Global Strategy Report, 15/2024
Abstract: This report examines the alleged Russian sabotage campaign in Europe, focusing on incidents in 2024 where there are well-founded suspicions of Russian intelligence involvement. The motivations behind this escalation of the conflict in the gray zone are analyzed, including Russia’s intention to weaken European support for Ukraine and the reconstituted capacity of its intelligence networks in Europe. It argues that these sabotage actions are synergistic with other hybrid strategies employed by Russia, such as cyberattacks and disinformation. The report also addresses the difficulties of deterrence and response, emphasizing the importance of law enforcement and counterintelligence action, as well as the need for effective strategic communication to raise awareness of the threat in European societies and convey a message of strength.
Keywords: Gray zone conflict, Hybrid warfare; Hybrid strategies, Intelligence, Russia, Europe.
How to cite: Jordán, Javier (2024), «How to interpret the Russian sabotage campaign in Europe», Global Strategy Report, 15/2024.
In the last few months, several incidents have been concatenated that correspond to a pattern typical of hybrid strategies. I am referring to the alleged Russian sabotage campaign on European territory. Alleged because so far there have been no judicial convictions proving the link between these criminal acts and the Russian intelligence services.
There are two reasons that make it difficult to legally determine the Kremlin’s ultimate responsibility. First, because it is to be expected that Russian intelligence (both SVR and GRU) will be taking steps to ensure plausible deniability; and second, because it is to be expected that European intelligence services will not prosecute evidence that would jeopardize their sources or cooperation with other services. As a consequence, violent acts – which a typical terrorist organization would have claimed in order to multiply the impact of political communication – are in this case shrouded in the ambiguity inherent to hybrid actions in the framework of a conflict in the gray zone.
The following is a list of the main events where there are well-founded suspicions of the involvement of Russian intelligence services.
- In March 2024, two facilities of a Ukrainian businessman in Leyton and East London were set on fire. The police arrested five people and have charged two of them, British citizens, with collaborating with Russian intelligence services.
- On March 30, 2024, a few days after the fires in the UK, another arson attack took place in an industrial building of the company Meest in Fuenlabrada (Madrid), a Ukrainian company dedicated to the logistics of parcel and food delivery. As it is the same company that suffered the fire in Leyton, the Spanish police suspect that both actions are linked.
- In April 2024, German authorities arrested two individuals with dual German-Russian citizenship on charges of preparing an attack on a military base in Bavaria and of being in contact with Russian military intelligence (GRU). German Interior Minister Nancy Faeser accused the Putin regime of trying to undermine German support for Ukraine. Statements that the Russian Embassy in Berlin called a crude provocation.
- In May 2024 Polish security services arrested nine individuals of Belarusian, Ukrainian and Polish nationality, accusing them of arson and sabotage in the country. One of these fires destroyed Warsaw’s main shopping center, which housed more than a thousand small stores. Polish Prime Minister Donald Tusk accused Russia of being behind the events. That same month Poland announced that it would restrict the movements of Russian diplomatic personnel in the country as a result of the hybrid actions executed by Moscow.
- In June 2024 Czech security services arrested an individual from South America who intended to set fire to a bus park in Prague. Prime Minister Petr Fiala accused Russia of being behind the plot and linked it to the Russian hybrid campaign in Europe.
- In July 2024 German security services, alerted by U.S. intelligence, disrupted a Russian plot to assassinate Armin Papperger, CEO of the defense company Rheinmetall, which plays a major role in military supplies to Ukraine.
The list is not exhaustive because it is difficult to delimit the exact contours of what is most likely a campaign orchestrated by Russian intelligence services. At the same time, the list only includes actions involving physical harm. Numerous arrests linked to Russian espionage in Europe are not the subject of this report. Nor does it include cyberattacks against critical infrastructure that would require a separate study. For example, in April 2024 the Czech Republic’s transport minister accused Russia in an interview with the Financial Times of having carried out “thousands of cyberattacks” to interfere with the rail system in Europe. Also consistent with the pattern of physical sabotage is the Russian jamming of the GPS signal in the Baltic Sea and Estonia. An action of clear authorship, albeit with ambiguous intent (Moscow can argue that it has a defensive purpose), and which in April 2024 prompted the Finnish airline Finnair to cancel its flights to Tartu airport. Russian jamming of the GPS signal had already posed similar problems for Norwegian and Finnish commercial aviation in 2022.
