Inside Palestine Action: Workshops, Sabotage and Security Breaches
Today I want to discuss a specific group of threat actors who continue to operate all over the UK and beyond and were given an official terrorist label in 2025.
I want to do a dive into Palestine Action because of their previous attacks as well as their ability, despite the terrorist label, to continue to operate in plain sight.
Since forming in 2020, the group has built its campaign around forced entry, occupation and deliberate damage at defence companies and other organisations it connects to Israel. Its members have breached factory compounds, smashed technical equipment, sprayed buildings and machinery with red paint, blocked production and published recordings of the resulting damage.
The organisation now promotes direct-action workshops for prospective supporters. Its public advertising tells participants they can learn how to help “Shut Elbit Down,” while separate promotional material has used the phrase “workout with a hammer” and encouraged supporters to attend direct-action training.
Three operations show how the campaign developed: the June 2024 attack on Instro Precision in Kent, the August 2024 raid on Elbit Systems UK near Bristol and the June 2025 penetration of RAF Brize Norton.
A warning that some of the videos in this article contain violent imagery
The Actors
Palestine Action was founded in Britain in 2020 by Huda Ammori and Richard Barnard.
Its members have occupied roofs, chained themselves to gates, entered buildings and damaged machinery. The group’s operations have generally been carried out by small teams wearing recognisable red clothing and carrying basic tools such as crowbars, hammers, paint-delivery devices and lock-on equipment.
The British government proscribed Palestine Action under the Terrorism Act 2000 in July 2025. The decision followed a longer campaign of criminal damage and came shortly after the breach at RAF Brize Norton.
In June 2026, the Court of Appeal upheld the proscription after an earlier court ruling had found the decision unlawful. Palestine Action therefore remains proscribed in the United Kingdom as of July 2026.
When reading each of these cases, really think about what specific security failures occurred and how you would go about fixing them.
From an auditing perspective, which vulnerability would you rate as a top priority to remove the viability of the attack route that was used to gain entry in each attack.
Example One: Instro Precision in Kent
The Target
Instro Precision operates at Discovery Park in Sandwich, Kent.
The company produces electro-optical and night-vision equipment. It was owned by Elbit Systems UK at the time of the June 2024 incident and had already been the target of repeated Palestine Action demonstrations and blockades. The company said its work supported the British armed forces, including the British Army.
Palestine Action accused the site of producing targeting technology connected to the Israeli military. Instro Precision and Elbit have disputed or qualified several claims made by activists about how their British operations support Israel.
The Attack
During the early hours of 17 June 2024, seven activists entered the Instro Precision facility.
According to police reporting and subsequent court coverage, the group filmed itself inside the site, damaged equipment, threw stock onto the floor, smashed computers with a crowbar and covered areas with red paint. The intruders then barricaded doors and waited for police.
The alleged damage was later estimated at approximately £1 million, although that figure formed part of an ongoing criminal case and should be treated as a prosecution claim rather than a final judicial finding. Defendants faced allegations including criminal damage, aggravated burglary and violent disorder.
Two additional men were arrested in August 2024 on suspicion of conspiracy to commit aggravated burglary and participating in the activities of an organised crime group. Kent Police said ten arrests had been made in total by that stage.
The case remained before the courts during later government and parliamentary discussions about Palestine Action. Ministers specifically avoided commenting on detailed allegations because the proceedings were sub judice.
How many vulnerabilities did you count, and which would you list as a top priority for remediation?
Example Two: Elbit Systems Near Bristol
The Target
The second operation took place on 6 August 2024 at an Elbit Systems UK facility at Aztec West, in Filton near Bristol.
Unlike the Kent intrusion, this operation began with a deliberate vehicle breach and escalated into direct violence against responders.
The site was part of Elbit’s British defence business. Palestine Action selected it as a high-value target and organised a team equipped to force entry and cause substantial damage once inside.
The Attack
Six activists arrived in a decommissioned prison van.
Prosecutors said the van was driven through the facility’s security perimeter, effectively functioning as a battering ram. The group entered wearing red boiler suits and carrying sledgehammers, crowbars and paint equipment.
Once inside, members of the team struck computers and other equipment and spread red paint throughout the facility. Prosecutors described the operation as meticulously organised and designed to cause maximum damage. The resulting loss was estimated at more than £1 million.
The use of an old prison van added a practical layer of cover. It was a heavy vehicle capable of defeating a gate, but it also resembled an official custodial vehicle. That appearance may not have defeated scrutiny on its own, but it was less conspicuous than an improvised armoured vehicle arriving at a business park.
