Arson, sabotage and 'disposable agents': How Russia is waging a covert war across Europe
How Russia is waging a sabotage war in the EU (RBC-Ukraine collage)
Russia is waging a sabotage campaign across Europe, targeting defense industry plants and logistics hubs. Yet despite the growing scale of these attacks, the official response has remained restrained.
Why has the Kremlin turned to large-scale sabotage? How does its system for remotely recruiting saboteurs work? And what can Europe learn from Ukraine's experience? Read the story by RBC-Ukraine.
Summer 2024. Ordinary-looking packages cross the borders of several countries, moving along Europe’s logistics routes. Inside are massage pillows and cosmetics — but they are deadly. Hidden inside are incendiary devices prepared by Russia’s GRU military intelligence service.
The packages later burst into flames almost simultaneously at warehouses and airport transit areas in Germany, the United Kingdom, and Poland. Only by sheer luck did the devices fail to detonate while the cargo was in the air — the consequences of such an attack would have been catastrophic for European aviation.
This GRU "parcel sabotage" operation is a revealing, but far from isolated, example of how Russia is waging a hybrid war against Europe while simultaneously pursuing its full-scale aggression against Ukraine.
According to an investigation by the VSquare center, the operation was coordinated by Andrei Baburov, a businessman from St. Petersburg. To carry out the mission, he remotely recruited former comrades from his days in the Soviet Navy, who had been legally living in the Baltic states in recent years.
Although some of the operatives were later arrested and the organizers, led by Baburov, were placed on an international wanted list, the case highlighted a new reality. Moscow is acting on an increasingly larger scale — and with growing audacity.
A series of arson attacks and acts of sabotage, combined with cyberattacks and repeated violations of NATO countries' airspace by Russian drones, is creating a fundamentally new challenge for Europe — one for which it has proved not fully prepared.
Industrial scale
Russian intelligence operations on European soil are nothing new. The Kremlin carried them out even in peacetime. The most notorious case remains the 2018 poisoning of Sergei and Yulia Skripal with Novichok in the United Kingdom. The attack was followed by a wave of expulsions of Russian diplomats-spies across almost the entire European Union.
After Russia launched its full-scale invasion of Ukraine, the activity of Russian intelligence services increased sharply. At first, Moscow relied primarily on espionage and cyberattacks. In April 2024, for example, the Czech government recorded thousands of attempts to hack the signaling systems of the country’s national railway. Similar attacks targeted logistics systems in Germany.
In 2025-2026, Russia’s subversive activity reached a new level and took on an “industrial” scale. Supply chains and European defense-industry companies have become the main targets.
Key Russian sabotage operations in Europe in 2024-2026 (RBC-Ukraine infographic)
In August alone this year, attempted acts of sabotage were reported at the facilities of Ukrainian drone developer Skyeton in Slovakia and Estonian company Milrem Robotics, which manufactures equipment for Ukraine's Armed Forces. Earlier, a wave of incidents hit BAE Systems plants in Wales, Diehl Metall in Germany, and WB Electronics in Poland. And these are only the most high-profile cases.
Dozens of other incidents with less visible consequences are being investigated as part of routine criminal proceedings. In Poland, for example, authorities are dealing with dozens of cases.
According to Przemyslaw Nowak, a spokesman for the Polish National Prosecutor's Office, who responded to an inquiry from RBC-Ukraine, the country's central prosecution system opened 67 criminal cases in 2025 under Article 130 of the Polish Criminal Code, which covers espionage and activities on behalf of a foreign intelligence service.
The trend has continued in 2026. In the first eight months of the year, law enforcement agencies opened at least 40 new proceedings. A simple extrapolation suggests that, at the current pace, 2026 could produce around 60 new cases — meaning the pace of recruitment and sabotage preparations is not slowing but remains consistently high despite public arrests and stronger counterintelligence measures.
A significant share of these cases involves preparations for sabotage, remote recruitment, and the collection of information about military facilities.

