
From suspected arson attacks at defence facilities to incendiary devices and drones, a growing series of incidents across Europe is raising concerns about an increasingly aggressive Russian hybrid campaign.
As Europe entered the final weeks of summer, governments across the continent were confronted with a security problem unfolding far from the battlefields of Ukraine.
While Russia intensified its military campaign against Ukraine, a series of suspected sabotage incidents began appearing across Europe, targeting defence companies, military-related infrastructure and facilities involved in supporting Kyiv.
The incidents are not entirely unprecedented. What has alarmed European officials and security experts is their apparent concentration and the increasingly direct connection to defence infrastructure.
Germany has gone as far as accusing Russia of being behind a failed drone operation at Leipzig airport, while authorities in several other countries are investigating fires and suspected arson attacks at facilities linked to the defence industry.
Moscow has rejected the allegations.
But European governments are increasingly warning that the incidents may represent more than a collection of isolated crimes.
Poland’s Interior Minister Marcin Kierwiński has described the developments as evidence that Russia could be changing its approach and intensifying sabotage operations across Europe.
The concern is that Europe is being drawn further into a confrontation that remains deliberately below the threshold of conventional war.
A Month of Suspicious Incidents
The latest wave has unfolded across several countries.
On August 4, a drone carrying explosives was discovered at Leipzig airport in Germany. The airport has been used to transport military equipment to Ukraine. Weeks later, Germany’s interior minister publicly attributed the operation to Russia.
Russia has demanded evidence and dismissed the accusation as absurd.
Days later, on August 10, a major fire broke out at a warehouse belonging to Bulgarian defence company EMCO in Tryavna. The company pointed to previous explosions at its facilities that had been investigated for possible Russian links and said human error had been ruled out.
On August 13, a fire at KNDS Ammo Italy near Rome caused a significant explosion. Italian prosecutors opened an investigation into possible outside interference, although the case was initially registered against unknown individuals for alleged negligent disaster.
Two days later, another fire struck the Milrem Robotics factory in Tallinn, Estonia, a company reported to be involved in supplying drones to Ukraine. Two suspects were arrested, while Estonian Prime Minister Kristen Michal said investigators were taking the possibility of Russian sabotage seriously.
The incidents continued.
On August 25, Slovak police said they had prevented an arson attack against a Ukrainian-owned drone manufacturer. Authorities reported seizing a large quantity of incendiary material and arresting three suspects whom police said had been acting on instructions.
Then came Poland.
On August 30, two fires were reported at sites connected to the country’s defence sector. One occurred at a company in Lublin producing helicopter components. Prime Minister Donald Tusk said arson could not be excluded.
A separate incident involving drone manufacturer WB Group appeared more deliberate. CCTV footage reportedly captured a masked individual throwing incendiary devices at the facility.
Tusk described the incident as another example of what he called Russia’s escalating activities.
The suspected campaign has also extended into Germany, where two Bulgarians were arrested in Munich over an alleged arson attack targeting a defence company.
Authorities in Germany are simultaneously investigating separate suspected sabotage attacks against power infrastructure.
Not every incident will ultimately be linked to Russia. Some could prove to have entirely different causes.
That uncertainty, however, is part of what makes covert sabotage so difficult to counter.
Why Defence Facilities?
Sabotage against military-related infrastructure is not new.
European investigators have previously examined suspected Russian operations involving seemingly unrelated targets, including commercial businesses. But security specialists say the recent concentration of incidents around defence facilities is unusual.
Daniela Richterova, a researcher at King’s College London’s Department of War Studies, says the increased targeting of military sites represents a significant development.
One explanation is the changing nature of the war in Ukraine.
Ukraine has increasingly demonstrated its ability to strike targets deep inside Russian territory, putting pressure on Moscow and challenging the assumption that the conflict can remain geographically contained.
Russia, according to this theory, may be responding by increasing the cost of European support for Kyiv.
Germany is particularly important in this context. After initially taking a more cautious approach, it has become one of Ukraine’s largest military supporters.
Sabotage can therefore serve a purpose beyond physical damage.
It can create uncertainty.
It can increase security costs.
