Enemies within: revolution of low-cost covert operations
Polish police transport a detained Russian saboteur, March 2025. Photo credits: Polish Prosecutor's Office

Enemies within: revolution of low-cost covert operations

Lukas Šimonis

Lukas Šimonis

September 4, 2026
13:27
Зміст

    The clandestine world’s new reality

    High-quality photos of military installations or convoys. Acts of sabotage against military equipment. Arson attacks on factories building military hardware or warehouses with supplies for Ukraine. Threats and physical violence against activists or CEOs of defense contractors. In the past, like the Cold war, such acts would have been carried out by highly trained intelligence officers or spies. Massive, highly coordinated spy rings run by intelligence officers and diplomats residing in a hostile country. That is how various intelligence agencies, particularly the Soviet KGB (later, Russian Federal security bureau, FSB) have been running their operations for decades. It required enormous resources, physical presence, personalized recruitment, and risky covert action. Not to mention that in an event that a spy ring is exposed, the state that sent them could face a massive retaliation. Yet as all forms of warfare, intelligence gathering and sabotage evolves as well. While the eyes of the world are set on Ukraine, where low-cost drones and unmanned ground vehicles transform the battlefield, a similar revolution is happening in the world of clandestine operations. Instead of using highly trained agents and spies, Russia is recruiting ordinary civilians to carry out various covert operations. This is certainly not news on its own, as news media largely mentioned Russians recruiting people on messaging apps, like Telegram. Lithuanian Ministry of Defense for example, even published an article that children are in danger of being recruited to carry out these tasks. Yet seemingly European countries react passively to this new reality and even avoid naming Russia as the nation behind it, as the aforementioned Lithuanian Ministry of Defense article avoids mentioning Russia specifically.  Thus, I believe that the true scale of this threat is severely underestimated, and in this article, I will analyze what kind of impact this will have on the future of military operations and national security.

    Why Russia turned to civilians

    Why is Russia recruiting civilians to carry out its work? After the full-scale Russian invasion of Ukraine in 2022, hundreds of Russian diplomats (many of whom were Russian intelligence officers and spies) were expelled out of Europe, United States and Canada, while those who remained were put under higher scrutiny, while Europe strengthened its counterintelligence capabilities. This has significantly degraded Russian capabilities. Facing a shortage of human and other resources, Russian intelligence institutions, like FSB and GRU (formally the Main Directorate of the General Staff of the Armed Forces of the Russian Federation) turned to recruiting civilians and criminal elements in European countries. The result of this is an unprecedented wave of sabotage and espionage that some claim to be acts of hybrid warfare. Now, using civilians is not new per se (and Russia is not the only country doing it) but powered by social media and internet, the sheer scale, accessibility, and low cost makes it truly revolutionary. This creates a new challenge for European militaries and national security agencies – a new reality where they must face a mass of adversaries from within.

    Anatomy of recruitment: how the trap works

    But to understand how it works, we must first explore just how people get recruited to carry out these tasks. Media often mentions recruiters using popular messaging app “Telegram”, yet this does not cover the full picture. Nobody reaches out to people asking “Hello, would you like to perform acts of sabotage for Russian intelligence?”. Recruiters seek out potential targets in social media, online forums, “Telegram” channels, and other messaging apps. Reportedly, there are Telegram groups where such “gigs” are offered en masse. Upon identifying a potential target, they make contact with them, sending innocent sounding messages, trying to gain their trust, rather than immediately suggesting work. If the targeted individual proves to be trustworthy (at least for basic tasks), recruiters offer them money or gifts to carry out specific, simple tasks, like to bring a parcel from point A to B.  For example, men that set IKEA warehouse in Vilnius (Lithuania) on fire back in 2024 were offered 10 thousand euros and an old BMW car. Although, people can be coerced into working for Russia by psychological pressure or blackmail. If recruited individuals successfully carry out their work (and keep quiet about it), they are usually given further, often even more dangerous tasks, such as espionage or sabotage. Unlike in traditional forms of intelligence work, recruiters don’t have to physically approach anyone or even reside in a targeted country. Intelligence officers can recruit people and carry out their work in complete safety and deniability, without risk of being caught and exposed, and causing diplomatic backlash.

