Posted

The new tactics of Russian special services against the European defense industry

Russia’s aggression against Ukraine has forced adjustments to the strategy of Russian intelligence and subversive activities in the European Union. While in the early stages of the full-scale invasion the Kremlin’s main instruments of influence were largely disinformation campaigns and cyberattacks on civilian infrastructure, today the priority target has become the defense-industrial complex (DIC) of EU countries. Organizing sabotage, diversions, and the physical elimination of key figures in the European defense industry has become a priority objective for Russian special services aimed at disrupting or impeding the supply of weapons to Ukraine. These measures form an integral part of the hybrid aggression that Russia is conducting directly on the territory of NATO member states.

The priorities regarding targets of intelligence interest have also shifted: instead of collecting classified data on production capacities and logistics, Russian special services now resort to the tactics of pinpoint sabotage and contract killings. The primary targets are the heads of defense companies and enterprises, as well as leading engineers and particularly valuable technology developers. The systematic nature of these actions indicates that the crimes committed by Russian agent networks in Europe should not be viewed as isolated incidents, but as part of hybrid aggression against the West.

According to data from the International Centre for Counter-Terrorism (ICCT), between February 2022 and February 2026 more than 150 exposed and confirmed cases of Russian sabotage operations were documented in Europe. These included arson attacks, explosions, acts of sabotage, and assassination attempts. The largest number of such cases occurred on the territory of Poland, France, Germany, Lithuania, and the United Kingdom. In every instance, the primary instrument for carrying out these terrorist tasks were “disposable agents” recruited online.

In early 2024, U.S. intelligence uncovered preparations by Russian special services for an assassination attempt on Armin Papperger, CEO of the German concern Rheinmetall. The information was promptly shared with German security services, allowing them to place the company’s head under enhanced protection in time and disrupt the operation while it was still in the preparation stage. On 11 July 2024, CNN was the first to officially report the foiled plot; the information was also confirmed by German Foreign Minister Annalena Baerbock.

On 28 January 2025, NATO Deputy Secretary General James Appathurai stated during a speech in the European Parliament that Russian intelligence had been preparing the murder of A. Papperger as part of a broader campaign to eliminate top managers of the European defense industry.

Papperger was not chosen by Russian special services at random. After 2022, Rheinmetall significantly increased the production of artillery ammunition, armored vehicles, and other weapons for the needs of the Ukrainian army. In May 2023, the company signed an agreement to establish a joint venture with Ukraine’s Ukroboronprom. On 29 October 2024, Kremlin spokesman Dmitry Peskov called the joint production facilities with Rheinmetall in Ukraine legitimate military targets for Russian missile and drone strikes.

A similar case occurred with the head of Rheinmetall: in December 2025, German intelligence received operational information about preparations by Russian special services for an assassination attempt on Stefan Tumann, founder and CEO of the German UAV manufacturer Donaustahl. As a result of preventive measures, police observed near Tumann’s residence and office in Straßkirchen a certain Sergey N., who was filming the house where the German businessman lived and collecting information about the businessman’s father, who resided in another city. The suspect was detained and his smartphones seized. However, due to insufficient time to decrypt their contents within the legal detention period, he was released and subsequently left for Spain.

Subsequent analysis of the data from the seized phones confirmed Sergey N.’s links to a Russian special service. It was also established that, after he had been compromised, the Russians used a Romanian citizen of Russian origin, Alla S., as his replacement. In March 2026, because of a coordinated special operation, Sergey N. was arrested in Spain and Alla S. in the German state of North Rhine-Westphalia. According to the investigation, both had been recruited via Telegram channels and tasked with gathering information on Tumann’s locations, schedules, and travel routes for subsequent use by a separate liquidation team. The uncovered assassination attempt and the findings of the preliminary investigation were first reported by the German newspaper Die Zeit in an article published on 5 August 2026.

Today, such “disposable agents” remain the primary instrument used by Russian special services to carry out dirty work, sabotage, and other crimes. This approach allows Russian intelligence to avoid directly deploying career officers and to minimize negative consequences in the event of operational failure. Individuals recruited online often act as “blind” executors for financial reward, without even understanding the ultimate purpose of the operation.

Despite intensified counterintelligence efforts by European special services and regular arrests of such agents, the Kremlin has not abandoned this terrorist practice and will only intensify it. The presence of many marginalized and financially vulnerable individuals in European countries provides Russian special services with a sufficient pool for recruiting new operatives.

For a long time, the security system of the European defense industry was built primarily around the physical and cyber protection of production sites, warehouses, and transport hubs. It now requires reinforcement, as protection is needed not only for the material and technical base but also for particularly valuable and important personnel. European law enforcement agencies and special services have demonstrated a sufficient level of capability to detect threats in a timely manner, as evidenced by the successful prevention of the assassination attempts on the heads of Rheinmetall and Donaustahl. At the same time, the existing protection system still has gaps caused by bureaucratic and regulatory peculiarities, as well as differing levels of security standards across individual EU member states.