JupiteX Get the app
Defence & Security11 Oct 2026 · about 6 min

Russian Sabotage in Europe Is No Longer ‘Symbolic’

The brief

State-sponsored sabotage is deliberate damage or disruption carried out for a government’s strategic goals, directly or through recruited intermediaries. It matters because it can weaken an opponent while disguising who ordered the attack. The article describes a move from visible intimidation toward operations that could affect Ukraine’s military support. Earlier attacks focused on symbolic objects. Russian-linked operatives vandalized opinion-makers’ cars, burned Ukrainian flags, and set fire to a Ukrainian restaurant. The August attack on Estonian robotics company Milrem was different. The company supplies Ukraine’s military, so the suspected aim was to disrupt, restrict, or cancel those deliveries. The danger is increasing because operations now increasingly involve explosives. That raises the possibility of civilian injuries and mass casualties, not only property damage. Estonia is advising defense companies on physical security, while European governments are considering whether their legal powers are strong enough to confront state-backed sabotage.

01

What is state-sponsored sabotage, and how is it different from earlier attacks on symbolic targets such as flags, cars, and restaurants?

State-sponsored sabotage is deliberate damage or disruption carried out for a government’s strategic goals, directly or through recruited intermediaries. It matters because it can weaken an opponent while disguising who ordered the attack. The article describes a move from visible intimidation toward operations that could affect Ukraine’s military support.

Earlier attacks focused on symbolic objects. Russian-linked operatives vandalized opinion-makers’ cars, burned Ukrainian flags, and set fire to a Ukrainian restaurant. The August attack on Estonian robotics company Milrem was different. The company supplies Ukraine’s military, so the suspected aim was to disrupt, restrict, or cancel those deliveries.

The danger is increasing because operations now increasingly involve explosives. That raises the possibility of civilian injuries and mass casualties, not only property damage. Estonia is advising defense companies on physical security, while European governments are considering whether their legal powers are strong enough to confront state-backed sabotage.

02

What kinds of targets are Russian-directed saboteurs now attacking in Europe, and how does the Milrem case show a shift toward disrupting military supplies to Ukraine?

The reported targets now include defense firms and companies connected to military supplies for Ukraine. Russia has also targeted defense firms in Denmark, according to Reuters, while an attempted explosive attack involved a plane in Germany. These cases point to pressure on infrastructure that supports Ukraine rather than simply sending political messages.

Milrem provides robotics to Ukraine’s military forces. Estonia’s counterintelligence chief said the August attack marked a new phase because its apparent purpose was to disrupt, restrict, or cancel supplies. The key mechanism is practical interference: damaging or threatening a supplier can slow deliveries, raise security costs, or stop cooperation.

This shift matters because it connects sabotage to the battlefield. The article presents the campaign as emerging while Ukraine stymies or pushes back Russia. Danish officials warned that sabotage and other attacks could increase, and Estonia is working with defense companies on physical security to protect the supply network.

03

How large is Estonia’s counterintelligence response, including the 20 people arrested since 2025 and the networks described as having up to seven layers of intermediaries?

Estonia’s response combines arrests, border screening, and cooperation with businesses. Since 2025, its authorities have arrested 20 people who traveled to Russia and were then recruited by Russian intelligence. They were civilians, not military or intelligence personnel, and Russia could have directed them toward useful jobs inside Estonia.

The networks are deliberately difficult to trace. Russia increasingly uses criminal groups, amateurs, and Ukrainians recruited through social media. Palloson said there may be as many as seven layers of intermediaries between Russia and a saboteur. Each layer can obscure the order, payment, or relationship linking an operation to the Kremlin.

The scale described is significant, but the article gives no total number of sabotage cases or suspects across Europe. Estonia is also advising defense companies about physical security. Palloson said he was comfortable with Estonia’s response and legal framework, while some European colleagues wanted stronger legal tools.

04

What could happen if sabotage increasingly involves explosives and targets defense companies, transportation, or other civilian-connected infrastructure?

Explosives make sabotage more dangerous because they can injure or kill people, not merely damage property. The article notes that European Union ambassadors discussed the possibility of a mass-casualty event caused by sabotage or other state-sponsored violence. Civilian-connected sites can expose people who are not involved in the conflict.

Defense companies are especially important because they support Ukraine’s military. The Milrem attack allegedly sought to disrupt, restrict, or cancel supplies. The attempted explosive attack on a plane in Germany shows how transportation could become part of the threat. Damage or fear around such sites could delay deliveries, disrupt travel, and force companies to spend more on protection.

European governments are responding, but their capacity differs. Estonia is giving companies physical-security advice, and Palloson said its legal framework was adequate. Some European officials believe they lack sufficient powers, while Danish officials expect sabotage and related attacks to increase in coming months.

05

Why would Russia use criminal groups, social-media recruits, and civilians who may not know their true employer instead of sending openly identifiable intelligence officers?

Russia can use criminal groups, amateurs, and civilians because they are harder to identify as state agents. This gives Moscow distance from an operation and makes investigators prove the connection. It also expands the pool of people who can perform simple tasks, rather than relying only on trained intelligence officers.

The article describes Ukrainians recruited through social media who may not know their true employer. Some reportedly believe they are working for Ukraine’s own internal security service. Palloson said networks can contain up to seven intermediary layers between Russia and the saboteur. Criminal groups may also propose new operations to Russia as a way to earn money.

This system complicates prevention and attribution. A recruited person may be motivated by payment, deception, or both, while the organizers remain hidden. Estonia has arrested civilians recruited after traveling to Russia, but Palloson said the growing use of layered networks makes potential saboteurs and spies harder to track.

06

How did Russian security services prepare the ground for the 2022 invasion of Ukraine, and what lessons is Estonia applying to protect itself?

The article says Russian security services prepared Ukraine for invasion by sending assassination squads ahead of time and bribing Ukrainian officials. The intended effect was to make a takeover easier by removing threats and weakening resistance inside the country. This background explains why Estonia treats espionage and sabotage as preparation, not merely isolated criminal acts.

Estonia is watching people who travel to Russia and may be recruited there. Since 2025, it has arrested 20 civilians suspected of being recruited by Russian intelligence. The government is also liaising with the defense sector and giving companies advice on physical security. These measures address both human networks and vulnerable supply businesses.

The country is also examining whether its legal tools are sufficient, although Palloson said he was comfortable with Estonia’s current framework. The broader lesson is to detect hidden networks early, protect strategically important companies, and prevent hostile actors from building influence before a crisis.

07

What is counterintelligence, and how does it protect a country from espionage, influence operations, and sabotage?

Counterintelligence is the work of detecting and stopping foreign intelligence activity. It includes identifying recruited agents, uncovering covert influence, protecting sensitive institutions, and disrupting sabotage plans. It matters because hostile states may use ordinary civilians or criminal networks, making threats difficult to recognize before damage occurs.

Estonia’s service illustrates several tools. Since 2025, authorities have arrested 20 people who traveled to Russia and were recruited by Russian intelligence. The government is liaising with defense companies and advising them on physical security. Investigators also face networks with up to seven intermediary layers, which can conceal the connection to Russia.

Counterintelligence therefore combines investigation, prevention, and coordination. Estonia is stopping suspected espionage at its border while helping companies protect important facilities and supplies. The article also notes a legal challenge: some European colleagues believe they lack the powers needed to handle these operations effectively.

This brief was written by AI from the original reporting and checked by other models. Names, figures and quotes come from the source; read it for full context.

Read more in the JupiteX app

Pulse is free. New stories every 4 hours, each one broken into the questions that explain it.

Or read more news on the web