    Money, not ideology: the face of Russia’s new recruits

    To understand the scale of this problem, we must analyze just who are the individuals that decide to carry out clandestine tasks for Russia. While logical reasoning would suggest that it might be people with grudges against the state, pro-Russian elements, criminals and so on, reality is different. While aforementioned groups of people are indeed potential recruits, ideological reasons are not the primary driving force behind these acts. The primary reason is pragmatic – money. Russia targets individuals seeking “easy” money, particularly those that come from vulnerable backgrounds (addictions, financial issues, criminal backgrounds), immigrants from Russia or Belarus (or even Ukrainian refugees). A worrying trend is Russian intelligence agencies increasingly using more teens, who are looking to make money, recognition or out of simple boredom. In other words, while ideological extremists are useful, Russia does not need people who hate NATO, Ukraine or their own government. All it needs is someone who is desperate to make a few hundred euros. And that reveals the true and growing scale of this issue. It is not a problem with a few ideological “useful idiots” or radicals, but rather a large pool of potential Russian intelligence assets working for monetary gain. Modern militaries work in an ecosystem together with an enormous number of civilian contractors, cooks, cleaners, maintenance and tech workers, drivers, logistics workers and so on. That is not to mention a myriad of people working in the defense sector, building military hardware, and ammunition. At the same time, all of this coexists with people who simply live near military installations or important infrastructure, factories. And all the people mentioned here (civilian contractors, defense industry workers, civilians living nearby military bases) all have families, friends, relatives and so on. In smaller countries, this includes tens of thousands of people, in larger – potentially tens of millions. A mass of people, where anyone can potentially be working for Russian intelligence. And while national security agencies can identify and track radicals or other fifth column groups, try to screen and question civilian contractors working for the military, it is impossible to predict if an average citizen will turn into a Russian intelligence asset.

    Decentralized cells over traditional spy rings

    The scale of this problem becomes even more dire if we analyze how these Russian intelligence operations work. As mentioned before, intelligence officers do not contact potential targets and ask if they want to work for FSB. People who get recruited, especially teens, often have no idea who they are really working for, or that they are doing illegal work at all. Of course, if a Telegram channel offers a “gig” like “set a NATO vehicle on fire” one can probably guess who benefits from it, but these are more violent, direct tasks. Very often, a recruited individual is merely a single part of a larger intelligence chain. For example, an intelligence agent from Moscow is tasked with finding and damaging railway track section that is used to bring military aid to Ukraine. Through social media, agent can find someone who works in logistics (like a driver) to identify where exactly the military aid is taken. After identifying the location, agent can contact someone, like a railway worker or someone who lives nearby to confirm (for example, take photos) if the trains carrying aid are passing through that section. Once confirmed, an intelligence officer (agent) can hire someone from the area to bring tools needed for sabotage to a designated location. Finally, another individual uses tools to sabotage the railway tracks. A chain where everyone operates without knowledge of the others commits sabotage, planned and managed safely by intelligence officers working from Moscow. This makes the work of national security agencies much more difficult, because you don’t have a tightly knit circle of intelligence operatives working together, but a few individuals working separately. Even if one is caught, they cannot say anything about others. What makes it even worse is the fact that given the nature of these tasks, recruited individuals might not even understand that they are working for foreign intelligence. Asking someone to take a photo of the passing train, or a warehouse might seem completely fine. Telling an online friend about some military aid you are delivering can sound innocent. Bringing a bag of tools from point A to point B is unsuspicious in nature. Even a person who is at the end of the chain, the one who commits an act of sabotage, might not know what their actions mean. And if people do not suspect that their “work” might benefit foreign intelligence, they are not likely to report it. In their mind, they are doing something simple and unsuspicious, like taking photos, or watching a military convoy. In other words, due to the nature of these operations, people might participate in them without even understanding it.

