A series of fires, attempted attacks and suspicious disruptions across Europe has raised fears that Russia is intensifying its campaign of sabotage against countries supporting Ukraine. Airports, defence companies, energy networks and logistics infrastructure appear to be among the most exposed targets.
The latest warning came from Denmark. On Thursday, the Danish Security and Intelligence Service, PET, said Russian intelligence services were actively preparing acts of sabotage against Danish defence companies connected to Ukraine. According to PET, Russian operatives have attempted to recruit Danish citizens through social media and gaming platforms, initially asking them to photograph companies or critical infrastructure. Such information could later be used to plan attacks. (Reuters)
The Danish statement followed Germany’s formal accusation that Russia was responsible for an attempted attack at Leipzig/Halle Airport in August. An explosive-laden drone was discovered in a restricted cargo area close to one of the airport’s runways. The incident forced a temporary suspension of flights at one of Europe’s largest cargo hubs, which is used by DHL and Ukraine’s Antonov Airlines.
After analysing police evidence, intelligence findings and similarities with previous operations, the German government concluded that the people involved had acted on behalf of Russian state agencies. Foreign Minister Johann Wadephul said the incident was not isolated but formed part of a broader pattern of Russian hybrid operations in Europe. (Reuters)
Berlin responded by announcing the closure of the Russian consulate in Bonn and ending its agreement with the Russian House cultural centre in Berlin. Germany also intends to seek additional EU sanctions and tighter travel restrictions against people linked to Russian state institutions.
EU foreign policy chief Kaja Kallas described the Leipzig incident as bearing the hallmarks of state-sponsored terrorism. European foreign ministers are now discussing additional sanctions and other coordinated measures. Lithuanian Foreign Minister Kęstutis Budrys warned that sabotage remains an inexpensive way for Moscow to create fear, increase social tensions and test the political resolve of European governments. (Reuters)
Defence companies in Poland and Estonia targeted
Concern has also increased sharply in Poland after a deliberate fire at a WB Electronics facility in Skarżysko-Kamienna. The company produces components for unmanned systems used by the Polish and Ukrainian armed forces.
Investigators said an incendiary device had been planted at the site. The fire destroyed warehouse facilities and caused damage estimated at no less than PLN 15 million. Prosecutors opened an investigation into both a terrorist offence and possible cooperation with a foreign intelligence service. However, Polish authorities have not yet publicly attributed the attack to Russia.
A second fire occurred within 24 hours at a warehouse in Lublin belonging to a company producing aircraft components. Officials are examining whether the incidents could be connected, but no such link has been confirmed. (Euronews)
A similar investigation is underway in Estonia. In August, a building used by Milrem Robotics, a manufacturer of unmanned military vehicles deployed in Ukraine, was targeted in an arson attack. Estonian Prime Minister Kristen Michal said the suspects had been identified and that investigators were examining possible Russian involvement. The company said the incident had not disrupted its production or deliveries to Ukraine. (Reuters)
Together, the Polish and Estonian cases suggest that European companies supplying Ukraine may have become particularly important targets. Even relatively small attacks can increase security costs, delay production and force governments to divert resources towards protecting factories, warehouses and transport routes.
Critical infrastructure under pressure
The danger is not limited to the defence industry. German authorities are investigating sabotage against two electricity substations.
At Turnow-Preilack in Brandenburg, specially constructed devices fired conductive material into high-voltage power lines, causing short circuits and temporarily shutting down a unit at the nearby Jänschwalde power plant. More than ten devices were reportedly discovered. The regional interior minister said the operation required considerable preparation and did not rule out either a foreign state or domestic extremists. (Reuters)
Another deliberate disruption occurred near Bergheim in western Germany, where cables were reportedly stretched across power lines. Five generating units were temporarily taken offline. The investigations remain open, and there is currently no evidence establishing that Russia was responsible for either attack. Nevertheless, their timing has reinforced concerns about the vulnerability of Europe’s energy infrastructure. (apnews.com)
A war conducted below the threshold of open conflict
The emerging pattern is characteristic of hybrid warfare. Rather than launching a conventional attack, an aggressor combines sabotage, cyberattacks, disinformation, espionage, drone incursions and the recruitment of local criminals or inexperienced intermediaries.
These operations offer several advantages. They are relatively inexpensive, difficult to attribute quickly and can be calibrated to remain below the threshold that might trigger NATO’s collective-defence mechanisms. They can also create confusion by making it difficult to distinguish between an accident, domestic extremism, ordinary crime and a state-directed operation.
The likely objectives extend beyond destroying individual facilities. Sabotage can obstruct military assistance to Ukraine, expose weaknesses in European security systems, increase public anxiety and encourage political divisions over the costs of supporting Kyiv.
European institutions say such incidents belong to a broader pattern of increasingly aggressive Russian behaviour. The EU has recorded activities ranging from incendiary devices in air cargo and attacks on underwater infrastructure to cyber operations, assassination plots and violations of European airspace. (EEAS)
Russia has repeatedly denied organising sabotage in Europe and describes Western accusations as politically motivated or part of an anti-Russian campaign. Attribution therefore remains crucial: authorities must avoid treating every unexplained fire or technical failure as a Russian operation. At the same time, the growing number of cases involving similar targets and methods makes it increasingly difficult to regard them as isolated events.
NATO says it sees no imminent threat of a conventional Russian attack on an alliance member. However, it has also confirmed that Moscow is intensifying hybrid activity in Europe. The distinction is important: the immediate danger may not be an invasion, but a prolonged campaign of disruption designed to weaken European countries without crossing clearly established boundaries of war. (Reuters)
Europe is therefore entering a period in which the protection of power grids, airports, ports, defence factories and digital networks will be as important as traditional military deterrence. The latest incidents suggest that the confrontation with Russia is no longer confined to Ukraine’s battlefields. It is increasingly being fought quietly inside Europe—through fires, drones, recruited intermediaries and attacks whose organisers expect to remain hidden.

