Subscribe
Geopolitics

CIA warns Europe: Russia planning sabotage in Baltics and Poland

Intelligence warnings that matter rarely arrive as screaming headlines. The one now circulating among European capitals came as a quiet advisory passed between allies: US intelligence, including the CIA, has told partner governments that Russian intelligence services may be planning sabotage and

7 min read
Soldiers carry a reconnaissance drone beside vehicles on exercise
Poland and the Baltic states are stepping up security at critical infrastructure after US intelligence warnings. | Digitally illustrated image
Margaret Hale
By Margaret Hale · 2026-08-13

TLDR

US intelligence has warned European governments that Russian intelligence services are planning sabotage and hybrid operations against critical infrastructure in the Baltic states and Poland. Officials caution the Kremlin may also be stoking fear as a disinformation play. No evidence exists of a planned full-scale Russian military assault on NATO territory.

KEY TAKEAWAYS

01CIA Director Burns confirmed disruption of a Russian sabotage campaign waged against European allies.
02Poland's Internal Security Agency indicted an 18-year-old in July 2026 for sabotage on behalf of Russian intelligence.
03NATO's North Atlantic Council formally condemned a surge in Russian hybrid actions against allied territory in May 2024.
04Russia's grey-zone tools include sabotage, with a railway explosion in Poland occurring in November 2025.
05Australian businesses with European operations face supply-chain and cyber exposure from infrastructure disruptions.

A warning delivered quietly

Intelligence warnings that matter rarely arrive as screaming headlines. The one now circulating among European capitals came as a quiet advisory passed between allies: US intelligence, including the CIA, has told partner governments that Russian intelligence services may be planning sabotage and hybrid operations targeting critical infrastructure in the Baltic states and Poland.

Officials are also cautioning that the Kremlin may be deliberately amplifying fear of imminent attack as a disinformation play in its own right. No evidence exists, officials say, of a planned full-scale Russian military assault on a European country.

What the CIA has said publicly

CIA Director William J. Burns has been candid about the scope of Russian operations for some time. Burns said: "Beyond Ukraine, we continue to work together to disrupt the reckless campaign of sabotage across Europe being waged by Russian intelligence, and their cynical use of technology to spread lies and disinformation designed to drive wedges between us."[1] That acknowledgement, made in a jointly authored piece, is notable for its explicitness: it concedes the campaign is ongoing and that active countermeasures are in place.

The Office of the Director of National Intelligence's 2026 Annual Threat Assessment is more specific. Russia's grey-zone tools include sabotage used to disrupt US and European allies, exemplified by the railway explosion in Poland in November 2025.[2] The assessment also found that disruptions to Europe's critical infrastructure by state-affiliated actors have the potential to cause loss of life and harm commercial interests, prompting European countries to increase spending on small UAV detection and other counter-hybrid capabilities.[2]

The Kremlin's two-track campaign

Understanding these warnings requires separating two distinct Russian objectives. The first is operational: physical sabotage of energy nodes, rail yards, telecommunications infrastructure and water systems disrupts NATO logistics and demoralises populations in frontline states. The second is psychological: by seeding rumours of imminent attack, Moscow can achieve political disruption, economic anxiety and diplomatic friction without firing a shot.

Officials briefing European counterparts have stressed that the two objectives are not mutually exclusive. A sabotage campaign and a disinformation campaign about a larger military threat can run simultaneously, each amplifying the other. Every incident, a power outage, a communications failure, an unexplained fire at a logistics hub, becomes ambiguous. That ambiguity is itself the weapon.

Poland's ground-level response

On 14 July 2026, Poland's Internal Security Agency filed an indictment against an 18-year-old identified as Illia K. for carrying out sabotage and diversionary tasks on behalf of Russian intelligence services.[3] The case illustrates a recurring feature of Russian hybrid operations: the use of young, locally present, financially motivated proxies who can be directed remotely and disavowed immediately upon arrest.

Poland's Internal Security Agency has documented the broader pattern in a 2025 special issue of its journal on terrorism and security, noting an increase since 2022 in hybrid threats, including sabotage by Russian actors, against critical infrastructure in the energy, transport, telecommunications and water supply sectors across the European Union.[4] Security at key infrastructure sites across Poland, Latvia and Estonia is being tightened in response to the latest intelligence.