    The strategic edge of Moscow’s new playbook

    Now, a question might rise, why would Russia recruit civilians or criminals, instead of highly trained agents or sleeper agents (so called “moles”)? For the same reason it has turned to using drones and other loitering munitions in Ukraine. Because they are cheap, disposable, deniable and effective.  Why recruit people in Russia, train them, pay salaries, send them abroad, give them diplomatic or other cover and risk it all if they are compromised, or even worse, become double agents? Of course, traditional operations did not entirely disappear, but using recruited locals for simple tasks is a cheaper and safer option. In a way, it is like using drones in warfare. Similarly to drones, local recruits are a far cheaper option than intelligence officers. In a “traditional” way, intelligence officers must be recruited, taught, paid, sent abroad with diplomatic or other sort of cover, and extracted. All of this takes time, money, and other human resources.  But if you are using local recruits hired online, for a few hundred euros (or a few thousand) you can get someone to commit sabotage or gather intelligence. That is a significantly cheaper option for “simple” tasks, while professional, career intelligence officers are freed up to work on tasks more suited towards highly trained experts, like deep cover operations. And even if recruits fail to do their tasks, the cost of failure is minimal, because they are disposable, just like drones. Men that set IKEA warehouse in Lithuania were promptly arrested, but to their handlers, it makes no difference. The task is done (the warehouse was set on fire), and they didn’t even need to pay the full price. Even in the case of failure, all the FSB or GRU have to lose is a little money and time. And just like with drones, there are thousands more ready to work. Next, the factor of deniability. Russia outright denies that it has anything to do with this sabotage and intelligence gathering campaign in Europe, and the European countries are reluctant (with a few exceptions) to blame Russia for it, for the fear of “escalation”. Russia can explain that nothing really binds these incidents with Russian authorities. While acts of sabotage undoubtedly benefits Russian war machine, they are committed by locals, not actual Russian agents. Locals receive orders online, from someone hiding behind a myriad of proxies and fake IP locations. Theoretically, nothing can trace it to Russia. And while Europeans and Americans do understand that Russia is behind it, pinning it on Russia is more difficult, as it is often considered “grey zone” or hybrid warfare.

    Finally, effectiveness. While an ordinary civilian can hardly surpass a trained professional (as an FPV drone cannot replace artillery), these operations are very cost effective, and hard to notice. Local people have an advantage over foreign agents because they know the area well and can operate without drawing suspicion or attention. A strange, unseen man taking photos of trains or military movements might draw attention, but an elderly villager looking at the same thing might seem natural. And it is important to know where you draw the line – is it espionage, or simple curiosity?

    Why states struggle to stop crowd-sourced saboteurs: five key factors

    Now, once we have established the scale and complexity of this problem, it is important to understand what militaries and national security agencies can and cannot do about it. While cheap drones can be shot down by air defense systems or jammed, human “drones” are far more difficult to counter. I dare say that this issue cannot be resolved completely (more on that later); nations can only aim at diminishing the pool of potential recruits and establishing new military doctrines. There are quite a few reasons why it cannot be resolved entirely, such as:

    • Because the pool of potential recruits is so vast, national security agencies simply do not have resources to track and identify each individual. It is physically impossible to track and screen every person, civilian contractor, or factory worker for a potential security leak. Since technically almost anyone can be recruited, it is impossible to predict just who might “flip to the other side”. Even more so, mass surveillance laws would most likely massively infringe human rights regarding privacy (especially communication), face public backlash and would promptly be shut down by national courts.
    • Physical barriers and protection, like fences, could deter some people, but it cannot protect the ecosystem around important targets. Military units have to leave their bases for training, bring in new equipment and supplies and so on. Fences cannot stop willing individuals from taking photos of these movements or surrounding infrastructure;
    • Thirdly, it is difficult to establish what is actually intelligence gathering and what is merely curiosity. A man taking photos of a military convoy might be a spy, but he can also be merely a civilian taking “cool” photos of military equipment. Someone asking where trains carrying military aid are going might be doing it for nefarious purposes, or they can be just trainspotters (people interested in locomotives). Worse yet, people might spread potentially dangerous information without realizing it. For example, a group of aviation enthusiasts are tracking and identifying military and civilian aircraft and posting it on social media. While this seems like an innocent hobby, in the wrong hands such information could help someone build a map of military movement or schedules. Thus, it is almost impossible to distinguish espionage from curiosity from a glance;
    • Next, because Russia primarily uses people seeking monetary gain, not ideological radicals, it will always find someone to hire. States can educate citizens on this threat, identify and monitor radical groups, but at the end of the day, as long as there are people willing to make quick money, Russia will have a never-ending supply of potential recruits;
    • Finally, due to cost effectiveness of these operations, and little political backlash (besides Europe’s favorite “strong condemnations”) Russia will continue using state’s own citizens to commit acts of sabotage or intelligence gathering.

