Skip to content

Europe

Independent · Brussels & Berlin

Europe · European security

Russian sabotage across Europe exposes intelligence sharing failures

Moscow is running a single covert campaign against NATO states, but fragmented cooperation between Kyiv and European capitals is leaving gaps that Russian operatives are exploiting

By , Energy and Industry Correspondent

Published

8 min read

Denmark's domestic intelligence service, PET, has issued a public warning: Russia is actively preparing sabotage operations on Danish soil, with companies connected to defence manufacturing and military logistics for Ukraine among the intended targets. The assessment, delivered in late summer 2026, is not an isolated alert. It fits a pattern of escalating Russian covert activity that stretches from the Baltic states through Poland and into Scandinavia, a campaign designed to slow arms shipments to Kyiv and demonstrate that NATO territory is vulnerable even without conventional military incursion.

A single campaign, fragmented defences

Russian sabotage in Europe is not a collection of unrelated incidents. Arson attacks on warehouses in Poland, reconnaissance of defence factories in Denmark, suspicious activity around transport infrastructure in the Baltic states, and online recruitment of operatives through Telegram all belong to one coordinated effort. Moscow does not compartmentalise its operations along national borders. European intelligence services, however, have been slower to adopt the same integrated approach.

The consequences are visible. A person flagged for suspected recruitment by Russian intelligence in one country can appear days later in another, operating freely because the warning never crossed a desk in time. Intelligence that sits inside a single agency, or inside a single national bureaucracy, gives Moscow room to move. The problem is structural: European security cooperation depends heavily on political declarations of solidarity, but the day-to-day exchange of operational information between services remains inconsistent and, at times, obstructed by institutional rivalry.

How Russia builds disposable agents

The recruitment model PET describes follows a template already observed in Poland and the Baltic states. Russian intelligence services identify individuals online, often through Telegram channels or other messaging platforms, and approach them with small, apparently low-risk tasks. Photograph a facility. Check when deliveries arrive. Observe which entrance has the weakest security. The initial requests look like minor errands, the kind of thing a person might do for a few hundred euros without considering the legal exposure.

Once a recruit has taken the first step, the assignments escalate. Set fire to a warehouse. Damage a railway signal box. Identify access points for a future operation. By the time the operative understands what they have become part of, they are already compromised, and Russian handlers have enough leverage to push further. The model depends on disposability: if an operative is caught, they lead investigators back only to a Telegram account, not to an officer in Moscow.

The nationality of those detained matters less than it appears. A significant number of people arrested in connection with sabotage or its preparation have been Ukrainian citizens or individuals travelling on Ukrainian passports. Russia's intelligence services deliberately recruit across nationalities, Ukrainians, Belarusians, Russians living in the EU, and citizens of host countries. An operative carrying a Ukrainian passport provides Moscow with two advantages: practical deniability, and an opportunity for Russian information operations to redirect blame towards Kyiv. A Ukrainian passport does not make an operation Ukrainian any more than a Russian passport makes it Russian. The control lies with whoever runs the network.

The breakdown inside Kyiv

If European intelligence sharing is imperfect, the situation inside Ukraine itself is hardly better. In a remarkable illustration of the problem, two of Ukraine's most important security structures, the Security Service of Ukraine (SBU) and the Main Directorate of Intelligence (HUR), ended up in an armed confrontation in Kyiv. Three HUR personnel were wounded. Both institutions subsequently issued conflicting accounts of what happened.

This is not a routine bureaucratic turf war. Ukraine is fighting a full-scale war against Russia, and its two principal intelligence and security bodies are shooting at each other. Whatever the investigation eventually concludes about the incident, the immediate effect is corrosive. Trust between institutions that should be coordinating against a single adversary has been damaged. Information that should flow between SBU and HUR now moves more slowly, or not at all. And if Ukraine's own services cannot cooperate with each other, European partners have reason to question how reliably intelligence will be shared outward.

What Kyiv withholds from its neighbours

The SBU-HUR confrontation is a symptom of a wider problem. Ukraine has not consistently shared all available intelligence on individuals involved in Russian recruitment networks or suspected sabotage operations with its European counterparts. A person under surveillance in Ukraine can travel to Poland, Lithuania, Germany or Denmark, and if the relevant files have not been transmitted, that person arrives in a new country as an unknown quantity.

The reasons for this withholding are various. Some of it stems from institutional habit: intelligence services everywhere guard their sources. Some reflects genuine concern about operational security, particularly when sharing information that might reveal how Ukraine collects intelligence on Russian networks. Some, frankly, reflects the disorganisation and rivalry that the SBU-HUR incident laid bare. But the effect is the same regardless of motive. Every hour that intelligence remains inside one agency or one country is an hour that Russian operatives can exploit.

Why proximity matters more than size

Britain's Secret Intelligence Service (MI6) and France's Direction Générale de la Sécurité Extérieure (DGSE) bring resources, global reach and technical capabilities that smaller European services cannot match. But the most valuable intelligence on Russian operations often comes from agencies that sit geographically and historically closer to Moscow. Poland's services, the Baltic intelligence structures, Denmark's PET, Sweden's security apparatus, and Ukraine's own networks have spent years, in some cases decades, studying Russian methods, identifying recruitment patterns and tracking operatives who move across borders.

These are not junior partners. They are frequently the first to detect new recruitment techniques, new target selections and new network configurations. A service in Tallinn or Warsaw may spot a pattern that London or Paris would take months to identify, simply because the threat is more immediate and the historical familiarity with Russian operational habits runs deeper. The combination matters: Western European services bring scale, Central and Eastern European services bring proximity and experience. Neither alone is sufficient.

The impossibility of guarding everything

Europe cannot place soldiers at every railway junction, warehouse, bridge, port and defence plant. The continent's logistics infrastructure is too vast and too open to be sealed by military patrols. Effective defence against Russian sabotage requires disruption at an earlier stage: during recruitment, during reconnaissance, during financing, during preparation. That demands precisely the kind of rapid, cross-border intelligence exchange that is currently patchy.

The asymmetry favours Moscow. Russia is running its sabotage campaign as one system, with direction from the centre and operatives who move across European borders. Europe responds through more than two dozen national intelligence services, each with its own institutional culture, legal framework and sense of how much to share and when. The Danish alert, the arrests in Poland, the incidents in the Baltic states, these are all manifestations of the same campaign. Treating them as separate national problems is exactly what Moscow hopes European governments will do.

The challenge for European governments is not a lack of information. It is a lack of mechanism. Political commitments to intelligence sharing exist on paper, but the speed and depth of operational exchange between, say, Kyiv and Copenhagen, or Tallinn and Paris, depends on relationships built over years and on institutional cultures that prioritise protecting sources over distributing warnings. Russia has no such hesitation. Its operatives recruit, move and act across borders with a fluidity that European services have not yet matched.

Sources

  1. Defence24.com

    defence24.com · 2026-09-03

Organisations

Security Service of Ukraine · Main Directorate of Intelligence of Ukraine · Secret Intelligence Service · Direction Générale de la Sécurité Extérieure · Danish Security and Intelligence Service

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.