And it can send a message to governments that continuing to support Ukraine could carry consequences.
Richterova describes this approach as “coercive signalling” — an attempt to influence European decision-making without triggering a conventional military confrontation.
Testing NATO’s Boundaries
There is another possibility.
Rather than simply trying to disrupt weapons supplies to Ukraine, Russia could be testing how far it can operate inside NATO countries without provoking a direct response.
Keir Giles, an expert at the Chatham House think tank, argues that Russia may be gathering information about the vulnerabilities of European countries and their willingness to respond.
Every operation provides information.
Which facilities are poorly protected?
How quickly do authorities react?
What evidence can investigators gather?
And, perhaps most importantly, where is the line that would trigger a stronger NATO response?
That makes sabotage potentially valuable even when an individual attack causes limited physical damage.
The objective may be the information gained from the operation itself.
A Familiar Cold War Playbook
Security researchers say the tactics have echoes of the Cold War.
Small-scale attacks that can be denied, outsourced or disguised as criminal activity allow a state to exert pressure without openly declaring responsibility.
The Soviet Union used networks of agents and intermediaries to conduct covert operations in Europe. Today’s suspected Russian operations appear to use a more modern version of the same concept.
Instead of highly trained intelligence officers carrying out every mission, many operations are believed to rely on individuals recruited online.
These so-called “gig economy saboteurs” are often Russian-speaking individuals from former Soviet states who are attracted by financial rewards rather than ideological commitment.
According to researchers, their handlers can remain in Russia while communicating with operatives remotely.
The approach is cheap, scalable and difficult to attribute conclusively.
But it also has weaknesses.
Amateur operatives can make mistakes, misunderstand instructions or abandon missions.
That happened during an alleged 2024 plot involving incendiary packages sent toward Europe. One participant reportedly struggled to locate a collection point, disrupting the operation.
The Leipzig airport case could represent something different.
If Russian nationals were deliberately sent to Germany to conduct the drone operation, rather than relying on local recruits, it could indicate a greater emphasis on precision and control.
The apparent malfunction of the devices, however, prevented the operation from achieving its intended effect.
From the “Grey Zone” Toward Something More Dangerous
The European security dilemma is becoming increasingly difficult to define.
Europe is not formally at war with Russia.
Yet European countries are providing weapons, intelligence, financial assistance and logistical support to Ukraine, while Russia continues to describe the West as directly involved in the conflict.
This creates what analysts often describe as a grey zone between peace and open warfare.
Richterova argues that the growing frequency and seriousness of suspected sabotage attacks could be shrinking that space.
The danger is not only deliberate escalation.
It is also the possibility of an accident.
An incendiary device placed inside a cargo facility could trigger a much larger fire. An explosive package could detonate aboard an aircraft. A drone carrying explosives could strike an occupied building or bring down a passenger plane.
The consequences would be dramatically different from those of a small-scale act of sabotage.
A single incident resulting in mass casualties could force governments to respond in ways they have so far avoided.
And once a direct confrontation begins, controlling its trajectory becomes far more difficult.
Europe Faces a Difficult Choice
European governments are now confronting a complicated question: when do dozens of apparently isolated incidents become evidence of a coordinated campaign?
Germany has reportedly recorded more than 165 suspected sabotage cases this year, although authorities have not attributed all of them to Russia.
That distinction matters.
Attribution requires evidence, and investigators must separate genuine hostile operations from accidents, ordinary criminal activity and unrelated acts of extremism.
Yet the broader pattern is increasingly difficult to ignore.
Across Europe, defence facilities are being targeted, suspected operatives are being arrested and governments are warning that hostile activity may be increasing.
For Russia, covert operations offer a way to impose pressure without crossing the threshold of open conflict.
For Europe, the challenge is determining how to respond without either underestimating the threat or taking actions that could accelerate the escalation everyone is trying to prevent.
The question is no longer simply whether individual acts of sabotage are connected.
It is whether Europe is witnessing the emergence of a sustained campaign — and how far that campaign could go before the grey zone between war and peace disappears entirely.


















Comments are closed.