Skip to main content
All assessments
SM-2026-TA-120Threat level: High

Tren de Aragua Under Coordinated Regional Pressure

Simultaneous enforcement in Brazil and Colombia is degrading the network's leadership and logistics while confirming that its expansion now runs through alliances with established local criminal organisations.

Download full PDF
Cover of Tren de Aragua Under Coordinated Regional Pressure

Executive summary

Tren de Aragua, the criminal organisation that originated in Venezuela's Tocoron prison system, is under the most coordinated regional enforcement pressure it has faced. The Associated Press reported that Brazilian police arrested 25 people across five states in a crackdown on the group after it developed ties with Brazilian organised-crime groups, with evidence indicating the Venezuelan network had been supplying weapons. Separately, Colombian authorities announced the capture of a suspected Tren de Aragua leader as security cooperation with the United States deepened. The enforcement pattern reveals the group's actual operating model. Tren de Aragua has not expanded by transplanting Venezuelan cells into unfamiliar territory. It expands by attaching itself to established local organisations, contributing weapons, migrant-corridor control, extortion expertise, and human-trafficking logistics in exchange for territory, protection, and market access. Specialist research on the Roraima cell dismantled earlier in 2026 described exactly this alliance-based playbook, including weapons trafficking from the Venezuelan border into other parts of Brazil. Sentinel Meridian assesses that coordinated pressure will degrade specific cells, disrupt leadership continuity, and raise the group's operating costs, but will not dismantle the network within the forecast horizon. The alliance model is resilient precisely because local partners survive the removal of Venezuelan nodes, and because migration corridors and informal economies continue to supply recruits, victims, and revenue.

Risk profile (1-5)
Alliance-based expansion
5/5
Migrant extortion and exploitation
5/5
Cross-border weapons logistics
4/5
Displacement into new host countries
4/5
Leadership disruption from enforcement
4/5
Network-wide dismantlement
2/5

Relative severity of each factor across the 6-18 month forecast horizon. Network-wide dismantlement scores low because the alliance model survives cell-level losses.

Key judgments

  • Enforcement is now genuinely regional. Near-simultaneous action in Brazil and Colombia, alongside continued U.S. pressure, marks a shift from national responses to coordinated multi-country targeting.
  • The alliance model is the network's core adaptation. Partnering with entrenched local groups gives Tren de Aragua market access without the cost of contesting territory directly.
  • Weapons supply is a distinguishing contribution. Police allegations that the group fed arms to Brazilian partners indicate a logistics role that outlasts any single cell.
  • Leadership arrests degrade coordination but rarely end operations. Cell-level autonomy and franchise-style branding allow continuity under new local commanders.
  • Displacement is the most likely near-term effect. Pressure in Brazil and Colombia raises the probability of consolidation into Peru, Chile, Ecuador, and Caribbean transit nodes.
  • Extortion of migrants and small businesses, sexual exploitation, and contract violence remain the durable revenue base; these require little fixed infrastructure and recover quickly.
  • Politicisation of the group's name complicates analysis. Its brand is invoked in migration and security debates well beyond documented operational presence, and attribution should be treated carefully.
  • Cooperation depends on political alignment. Changes of government, or friction over U.S. security assistance, could reduce the intelligence sharing this campaign relies on.

The full assessment, including sourcing, analytic confidence statements, and indicators and warnings, is available in the downloadable PDF.

Download full PDF

Related assessments

SM-2026-TA-118Threat level: High

QTFY's IoT Obfuscation Network and Persistent PRC Cyber Access

U.S. authorities disrupted QScan and QTRouter, platforms attributed to the PRC-linked QTFY group that weaponized thousands of IoT devices and proxy systems to obscure cyber operations against government, defense, financial, academic, and critical-infrastructure targets.

  • Cybersecurity
  • Critical Infrastructure
  • China