notably, previous TVE attackers from a wide range of ideologies fall along various points on this spectrum—few mass attacks are solely personally or socio-politically motivated.

On this spectrum, NVE attackers have primarily fallen in the center, combining both personal and group grievances, with no specifically defined in-group versus out-group, but core beliefs of misanthropy that shape their worldview and lead to indiscriminate and larger-scale acts of violence. 

The use of a spectrum approach was considered beneficial in allowing various multi-stakeholder agencies to determine if perpetrators can be considered within their remit. For example, while some may be primarily focused on personal grievances and therefore fall outside of the scope of counterterrorism investigations, they may fall within the remit of prevention campaigns and rehabilitation organizations.  

In a different stream of discussion, participants stressed the ongoing need to analyze core components of attacks themselves (target choice, weapon choice, behaviors, clothing, etc.), particularly in cases when ideology is unclear. This second feature of analysis provided another axis for plotting attacks onto a matrix, rather than a spectrum.

Looking Ahead

Several key considerations in how to define and assess these threats going forward emerged through the discussion. Definitions of this phenomenon will have wide-reaching impacts, shaping research agendas, influencing tech platforms’ policies, determining what content should be removed from online sites, and determining the legal implications of involvement in these networks. Participants noted that the difficulty in creating definitions for NVE poses significant issues for governments attempting to address the phenomenon, as many governments use list-based approaches  (like sanctions designations) centered around concrete, relatively stable groups. 

While there is no universal definition of terrorism, there is convergence on many key elements of a definition. These are reflected in 19 international treaties and conventions, and in numerous UN Security Council resolutions, for example. Resolution 1566 (2004) in particular is often considered to be the closest to an internationally agreed definition. However, in the case of “violent extremism,” there is no comparable agreed language. Many governments do not have official definitions for the term, and there are contentious debates about risks posed by using the term “extremism” (without the precursor “violent” with critics stressing several human rights concerns. 

While existing sanctions and lists of designated individuals and groups have helped address some gaps left by definitional variations, they may not have the same utility in relation to the amorphous networks of NVE perpetrators. Definitions of NVE also differ from country to country, creating challenges for international, coordinated responses. While few governments have already created definitions of NVE, further collaboration is needed to align on a shared understanding to benefit mitigation efforts.

Crucial for analysis, participants emphasized that even though perpetrators’ reasoning behind their violence may not be immediately clear, it is crucial to avoid hasty categorization or even dismissal of cases as “non-ideological.” While an ideology may not seem coherent to outsiders, the attacker and other individuals in their network may see their beliefs as an entirely cohesive worldview. Further research and analysis are essential to thoroughly understand NVE as a phenomenon and determine how PCVE approaches may be suited to address the issue.

GIFCT’s Work

GIFCT was founded to address the exploitation of social media platforms by terrorist organizations as defined by the United Nations Security Council Resolution 1267 Sanctions List; this includes individuals and groups associated with Al-Qaida, ISIL, and listed affiliates. However, GIFCT has since evolved to better address the contemporary threat landscape, both online and offline, given the close relationships between the two. Through its work to foster a collaborative community of industry members; manage the hash-sharing database; respond to the online components of offline, global attacks through its Incident Response Framework; and support industry and multi-stakeholder partners adapt to evolving threats through its research arm, the Global Network on Extremism and Technology, GIFCT creates a unique space to develop and deploy innovative solutions as terrorism threats and trends evolve rapidly online. 

The Human Rights Impact Assessment, commissioned by GIFCT and its Operating Board early on to shape the evolving organization, offered  a variety of recommendations focused on bringing together a multi-stakeholder cohort to develop better definitional frameworks for terrorism and violent extremism. These were based on behavioral characteristics to ensure a more effective approach to limiting online harms. The workshop at TASM was developed to build on this process and further a multi-stakeholder dialogue to advance common understandings of evolving methods to address online TVE activity.

