← Back to News

The Overseas Risk Nobody's Tracking: 30 Days of Real Incidents Near the World's Business Hubs

15 September 2026

The Risk

Most corporate duty-of-care programmes — and the close protection teams tasked with actually executing them on the ground — assess risk at the country level: a single traffic-light score covering an entire nation, updated infrequently, often bought in from a third party with no visibility into what's actually happening this week. That's a blind spot by design: a "medium risk" country rating tells a principal's advance team nothing about whether the specific city block their office sits in, or the district their principal is staying in, has had six violent incidents in the last month or zero. Organisations and the CP teams working for them act on the score they have, not the risk that's actually there, and usually only discover the gap after an incident has already touched the people they're responsible for.

The Numbers

We pointed our own platform at seven major international business and expat hubs — the kind of cities organisations post staff to routinely — and pulled every real, geolocated security incident within 30km of each city centre over the last 30 days: dark web chatter, local news reporting, and structured conflict data, automatically classified by type.

Across those seven cities alone:

  • 15 terrorism-tagged incidents
  • 14 armed conflict events
  • 69 violence-tagged incidents
  • Further incidents flagged for civil unrest and public disorder, not counted above

Broken down by city:

  • Lagos: 11 violent, 6 terrorism-tagged, 1 armed conflict
  • Nairobi: 14 violent, 5 terrorism-tagged, 1 armed conflict
  • Mumbai: 20 violent, 3 terrorism-tagged, 1 armed conflict
  • Johannesburg: 17 violence-tagged incidents
  • Dubai: 7 armed conflict, 3 violence-tagged
  • Mexico City: 1 incident, tagged terrorism, conflict and violence simultaneously
  • Manila: 3 armed conflict, 3 violence-tagged

That's a live, 30-day snapshot from ongoing collection — not a backward-looking annual report, and not a single-country headline story.

The Threat Actors

A count is only half the picture. Fenestra's threat actor registry lets us name who's actually driving the risk in each region, and what they actually do, not just tally incidents.

Al-Shabaab (Nairobi). The Al-Qaeda-affiliated group based in Somalia is also active across Kenya, Ethiopia, Djibouti and Uganda. It's the group behind Nairobi's most infamous attacks (Westgate, 2013; the DusitD2 hotel complex, 2019), and our collection is still surfacing its aftermath in the city today — a mall-attack survivor's story appeared in our Nairobi feed in just the last week. Fenestra's registry links the group to 6,165 recorded conflict events and over 40,000 associated deaths regionally — overwhelmingly against the Somali state (5,084 events), but the Government of Kenya shows up too, in 301 recorded events, which is exactly why Nairobi stays in scope.

Known TTPs (from our own recorded event data):

  • Bombings and grenade attacks
  • Ambushes and sieges
  • IEDs and landmines
  • Suicide bombings
  • Mortar attacks and raids
  • One-sided violence against civilians (629 recorded events, alongside its fight against state forces)

Lagos. No single group sits behind this month's numbers — the real driver is a wave of kidnapping-for-ransom gangs and violent street crime, not an insurgency. Nigeria's best-known non-state armed group, ISWAP, operates 1,000km away in the Lake Chad Basin, nowhere near Lagos - a country-level view ("Nigeria: elevated terrorism risk") would point straight at ISWAP and miss the real picture entirely. One thread is worth naming, though: one of this month's incidents was a fatal attack by "suspected cultists" on a security guard. Nigeria's campus-cult-turned-organised- crime networks are real and, in one case, large enough to have their own Fenestra registry entry: Black Axe (Neo-Black Movement of Africa), founded in 1977, now a transnational criminal organisation estimated at 30,000+ members across dozens of countries, targeted by a 2024 INTERPOL operation that arrested 300 suspects in 21 countries. We can't confirm this specific incident was Black Axe-linked - Fenestra's own data on the group is overwhelmingly Nigeria-based generally, not tied to this specific case - but it's the organisation Nigerian "cult violence" headlines are, more often than not, describing:

  • Extortion and cult-initiation violence
  • Gang-style shootings
  • Increasingly cyber-enabled: business email compromise (BEC) fraud, romance scams, money laundering

Lashkar-e-Taiba (Mumbai). The group behind the 2008 Mumbai attacks resurfaced in our Mumbai collection this month too — an Indian anti-terror court issuing a fresh warrant against its founder, Hafiz Saeed. Not a new attack, but a live reminder that the legal and security apparatus around a known group never fully stands down. Fenestra's registry records 12 recorded conflict events linked to the group, all classified as one-sided violence against civilians in India, with 292 total recorded deaths.

Johannesburg. No group claimed responsibility for this month's violence, and none is named in Fenestra's registry for it - but two real threads stand out. A Nigerian bishop was shot and killed in the city this month, sparking community demands for justice. Separately, gang violence in the Westbury suburb escalated sharply, with two more people killed mid-month on top of an already elevated toll. Neither is tied to a named organisation yet - a reminder that a serious, real security incident doesn't always arrive with a threat-actor label attached, and travel/CP teams need visibility into the raw pattern, not just registry hits.

Mexico City. This month's incident was a targeted, multi-victim killing of a local musician and his family. Two named individuals have since been charged; no organised group has been publicly attributed, and none is named in Fenestra's registry for it. Not every violent incident traces back to a "threat actor" in the conventional sense.

Dubai — a different shape of risk. Not a non-state group, but direct state-on-state friction. This month's real activity near Dubai:

  • Iran and the US/Gulf states trading attacks on shipping around the Strait of Hormuz
  • UAE forces intercepting an Iranian drone over its own territorial waters
  • Iran striking a US-linked air base in the UAE with drones, per its own state media

Manila. The clearest signal this month wasn't a non-state group either: real reporting covered the Philippines training to use BrahMos missiles specifically against "Chinese naval targets," against the backdrop of the wider South China Sea standoff. Like Dubai, the real risk here is state-level friction, not an organised non-state actor - and like Mexico City and Johannesburg, we won't force one onto the data where it doesn't belong.

The Fix

  • Don't rely on a single country-level score. Real risk varies by city, by district, and by week — a national rating averages all of that away.
  • Ground travel and site risk in continuously updated, geolocated data, not an annual or quarterly refresh.
  • Name the actor when you can. "Nigeria: elevated terrorism risk" tells you far less than knowing ISWAP operates 1,000km from Lagos while the city's real exposure is kidnapping gangs — attribution changes what you actually plan for.
  • Check the corridor, not just the destination. The incidents that matter to a travelling principal or a posted employee aren't only at the pin on the map — they're along the route.
  • Monitoring should continue for the life of a posting or a trip, not stop once a decision to travel or relocate has already been made.

This is exactly what Fenestra TI's geospatial intelligence is built to do — continuous monitoring around your offices, sites, travelling staff and protected principals, and our Itinerary Threat Monitoring capability checks every leg of a route against our own live data before anyone boards a flight or a principal moves, not a static score set once at booking.

Whether you're running a corporate duty-of-care programme or a close protection detail, get in touch if your people are overseas and you'd like to see what real, continuous geospatial visibility looks like.

⚙