Russia recruits "disposable agents" via Telegram

The disposable digital task hardens into a physical weight on Europe’s infrastructure.
Image composition · tobriefA Polish citizen and a Belarusian walked into a Warsaw prosecutor's office in handcuffs on 25 June. Their alleged crime: photographing critical infrastructure, hanging posters, spraying graffiti and monitoring Belarusian exile gatherings, all on instructions received through Telegram, paid in cryptocurrency. They are not the story. The recruitment model behind them is.
Across Poland, Germany and France, prosecutors and security officials describe the same operational pattern: Russian or Russian-linked intelligence services allegedly recruiting cheap, short-term agents online, assigning narrow tasks with no view of the broader operation, collecting proof of completion, paying small sums and cutting contact. The method turns ordinary people into intelligence tools they may not fully understand they have become.
The Warsaw Workflow
Poland's national prosecutor's office provides the clearest public picture of how this works. ABW (Poland's internal security agency) detained Polish citizen Rafał G. and Belarusian citizen Aliaksei B., charging them with acting for a foreign intelligence service between March 2024 and February 2025 in Rzeszów, Warsaw and Łódź (Prokuratura Krajowa, ABW). The pair allegedly received tasks through Telegram, documented targets with photographs and produced propaganda material.
ABW added a separate dimension: the suspects also filmed events organised by Belarusian exiles in Warsaw (Prokuratura Krajowa). That pushes the file beyond infrastructure reconnaissance into surveillance of diaspora communities opposed to Lukashenko's government.
The structure matters more than the individuals. Each recruit sees only their task: take this photo, hang this poster, buy this SIM card. No single person needs to know the operation's purpose. That compartmentalisation makes disruption harder and attribution slower.
Germany: From Screens to Rail Yards
Germany shows what happens when online recruitment meets physical preparation. North Rhine-Westphalia's interior minister Herbert Reul warned that Russian services now rely on Wegwerf-Agenten (disposable agents): cheap, interchangeable people recruited through social platforms, deliberately kept ignorant of who is really giving orders (FAZ, ZEIT).
Two German cases show the cyber-to-physical bridge. Investigators describe alleged agents, one based in Cologne, preparing arson and explosive attacks on freight transports. One suspect allegedly sent two test packages to probe shipping routes and security gaps (Kölner Stadt-Anzeiger). At Minden railway station, an illegally mounted live camera monitored a shunting area used by Bundeswehr and Ukraine-related transports (WDR). One moved boxes through commercial shipping to map vulnerabilities. The other watched military logistics in real time. Both began with a Telegram message to someone who needed money.
France adds a cautionary boundary. Near Toulouse, a Belarusian man was indicted on 5 June for delivering information to a foreign power after filming tests at Delair, a drone manufacturer. Days earlier, Molotov cocktails had been thrown at the factory but failed to explode. According to Le Monde, investigators had not linked the suspect to the attackers. Proximity is not proof: surveillance and physical intimidation sat close together without evidence of a single command chain.
The Gap That Makes It Work
NATO defines hybrid threats as the combined use of military and non-military, overt and covert measures, including proxies and irregular groups (NATO). The disposable-agent model works because each operation stays below Article 5 of the North Atlantic Treaty (the clause treating an attack on one ally as an attack on all). The actions disrupt without cleanly crossing the threshold where collective defence becomes politically straightforward (AP/ABC).
The crime scene is always local. A camera in Minden. A test parcel in Cologne. A photograph in Rzeszów. National prosecutors can charge the executor. Europol (the EU's police-cooperation agency) and Eurojust (its prosecution-coordination body) can connect files across borders. But proving that a specific Telegram channel traces back to a Russian intelligence directorate remains the hardest link in the chain, and neither agency can prosecute it. Czech media already cover the German and Polish cases as warnings for their own defence-supply chains (Novinky, ČT24). The EU's Critical Entities Resilience Directive can force operators in energy, transport and digital infrastructure to harden their targets (CER Directive). It cannot prove who sent the Telegram message.
The record supports a clear conclusion: Europe faces a documented pattern of Russia-linked, remotely tasked, compartmentalised agent recruitment aimed at infrastructure, defence supply chains and exile communities. The aim is to make support for Ukraine more costly and harder to protect. Poland and Germany have the strongest public cases. France shows how close surveillance and sabotage can sit without yielding courtroom-grade proof. Europe can harden rail yards, factories and telecoms accounts. It still lacks a clean way to prosecute the handler behind the recruit.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 7/9/2026, 2:44:37 AM
- Pipeline run:
- eu_pipeline_20260709_005006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication