Russia is escalating a covert campaign against European weapons manufacturers supplying Ukraine, recruiting criminal networks to carry out arson and sabotage while keeping its own intelligence operatives safely beyond the reach of European law enforcement, according to Western intelligence assessments.
The attacks are part of a broader strategy attributed to the GRU, Russia’s military intelligence service, designed to disrupt the flow of weapons to Ukraine while preserving Moscow’s ability to deny direct involvement.
More ominously, intelligence officials believe the operations have been calibrated to remain below the threshold that could trigger NATO’s collective-defence mechanism, allowing the Kremlin to test how much disruption the alliance will tolerate without provoking a direct confrontation.
A NATO official said: “In recent years, Russia has accelerated its destabilisation campaigns against Allies through cyber attacks, assassination attempts and acts of sabotage.”
Read more related news:
North Korea is building Putin’s war machine as 50,000 more troops loom
The world is foolishly ignoring North Korea’s dangerous entry into Europe’s war
Putin’s war bill comes home: Russians pull billions as Kremlin asset grab fears soar
Third night of fire as Ukraine rips into Russia’s logistics backbone
The pattern has become increasingly difficult to dismiss as coincidence.
On August 15, a building belonging to Milrem Robotics, an Estonian drone manufacturer and one of only two foreign suppliers of unmanned ground vehicles to Ukraine’s military, was set alight in Tallinn.
Latvian authorities subsequently arrested three Latvian citizens over the arson. Estonia’s prime minister, Kristen Michal, said investigators were examining whether the fire was connected to Russia and constituted sabotage.
Five days earlier, a lorry fire near a storage facility triggered a major explosion at EMCO, a Bulgarian arms manufacturer producing 155mm artillery shells for Ukraine.
On August 13, an unexplained fire broke out in a gunpowder-processing unit at KNDS Ammo Italy’s ammunition plant in Colleferro, south of Rome.
In the Czech Republic, four people were detained following a fire that nearly destroyed a factory operated by arms manufacturer LPP Holding, which produces drones and thermal-optical equipment for Ukraine.
Lithuanian authorities have also charged six people accused of plotting to burn down a facility manufacturing radio-wave scanners destined for Ukrainian forces.
Taken individually, each incident can be investigated as an act of criminality or industrial accident. Taken together, western officials see a more troubling pattern.
The alleged GRU model is deliberately indirect.
Normunds Mežviets, head of Latvia’s state security service, said Russian intelligence officers can remain inside Russia while using encrypted platforms such as Telegram to recruit intermediaries in target countries.
Local criminal networks then identify recruits and distribute instructions. Payments are often made in cryptocurrency, with those carrying out the attacks potentially unaware that their ultimate sponsor is the Russian state.
The arrangement offers Moscow two advantages, deniability and distance.
A Russian intelligence officer caught directing an operation would create an obvious diplomatic crisis. A local criminal arrested after an arson attack can instead be portrayed as an isolated offender.
That ambiguity is particularly valuable inside an alliance struggling to maintain a common response.
Eastern European governments, particularly in Poland and the Baltic states, have been outspoken in attributing hostile activity to Moscow. Western European governments have been more cautious, with officials in Italy and Bulgaria playing down the possibility of Russian involvement in recent incidents.
That divergence matters.
Every unexplained explosion or suspicious fire that produces no unified political response gives Moscow another opportunity to probe the limits of European tolerance.
NATO secretary-general Mark Rutte has repeatedly described suspected Russian sabotage as “reckless and dangerous”, arguing that the alliance’s response must be “clear, swift and decisive”.
But the difficulty is determining what response is proportionate when the evidence is deliberately obscured and the perpetrators are often ordinary criminals operating several steps removed from their alleged handlers.
The risk is that the grey zone itself becomes the battlefield.
Since Russia’s full-scale invasion of Ukraine in 2022, many of the diplomatic channels that previously helped Washington, European capitals and Moscow manage crises have withered. That has left fewer mechanisms for containing incidents before they escalate.
For European governments, the weapons factories now under scrutiny are not simply industrial sites. They form part of the supply chain sustaining Ukraine’s ability to fight.
For Moscow, disrupting them offers a relatively inexpensive way of imposing costs on its adversaries without firing directly at NATO territory.
And for NATO, the attacks pose a strategic question that is becoming harder to avoid, how many acts of sabotage can occur inside the alliance before a pattern becomes an attack in all but name?
Rutte has warned that Putin is preparing Russia to be capable of using force against NATO within five years.
The campaign against Europe’s defence industry suggests the confrontation may already be under way — just not in the form of a conventional war.





Leave a Comment