European Intelligence Agencies Attribute Pan-Continental Sabotage Campaign to Russian Military Intelligence
Security services across Europe have formally linked a series of arson attacks, drone incursions, and surveillance operations targeting defense infrastructure to Russian military intelligence. The coordinated attribution follows the disruption of specific plots in Romania and Denmark, prompting widespread diplomatic expulsions.
- European Security Agencies
- View the campaign as a strategic escalation testing NATO's collective defense threshold.
- Strategic Analysts
- Focus on the shift from traditional espionage to proxy warfare and the resulting escalation risks.
- Russian State
- Denies involvement and frames European countermeasures as hostile provocations.
Perspectives this story doesn't cover
- Local proxy recruits
- Civilian infrastructure operators
Fast facts
- European intelligence agencies have formally linked a series of sabotage plots against defense infrastructure to Russian military intelligence.
- Romania's SRI detained a Russian citizen on Tuesday for surveilling NATO communications centers and Ukrainian cargo aircraft.
- Denmark's intelligence service warned that Russian operatives are actively recruiting citizens online to target defense companies.
- Hungary expelled 10 Russian diplomats on Tuesday for activities incompatible with their diplomatic status, prompting threats of retaliation from Moscow.
- The sabotage campaign relies heavily on recruited local proxies to maintain plausible deniability and avoid triggering a direct NATO military response.
Why this matters
The formal attribution of these attacks shifts the European response from localized criminal investigations to a continental defense posture. By relying on recruited proxies to target logistics hubs and defense contractors, Moscow is testing the threshold of NATO's collective defense commitments without triggering a direct military confrontation.
European defense contractors and military logistics hubs are operating under heightened security protocols this week after intelligence services across the continent formally attributed a wave of infrastructure sabotage to Russian military intelligence. The coordinated attribution moves a series of previously isolated arson attacks, drone incursions, and surveillance arrests into a unified framework of state-sponsored hybrid warfare directed by Moscow.[1][3]
The shift in posture follows the disruption of multiple active plots in early September 2026. On Tuesday, Romania's domestic intelligence service, the SRI, announced the detention of a Russian citizen who had been surveilling NATO communications centers and Ukrainian Antonov cargo aircraft on Romanian territory since February. The SRI stated the suspect was instructed by an intermediary to capture "photo-video materials with targets of strategic military interest."[4]
The Romanian operation mirrors warnings issued days earlier by Denmark's Security and Intelligence Service (PET). Emil Gresholm, PET's head of counter-espionage, confirmed that Russian operatives are actively recruiting citizens through social media and gaming platforms to prepare for physical attacks against companies supplying military aid to Kyiv. Gresholm noted that Russia is "both planning and carrying out acts of sabotage against defence companies and the defence industry in Europe."[2]
The tactical shift relies heavily on proxy actors rather than traditional intelligence officers operating under diplomatic cover. Following the expulsion of more than 700 Russian diplomats from European capitals since 2022, Moscow's military intelligence directorate, the GRU, has increasingly outsourced physical sabotage to local criminal networks and vulnerable individuals recruited online.[1][3]
The tactical shift relies heavily on proxy actors rather than traditional intelligence officers operating under diplomatic cover.
This proxy strategy is designed to maintain plausible deniability while stressing European investigative resources. Recruits are often paid small sums—sometimes just 2,000 to 3,000 euros—to execute high-risk operations, such as the August 5 drone attack targeting a Ukrainian An-124 cargo plane at Germany's Leipzig/Halle Airport, which Berlin formally attributed to Russian state actors.[1][4]
The diplomatic fallout is accelerating alongside the physical security measures. On Tuesday, Hungary—a state that had previously maintained warmer relations with Moscow during former Prime Minister Viktor Orban's 16 years in power—ordered the expulsion of 10 Russian diplomats. Hungarian Foreign Minister Anita Orban cited activities "unacceptable for diplomats under the Vienna Convention," prompting Russian Foreign Ministry spokeswoman Maria Zakharova to promise a "harsh and painful" response.[5]
The reliance on local proxies lowers the operational barrier for attacks but increases the risk of miscalculation. Western intelligence officials note that while the campaign aims to disrupt supply lines and degrade public support for Ukraine, the use of untrained operatives raises the probability of mass-casualty events, such as the disrupted mid-2026 plot to place incendiary devices on cargo aircraft.[1][3]
The European Union is now drafting joint defense initiatives to counter the campaign, including a proposed anti-drone shield and enhanced intelligence-sharing protocols. The immediate challenge for the 32 NATO member states is defining the threshold at which a proxy sabotage campaign crosses from a law enforcement issue into an armed attack requiring a collective military response.[1][2]
Sources
[1]CEPAStrategic AnalystsNo Magic Bullet to End Russian Sabotage
Read on CEPA →
[2]London Business NewsEuropean Security AgenciesDanish intelligence warns Russia is 'preparing sabotage' attacks on NATO soil
Read on London Business News →
[3]TVC NewsStrategic AnalystsRussia Intensifies Sabotage Campaign Across Europe – Report
Read on TVC News →
[4]TVP WorldEuropean Security AgenciesRomanian intelligence agency says it foiled Russian sabotage plot
Read on TVP World →
[5]The Moscow TimesRussian StateHungary Expels 10 Russian Diplomats for 'Unacceptable Activities'
Read on The Moscow Times →
Comments
More in Defense & Security
See all →Nuclear Command
Securing the U.S. Nuclear Arsenal: The Cryptographic Chain From Presidential Order to Warhead Unlock
6 sources
Intelligence Tradecraft
Overcoming Confirmation Bias: How the Analysis of Competing Hypotheses Structures Intelligence Evaluation
6 sources
Yemen Conflict
Houthi Attacks Ignite Fires at Saudi Oil Facilities, Shattering Four-Year Truce
3 sources
Nuclear Strategy
The Five Phases of OPLAN 8010: How the U.S. Nuclear War Plan Defines Target Categories and Execution Options
5 sources
Every angle. Every day.
Get Defense & Security stories with full source coverage and perspective breakdowns delivered to your inbox.




