Skip to main content
Infrastructure SabotageSecurity Posture· 3 min read· in Defense & Security

European Intelligence Agencies Attribute Pan-Continental Sabotage Campaign to Russian Military Intelligence

Security services across Europe have formally linked a series of arson attacks, drone incursions, and surveillance operations targeting defense infrastructure to Russian military intelligence. The coordinated attribution follows the disruption of specific plots in Romania and Denmark, prompting widespread diplomatic expulsions.

By Miguel Carvalho

European Security Agencies 45%Strategic Analysts 35%Russian State 20%
European Security Agencies
View the campaign as a strategic escalation testing NATO's collective defense threshold.
Strategic Analysts
Focus on the shift from traditional espionage to proxy warfare and the resulting escalation risks.
Russian State
Denies involvement and frames European countermeasures as hostile provocations.

Perspectives this story doesn't cover

  • Local proxy recruits
  • Civilian infrastructure operators

Fast facts

  • European intelligence agencies have formally linked a series of sabotage plots against defense infrastructure to Russian military intelligence.
  • Romania's SRI detained a Russian citizen on Tuesday for surveilling NATO communications centers and Ukrainian cargo aircraft.
  • Denmark's intelligence service warned that Russian operatives are actively recruiting citizens online to target defense companies.
  • Hungary expelled 10 Russian diplomats on Tuesday for activities incompatible with their diplomatic status, prompting threats of retaliation from Moscow.
  • The sabotage campaign relies heavily on recruited local proxies to maintain plausible deniability and avoid triggering a direct NATO military response.

Why this matters

The formal attribution of these attacks shifts the European response from localized criminal investigations to a continental defense posture. By relying on recruited proxies to target logistics hubs and defense contractors, Moscow is testing the threshold of NATO's collective defense commitments without triggering a direct military confrontation.

European defense contractors and military logistics hubs are operating under heightened security protocols this week after intelligence services across the continent formally attributed a wave of infrastructure sabotage to Russian military intelligence. The coordinated attribution moves a series of previously isolated arson attacks, drone incursions, and surveillance arrests into a unified framework of state-sponsored hybrid warfare directed by Moscow.[1][3]

The shift in posture follows the disruption of multiple active plots in early September 2026. On Tuesday, Romania's domestic intelligence service, the SRI, announced the detention of a Russian citizen who had been surveilling NATO communications centers and Ukrainian Antonov cargo aircraft on Romanian territory since February. The SRI stated the suspect was instructed by an intermediary to capture "photo-video materials with targets of strategic military interest."[4]

The Romanian operation mirrors warnings issued days earlier by Denmark's Security and Intelligence Service (PET). Emil Gresholm, PET's head of counter-espionage, confirmed that Russian operatives are actively recruiting citizens through social media and gaming platforms to prepare for physical attacks against companies supplying military aid to Kyiv. Gresholm noted that Russia is "both planning and carrying out acts of sabotage against defence companies and the defence industry in Europe."[2]

The tactical shift relies heavily on proxy actors rather than traditional intelligence officers operating under diplomatic cover. Following the expulsion of more than 700 Russian diplomats from European capitals since 2022, Moscow's military intelligence directorate, the GRU, has increasingly outsourced physical sabotage to local criminal networks and vulnerable individuals recruited online.[1][3]

Recent intelligence disruptions and diplomatic expulsions linked to the Russian sabotage campaign.
The tactical shift relies heavily on proxy actors rather than traditional intelligence officers operating under diplomatic cover.

This proxy strategy is designed to maintain plausible deniability while stressing European investigative resources. Recruits are often paid small sums—sometimes just 2,000 to 3,000 euros—to execute high-risk operations, such as the August 5 drone attack targeting a Ukrainian An-124 cargo plane at Germany's Leipzig/Halle Airport, which Berlin formally attributed to Russian state actors.[1][4]

The diplomatic fallout is accelerating alongside the physical security measures. On Tuesday, Hungary—a state that had previously maintained warmer relations with Moscow during former Prime Minister Viktor Orban's 16 years in power—ordered the expulsion of 10 Russian diplomats. Hungarian Foreign Minister Anita Orban cited activities "unacceptable for diplomats under the Vienna Convention," prompting Russian Foreign Ministry spokeswoman Maria Zakharova to promise a "harsh and painful" response.[5]

Hungary ordered the expulsion of 10 Russian diplomats on Tuesday over activities incompatible with their status.

The reliance on local proxies lowers the operational barrier for attacks but increases the risk of miscalculation. Western intelligence officials note that while the campaign aims to disrupt supply lines and degrade public support for Ukraine, the use of untrained operatives raises the probability of mass-casualty events, such as the disrupted mid-2026 plot to place incendiary devices on cargo aircraft.[1][3]

The European Union is now drafting joint defense initiatives to counter the campaign, including a proposed anti-drone shield and enhanced intelligence-sharing protocols. The immediate challenge for the 32 NATO member states is defining the threshold at which a proxy sabotage campaign crosses from a law enforcement issue into an armed attack requiring a collective military response.[1][2]

Sources

Source coverage

5 outlets

3 viewpoints surfaced

European Security Agencies 45%Strategic Analysts 35%Russian State 20%
  1. [1]CEPAStrategic Analysts

    No Magic Bullet to End Russian Sabotage

    Read on CEPA
  2. [2]London Business NewsEuropean Security Agencies

    Danish intelligence warns Russia is 'preparing sabotage' attacks on NATO soil

    Read on London Business News
  3. [3]TVC NewsStrategic Analysts

    Russia Intensifies Sabotage Campaign Across Europe – Report

    Read on TVC News
  4. [4]TVP WorldEuropean Security Agencies

    Romanian intelligence agency says it foiled Russian sabotage plot

    Read on TVP World
  5. [5]The Moscow TimesRussian State

    Hungary Expels 10 Russian Diplomats for 'Unacceptable Activities'

    Read on The Moscow Times

Comments

Stay informed

Every angle. Every day.

Get Defense & Security stories with full source coverage and perspective breakdowns delivered to your inbox.