In addition to these incidents, there are others where so far there is no trace pointing to Russia, although at first glance they follow a similar pattern, and despite the fact that they are mentioned (without solid grounds) in some analyses as examples of the Russian campaign. Until proven otherwise, they would be false positives in the hybrid pattern. To cite a few of them:
- In October 2022 several terrestrial fiber optic lines were sabotaged outside Marseille, an incident parallel to previous actions elsewhere in France. In July 2024, further sabotage of fiber optic networks was reported in six French territorial departments.
- In early October 2023, two submarine telecommunications cables and a gas pipeline in the Baltic Sea were ruptured, affecting Estonia, Finland and Sweden. Estonian Prime Minister Kaja Kallas claimed that this was a connected incident. In August 2024, the Chinese government acknowledged that it was an accident caused by the Hong Kong-flagged, Chinese-operated merchant ship Newnew Polar Bear. Even so, Estonian authorities did not admit the validity of this report as evidence in their own criminal investigation.
- On March 17, 2024, an explosion and subsequent fire occurred at a BAE Systems 155mm munitions manufacturing plant in Monmouthshire (South Wales, UK). The incident did not result in catastrophic damage to the facility and so far has not been proven to be sabotage. The incident attracted attention because it occurred two days after a fire broke out at a plant that also supplies artillery ammunition to Ukraine in Scranton (Pennsylvania, USA). Both episodes fit the pattern but it is perfectly plausible that they were simple accidents. In July 2024 there was also an explosion at a General Dynamics munitions manufacturing plant in Arkansas that killed one person and in which a proven connection to Russian intelligence has also not been established.
- In April 2024, a communications cable that is part of the critical infrastructure at Evenes Air Base in Norway, where its air force’s F-35 aircraft are stationed, was deliberately cut. Although this is a critical air base for the country’s air defense, the authorship of the sabotage could not be determined.
- In early May 2024, a fire broke out at an IKEA in Vilnius, Lithuania, which was quickly extinguished. Although it has been linked to the fires in Poland that same month – something implied by Polish Prime Minister Donald Tusk, Lithuanian authorities have been considerably more cautious about pointing the finger directly at Russia.
- In July 2024 a series of ‘malicious activities’ (including arson) against several major high-speed lines connecting Paris affected tens of thousands of passengers at the start of the Olympic Games. Although French authorities suspect that the perpetrators were linked to domestic far-left groups they did not completely rule out the involvement of a foreign power.
The problem with false positives is that they amplify the impact of sabotage with a certain connection to Russian services, creating the impression of a hybrid campaign that is broader and more persistent than it really is. And to further complicate the picture, we must add the sabotage of two lines of the Nord Stream 1 and 2 gas pipelines in September 2022. An action that seemed to correspond to the pattern of Russian hybrid strategies but which investigations by the Wall Street Journal and the German international broadcaster Deutsche Welle convincingly link to a Ukrainian military authorship….
The question that arises when looking at this chain of events in 2024 is why now? If we take as valid the hypothesis that they are part of a Russian hybrid strategy, the reasons would be as follows:
- The intent has been present since the beginning of the Russian invasion of Ukraine. The Ukrainian war has meant an escalation of the conflict in the already existing gray zone between Russia and NATO/EU member countries. Western military aid for Ukraine to defend itself legitimately is interpreted by Moscow as a proxy war aimed at the military attrition of Russia. Something that in the field of facts is happening: more than one hundred thousand soldiers dead, half a million wounded, more than three thousand tanks destroyed, etc. etc. etc. Therefore, for the Kremlin two motivations converge. First, one of grand strategy: Russian leaders see the war in Ukraine as part of a larger and existential confrontation where Moscow intends to redefine the international system according to its interests against the United States and Europe which, according to its vision, deny it this possibility for geopolitical reasons as well as for reasons of ‘clash of civilizations’. The second motivation is pragmatic in nature, seeking to weaken European economic and military support for Ukraine, which is an essential critical requirement of Kiev’s war effort. Without external assistance, the battlefield picture would be considerably bleaker for Ukraine than it already is today, with costly but progressive Russian advances in the Donbas that the success of this summer’s Ukrainian offensive in Kursk has failed to stem.