Criminal proceedings under Article 130 of the Polish Criminal Code (espionage and related crimes), 2025-2026 (RBC-Ukraine infographic)
Importantly, these figures cover only the most complex cases handled by the Polish National Prosecutor's Office. When investigations conducted by regional prosecutor's offices are included, the actual scale of Russian activity is even greater.
Still, the figures from Warsaw reflect only one dimension of the campaign. Most sabotage operations do not begin with an explosion or arson attack, but with lengthy preparatory work — gathering intelligence and surveilling targets — which Russian operatives organize as a cross-border relay among agents of different nationalities.
One case in Germany offers a clear example of this tactic. In December 2025, Ukrainian citizen Serhii N., who had been recruited by Russian intelligence, surveilled a German businessman supplying drones and components to Ukraine’s Armed Forces, filming his workplace. When Serhii N. traveled to Spain, the Russians did not abandon the operation. By March 2026 at the latest, surveillance had been taken over by Alla S., a Romanian citizen.
German Federal Prosecutor's Office said such surveillance activities constitute a preparatory phase for subsequent intelligence-gathering or coercive operations against a specific target.
In response to RBC-Ukraine's inquiry, the German agency declined to disclose the overall number of such cases. But the case itself clearly confirms that before carrying out an arson attack or explosion, Moscow deploys a network of such observers, in which one agent is replaced by another if the first is exposed or moves away.
What Moscow wants
By stepping up sabotage operations across Europe, the Kremlin is pursuing several goals at once. As Hanna Shelest, Security Studies Program Director at the Foreign Policy Council "Ukrainian Prism," told RBC-Ukraine, the objective goes beyond physically destroying a specific defense facility.
"First, it's good old-fashioned bullying — showing that 'I can do it.' Second, it is about provoking a reaction. Russia cannot constantly look like the bad guy. It needs to portray itself as if it is merely defending itself and that we are to blame for everything. This works both in Russia and in countries of the Global South," the expert explained.
The third goal is to deliver an asymmetric response to military aid for Ukraine.
"They can’t impose sanctions on Germany. But Ukraine has significantly expanded military cooperation and defense production specifically with Germany. So they need to take some kind of action to dampen the German public's enthusiasm and willingness to help us," Shelest said, citing the recent failed sabotage attempt in Leipzig as an example.

Photo: Fire at the Mesko plant in Poland (video screenshot)
NATO officials assess the Kremlin's objectives in much the same way, although the Alliance's public response to the wave of sabotage has remained restrained. In a response to RBC-Ukraine's inquiry, a NATO headquarters official said hostile attempts to destabilize Europe were nothing new, and that their main goal was to undermine democracies and pressure the West into abandoning support for Kyiv.
"Russia wants to create fear, destabilise our societies, and deter us from supporting Ukraine. This will not work. Allies and partners continue to see a range of hybrid or grey-zone activities, including cyber-attacks, information threats, political interference, sabotage, and other hostile actions," the NATO official said.
However, to carry out such large-scale plans while minimizing its own risks, Moscow has had to change the way it selects operatives.
Who are the Kremlin's agents
After the Skripal case, traditional career spies became too risky and expensive a resource for Moscow. Russian operatives working under diplomatic cover are now subject to particularly close scrutiny across Europe. Increasingly, they are being replaced by "disposable agents" recruited locally.
According to a report by the Royal United Services Institute (RUSI), Russian intelligence has launched a large-scale campaign to remotely recruit operatives through anonymous Telegram channels and classified ad platforms.
The process is simple: a handler sends the target’s coordinates and a price list, while payment is transferred to a cryptocurrency wallet only after the operative provides video proof of setting a fire or planting an explosive.
According to RUSI analysts, this network-based approach allows Russian intelligence services to completely isolate operatives from career intelligence officers, minimizing the risk of an intelligence network being exposed and creating an effective buffer against counterintelligence agencies.
Young people and migrants are most often recruited for simpler operations. One example is the case of 16-year-old Danylo B., who was sentenced by a court in Lublin in 2024 after fleeing the war to Poland.

Arrest of a suspect in the arson attack on the Skyeton plant in Slovakia (RBC-Ukraine collage)
Looking for a side job on Telegram, he agreed to install hidden cameras along the Przemysl-Warsaw railway line to monitor military trains in exchange for several hundred dollars in cryptocurrency. A Polish court sentenced the teenager to 18 months in prison.
More complex operations involve people with criminal backgrounds. In October 2025, England and Wales' Central Criminal Court sentenced 20-year-old Briton Dylan Earl to 17 years in prison for organizing the arson attack on commercial warehouses holding aid for Ukraine, funded by entities linked to the Wagner private military company.
The most cynical aspect of this strategy is that Russian intelligence deliberately recruits Ukrainian citizens for sabotage operations. The targets are most often either covert collaborators who left Russian-occupied territories for the EU with Russian assistance or financially vulnerable refugees struggling to make ends meet.
Still, at least some European capitals understand what Moscow is trying to achieve.
"Russian intelligence services are killing two birds with one stone. First, they are preparing acts of sabotage, and second, they are driving a wedge between Poles and Ukrainians. They can say: 'Look, it's Ukrainians preparing acts of sabotage in Poland'," Polish minister-coordinator of special services, Tomasz Siemoniak, said in October last year.
But recognizing the threat is only part of the task. The more important question is how to respond.
Europe's response
Until recently, European capitals had responded to hybrid attacks in a highly procedural manner. Law enforcement agencies investigated individual incidents, arrested operatives, and secured convictions, while political leaders issued general statements expressing concern.
But days ago, Germany took its first tough nationwide response. The trigger was the investigation into the high-profile August 4 incident at Leipzig Airport, where Russian agents allegedly attempted to destroy a Ukrainian An-124 transport aircraft using drones.
For the first time, Berlin publicly and directly blamed the Kremlin for a planned act of sabotage. Interior Minister Alexander Dobrindt said the operation had been professionally planned and coordinated by Russian state structures.
"Taken together, police investigations, operational patterns and intelligence data prove Russia's responsibility for the attempted attack. The federal government therefore concludes that Russia is responsible for this hybrid attack," he said.
In response, Germany announced a series of tough measures, including the closure of Russia's consulate general in Bonn, a ban on the activities of the "Russian House" in Berlin, and new sanctions against Russia.
Unlike the Skripal poisoning, however, the incident did not trigger a coordinated response across the EU. European capitals have been acting individually.
For example, Polish Prime Minister Donald Tusk publicly described a fire at a plant producing components for drones in Skarzysko-Kamienna as deliberate arson. But this has not yet led to joint or coordinated action at the EU level.
"There are not that many Russian diplomats left in Europe. Most countries have already reduced their numbers, and in many of them, there are very few left. Consulates are now being closed as a diplomatic demarche when something happens in a particular country. As for a larger package of sanctions, that is what I would expect," Shelest said, explaining the current dynamic.
According to Dmytro Shevchenko, Ukraine's former consul in Munich and chancellor of the Ukrainian Free University, Berlin’s response to hybrid threats remains largely defensive.
"Germany is reactive rather than proactive in this regard. It would be better to work more proactively, but there is nevertheless a response. Defensive capabilities are being strengthened, including through increased spending on the armed forces, stronger counter-sabotage efforts inside the country, and an expansion of the technical capabilities," the expert told RBC-Ukraine.
The main danger is that the Kremlin is using its own sabotage operations to destabilize European societies. Local populists, such as Germany's Alternative for Germany (AfD), have been reluctant to condemn Russia’s actions and instead shift the blame onto their own governments.
Their narrative is essentially that Europe is already participating in the war because it provides financial and military aid to Ukraine, and therefore it is hardly surprising that acts of sabotage are taking place on European soil. Last week, the AfD scored a major victory in local elections.

