Russia’s Shadow War: Criminal Networks Used to Attack Europe’s Defence Industry

RKS NEWS
RKS NEWS 5 Min Read
5 Min Read

Russia is increasingly accused of taking its hybrid war deep into Europe, using criminal networks and recruited operatives to target defence companies, military facilities and businesses supporting Ukraine.

Western intelligence assessments cited in recent reports indicate that the Kremlin is relying on proxies to carry out sabotage, allowing Russian intelligence services to strike European targets while attempting to conceal Moscow’s direct involvement.

The alleged strategy is straightforward: damage European defence capabilities, intimidate countries supporting Ukraine and create disruption — while leaving behind enough distance for the Kremlin to deny responsibility.

One of the latest cases emerged in Slovakia, where police reportedly stopped an attempted arson attack at a drone-production facility operated by Ukrainian company Skyeton in Prešov. Suspects were detained as investigators examined whether the incident was connected to a broader Russian-backed sabotage campaign.

It is not an isolated concern. European authorities have investigated a growing number of suspicious incidents involving defence-related facilities, including a fire at Estonia’s Milrem Robotics and incidents at military-industrial sites in Bulgaria and Italy. Not every case has been publicly proven to have a Russian connection, but European security agencies increasingly view sabotage as part of a wider pattern of hostile activity.

Moscow’s use of proxies

The most disturbing element is the reported use of criminals as disposable agents.

Rather than sending identifiable Russian operatives into European countries, intelligence networks are suspected of recruiting people through criminal circles and online platforms to carry out tasks such as arson and sabotage.

This gives Moscow what intelligence officials describe as plausible deniability: the Kremlin can attempt to distance itself from the attack while still achieving the strategic effect.

The message behind the tactic is clear — Europe can be targeted from within, without the attacker necessarily carrying a Russian passport.

GRU’s Unit 29155

At the centre of years of Western investigations has been Unit 29155 of Russia’s military intelligence service, the GRU.

The unit has been linked by Western governments and investigators to covert operations abroad, including sabotage, assassination attempts and attacks on military-related facilities. One of the most prominent cases was the 2014 explosions at ammunition depots in Vrbětice, Czechia, which Czech authorities later attributed to Russian GRU operatives.

The evolution from deploying intelligence officers to recruiting local proxies represents an even more aggressive form of hybrid warfare: Russia can attack European interests while attempting to hide behind criminals, intermediaries and deniable networks.

Europe is being tested

The targets are not random.

Defence factories, drone manufacturers, ammunition plants and companies supplying Ukraine represent precisely the infrastructure Russia has a strategic interest in disrupting.

The objective goes beyond physical damage. Sabotage can slow weapons production, increase security costs, spread fear among workers and businesses, and test how far European governments are prepared to respond.

Recent reporting has even suggested that Russian-linked operations are being designed to remain below the threshold that could trigger a direct military response from NATO.

That is what makes the strategy particularly dangerous.

Russia does not necessarily need to launch missiles at European factories to wage war against them. It can allegedly recruit criminals, exploit vulnerabilities and turn Europe’s own criminal networks into instruments of state power.

This is no longer simply a war fought on Ukrainian territory. It is an increasingly aggressive campaign of pressure, disruption and intimidation aimed at the European states standing behind Ukraine.

And the more Moscow relies on deniable proxies, the harder it becomes for Europe to treat each incident as an isolated crime rather than what intelligence agencies increasingly describe as a broader Russian hybrid campaign.