
TLDR
US intelligence has warned European governments that Russian intelligence services are planning sabotage and hybrid operations against critical infrastructure in the Baltic states and Poland. Officials caution the Kremlin may also be stoking fear as a disinformation play. No evidence exists of a planned full-scale Russian military assault on NATO territory.
KEY TAKEAWAYS
A warning delivered quietly
Intelligence warnings that matter rarely arrive as screaming headlines. The one now circulating among European capitals came as a quiet advisory passed between allies: US intelligence, including the CIA, has told partner governments that Russian intelligence services may be planning sabotage and hybrid operations targeting critical infrastructure in the Baltic states and Poland.
Officials are also cautioning that the Kremlin may be deliberately amplifying fear of imminent attack as a disinformation play in its own right. No evidence exists, officials say, of a planned full-scale Russian military assault on a European country.
What the CIA has said publicly
CIA Director William J. Burns has been candid about the scope of Russian operations for some time. Burns said: "Beyond Ukraine, we continue to work together to disrupt the reckless campaign of sabotage across Europe being waged by Russian intelligence, and their cynical use of technology to spread lies and disinformation designed to drive wedges between us."[1] That acknowledgement, made in a jointly authored piece, is notable for its explicitness: it concedes the campaign is ongoing and that active countermeasures are in place.
The Office of the Director of National Intelligence's 2026 Annual Threat Assessment is more specific. Russia's grey-zone tools include sabotage used to disrupt US and European allies, exemplified by the railway explosion in Poland in November 2025.[2] The assessment also found that disruptions to Europe's critical infrastructure by state-affiliated actors have the potential to cause loss of life and harm commercial interests, prompting European countries to increase spending on small UAV detection and other counter-hybrid capabilities.[2]
The Kremlin's two-track campaign
Understanding these warnings requires separating two distinct Russian objectives. The first is operational: physical sabotage of energy nodes, rail yards, telecommunications infrastructure and water systems disrupts NATO logistics and demoralises populations in frontline states. The second is psychological: by seeding rumours of imminent attack, Moscow can achieve political disruption, economic anxiety and diplomatic friction without firing a shot.
Officials briefing European counterparts have stressed that the two objectives are not mutually exclusive. A sabotage campaign and a disinformation campaign about a larger military threat can run simultaneously, each amplifying the other. Every incident, a power outage, a communications failure, an unexplained fire at a logistics hub, becomes ambiguous. That ambiguity is itself the weapon.
Poland's ground-level response
On 14 July 2026, Poland's Internal Security Agency filed an indictment against an 18-year-old identified as Illia K. for carrying out sabotage and diversionary tasks on behalf of Russian intelligence services.[3] The case illustrates a recurring feature of Russian hybrid operations: the use of young, locally present, financially motivated proxies who can be directed remotely and disavowed immediately upon arrest.
Poland's Internal Security Agency has documented the broader pattern in a 2025 special issue of its journal on terrorism and security, noting an increase since 2022 in hybrid threats, including sabotage by Russian actors, against critical infrastructure in the energy, transport, telecommunications and water supply sectors across the European Union.[4] Security at key infrastructure sites across Poland, Latvia and Estonia is being tightened in response to the latest intelligence.
NATO's formal condemnation
NATO's posture has hardened incrementally. The North Atlantic Council issued a formal statement in May 2024 expressing deep concern over Russian hybrid actions on allied territory, including sabotage, violence, cyber and electronic interference, and disinformation, pledging to enhance resilience and preparedness to deter and defend against such operations.[5]
NATO Secretary General Jens Stoltenberg said: "On Russian hybrid actions against NATO allies in Europe, let me say that what we have seen over the last weeks or months is a surge in hostile actions by Russia against NATO allies and that includes sabotage, arson attempts, cyber-attacks, and also trying to use migration as a tool to coerce NATO allies."[6] None of these tools, individually, constitutes an act of war under international law. Each retains plausible deniability. Together, they constitute a sustained campaign against the cohesion and infrastructure of the alliance.
Since Russia's full-scale invasion of Ukraine in February 2022, Moscow has repeatedly employed hybrid tactics against NATO member states, blending cyberattacks, disinformation, physical sabotage and arson to destabilise support for Kyiv and deter Western aid. In 2024 and 2025, Russian FSB units and proxy networks targeted critical nodes in European supply chains, from GPS jamming along Baltic Sea shipping lanes to arson in industrial rail yards in Germany, Poland and the Baltics.
The documented pattern
Poland's security services have recorded a marked increase since 2022 in hybrid threats against critical infrastructure across the EU, spanning the energy, transport, telecommunications and water supply sectors.[4] The shape of these operations follows a consistent logic: identify a critical node, find or recruit a local proxy, direct the task remotely, and ensure the connection to Russian intelligence is severable. The Illia K. indictment fits that template precisely.
NATO and the EU have responded by integrating resilience measures into the Critical Entities Resilience and NIS2 directives, boosting spending on small UAV detection and critical infrastructure protection, and conducting joint exercises under the Eastern Flank initiative. Whether those measures are sufficient against an adversary that continues to recruit, adapt and probe for weaknesses is the question European security planners are living with daily.
Australian exposure
Australian businesses with supply chains running through Baltic Sea ports, German logistics hubs or Polish industrial facilities face real exposure to cascading delays if key nodes are taken offline, whether by sabotage or by the disruption that follows a credible threat. Cyber operations attributed to state-affiliated actors do not respect corporate nationality; an Australian firm operating European cloud infrastructure or using European managed-service providers sits inside the same threat perimeter as local targets.
The ODNI assessment's finding that such disruptions carry the potential to harm commercial interests is an explicit acknowledgement, from the peak US intelligence community, that the economic blast radius of Russian hybrid operations extends well beyond their physical point of impact.[2] Australian boards with European exposure would be prudent to review business continuity planning, not because conventional war is coming, but because the operations already underway are designed to cause exactly the kind of quiet, deniable disruption that continuity plans are built to address.
SOURCES & CITATIONS
- CIA Director Burns on Russian sabotage campaign in Europe
- ODNI Annual Threat Assessment 2026
- ABW indictment of Illia K. for sabotage on behalf of Russian intelligence, July 2026
- ABW special edition: Terrorism, Studies, Analyses, Prevention 2025, hybrid threats against EU critical infrastructure
- North Atlantic Council statement on Russian hybrid activities, May 2024
- NATO Secretary General Stoltenberg joint press conference, June 2024
FREQUENTLY ASKED QUESTIONS
What specifically did the CIA warn European governments about?
Is Russia planning a full-scale military attack on a European country?
What is the Illia K. case and why does it matter?
How does this affect Australian businesses?

Margaret Hale writes about politics, policy and the culture of business. She is drawn to the people behind decisions and to the moments when a political story turns out to be a human one.



