Russia’s hybrid aggression against Europe has intensified markedly in 2026, and one of its most dangerous strands is the expansion of sabotage. In recent months, European intelligence services have increasingly warned of Russian sabotage, the recruitment of operatives, and preparations for attacks on sites linked to support for Ukraine. The aim is not only to inflict material damage, but also to impose extra security costs on European states, raise the risks and price of military aid to Ukraine, and heighten fear of further escalation. Denmark’s security service (PET) says Russian sabotage activity is intended to obstruct the supply of assistance to Ukraine and to weaken political, economic and military support for Kyiv among European publics and politicians — in other words, to turn support for Ukraine itself into a standing source of domestic risk and additional expense for European governments.
In early September 2026, European services recorded fresh signs that Russian recruitment among Europeans was picking up. On 3 September 2026, Alexandru Musteață, director of Moldova’s Information and Security Service, reported a rise in attempts to recruit citizens via Telegram to carry out sabotage outside the country, most of it directed against Ukraine. Russian handlers, he said, are looking for so-called disposable agents, offering modest payments of €100 or more depending on the complexity of the task. On 5 September 2026, Denmark’s PET reported attempts by Russian services to recruit local residents through social media to prepare and carry out sabotage against defence firms and companies tied to military support for Ukraine. PET assesses the threat of Russian sabotage as high and already advises such companies to strengthen their own protection rather than wait for a specific warning from the services.
In early September, two Bulgarian citizens were detained in Munich after an incendiary attack on a construction site belonging to Rohde & Schwarz, a major German producer of defence-sector technology. In May 2026 the company formed a partnership with the Ukrainian electronic warfare systems maker INFOZAHYST to jointly adapt and promote EW systems, counter-drone capabilities and mobile electronic warfare platforms. Although a Russian link in the Munich attack has not been established, the incident occurred at a company that works directly with Ukraine’s defence sector and again showed how vulnerable such firms are to simple attacks that require little sophisticated preparation.
A telling example of cheap operatives was the case of explosive parcels sent in 2024 from Vilnius to several European countries. According to Lithuania’s Prosecutor General’s Office and an international investigation coordinated by Eurojust, in March 2026 law-enforcement agencies in Lithuania, Poland, the Netherlands, Germany and the United Kingdom identified 22 people who, investigators believe, acted in the interests of Russian intelligence structures. Operatives were recruited for individual tasks via Telegram and personal contacts, with payment offered in cryptocurrency among other forms. The attacks themselves hit Germany, Poland and the United Kingdom and showed how splitting tasks among different people can enable complex sabotage without professional agent networks.
After the mass expulsion from Europe of Russian intelligence officers working under diplomatic cover, the Kremlin has shifted more actively to so-called “disposable agents.” According to the IISS, Russia is offsetting the loss of part of its traditional agent networks through remote recruitment. Potential operatives are found via Telegram, Viber, Instagram, gaming platforms and other digital environments, then given simple tasks. They come from various social groups, above all the socially vulnerable and people with criminal backgrounds. At the first stage they may be asked to photograph a plant, warehouse, vehicle, access roads or an entry-control system. Some may not even know who the real client is or how the collected data will be used. Poor training raises the risk of failure, but for Russian services that is offset by low cost and the ease of replacement. RUSI describes the model as a kind of “gig economy” of sabotage, in which a service hires an operative for a specific task instead of running a long-term professional agent. Money is increasingly the main motive, which greatly widens the pool of potential recruits. For the Kremlin the advantages are low cost and rapid scale: a disposable agent is far cheaper than a professional intelligence officer; the remote model makes it harder to prove a direct link to Russian services; and after a task is completed or fails, the operative can be replaced quickly. Russian services can therefore work with large numbers of people in different countries at once without building a separate professional network for each operation.
The intensified hunt for cheap operatives should be seen not merely as a recruitment campaign, but as a direct indicator that Russia is preparing a new stage of hybrid escalation against Europe. Against the backdrop of PET’s reports of concrete sabotage preparations and IISS findings on the accelerating use of proxy operatives, Russian services are in effect expanding a reserve of people who can be used simultaneously for reconnaissance, surveillance, arson and attacks on infrastructure in different countries. The wider that reserve, the more operations the Kremlin can run in parallel while still denying a direct link to any given operative. That allows Russia to increase the number of sabotage operations without a matching rise in its own costs and risks. The strategic aim of this escalation is to use the constant threat of new attacks to raise the financial and security price of supporting Ukraine for European states and thereby influence their political decisions. The calculation rests less on the scale of any single act of sabotage than on the cumulative effect of dozens of incidents that force governments to keep spending on protection, counter-intelligence and the defence of critical sites.




