Europe targeted by spiralling campaign of sabotage and Russia is the chief suspect

While Europe wrapped up a record-breaking summer of extreme heat and many European political leaders stepped away for seasonal breaks, Russia never paused its expanded campaign of hybrid aggression across the continent. Alongside intensifying deadly military strikes on civilian infrastructure across Ukraine throughout August, Moscow has sharply ramped up a coordinated sabotage campaign targeting European defense and military-linked sites, according to senior European security officials and independent defense analysts.

The string of high-profile incidents began one month ago, when explosive-laden drones were discovered at Leipzig Airport, a key logistics hub for military aid bound for Ukraine. On Friday, German Interior Ministry formally pinned responsibility for the plot on Moscow, a claim that Russian President Vladimir Putin has repeatedly dismissed as unfounded, with Kremlin officials calling the accusation “absurd.”

The Leipzig discovery was just the opening act of a month-long wave of suspicious incidents stretching from Southern Europe to the Baltic. On August 10, a large fire broke out at a defense manufacturing plant owned by Bulgarian firm EMCO, with initial reports linking the blaze to a truck ignition during a fuel delivery. Three days later, a fire at the KNDS Ammo Italy facility outside Rome triggered a massive explosion; local prosecutors have opened an investigation into negligent disaster involving unknown persons, with local outlet La Repubblica reporting that foreign interference is a key line of inquiry.

On August 15, a fire destroyed the Tallinn factory of Milrem Robotics, a company that supplies unmanned systems to the Ukrainian military, per Kyiv Post. Estonian authorities have arrested two suspects and confirmed that possible Russian sabotage is being treated as a high-priority line of investigation. On August 25, Slovak police announced they had foiled an arson plot targeting a Ukrainian-owned drone manufacturer, seizing a large cache of incendiary materials and arresting three suspects who investigators confirm were acting on external orders. The case is notable because Slovakia has long maintained close political ties to Moscow.

The wave of incidents continued into late August, with Poland — a nation that has emerged as one of the most frequent targets of Russian sabotage — reporting two new attacks on August 30. A fire broke out at a helicopter component manufacturing facility in Lublin, where Prime Minister Donald Tusk confirmed arson cannot be ruled out. A second attack on Polish drone producer WB Group was caught on closed-circuit television, showing a masked individual throwing incendiary devices at the facility. Tusk labeled the incident a “continuation of Russia’s escalatory activities” across Europe. The pattern spilled into September, when German authorities arrested two Bulgarian suspects in Munich on suspicion of arson, after they allegedly threw incendiary devices from a vehicle at the site of defense firm Rhode & Schwartz.

While Russian-linked sabotage across Europe is not a new phenomenon — past plots have targeted seemingly random sites ranging from Ikea retail locations to Polish paint supply stores — analysts agree that the current concentration of attacks on military and defense infrastructure marks a significant shift. “The intensity of attacks on military sites we have seen over the past two months is unprecedented,” explained Daniela Richterova, a researcher in the Department of War Studies at King’s College London. She links this sharp uptick in activity to battlefield developments in the war in Ukraine, noting that Kyiv has increasingly expanded strikes deep into Russian territory, putting political and military pressure on the Kremlin to respond.

Richterova argues that the current Kremlin strategy is best described as “coercive signalling”: Moscow is raising the stakes for European nations that provide military support to Ukraine, aiming to pressure governments to pull back on aid by demonstrating the domestic security risks of backing Kyiv. Germany, which has become Ukraine’s largest bilateral supplier of military aid after ramping up support following the 2022 invasion, has become a key target for this campaign.

Other analysts offer alternative interpretations, suggesting that the sabotage campaign is as much about testing NATO’s defensive posture and willingness to respond as it is about cutting off military aid to Ukraine. “Russia is probing the boundaries of what European nations will accept as acceptable behavior, while collecting data on what attack methods work and which critical infrastructure is most vulnerable,” said Keir Giles, a senior researcher at the London-based Chatham House think tank. He frames the current campaign as deliberate preparation for a next phase of Russian aggression in Europe, designed to test how much retaliation Moscow can expect even after repeated attacks on allied territory.

The International Institute for Strategic Studies (IISS), which tracks cross-European sabotage incidents, notes that the current surge mirrors a similar spike in activity in 2024, shortly after Ukraine’s Western allies approved the use of long-range Western-supplied weapons to strike targets deep inside Russia. That 2024 wave was dominated by a parcel bomb plot, where Russia was accused of sending packages containing liquid explosives to locations in the UK and Poland; one device ignited shortly before it was to be loaded onto a DHL cargo plane, an incident analysts now view as a test run for a larger future attack. “That plot marked a clear escalation in Moscow’s willingness to risk mass civilian casualties,” Giles added. The plot was so serious that the White House directly intervened to warn the Kremlin to halt the activity, drawing a line that Moscow appeared to acknowledge at the time, but attacks have continued unabated.

German domestic media recently published leaked details from a federal police report showing that more than 165 suspected sabotage incidents have been recorded across Germany alone in 2025, though the report does not officially assign blame for the majority of cases. German security sources familiar with the Leipzig investigation have told local media that the individuals who placed and launched the explosive drones at the airport are believed to be Russian operatives, with at least one thought to have entered Germany specifically to carry out the plot.

This would mark a break from the majority of recent Russian sabotage operations in Europe, which have almost exclusively relied on Russian proxies often described as a “gig economy of sabotage.” Most of these operatives are Russian-speaking residents from former Soviet states, recruited online to carry out attacks for cash rather than ideological commitment. The BBC previously reported on a case in Poland where a pair of recruited saboteurs had previously volunteered to fight for Ukraine against Russian forces, demonstrating the cash-driven nature of the work. Operational handlers almost always remain based in Russia, coordinating attacks remotely via online communication tools. The IISS compares this model to the use of disposable kamikaze drones: low-cost, easy to deploy in large numbers, and designed to be expendable if operatives are caught. The amateur nature of most operatives does lead to mistakes, however: the 2024 parcel plot was partially aborted after one operative failed to locate a correct parcel pickup point, abandoning the mission entirely. If Moscow deployed professional operatives for the Leipzig plot, analysts say that indicates the Kremlin prioritized a precise, successful attack on the critical aid hub. In the end, the drones malfunctioned and never reached their intended target.

Russian hybrid sabotage campaigns draw heavily on Cold War-era playbooks, according to Richterova’s research. Soviet-era sabotage target lists included almost identical types of infrastructure, and the Soviet Union relied on the same deniable, small-scale attack model during peacetime, with plans to scale up operations once open conflict began. “I think we are still in the grey zone between peacetime and open war, but the attacks we have seen over recent weeks are rapidly shrinking that grey space,” Richterova explained. “That increases the risk of miscalculation around what happens next.”

As NATO works to coordinate a unified response to the rising threat, key strategic questions remain unanswered: at what point do dozens of small, deniable attacks add up to an open act of Russian aggression that requires a formal allied response? The greatest risk of all, analysts warn, is accidental escalation. If an explosive package had detonated mid-flight on a cargo plane, or if a Leipzig drone had struck a commercial passenger aircraft, the resulting casualties would force NATO to take tangible action that could spark a direct conflict between the alliance and Russia. “A major accidental attack that causes mass casualties would leave NATO no room to step back,” Richterova said. “In the current heightened security environment, the alliance would have no choice but to respond.”