Throughout 2026, warnings regularly appeared in the European information space that Russia was preparing new hybrid operations against NATO countries. Those warnings were not unfounded. Western intelligence services have repeatedly said that Moscow uses sabotage, cyberattacks and information campaigns as tools of political pressure on the West.
In the second half of August 2026, several EU countries saw incidents — or foiled attempts — involving defence companies and military logistics sites. They included a suspected arson attack, preparations for sabotage, interference with satellite navigation, attempts to seize the accounts of European officials, and an information operation that used generative artificial intelligence. Russia’s involvement has not been officially established in every case. Still, the choice of targets and methods matches a pattern of hybrid activity that European security services have previously linked to Russian structures. Of particular concern is that such operations are increasingly creating a direct threat to people who work at defence, critical and transport infrastructure sites.
On the night of 15 August 2026, a fire broke out in Tallinn in a building used by the Estonian defence company Milrem Robotics, which produces robotic systems and unmanned ground platforms, including THeMIS vehicles supplied to Ukraine. Estonia’s Prosecutor General’s Office said investigators were treating the incident as possible arson and examining whether it could have been sabotage. Margo Palloson, director general of Estonia’s Internal Security Service, said Russia remained a long-term threat to the country. Three suspects in the case were later detained in Latvia, but investigators have not yet published final conclusions about who commissioned the attack or why.
On 21 August 2026, Bulgaria’s State Agency for National Security, working with police and the communications regulator, found a powerful GPS jamming device in a secured complex in Sofia’s Dragalevtsi district. The equipment disrupted satellite signals, including those near the airport. Bulgarian security authorities did not name a possible organiser. Systematic interference with satellite navigation has already been recorded elsewhere in Europe, especially in the Baltic region, where it has repeatedly been linked to Russian activity.
On 23 August 2026, The Telegraph, citing Western intelligence sources, reported a new wave of Russian sabotage aimed at European defence companies, including firms that supply weapons to Ukraine. According to the paper’s sources, Russian intelligence services may recruit criminals and socially vulnerable people for such operations. Recruitment is carried out through intermediaries and Telegram, and payment is made in cryptocurrency. That makes it harder to connect the people who carry out the attacks with those who order them and allows Moscow to try to stay below the threshold that would trigger a collective NATO response.
On 25 August, POLITICO reported on an internal presentation by the EU’s Interinstitutional Cybersecurity Board in which the hijacking of senior officials’ accounts was named one of the key cyber threats of 2026. Russia-linked hacking groups were said to be using highly targeted phishing and sophisticated social engineering to gain access to politicians’ Signal and WhatsApp accounts. At least five European security services issued warnings about such attacks during the year, and Dutch security authorities directly linked some of this activity to Russia.
The same day, Slovak police said they had prevented an arson attack on a drone-manufacturing plant in the east of the country. Three foreigners were detained — two in Slovakia and one in Germany. Officers seized a large quantity of incendiary mixture, tools, phones, an action camera and a hand-drawn plan of the plant. About 70 employees could have been at the site at the time of the planned attack, so a fire would have posed a real threat to life and could have caused major material damage. Police did not officially name the company, but Slovak media reported that the likely target was a production site of the Ukrainian firm Skyeton.
Germany, one of Ukraine’s key military and political partners, also remains a potential target of hybrid operations. In August, German investigators examined a suspected attack near Leipzig/Halle Airport, a major cargo and military logistics hub used by NATO and by Ukraine’s Antonov Airlines. German media, citing security sources, reported possible involvement by Russian intelligence services. On 27 August, ABC News, citing a U.S. intelligence source, said a drone discovered earlier in the month had a design “typical” of devices associated with Russia’s GRU.
Alongside physical and cyber threats, Moscow has continued to run information operations. On 25 August, OpenAI said it had blocked a cluster of ChatGPT accounts that were highly likely being used by operators in Russia via VPN. The operators entered Russian-language prompts to generate English- and German-language material that was later spread on Telegram, X, Facebook, LinkedIn and Substack. A central element of the campaign was the promotion of the International Burke Institute, which presented itself as an expert community and systematically published content favourable to Russia and critical of Europe and Ukraine. OpenAI assessed that the campaign had a relatively small reach, but that it stood out for its complex infrastructure, use of other people’s names and academic material, creation of a pseudo-expert image, and efforts to conceal the Russian origin of the operators.
The events of late August do not yet prove that all of these incidents were parts of a single centralised operation. Investigations are still under way in several cases, and Russian involvement remains a working hypothesis or an assessment from intelligence sources. Taken together, however, the incidents point to a dangerous trend. Defence plants, transport hubs, satellite navigation systems, officials’ accounts and the information space are simultaneously becoming targets of operations designed to cause material damage, create an atmosphere of instability and make support for Ukraine harder.
For Europe, this is a test of its ability to protect critical infrastructure, share intelligence and distinguish confirmed facts from reasoned suspicion and information manipulation. That ability will determine whether European states can resist hybrid pressure without letting fear of escalation weaken their political unity or their support for Ukraine.