NATO's formal condemnation

NATO's posture has hardened incrementally. The North Atlantic Council issued a formal statement in May 2024 expressing deep concern over Russian hybrid actions on allied territory, including sabotage, violence, cyber and electronic interference, and disinformation, pledging to enhance resilience and preparedness to deter and defend against such operations.[5]

NATO Secretary General Jens Stoltenberg said: "On Russian hybrid actions against NATO allies in Europe, let me say that what we have seen over the last weeks or months is a surge in hostile actions by Russia against NATO allies and that includes sabotage, arson attempts, cyber-attacks, and also trying to use migration as a tool to coerce NATO allies."[6] None of these tools, individually, constitutes an act of war under international law. Each retains plausible deniability. Together, they constitute a sustained campaign against the cohesion and infrastructure of the alliance.

Since Russia's full-scale invasion of Ukraine in February 2022, Moscow has repeatedly employed hybrid tactics against NATO member states, blending cyberattacks, disinformation, physical sabotage and arson to destabilise support for Kyiv and deter Western aid. In 2024 and 2025, Russian FSB units and proxy networks targeted critical nodes in European supply chains, from GPS jamming along Baltic Sea shipping lanes to arson in industrial rail yards in Germany, Poland and the Baltics.

The documented pattern

Poland's security services have recorded a marked increase since 2022 in hybrid threats against critical infrastructure across the EU, spanning the energy, transport, telecommunications and water supply sectors.[4] The shape of these operations follows a consistent logic: identify a critical node, find or recruit a local proxy, direct the task remotely, and ensure the connection to Russian intelligence is severable. The Illia K. indictment fits that template precisely.

NATO and the EU have responded by integrating resilience measures into the Critical Entities Resilience and NIS2 directives, boosting spending on small UAV detection and critical infrastructure protection, and conducting joint exercises under the Eastern Flank initiative. Whether those measures are sufficient against an adversary that continues to recruit, adapt and probe for weaknesses is the question European security planners are living with daily.

Australian exposure

Australian businesses with supply chains running through Baltic Sea ports, German logistics hubs or Polish industrial facilities face real exposure to cascading delays if key nodes are taken offline, whether by sabotage or by the disruption that follows a credible threat. Cyber operations attributed to state-affiliated actors do not respect corporate nationality; an Australian firm operating European cloud infrastructure or using European managed-service providers sits inside the same threat perimeter as local targets.

The ODNI assessment's finding that such disruptions carry the potential to harm commercial interests is an explicit acknowledgement, from the peak US intelligence community, that the economic blast radius of Russian hybrid operations extends well beyond their physical point of impact.[2] Australian boards with European exposure would be prudent to review business continuity planning, not because conventional war is coming, but because the operations already underway are designed to cause exactly the kind of quiet, deniable disruption that continuity plans are built to address.

FREQUENTLY ASKED QUESTIONS

What specifically did the CIA warn European governments about?
US intelligence, including the CIA, warned European partner governments that Russian intelligence services may be planning sabotage and hybrid operations targeting critical infrastructure in the Baltic states and Poland. Officials also cautioned the Kremlin may be amplifying fear of imminent attack as a disinformation play in its own right.
Is Russia planning a full-scale military attack on a European country?
No. Officials explicitly say there is no current evidence of a planned full-scale Russian military assault on a European country. The concern is hybrid operations, sabotage, cyberattacks, arson, GPS jamming and disinformation, not conventional military invasion.
What is the Illia K. case and why does it matter?
On 14 July 2026, Poland's Internal Security Agency filed an indictment against an 18-year-old identified as Illia K. for carrying out sabotage and diversionary tasks on behalf of Russian intelligence services. The case illustrates Russia's use of young, locally present proxies who can be remotely directed and disavowed, a recurring feature of Russian hybrid operations.
How does this affect Australian businesses?
Australian businesses with European supply chains or operations face exposure to cascading delays if key infrastructure nodes are disrupted by sabotage. Cyber operations attributed to state-affiliated actors also affect Australian firms using European cloud infrastructure or managed-service providers, regardless of corporate nationality.
Margaret Hale

Margaret Hale

Margaret Hale writes about politics, policy and the culture of business. She is drawn to the people behind decisions and to the moments when a political story turns out to be a human one.

Related topics
What's your reaction?

Make us a preferred source on Google

Tap once and our reporting shows at the top of your Google search results and AI answers. You can change this at any time.

Add as a preferred source on Google
Subscribe — it's free