Incident Response

In developing the recently updated IRF, GIFCT focused on behavioral signals and deliberately did not list any specific ideologies, groups, motivations, etc. as part of its activation criteria. This ensures responses can remain adaptive to emerging and developing TVE threat areas, particularly in the context of time-sensitive incidents. 

Over the past years, GIFCT’s IRF has been activated in responses to a range of attacks with suspected or confirmed components of NVE ideologies, including attacks in Eskişehir, Türkiye; Nashville, Tennessee; Trescore Balneario, Italy, and more.

Hash-Sharing Database

GIFCT’s hash-sharing database (HSDB) is a cross-platform database that enables the sharing of “hashes” (or “digital fingerprints”) of known TVE content between member platforms in a secure, efficient, and privacy-protecting manner. The HSDB taxonomy, which serves as formal guidance for HSDB inclusion, is deliberately ideologically agnostic, allowing GIFCT to ingest hashes regardless of ideology, provided they meet the inclusion criteria. The inclusion criteria are based on behavioral indicators of TVE content, which allow adaptive and agile responses to a wide variety of threats. 

Notably, GIFCT has responded to numerous incidents relating to NVE attack perpetrators, and hashes relating to the Perpetrator Content Incidents (PCI) IRF activation type are ingested into the HSDB. While NVE “groups” or “movements” are not represented in international or multilateral frameworks, such as listings or sanctions designations, the HSDB taxonomy allows GIFCT and its members to share hashes of attack-related content following incident activations, which may include the live stream of murder or attempted murder produced by the attack’s perpetrator or an accomplice.

Multi-Stakeholder Initiatives

GIFCT’s Working Groups convene a multi-stakeholder cohort of experts to tackle emerging challenges and risk areas and innovate new solutions to address these threats. In 2025, GIFCT convened a Working Group on Addressing Youth Radicalization and Mobilization, with one of the Working Group outputs being a research paper exploring subcultures of nihilistic violence.

Further, in 2026, GIFCT has brought together a Gaming and Youth Working Group, building upon previous years’ findings to better understand the intersection of youth and gaming spheres in relation to terrorism and violent extremism — a focus highly relevant to any discussion on NVE. 

GIFCT’s research arm, the Global Network on Extremism and Technology (GNET), has a dedicated tag for all Insights on research relating to NVE, to better understand this phenomenon, and provide actionable recommendations to stakeholders in addressing NVE threats. 

GIFCT also recently launched its Definitions and Legislation Project—a resource for practitioners seeking to better understand how terrorism and violent extremism are defined and legislated globally. Given the lack of universally agreed definitions of terrorism and violent extremism, the project explores the complementary – and sometimes conflicting – nature of these frameworks, and highlights the risks that can arise when relying solely on designation lists. It also provides strategies to support tech companies working to identify and action TVE content on their platforms in a consistent and responsible way.

Why it Matters

As the threat landscape evolves and new definitions emerge to characterize hybrid harms, counterterrorism, PCVE, and trust and safety communities need frameworks flexible enough to account for new types of harm, yet structured enough to maintain a defined scope of work. The TASM workshop was a valuable step in that direction: by testing definitional thinking against real case studies with a range of stakeholders, participants emerged with a stronger common understanding that continues to inform GIFCT’s work.

GIFCT’s own tools reflect this same balance. Using a behavior-based approach, rather than one built solely around fixed ideologies or designated groups, allows tools like the IRF and HSDB to adapt as threats change, with iterative updates informed by both internal research and multi-stakeholder input. This approach is what allows GIFCT and its members to address incidents of NVE despite its ambiguous and hybrid nature: perpetrators may not fit neatly into existing ideological categories, but their behaviors and content may still be identified and actioned in line with GIFCT’s taxonomy.

Continued collaboration across sectors, paired with tools and taxonomies grounded in behavior and informed by collaborative feedback, will be essential as hybrid threats like NVE continue to redefine the threat landscape, ensuring that GIFCT and its members are able to respond quickly, effectively, and responsibly to online threats.