- Capability is what has probably shifted in Russia’s favor. From similar actions (e.g., in Bulgaria in 2011 with the sabotage of an ammunition depot destined for Georgia, and in the Czech Republic on two separate occasions in 2014 with companies supplying military materiel to Ukraine) we know that Russian actions are preceded and accompanied by intelligence and logistical support provided by Russian operatives present in the country. In the case of the attack on Czech defense companies the Czech authorities have incriminated the married couple Nikolay and Elena Šapošnikov, underlining their role both in terms of HUMINT and logistical support to GRU operatives linked to direct action. The current sabotage campaign seems to indicate that the Russian services have managed to reconstitute their intelligence network in Europe after the expulsion of dozens of legal (with diplomatic cover) and illegal operatives shortly after the invasion of Ukraine began. Expulsions that European governments had previously carried out, for example, on the occasion of the attempted assassination of Sergei and Yulia Skripal in the UK in March 2018. The regeneration of the intelligence infrastructure makes it possible to identify and select targets, directly execute sabotage or subcontract organized crime groups as intermediaries to commit such actions.
- Finally, sabotage actions – involving an escalation of the conflict in the gray zone – are synergistic with other hybrid strategies employed by Russia, such as cyber-attacks executed by APT28, and disinformation. Despite the measures adopted by the European Union and the different governments to counter Russian propaganda, the narrative promoted by the Kremlin has taken hold in broad sectors of the extreme right and extreme left in Europe. Different alternative voices have joined this dynamic spontaneously – and most probably without direct intermediation by the Russian intelligence services. From those sympathetic to all sorts of conspiracy theories to political content disseminators with dedicated audiences. The consequence is that openly hostile actions by Moscow that should become, in political and public opinion terms, an additional reason for military support to Ukraine clash with the skepticism of social segments sympathetic to the Putin regime’s narrative.
As we saw in a previous article, in countering hybrid strategies it is necessary to identify, deter and respond. The Council of the European Union has already identified the Russian sabotage campaign and has begun to respond by establishing a new framework of sanctions against individuals and entities linked to it.
Deterrence is, however, more complex. Deterrence by denial loses credibility as adequate protection of all potential targets becomes impractical. Sabotage of a given facility can be deterred by tightening its security but that will only redirect to less hardened targets. Moreover, the purpose of hybrid actions is not so much destructive as disruptive, so that even the attack against the security perimeter of a critical infrastructure – properly publicized – is sufficient to cause second- and third-order impacts in the economic, social or information sphere.
On the other hand, retaliatory deterrence faces the fact that, after more than two and a half years of military support to Kiev and numerous economic sanctions packages, there is little left to threaten the Russian government with. Moreover, all these coercive measures have not conditioned the central aspects of Russian policy regarding the war in Ukraine or the use of hybrid strategies against European countries, something that is evidenced by the very campaign we are analyzing. An alternative would be to threaten to lift the veto on Ukraine’s use of European long-range munitions (Storm Shadow/SCALP missiles) against targets on Russian territory if Moscow continues the chain of sabotage. But such a decision would mean crossing a red line that on this occasion President Putin has expressly described as a casus belli. A risk difficult to take.
Therefore, the burden of the response falls primarily on police and counterintelligence action aimed at uncovering and neutralizing the SVR and GRU networks in Europe. An action that should at the same time be accompanied by strategic communication to generate awareness of the threat in European societies and to convey a message of strength in the face of the intimidating and socially divisive purpose pursued by hybrid strategies.
Additional references
Cózar Murillo Beatriz y Villanueva López, Christian D. (ed.), La guerra de Ucrania III: De la reconquista de Jersón al estancamiento, Madrid: Catarata/Ejércitos.
Jordán, Javier (2022), “La disuasión en la zona gris: una exploración teórica”, Revista Española de Ciencia Política, No 59, pp. 65-88.
Kubica, Lucjan (2024), Ukraine’s position in Russia’s strategic thinking: Domestic, regional and international order, Hybrid CoE Paper 20.
Richterova, Daniela (2024), “The Long Shadow of Soviet Sabotage Doctrine?”, War on the Rocks, August 19.
Soldatov, Andrei & Borogan, Irina (2024), “Putin’s New Agents of Chaos. How Russia’s Growing Squad of Saboteurs and Assassins Threatens the West”, Foreign Affairs, August 9.
Watling, Jack, Danylyuk, Oleksandr V & Reynolds, Nick (2024), The Threat from Russia’s Unconventional Warfare Beyond Ukraine, 2022–24. RUSI Special Report.

