What was, as recently as a year ago, still being characterised as a nuisance of “pin prick”, low-level attacks against soft European targets is now being interpreted as a far more serious threat. 

To frontline states such as Poland, for example, it is already a matter of fact that Russia now poses as great a threat to civilian life in Europe as does Islamist terrorism, the main preoccupation of domestic intelligence agencies on the continent over the past two decades. 

[…]

More detailed, recent assessments of Russian sabotage actions in Europe, another official says, are increasingly being considered in the light of a Nato 2023 Joint Threat Assessment — a classified report shared among the alliances’ defence chiefs — that Russia was gearing its military and economy for a possible hot war with Europe by 2029. 

But it is a thorny topic. By its nature, Russia’s sabotage campaign in Europe is diffuse and hard to read. Aggressive but ultimately clumsy attempts to sow chaos might yet be reflective of the dynamics inherent in a sprawling, authoritarian state, in which every officer is desperately trying to show initiative and accomplishment to superiors, rather than revealing any doctrine or plan.

Officials and lawmakers are also wary of doing Russia’s job for it: public fear, policy paralysis and the tying up of valuable investigative resources are, all agree, one of the campaign’s main objectives.

[…]

Through messaging apps like Telegram and Viber, Russian recruiters can reach huge potential pools of willing individuals. 

Just like in the legitimate gig economy, Earl was eager to leverage his own network of criminal contacts to help establish his usefulness for his “client” and ensure more work would come his way. “They have a warehouse in Czech Republic to burn for 35 thousand,” he wrote to a drug dealer contact shortly after setting the blaze in London.

It is the sheer number of such attacks, rather than granular detail about each individual instance, that is now enabling European intelligence agencies to see patterns, drawing connections between events even in cases where no Russian involvement has been proved, disclosed or detected. 

For example: three individuals — two Ukrainians and a Romanian — have been charged with setting fires at properties and a car linked to UK Prime Minister Sir Keir Starmer this May. Prosecutors have not mentioned any connection to Russia.

But from an intelligence perspective, it is notable that elsewhere in Europe politicians’ cars and properties have been targeted in near identical circumstances, particularly in Estonia, which borders Russia and where Britain has its largest contingent of troops deployed on the continent. 

[…]

“There is always this demand for a smoking gun, which is understandable, and legally of course also correct. [But] does the logic of in dubio pro reo [let doubt favour the accused] have to be suspended somehow when we’re dealing with hybrid warfare? Do we need to have the courage to name what we’re dealing with without being able to prove it down to the very last legal detail?” [says Konstantin von Notz, a member and former chair of the German parliamentary committee that supervises the country’s intelligence agencies.]

In October, a Finnish court dismissed a case against the captain and senior crew of the Eagle S, a Russian-linked tanker that had dragged its anchor for 90km back and forth over the bed of the Baltic Sea, breaking five undersea cables. The cost of repairing one of them — the Estlink 2, a key electricity link between Finland and Estonia, will run to at least €60mn and take months to complete.

The crew claimed a mechanical failure in the anchor winch was responsible. The court eventually found it had no jurisdiction, ruling that instead, any prosecution would have to take place in the vessels’ flag state: the Cook Islands. The Finnish government now faces a €195,000 legal bill.

It is exactly such legal, jurisdictional and political grey areas that Russia is seeking to exploit in its sabotage campaign, and to widen.

The danger, says, von Notz, is that European governments become paralysed by their own rules. Instead, they need to become far more aggressive in tackling the problem head on. And calling it out.

One key to understanding Russia’s current objectives in Europe can be found in recent history.

Thanks to intelligence troves such as the vast set of notes on KGB files brought to Britain by Vasily Mitrokhin in 1992, and the archive of the Czechoslovak secret police StB, preserved largely intact in Prague, a remarkable amount is known about Soviet-era sabotage tradecraft and doctrine.

