Anderson Fagundes da Silva, Director & Partner at NSA Global, considers the repercussions for corporate security after the US designation of Brazil’s largest criminal groups as terrorist organizations.
Article Chapters
ToggleThe recent decision by the US to designate Brazil’s two largest criminal organizations – the Primeiro Comando da Capital (PCC) and Comando Vermelho (CV) – as Foreign Terrorist Organizations (FTOs) and Specially Designated Global Terrorists (SDGTs) marks a significant shift in the international approach toward transnational organized crime.
Effective June 2026, the designation places both groups in the same legal framework previously reserved for organizations such as ISIS, Al-Qaeda, MS-13 and several major Mexican cartels.
While the political and diplomatic implications have generated considerable debate in Brazil, the corporate security implications may prove even more significant.
For multinational corporations, financial institutions, logistics operators, critical infrastructure providers and global supply chains, this designation introduces a new risk landscape that extends far beyond traditional crime prevention.
From the US government’s perspective, the designation is not based solely on drug trafficking.
It reflects a broader assessment that these organizations have evolved into sophisticated transnational criminal enterprises capable of threatening regional stability, influencing governments, controlling territory, conducting large-scale money laundering, facilitating arms trafficking and operating across multiple countries.
Over the last decade, both PCC and CV expanded their operational footprint beyond Brazil, establishing connections throughout South America, Europe and other international markets.
Their activities increasingly resemble those of hybrid threat actors, combining criminal, economic and political influence mechanisms.
The designation also aligns with a broader US strategy initiated in 2025 through Executive Order 14157, which expanded the use of terrorism-related authorities against transnational criminal organizations and cartels considered threats to US national security.
For many organizations operating in Latin America, the immediate reaction may be to view the designation as primarily a governmental or law enforcement issue. That would be a mistake.
The FTO designation fundamentally changes the legal and compliance environment surrounding any direct or indirect interaction with PCC or CV-controlled ecosystems.
Under US counterterrorism regulations, providing material support to an FTO can trigger severe criminal, civil, regulatory and financial consequences.
Material support is broadly interpreted and can include financial transactions, logistical services, transportation arrangements, contracting relationships, security payments, facilitation activities and other forms of assistance.
As a result, organizations may now face heightened scrutiny regarding:
• Third-party relationships
• Supply chain integrity
• Vendor management
• Financial transactions
• Real estate operations
• Cash-intensive business activities
• Community engagement programs in high-risk territories
The challenge becomes particularly acute in regions where criminal organizations exert de facto control over neighborhoods, transportation routes, informal labor markets, utilities or local commercial ecosystems.
Historically, corporate security teams focused on physical threats such as cargo theft, extortion, kidnapping, workplace violence and fraud.
Following the FTO designation, organizations must increasingly integrate security and compliance functions. This means that corporate security leaders will need to work more closely with:
• Legal departments
• Anti-money laundering (AML) teams
• Ethics and compliance functions
• Internal audit
• Enterprise risk management
• Procurement and supply chain teams
The objective is no longer limited to preventing criminal losses. Organizations must also demonstrate that they have implemented reasonable controls to prevent inadvertent support to designated entities.
For multinational corporations subject to US jurisdiction, the stakes are particularly high.
1. Enhanced Third-Party Due Diligence – Organizations should immediately reassess third-party risk management frameworks. Vendors, subcontractors, transportation providers, security companies, labor suppliers and local partners operating in high-risk geographies require enhanced screening and continuous monitoring. Traditional financial integrity checks may no longer be sufficient.
2. Supply Chain Risk Mapping – Supply chain visibility becomes critical. Companies should identify areas where criminal organizations may influence logistics corridors, ports, warehouses, fuel distribution, cargo transportation or local distribution networks. The objective is to understand not only operational risk but also exposure to potential sanctions-related liabilities.
3. Intelligence and Threat Monitoring – Corporate intelligence capabilities must evolve. Monitoring should include: criminal convergence trends, organized crime infiltration, money laundering indicators, terrorism-financing red flags and regional political and regulatory developments. Security teams should establish stronger links with public-sector intelligence partners and industry information-sharing networks
4. Physical Security and Critical Infrastructure Protection – Organizations operating in sectors such as logistics, mining, energy, telecommunications, banking and agribusiness should reassess threat models. The designation may increase law enforcement pressure on criminal groups, potentially leading to shifts in criminal behavior, retaliatory violence, territorial disputes, and greater operational volatility in affected regions
5. Crisis Management and Executive Protection – Executives and corporate assets operating in high-risk regions may face evolving threat dynamics. Crisis management plans should be reviewed to address scenarios involving organized crime disruption, regulatory investigations, sanctions-related incidents, supply chain interruptions and reputational crises. Security leaders should ensure that escalation protocols, incident response plans and executive protection programs reflect this new reality
Perhaps the most important implication of the PCC and CV designation is conceptual. For years, many organizations treated organized crime as a local security issue.
The US designation effectively reframes these groups as national security threats with global implications.
Whether one agrees or disagrees with the legal classification, the practical consequence is clear: the threshold for corporate risk management has changed.
Corporate security leaders can no longer evaluate criminal organizations solely through the lens of loss prevention or physical protection.
They must now consider sanctions exposure, regulatory enforcement, financial crime risks, geopolitical developments, and reputational consequences.
In many respects, this represents the convergence of corporate security, intelligence, compliance and enterprise risk management.
Organizations that adapt quickly will strengthen resilience and governance. Those that fail to recognize the significance of this shift may find themselves exposed not only to criminal threats but also to complex legal, regulatory and financial consequences that were previously outside the traditional scope of corporate security.
As Latin America continues to experience the globalization of organized crime, security leaders must prepare for a future in which the line between criminal risk and national security risk becomes increasingly blurred.
Anderson is Director & Partner at NSA Global and has more than 25 years of experience in corporate security, crisis management, investigations, business continuity, resilience and risk management. He is a former Military Police Officer of the Brazilian Army and has held senior security leadership positions across ports, logistics, manufacturing, technology and multinational organizations throughout Latin America. A lawyer and internationally recognized speaker, Anderson holds a Master’s degree in Risk, Crisis & Disaster Management from the University of Leicester (UK), is a Certified Business Continuity Professional (CBCP) and completed executive programs in National and International Security and Crisis Leadership at Harvard University. He is also a member of ASIS International, OSAC and the OECD Global Anti-Corruption & Integrity Forum.
This article was originally published in the July edition of Security Journal Americas. To read your FREE digital edition, click here.