German Foreign Minister Johann Wadephul and Interior Minister Alexander Dobrindt at a briefing on Russian sabotage (Getty Images)
"The problem is that additional political measures against Russia are running into opposition from populists who say we need to reach an agreement with Russia and negotiate. So far, it appears that the German government has failed to effectively communicate to the public that meaningful negotiations with Russia are practically impossible," Shevchenko stressed.
As a result, European capitals are focusing less on punishing Russia than on strengthening their own resilience. The main task for governments is to prevent populists from exploiting public fears to destabilize their countries and shift the overall security policy.
NATO's dilemma
Sabotage is, in one form or another, an element of warfare, which means it should fall within the remit of the collective security structure — NATO. Yet the Alliance's public response to the wave of sabotage across Europe remains notably restrained.
On September 1, NATO Secretary General Mark Rutte expressed solidarity with Germany over the Leipzig incident.
"NATO will continue to strengthen our ability to deter and defend all Allies against any threat – including malign actions like those seen in Leipzig and elsewhere across the Alliance,” Rutte said.
In response to an inquiry from RBC-Ukraine, a NATO headquarters official elaborated that the Allies had agreed to invest in greater capabilities to counter risks arising from hybrid activities. This includes, among other things, cyber defense and the protection of critical infrastructure.
According to the official, NATO is also doing more to facilitate information-sharing among its members, using a range of sources and technologies to track patterns and trends.
“We are strengthening our resilience in strategic sectors and investing in civil preparedness. We are also strengthening the resilience of our societies. NATO continues to work around the clock to keep our one billion people safe,” the official said.
Behind Brussels' restrained diplomatic language, however, lies a significant expansion of practical work by NATO intelligence services.
"At the level of the armed forces and intelligence services, activity has increased. They are significantly raising the level of threat assessment, analysis, and preparedness. Their actions are much more sharp-edged. They simply do not want to show Russia too much about how this preparation is being carried out," Shelest stressed.
At the same time, despite repeated calls from some politicians to invoke Article 4 of the NATO treaty for formal consultations over Russian sabotage, the Alliance currently prefers to operate through expanded intelligence sharing and the protection of critical infrastructure.
Asked directly by RBC-Ukraine where the threshold lies beyond which a series of sabotage operations would require invoking Article 5 on collective defense, NATO headquarters declined to answer.
There is, however, only one case in NATO's history when Article 5 has been invoked, and it bears some similarities to the current situation, although it was on a vastly greater scale. That was the September 11, 2001, terrorist attack, when hijackers crashed captured aircraft into the Twin Towers in New York.

NATO counterterrorism training (Getty Images)
This situation opens up a new area for cooperation with Ukraine — similar to the cooperation already developed on cyberattacks and air defense.
As Foreign Ministry spokesman Heorhii Tykhyi noted, Kyiv is already actively offering European capitals the unique expertise of its specialists in combating disinformation, cyber threats, and subversive operations.
"If you want to strengthen your country’s security ahead of elections, invite Ukrainians. That is our simple message to our European colleagues. With a number of countries, this cooperation is already underway. We just don't publicize it,” Tykhyi said in response to a question from RBC-Ukraine.
Ultimately, Russia's hybrid pressure on Europe is not a temporary anomaly but a new long-term reality. The choice now facing European capitals is fairly simple: wait for the next detonator to go off in the air or at a production facility, or build a truly effective collective shield — drawing, among other things, on Ukraine's unique experience.