The Financial Times reports this, citing data from five European intelligence agencies.
What is known about the threat to executives of defense companies in Europe?
According to the publication’s sources, the Kremlin has ordered an expansion of sabotage and hybrid operations in Europe amid the war against Ukraine and economic difficulties in Russia. The heads of major defense conglomerates, as well as small companies that manufacture drones and drone components, have become potential targets of Russian intelligence services.
Sinan Selen, head of Germany’s Federal Office for the Protection of the Constitution (BfV), confirmed the threat of targeted violent actions. Speaking before members of the Bundestag, he stated that Russia is planning attacks on specific individuals with the involvement of state agencies or operatives under its control.
According to FT sources, Russia’s military intelligence agency, the GRU, plays a leading role in preparing such operations. Its operatives are increasingly collaborating with criminal groups and intelligence networks in various countries. At the same time, different groups are tasked with specific stages of the operations – from surveilling potential victims to logistics, planning, and execution. Previously, Russian intelligence agencies more often relied on operatives recruited online for money.
European intelligence agencies have already managed to uncover and prevent some planned attacks. In other cases, law enforcement officials have documented suspicious surveillance of potential victims near their homes and workplaces. In light of these threats, German counterintelligence has stepped up cooperation with defense contractors and is advising executives to hire private security.
Some industry representatives told the FT that they have stepped up personal security measures over the past six months in accordance with recommendations from government security agencies. The additional costs create a financial burden, especially for small companies and startups. According to one of the publication’s sources, his company even relocated its production facility to Western Europe due to Russian threats.
Intelligence analysts cite psychological pressure on representatives of the defense industry as one of the goals of such operations. According to their assessments, the Kremlin aims to make companies doubt the wisdom of cooperating with Ukraine, even if the attacks are not carried through to the end.
It is worth noting that threats against executives of defense companies intensified as early as 2024, when U.S. and German intelligence agencies uncovered a suspected Russian plot to assassinate Armin Papperger, the CEO of the German conglomerate Rheinmetall. According to intelligence reports, he may have been targeted because of his support for arms deliveries to Ukraine. The CEO is currently under round-the-clock protection by police and private security guards.
As the FT notes, the threat extends not only to the defense industry but also to critical infrastructure companies and the energy sector. Security experts report an increase in requests from companies seeking to protect their employees from potential Russian operations.
It is worth noting that Russia is increasingly attempting to strike targets that directly impact the front lines. According to Danish intelligence, Russian intelligence agencies recruit untrained intermediaries using Telegram and other social media platforms to carry out their dirty work. The perpetrators of these sabotage operations may be homeless people or drug addicts looking for quick cash.
At first, these mercenaries are assigned simple tasks, such as photographing targets, and are later drawn into actual attacks. Western officials are seriously concerned about this trend because, according to the NYT, any such hybrid operation could result in significant loss of life.
We previously reported that the Kremlin plans to deploy GRU and FSB agents to carry out attacks on logistics routes and communications hubs in Europe. According to The Ukrainian Main Intelligence Directorate had warned, the aggressor’s priority targets include Starlink satellite internet receiving stations and military bases within the EU. To counter these challenges, the European Union is already developing a new emergency security protocol to coordinate actions during such incidents.


