Threat Insight
Russia Targets Businesses and Officials Behind Europe’s Ukraine Defense Supply Chain
In 2024, Western officials warned that Russia was conducting sabotage across Europe, including arson, vandalism and assassination plots. That same year, US intelligence reportedly helped Germany disrupt a Russian plot against Rheinmetall’s CEO, whose company is central to European ammunition and armored vehicle support for Ukraine. [1]
In late 2025 and early 2026, German authorities were reportedly investigating surveillance of the CEO of German drone manufacturer Donaustahl and his family. Donaustahl forms part of the European industrial base supporting Ukraine’s drone and weapons production. [2][3]
These cases sit within a wider pattern. In 2024, Western officials warned that Russia was conducting sabotage across Europe, including arson, vandalism and assassination plots. CSIS has described this broader activity as part of Russia’s shadow war against the West. [8]
In April 2026, Russia’s Ministry of Defense publicly released addresses of European drone manufacturers supporting Ukraine. Dmitry Medvedev, Russia’s former president and current deputy chair of the Security Council, also described such sites as potential Russian targets. [4][5]
Taken together, these incidents suggest that Russia’s campaign is expanding. The focus is no longer limited to intelligence collection, sabotage or disruption of logistics. Moscow may also be prepared to pressure the people, facilities and supply chains that make European defense support to Ukraine possible. [8]
The timing matters. Ukraine’s reliance on drones has increased sharply, while European states are expanding production capacity and building joint ventures with Ukrainian firms. Russia therefore has a growing incentive to disrupt the European-Ukrainian defense-industrial base before it becomes more resilient.
Timing
This activity has developed since Russia’s full-scale invasion of Ukraine in 2022 and appears to have intensified from 2024 onward.
In 2024, Western officials warned that Russia was conducting sabotage across Europe, including arson, vandalism and assassination plots. That same year, US intelligence reportedly helped Germany disrupt a Russian plot against Rheinmetall’s CEO.
In April 2026, Russia’s Ministry of Defense publicly released addresses of European drone manufacturers supporting Ukraine. Dmitry Medvedev also described such sites as potential Russian targets.
Ukraine’s reliance on drones has increased sharply, while European states are expanding production capacity and building joint ventures with Ukrainian firms. Russia therefore has a growing incentive to disrupt the European-Ukrainian defense-industrial base before it becomes more resilient.
Geographic Scope, Actors and Targets
The threat extends beyond Germany, but the level and type of Russia-linked activity vary across Europe. Reporting points to sabotage, arson, proxy activity and espionage investigations in some countries, while others have so far mainly appeared in Russian target-signalling. [7][8][9]
Russia’s public listing of UAV-related company addresses expanded the intimidation campaign to additional countries. This matters because it separates alleged operational activity from target-signalling: some states have experienced reported Russian-linked operations, while others have so far mainly been named or exposed as potential targets. [4][5]
Russia is the primary actor, most likely acting through its intelligence services. In the cyber and logistics campaign, Western authorities have specifically attributed activity to GRU Unit 26165, while the Donaustahl reporting refers more broadly to Russian intelligence services. [1][6]
The operating model increasingly appears to combine state-led intelligence targeting with low-level recruited agents. These low-level agents are often not trained intelligence officers. Reporting describes them as disposable agents, with broader European cases showing recruitment through online channels, including Telegram. This gives Russia deniability and scale. Even failed operations can create pressure, fear and additional security costs for the target. [8][9]
The target set is not limited to major defense primes. Russia is also likely interested in small and medium-sized manufacturers, drone start-ups, component suppliers, logistics firms, IT providers and executives who publicly support Ukraine or are associated with rapid defense production. [6][7]
Tactics and Methods
Russia is using a combined campaign of surveillance, sabotage, cyber espionage, public intimidation and supply-chain targeting. [6][7][8]
In the Donaustahl case, alleged operatives reportedly filmed the CEO’s home, photographed resident information and tried to identify his whereabouts through family members. In the Rheinmetall case, US intelligence reportedly detected a mature assassination plot before German authorities increased protection around the CEO. [1][2]
These incidents show that the personal security of defense executives is now part of the attack surface.
Russia is also targeting the wider support ecosystem. GRU-linked cyber activity has focused on logistics and technology companies involved in transporting aid to Ukraine. Observed GRU-linked activity included attempts to access shipment-related information such as train schedules, manifests, routes, cargo contents and sender/recipient details.
That intelligence can support both strategic understanding and future physical disruption. [6]
The public release of European drone manufacturer addresses is best assessed as target signalling: intimidation, information operations and possible enabling of future targeting by sympathizers or recruited proxies. When viewed alongside sabotage plots, arson cases and the reported interception of explosives allegedly bound for Bavaria, the public naming of companies should be treated as a warning indicator, not just propaganda. [4][5][7]
Implications for European Defense Industry
The Donaustahl case as well as the Rheinmetall incidents show that the personal security of defense executives is now part of the attack surface. Drone manufacturers, dual-use technology firms and newer defense-sector entrants may be especially exposed. Many are strategically important to Ukraine’s defense production, but are smaller than traditional defense primes and may have less mature physical security, counterintelligence and executive protection programs.
GRU-linked cyber activity has focused on logistics and technology companies involved in transporting aid to Ukraine. This combined with the public release of European drone manufacturer addresses is best assessed as target signalling: intimidation, information operations and possible enabling of future targeting by sympathizers or recruited low-level agents. When viewed alongside sabotage plots, arson cases and the reported interception of explosives allegedly bound for Bavaria, the public naming of companies should be treated as a warning indicator.
If you or your organization have concerns about the topic above or need support, please reach out to your Truesec contact for further assistance.
References
[1] Die Zeit / The Insider, August 2026: reporting on alleged Russian intelligence preparation of an assassination attempt against Donaustahl CEO Stefan Thumann
[2] CNN, July 2024: reporting on US and German disruption of alleged Russian plot to assassinate Rheinmetall CEO Armin Papperger
[3] BBC, July 2024: German reaction to the reported Russian assassination plot against Rheinmetall’s CEO
[4] Euractiv, April 2026: reporting on Russia publishing addresses of European drone producers and Medvedev describing them as potential targets
[5] IntelliNews, April 2026: reporting on Russian Ministry of Defence publication of Ukrainian-linked UAV enterprise locations in Europe
[6] CISA / NSA / FBI / NCSC-UK and partners, April 2026: joint advisory on Russian GRU targeting Western logistics entities and technology companies
[7] Euronews, April 2026: reporting on German intelligence warnings to the defence industry about espionage, sabotage, and attacks
[8] CSIS, March 2025: Russia’s Shadow War Against the West
[9] DR, David Blach Andersen, “Rusland hyrer teenagere til at spionere og sabotere i Europa”, 2 August 2026
Stay ahead with cyber insights
Newsletter
Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.
Your current browser privacy settings may be preventing this form from loading properly. To continue, please allow cookies/tracking for this site or temporarily disable strict privacy protection, then refresh the page.
If you’re still experiencing issues, please contact us at hello@truesec.com