The Shadow War Comes to Denmark
What Happens Next
Russia Recruits Danes for Sabotage Against Defence Firms as Europe’s Shadow War Escalates
Russia is attempting to recruit Danish citizens for activities connected to sabotage against Denmark’s defence industry, according to the country’s security service, pushing Europe’s confrontation with Moscow deeper into the murky territory between espionage and open warfare. Danish authorities say companies connected to military support for Ukraine are among the potential targets.
The warning matters far beyond Denmark. Europe is pouring weapons, ammunition and military technology into Ukraine while Russia is accused of increasingly trying to disrupt that support without launching conventional attacks on NATO territory — using cyber operations, reconnaissance, proxies and suspected acts of sabotage instead.
PET Says Russia Is Recruiting Danish Citizens
Denmark’s Security and Intelligence Service, PET, says Russian intelligence services are attempting to recruit people inside Denmark, including through social-media and gaming platforms. Tasks can begin with seemingly limited activities such as photographing infrastructure or locations before potentially escalating into more serious intelligence or sabotage work.
Emil Gresholm, PET’s head of counter-espionage, said Russia is conducting sabotage operations across Europe and that Denmark’s defence sector is among the areas being targeted. The concern is therefore not simply that Russian operatives could enter Denmark themselves, but that individuals already living there could be recruited as disposable intermediaries.
PET has separately warned that Russia increasingly relies on helpers and proxy groups to identify targets and conduct physical sabotage. That method creates distance between an operation and the Russian state while potentially making attribution considerably harder.
Defence Companies Supporting Ukraine Are in the Crosshairs
The obvious strategic logic is Ukraine.
Denmark has become one of the European countries supplying military assistance to Kyiv, and companies involved in producing, storing, transporting or supporting military equipment can become important nodes in the wider Ukrainian supply chain. Danish military intelligence has previously assessed that Russia is interested not only in military donations but also in the industries, producers and transport networks facilitating those supplies.
A successful sabotage operation would not need to destroy an entire defence factory to have an effect. Damage to machinery, warehouses, power supplies, transport links or specialised components could delay production or deliveries while forcing companies and governments to spend significantly more on security.
There is also a psychological objective. PET assesses that Russian sabotage activity is intended partly to obstruct concrete supplies to Ukraine and partly to create fear of escalation inside Western societies, potentially weakening public and political willingness to continue supporting Kyiv.
Why Russia Uses Proxies Instead of Its Own Agents
The apparent recruitment model offers Moscow several advantages.
A person recruited online may have little visible connection to Russia. They may also be given only part of an operation, preventing them from knowing its wider purpose or who ultimately ordered it. Russian services can therefore potentially conduct relatively low-cost operations while putting significant distance between senior intelligence officials and the physical act itself.
Denmark’s military intelligence service has described a broader Russian sabotage campaign across Europe and said Russia has often used people who are not directly connected to its intelligence agencies. DDIS assesses the sabotage threat against the Danish Armed Forces as HIGH.
That does not mean Denmark believes a wave of attacks is inevitable. It does mean its intelligence services consider the threat credible enough to require substantially greater attention.
The Threat Extends Beyond Defence Factories
Defence manufacturers are only one potential part of the target picture.
PET says Russian intelligence services continuously gather information about critical infrastructure across Western countries, including Denmark. It assesses that Russia is likely to possess plans that could be activated against infrastructure if confrontation with the West escalated further.
That could make ports, railways, energy installations, communications networks and other infrastructure strategically important because modern military supply chains depend on civilian systems as much as dedicated military bases.
PET nevertheless draws an important boundary around the current threat. It says it has no indication that Danish critical infrastructure is presently being prioritised for widespread Russian destruction and does not currently assess Moscow as intending to cause extensive damage to it. The assessment could, however, change rapidly if relations deteriorate further.
Europe Is Already Confronting Suspected Sabotage
Denmark’s warning comes amid a wider series of security incidents across Europe.
Germany has accused Russia of responsibility for an explosive-laden drone attack targeting Leipzig/Halle Airport, an important logistics hub, while German authorities are investigating additional suspected sabotage incidents involving infrastructure and a fire at the premises of defence technology company Rohde & Schwarz in Munich. Moscow has denied allegations that it is conducting such operations.
The pattern is strategically significant because sabotage can produce effects disproportionate to the resources needed to carry it out. A conventional attack on a NATO defence plant could create an immediate military crisis between Russia and the alliance. A fire, power failure, drone incident or act committed by an apparently unaffiliated criminal creates far greater uncertainty.
That ambiguity is part of the weapon.
Why This Stops Short of Conventional War
None of this means Russia is preparing to invade Denmark.
DDIS has repeatedly distinguished between Russia’s growing hybrid threat and an immediate conventional military attack. Its assessment has been that Russia’s military threat towards NATO will increase as Moscow rebuilds its forces, while Denmark does not currently face a regular Russian military assault.
Hybrid warfare operates precisely inside that gap.
Espionage, cyberattacks, sabotage, disinformation and proxy operations can impose costs on an adversary without necessarily crossing the clear threshold associated with missiles, soldiers or conventional military strikes.
For NATO, that creates an uncomfortable question: how much Russian activity can take place inside allied territory before isolated incidents become regarded collectively as an attack requiring a much stronger response?
The Risk of Escalation
Sabotage against a defence company would not automatically trigger NATO’s Article 5 collective-defence clause. The political response would depend heavily on the scale of the damage, casualties, attribution and evidence of Russian state involvement.
But the danger increases if operations become more destructive.
A small arson attack causing limited property damage sits at one end of the spectrum. An operation killing civilians, crippling vital infrastructure or destroying strategically important military production could create intense pressure for retaliation.
European governments could initially respond through arrests, expulsions of intelligence officers, sanctions, financial restrictions and more aggressive counter-intelligence operations rather than direct military force.
The larger strategic danger is cumulative. Numerous individually limited attacks could gradually normalise Russian operations inside NATO states while simultaneously pushing European governments towards tougher countermeasures.
What Happens Next
Denmark is likely to increase scrutiny around defence manufacturers, logistics networks and sensitive infrastructure while expanding efforts to identify recruitment conducted through online platforms.
PET’s own hiring activity shows the priority being given to the problem: the service is currently recruiting investigators specifically for Denmark’s defence against Russian espionage and sabotage.
Companies involved in Ukraine’s military supply chain will also increasingly have to treat personnel security, cyber defence and suspicious physical incidents as interconnected threats rather than separate problems.
The confrontation therefore looks increasingly different from the Cold War image of professional spies exchanging secrets in capitals. Europe’s new security problem can involve anonymous accounts, recruited civilians, incendiary devices, drones, power infrastructure and factories hundreds of miles from Ukraine.
Russia denies the allegations made against it, including the latest Danish claims. Its ambassador to Denmark has argued that no concrete evidence was publicly presented and has linked the worsening security environment to Copenhagen’s military support for Ukraine.
What Denmark is warning about is not a Russian invasion force approaching its borders. It is potentially harder to deter: a shadow campaign capable of operating inside European societies while remaining deliberately below the point at which NATO would unquestionably treat the situation as war.