    Adapting doctrines over quick fixes: a roadmap for the West

    I believe that instead of searching for a “silver bullet” that would solve this problem, the European countries should instead adopt changes in policy and military doctrine to adapt to a rapidly changing security environment. For example:

    • As many people who perform these tasks are simply unaware of what they are even doing, governments must raise public awareness about Russian online recruitment issue. Now, several European countries (like Lithuania) are already doing so, but it is usually limited to public statements or online advertisements about dangers it poses. States must adopt a widespread public awareness campaign, so more people would be aware of this issue and wouldn’t fall for online recruitment accidentally, and that is especially important for teens. While this will not stop people who are desperate for money, citizens might become more aware that seemingly “innocent” tasks done for money might be a part of a sinister plot in reality. However, it is important to note that it must not turn into a moral panic about spies on every corner, because it will only cause unnecessary social division;
    • Increase in OPSEC (operational security) for the military. During the World War 2, Allies have adopted the “loose lips sink ships” policy, which encouraged citizens and servicemen to avoid unnecessary talk that could hinder military effort and national security.  Military personnel, just like civilian populace, must be taught about this security challenge, and how to counter it. And this must not be training done for the sake of training, but simple, useful tips on how to avoid sharing sensitive information. That is especially important in the age of social media, where a photo or video could expose location of troops, security details or nature of military training/exercise;
    • Cooperation between the private sector and military/national security agencies. The private sector must be made aware that it is a target for espionage and sabotage, and thus, must increase its security measures and cooperate with the state in preventing it. Employees, just like military personnel, must be taught to avoid unnecessary spread of information. In turn, the state must do more to protect important defense companies and warn them of possible attacks, not only against infrastructure, but employees too. This is especially important knowing that Russia planned assassinations of CEOs of European defense contractors;
    • I believe that this issue will not go away (simply because of its effectiveness) so the military must adapt to it. Besides OPSEC training, the military must understand that they are likely operating under constant surveillance and must adapt planning of operations to it. While it is impossible to hide every soldier or vehicle, militaries make organized and systematic intelligence gathering more difficult by adopting dispersion, limiting visible equipment (for example, cover vehicles moved by rail with tarp), strictly control just who gets to see bases, and let counterintelligence identify possible weak points in security and suspicious individuals. Instead of trying to be invisible, the military should aim at degrading systematic intelligence gathering capabilities;
    • Finally, European countries must not let these attacks or intelligence gathering attempts go unanswered. While nobody is suggesting initiating wars over it, policy makers should aim at imposing sanctions and further diplomatic isolation, as “strongly worded letters” or “condemnation” simply does not work with a country like Russia.

    In summary, while the threat of “enemy within” is not going away and poses one of the gravest security threats faced by European countries, with the right changes in public policy and military planning, it is possible to dampen it. It is important to note, that while this article is focused on espionage and sabotage attempts made by people recruited by Russia, other countries, like China or Iran, or even terrorist groups are likely to follow this example, as these online recruited “human drones” proved to be effective, cheap, and hard to stop tool of hybrid warfare. Hostile intelligence agencies no longer need ideological supporters or intelligence officers to commit sabotage or gather data. It no longer needs to infiltrate military bases or defense contractors. All it needs is someone near it and willing enough to make easy money. And people like that will exist forever.

    SUPPORT MILITARNYI

    PrivatBank ( Bank card )
    5169 3351 0164 7408
    Bank Account in UAH (IBAN)
    UA043052990000026007015028783
    BTC
    bc1qg0z99m95fte7kj8faa7h2kvnq92wvc53exe8gm
    USDT
    0x8676644fA7B6d328310283cAC1065Ae01d97CEe7
    ETH
    0xfD02863D3289416fcF50975c9DFda13623f97758
    Popular
    Button Text