Coronial
VICcommunity

Finding into death of Hassan Khalif Shire Ali

Deceased

Sestilio Malaspina; Hassan Khalif Shire Ali

Demographics

male

Date of death

2018-11-09

Finding date

2021-06-28

Cause of death

Sestilio Malaspina: stab wound to the chest; Hassan Khalif Shire Ali: gunshot wound to the chest

AI-generated summary

A 74-year-old Italian-Australian, Sisto Malaspina, was fatally stabbed during a terrorist attack in Melbourne's CBD on 9 November 2018. Hassan Khalif Shire Ali, aged 30, detonated an improvised explosive device in his vehicle, then attacked multiple people with a knife, fatally injuring Sisto. Police shot Hassan, who died from his gunshot wound. The coronal investigation examined whether security and intelligence agencies could have prevented the attack. Key findings identified deficient SIU procedures between 2015-2018, including delayed CVE referral processes, incomplete ANZCTC threat assessments, and premature downgrading of Hassan's risk profile despite significant intelligence gaps. While opportunities to improve management existed, the evidence does not establish that Hassan's trajectory toward the attack would have been averted by timely intervention. The incident was classified as a premeditated ISIS-inspired terrorist act.

AI-generated summary and tagging — may contain inaccuracies; refer to original finding for legal purposes.

Contributing factors

  • deficient SIU Standard Operating Procedures
  • delayed CVE Unit referral
  • premature threat assessment downgrade
  • intelligence gaps in ANZCTC assessment
  • failure to communicate address information via LEAP flags
  • mental health issues including paranoia and psychological distress
  • ISIS-inspired extremist ideology
  • social isolation and relationship breakdown
  • financial difficulties and drug use
  • lack of automated task management systems

Coroner's recommendations

  1. Victoria Police review and amend SIU Standard Operating Procedures to: prescribe timeframes for task completion; ensure outstanding tasks reach Team Manager; establish mechanisms for regular file review regardless of threat level; specify when fresh ANZCTC assessments should occur; establish procedures for ASNET information circulation; create documented process for classified verbal information; establish CVE Unit referral process; implement senior management review before downgrading NSPOIs despite high ANZCTC ratings; establish expectations for partner agency consultation
  2. Victoria Police deliver training to all SIU staff about SOPs and procedures of CTC partners, particularly CVE Unit
  3. Victoria Police develop training and policy to ensure disputed address details are recorded on LEAP and easily accessible to members verifying identification
  4. Victoria Police review and amend policy on annotations to NSPOI and LEAP warning flags, including when and how to annotate flags to address specific intelligence gaps
  5. Victoria Police develop and implement review process following any actual or attempted terrorist incident to identify improvement opportunities in national security intelligence collation, analysis and assessment, and NSPOI management
  6. Victoria Police and national security intelligence partners develop joint review process following actual or attempted terrorist incidents to identify improvement opportunities
Full text

Related cases

Source and disclaimer

This page reproduces or summarises information from publicly available findings published by Australian coroners' courts. Coronial is an independent educational resource and is not affiliated with, endorsed by, or acting on behalf of any coronial court or government body.

Content may be incomplete, reformatted, or summarised. All court orders for redaction and non-publication are respected; documents with technically defective redaction have been excluded from the database entirely. Always refer to the original court publication for the authoritative record.

Copyright in original materials remains with the relevant government jurisdiction. AI-generated summaries and tagging are for educational purposes only, may contain inaccuracies, and must not be treated as legal documents. We welcome feedback for correction —