Once the vehicle was committed to the gate, the operation changed immediately from covert approach to rapid forced entry. The attackers were relying on speed. They had to cross the compound, reach the building and begin destroying equipment before police could assemble an effective response.
How many vulnerabilities did you count, and which would you list as a top priority for remediation?
The Assault on Police Sergeant Kate Evans
Police Sergeant Kate Evans responded to the intrusion.
During the confrontation inside the facility, activist Samuel Corner struck Evans twice in the back with a seven-pound sledgehammer. The blows fractured her spine.
Evans was a police officer, not a private security guard. Court reporting said the injury prevented her from returning to full duties and had a continuing physical and psychological effect.
Example Three: RAF Brize Norton
The Target
RAF Brize Norton in Oxfordshire is the Royal Air Force’s principal air-transport base and home to the Voyager tanker fleet.
The station supports air-to-air refuelling, strategic transport and government travel. It is a large operational site containing high-value military aircraft and thousands of military personnel, civilian staff and contractors.
On 20 June 2025, Palestine Action announced that two of its activists had entered the base and damaged two Voyager aircraft.
The Attack
Video released by the group showed two people moving through the airfield on electric scooters.
The activists reached the aircraft, sprayed red paint into or around the engines using modified fire extinguishers and struck parts of the aircraft with crowbars. They also painted sections of the runway and left a Palestinian flag before departing.
Most strikingly, the intruders appear to have left the base without being detained at the scene.
Paint or other material introduced into an engine area cannot simply be wiped away before the aircraft returns to service. Technicians have to determine where the substance travelled, whether components were damaged and whether the aircraft can fly safely.
Early court reporting placed the alleged damage at approximately £7 million. More recent proceedings have referred to an allegation of approximately £15 million.
How many vulnerabilities did you count, and which would you list as a top priority for remediation?
The Workshops
This part really is interesting, as a group with an official terrorist designation is opening promoting such activities on their website, even hosting “workshops.”
The public workshop page (i wont be linking to) says the sessions cover direct-action theory, Western complicity and a legal overview.
Separate promotional posts indexed in search results advertise the workshops using the words “workout with a hammer” and “direct action training available.”
Another associated action guide goes further. It tells supporters to pick up “a hammer, crowbar, lock-on or bucket of paint” and take direct action, while directing them toward training and demonstration material.
Crowbars were used in Kent. Sledgehammers and crowbars were carried into the Bristol facility. A sledgehammer was then used against Sergeant Evans. Crowbars and paint equipment were used against aircraft at Brize Norton.
Previous reporting on Palestine Action training material described advice about forming small cells, using burner phones, paying cash for equipment, conducting reconnaissance and purchasing items including sledgehammers.
The Home Office also alleged that Palestine Action prepared supporters for covert operations and encouraged cells to disrupt, damage or destroy selected targets. Those claims formed part of the government’s proscription case and were later examined during litigation over the ban.
The workshops sit inside a movement with an established pattern of recruiting people, selecting facilities, breaching perimeters and destroying property.
Conclusion
None of these attacks required James Bond levels of training or skill, but simply a willingness for destruction and mayhem.
For security personnel, each of these cases should be used as training and thought experiments for how to better secure your own facilities. By understanding how threat actors will infiltrate a target building you can put defenses in place beforehand to counter them.
Further, understand these actors motives, and specifically what they wanted to accomplish once inside. “The server room” was never on their list of targets, so when you are considering what may or may not be in the crosshairs of a bad guy, remember it may not be what you think.
Training Resources:
For individuals looking for a hands on training that includes all of the above topics, Covert Access Team (covertaccessteam.com) provides training courses focused on physical penetration testing, lockpicking, bypassing techniques, social engineering and other essential skills.
Covert Access Training - 5 day hands on course designed to train individuals and groups to become Covert Entry Specialists
Physical Audit Training - 2 day course on how to setup and run a physical security audit
Elicitation Toolbox Course - 2 day course of that primarily focuses on elicitation and social engineering as critical aspects of Black Teaming
Strategic Operations for Lone Operators - Advanced course for those who are interested in learning how to become a one man infiltration team.
Counter Elicitation - 2 day course on how to recognize and prevent elicitation attempts, and safegaurd your secrets.
Cyber Bootcamp for Black Teams - 2 day course designed explicitly for physical penetration testers who need vital cyber skills to add to their toolbox.
Private Instruction - Focused learning & training based on your needs .