And there are a “number of striking continuities between what Soviet bloc intelligence services were planning for during the cold war and what we appear to see happening now,” says Daniela Richterova, co-director of the King’s Centre for the Study of Intelligence in London.

Take, for example, the operational “families” of targets stipulated by the StB in the 1970s. “It’s almost like a shopping list,” Richterova says. Seven groups of targets are identified, ranging from military bases to reservoirs and communications systems. 

“We have seen almost all of these same operational targets attacked or attempted in the last two years,” says Richterova. 

Further, the files suggest how and why activity is escalated. “The archival documents explicitly say there is a doctrinal separation for each stage of tension,” Richterova says. “During peace time, Russian intelligence aims to carry out smaller scale and more subtle attacks which are supposed to look like accidents. Random fires and vandalism and so on. During an actual war they would meanwhile activate a range of agents saboteurs to carry out all kinds of destructive actions.”

Where Europe finds itself now aligns with a middle “prewar” phase stipulated in the StB files, Richterova says. 

The same range of low-level deniable and disruptive attacks takes place, albeit at greater scale, but these come augmented with a range of attacks designed both to show mettle, and also to cause panic about Russian ability and willingness to cause harm. That includes a greatly expanded tolerance for civilian casualties.

But a third objective exists alongside these: attacks and operations as reconnaissance. 

Russian military intelligence doctrine leans heavily on the idea of razvedka boyem — reconnaissance through battle — in which information is found out about an enemy’s weaknesses by constantly probing and testing for them. And when you find a weakness, you continue to push. “Reinforce success” is an idea drummed into students at Russian military intelligence academies. 

This helps explain the spate of drone incursions over European soil, which began in September when over a dozen flew into Poland, closing several airports. Sightings have since been reported in Belgium, Denmark, Germany and others, near military bases or airports.

An aggressive tactic revealed — perhaps surprisingly even to Russia — a major vulnerability that can be exploited continent-wide with little cost.

[…]

Discussions around what effective deterrence might look like are in their early stages. European states have just begun to hold regular meetings between senior national security officials to specifically tackle the issue.

“Containment is not enough,” declared Italy’s minister of defence, Guido Crosetto, in the preface to a white paper on the subject last month.

What being proactive looks like, however, is still a sensitive topic. Many responses are on the table, from further sanctions to retaliatory cyber attacks.

Fundamentally, however, many in European Nato still fear any course that they perceive as inflammatory, particularly at a time when Washington is going all out to try and de-escalate — even if that means selling out its allies.

“Europe has tied itself in knots in terms of what it can do to respond,” says Giles. “The assumption still holds that you will never have escalation dominance with Russia . . . but it’s complete nonsense. It’s nonsense that Putin never de-escalates.”

Posted by IHateTrains123

1 Comment

  1. A long and detailed piece by the Financial Times that details the growing grey war being waged by Russia against Europe. In this grey war Russia recruits saboteurs online and have used them to conduct a series of disruptive actions ranging from [arson](https://www.bbc.com/news/articles/c04g5x1wq5vo) to [bombing busy railroad tracks](https://www.theguardian.com/world/2025/nov/18/ukrainians-working-for-russia-rail-blasts-says-poland-prime-minister-donald-tusk).

    Yet this campaign has been documented by the media since 2024, instead the novelty of the article is in explaining the challenges involved in countering this threat. Principally legal, jurisdictional and political grey areas are being exploited by the Russians to thwart a European response.

    Such as the latest case against the crew of the Eagle S, a Russia linked tanker that severed five undersea cables, was thrown out by a Finnish court citing jurisdictional problems. Similarly a recent case that saw the prosecution of two Ukrainians and a Romanian, for setting Keir Starmer’s house and car on fire, did not mention any connection to Russia.

    The challenge of course is what is the best practice to countering this continual and possibly growing threat.

    Archived version for those that want to read the full article: [Russia’s hybrid warfare puts Europe to the test](https://archive.fo/FvmAV)

    !ping Europe&Foreign-policy

Leave A Reply