Russia Hires Telegram Saboteurs

The disposable digital task hardens into a physical weight on Europe’s infrastructure.
Cumadóireacht íomhá · tobriefTwo men were brought into a Warsaw prosecutor's office in handcuffs on 25 June: one Polish, one Belarusian. The allegations against them were almost banal in their detail. They had photographed critical infrastructure, put up posters, sprayed graffiti and watched gatherings of Belarusian exiles. The instructions, prosecutors say, came through Telegram. The payment came in cryptocurrency.
The men matter less than the system that allegedly recruited them.
Across Poland, Germany and France, prosecutors and security officials are describing a similar pattern. Russian or Russia-linked intelligence services are alleged to be finding cheap, short-term recruits online, giving them narrow jobs, asking for proof that the work was done, paying modest sums and then disappearing. The recruit sees the task, not the operation. A photograph here, a SIM card there, a parcel sent through a courier network. Taken alone, each act can look small. Together, they form a cheap intelligence machine.
The Warsaw Workflow
The clearest public account so far comes from Poland's national prosecutor's office. Poland's internal security agency, the ABW, detained Polish citizen Rafał G. and Belarusian citizen Aliaksei B. The two were charged with acting for a foreign intelligence service between March 2024 and February 2025 in Rzeszów, Warsaw and Łódź (Prokuratura Krajowa, ABW). Prosecutors say they received tasks through Telegram, photographed targets and produced propaganda material.
The ABW added another element. The suspects also allegedly filmed events organised by Belarusian exiles in Warsaw (Prokuratura Krajowa). That takes the case beyond infrastructure reconnaissance and into the monitoring of diaspora communities opposed to Alexander Lukashenko's regime.
The method is the point. Each person is given only a sliver of the job: take this picture, hang this poster, buy this SIM card. They do not need to know why it matters. That compartmentalisation protects the handler, slows attribution and leaves police with a local suspect rather than a clean route back to the intelligence service behind the task.
Germany: From Screens to Rail Yards
Germany shows how quickly online recruitment can move into the physical world. Herbert Reul, the interior minister of North Rhine-Westphalia, has warned that Russian services now rely on Wegwerf-Agenten, or disposable agents: cheap, replaceable recruits found through social platforms and kept deliberately ignorant about who is really giving the orders (FAZ, ZEIT).
Two German cases show the bridge between a screen and a rail yard. Investigators have described alleged agents, including one based in Cologne, preparing arson and explosive attacks on freight transports. One suspect allegedly sent two test packages to examine shipping routes and security gaps (Kölner Stadt-Anzeiger). At Minden railway station, an illegally mounted live camera monitored a shunting area used by Bundeswehr and Ukraine-related transports (WDR). One case mapped vulnerabilities in commercial logistics. The other watched military movement in real time. Both, investigators say, began with a Telegram message to someone who needed money.
France adds a useful caution. Near Toulouse, a Belarusian man was indicted on 5 June for delivering information to a foreign power after filming tests at Delair, a drone manufacturer. Days earlier, Molotov cocktails had been thrown at the factory but failed to explode. According to Le Monde, investigators had not linked the suspect to the attackers. The lesson is important: surveillance and intimidation can sit close together without proving a single command chain.
The Gap That Makes It Work
NATO defines hybrid threats as the use of military and non-military tools, open and covert, including proxies and irregular groups (NATO). The disposable-agent model fits neatly into that grey area. It disrupts, intimidates and gathers intelligence while staying below Article 5 of the North Atlantic Treaty, the clause that treats an attack on one ally as an attack on all (AP/ABC).
The crime scene is always local. A camera in Minden. A test parcel in Cologne. A photograph in Rzeszów. National prosecutors can charge the person who carried out the task. Europol, the EU's police-cooperation agency, and Eurojust, its prosecution-coordination body, can help connect cases across borders. But the hardest step remains proving that a particular Telegram channel leads back to a Russian intelligence directorate. Neither Europol nor Eurojust can prosecute that link themselves.
That is why these cases are now being watched beyond the countries where they began. Czech media have already treated the German and Polish files as warnings for their own defence supply chains (Novinky, ČT24). The EU's Critical Entities Resilience Directive can require operators in energy, transport and digital infrastructure to strengthen their defences (CER Directive). It cannot, by itself, prove who sent the Telegram message.
The public record now points to a clear pattern: Russia-linked, remotely tasked, compartmentalised recruitment aimed at infrastructure, defence supply chains and exile communities. The purpose is to make European support for Ukraine more expensive, more nervous and harder to protect. Poland and Germany have the strongest public cases. France shows how close surveillance and sabotage can come without producing courtroom-grade proof. Europe can harden rail yards, factories and telecoms accounts. It still has no clean way to put the handler behind the recruit in the dock.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 7/9/2026, 2:44:37 AM
- Pipeline run:
- eu_pipeline_20260709_005006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication