The Disposable Agents

Share

What Moscow's outsourcing of sabotage tells us about the EU's security architecture
By Our Brussels Correspondent

On 1 September 2026, the German government formally accused Russia of an attempted drone attack on Leipzig/Halle airport. The target was not a military installation. It was a cargo hub — the primary logistics facility through which NATO member states route military equipment to Ukraine. Six drones flew over the facility for seven hours. They were observed by police and military personnel. The background, German authorities said at the time, was unclear. On 1 September, the background became clear. German investigators have since identified two suspects: Oleg L., a Russian national whose DNA was found at the scene and who was recognised as a GRU operative when he entered Germany at Berlin airport on a flight from Turkey, and Belarusian Andrei K., suspected of involvement in a separate arson attack in Poland. Oleg L. was not placed under surveillance after entering Germany. The question of why a known GRU operative was allowed to enter and move freely within Germany without surveillance has not been answered. It joins the others.

The Leipzig attack is one of a documented series. German prosecutors have charged two Ukrainian men for their role in an alleged Russian plot to blow up postal depots — sending parcels containing GPS trackers to map logistics routes, with explosive packages to follow. Three parcels from a related Lithuanian cell had already ignited at warehouses in Leipzig, Birmingham and Warsaw before the plot was uncovered; German prosecutors say the bombs were, in their formulation, "a dry run" for a plan to bring down airlines crossing the Atlantic. In Poland, a bomb placed on the Warsaw-Lublin railway line in November could have caused dozens of deaths; the derailment of a crowded passenger train was averted by the driver. In Serbia, two men arrested in June at the Hungarian border were found to be carrying drone components, explosive material hidden in a "bunker" compartment of their vehicle, and documents that did not bear their names. German investigators have since linked both cases and described the men as part of a broader Russian sabotage network. In Lithuania, prosecutors have charged fifteen individuals for their role in a separate parcel bomb plot. These are not isolated incidents. They are a campaign.

What distinguishes this campaign from previous Russian intelligence operations in Europe is its method of recruitment. Faced with a depleted network of trained undercover operatives following the mass expulsions of 2022, Moscow has turned to proxies — recruiting from criminal networks, disillusioned young men, and what German security officials describe as "disposable agents." Missions are contracted out via Telegram for cash lump sums. The approach, as one official told the Financial Times, "lacks sophistication" but "makes up for it in mass." Consider Danilo B., one of the two men arrested at the Serbian-Hungarian border. He is a 35-year-old Belgrade resident who had been living and working in St Petersburg. He studied political science and economics in Belgrade and participated in debates at the Aleksandr Gorchakov Public Diplomacy Support Fund, a Russian state institution founded by the Ministry of Foreign Affairs. His online profile states that he "invests in stocks and cryptocurrencies." A drone was found on the back seat of his Peugeot. He defended himself in silence before the prosecutor.

The European Union's response to this campaign is distributed across twenty-seven member states, each with its own counter-intelligence architecture, its own thresholds for attribution, and its own political calculations about how loudly to name Russia. Germany formally attributed the Leipzig attack on 1 September. Other member states have been slower, or quieter, or both. The EU has no centralised intelligence agency. It has Europol, whose mandate covers organised crime and terrorism. It has the EU Intelligence and Situation Centre, INTCEN, which analyses rather than collects intelligence, depends entirely on what member states choose to share with it, has been described by its own overseers as "toothless," and — this publication can report — has no formal legal basis for its establishment and no publicly available mandate document, facts confirmed by the European External Action Service when asked directly. Within INTCEN sits the EU Hybrid Fusion Cell, established in April 2016, specifically designed to gather and analyse information on hybrid threats from member states — a function that depends, like INTCEN itself, entirely on what member states choose to share. None of these institutions has a mandate to respond operationally to what Germany's government has formally described as a Russian attack on EU territory. The Commission has issued no statement on the Leipzig attribution. The Commission did, however, describe Hungary's expulsion of ten Russian diplomats on 8 September as "an expected reaction due to Russia's persistent campaign in using hybrid attacks against the EU and its member states" — a formulation that raises the question of why the same campaign, documented across six EU member states in a single quarter, has not produced an equivalent statement about Leipzig. The High Representative for Foreign Affairs and Security Policy has noted that the situation is being monitored. INTCEN, which has no mandate, is monitoring it.

Between June and September 2026, Russian-linked operatives have been arrested in Serbia, charged in Germany and Lithuania, linked to attacks in Poland, the United Kingdom and Germany, and formally attributed by one EU member state government to Russian intelligence. The documented scale of the campaign across EU territory in a single quarter has not produced a coordinated EU institutional response, a common attribution statement, or a review of the adequacy of existing security architecture. It has produced, from the Commission, a statement that the situation is being monitored. The Hybrid Fusion Cell, whose function is to monitor hybrid threats, is monitoring. INTCEN, which has no mandate, is monitoring. Danilo B., who invests in stocks and cryptocurrencies, is in custody in Serbia. His replacement, whose online profile has not yet been reviewed, is presumably elsewhere.