Observations from the Recent Assassination of Shinzo Abe

Japanese Security Services apprehending 41-year-old Tetsuya Yamagami, an ex-member of the Maritime Self-Defense Force, after shooting the former premier Shinzo Abe using a homemade improvised gun.

Two days before the Japanese parliamentary election, on July 8, 2022, former Prime Minister Shinzo Abe was assassinated by Tetsuya Yamagami. Despite Japan's stringent firearm regulations, the shooter managed to create a homemade firearm and assassinate Abe, described by Reuters as “the longest-serving leader in modern Japan” (Reuters, 2022). This tragedy illustrates that where evil exists, it will find a way.

What is particularly troubling, in addition to the loss of life, is that the shooter fired twice; the first shot missed. Abe’s security team failed to react adequately after the first shot, and 2.5 seconds later, the shooter fired again, fatally wounding the former Prime Minister.

The security team not only failed to respond according to established procedures for such incidents, but investigators later revealed that the assassin had conducted surveillance of Abe at an event just days earlier — and no one noticed. It is unclear whether it would have been possible to detect the assassin’s surveillance in the absence of obvious signs. However, the attack again demonstrated classic pre-attack indicators, including pre-attack surveillance, sector-specific incidents, and the acquisition of materials. While it is easy to judge in hindsight, those involved in protection, security, or enforcement should never become complacent. Whether operating in non-permissive environments, patrolling city streets, or managing a corporate security program, it is crucial to adhere to standard operating procedures, many of which have been developed from hard-learned lessons. One of these lessons is the importance of remaining vigilant and attentive to proven best practices that save lives.

The Office of the Director of National Intelligence (DNI), specifically the Joint Counterterrorism Assessment Team (JCAT), routinely provides valuable training and open-source information to help organizations prepare for security threats. Among their practical recommendations are several indicators that can signal suspicious activity. These indicators should be familiar to every security professional, as many lessons learned in challenging environments globally and domestically apply to various organizational threats (see indicator list below):

  • Eliciting Information

  • Testing of Security

  • Recruiting

  • Observation/Surveillance

  • Photography

  • Materials Acquisition/Storage

  • Acquisition of Expertise or Capability

  • Weapons Discovery

  • Sector-Specific Incidents

  • Breach/Attempted Intrusion

  • Misrepresentation

  • Theft/Loss/Diversion

  • Sabotage/Tampering/Vandalism

  • Cyber Attack

  • Expressed or Implied Threats

  • Aviation/Drone Activity

Because many of these indicators can be legal, the investigating entity, whether in the private sector or otherwise, must carefully document, verify, and compile data. Applying subject matter expertise transforms this data into actionable intelligence. While not all intelligence is actionable, recognizing and compiling indicators can provide a better understanding of a violent offender’s or organization's intentions before an attack occurs.

BY JOSIAH ONEIL

Josiah O'Neil, Founder and CEO of O'Neil Security Group, is a seasoned security expert with experience as a private contractor, Special Agent with the Diplomatic Security Service, and law enforcement officer in California. He also served in the military, honing his skills in combat operations, and now leads OSG, an all-source security solutions provider.


Previous
Previous

Schools Tighten Security, but Measures Vary Widely Across the U.S.