Russia’s Telegram sabotage pipeline

A swarm of disposable devices encrusts the vital junctions of European infrastructure.
Image composition · tobriefA Telegram message promises easy money. The first job sounds harmless enough: photograph a building, check an access route, turn up at a protest. Payment comes after proof. If the person delivers, the requests become sharper.
Polish, German and French security services have now arrested or indicted people pulled into this pipeline. They are not trained spies. They are ordinary recruits, found online and given small, separate tasks they may not fully understand. The model is cheap, difficult to classify at the start, and exposes a weakness Europe knows well: local files can sit in separate national systems for too long before they form a shared picture of sabotage.
Photograph first, escalate later
Poland's ABW, the domestic security agency, has provided the clearest public record so far. Prosecutors described the arrest of a Pole and a Belarusian who photographed sites important to state security on orders from a Telegram moderator. The case was classified as "diversion directed against Poland" (Interia). Interior Minister Tomasz Siemoniak named Warsaw, Wrocław, Kraków, Zakopane and Bydgoszcz as cities where this type of recruitment was taking place (RMF24, Radio Alex).
Another operation paid people to join demonstrations among Ukrainian refugees that were made to look grassroots. The purpose was to use corruption scandals and internal Ukrainian disputes to sharpen tensions between Poles and Ukrainians.
Polish experts call these people "disposable agents" — recruited through money, pressure or manipulation (Rzeczpospolita). The first act can look like vandalism, activism or curiosity. For the handler, it is also a test: will this person obey instructions, provide evidence, and take the next step?
For Malta, the point is not that the same case has appeared here. It is that the method travels well. A small state with ports, energy infrastructure, gaming platforms, financial services and a dense political community cannot treat online recruitment as somebody else's counter-intelligence problem.
Same playbook across borders
Germany's BfV, the domestic intelligence service, described the same mechanism in its 2025 annual report. Russian services, it said, recruit helpers through Telegram for photography, infrastructure observation and early-stage sabotage (BR). The design blurs the first reading of an incident. Is it state-directed, ordinary crime, or an accident? By the time the answer is clearer, the handler may already have moved on.
Three men were convicted in Germany for spying on rail lines linked to support for Ukraine (DW, ZEIT).
France has the sharpest single case. Near Toulouse, a Belarusian man was indicted on 5 June after technicians at Delair, a drone manufacturer, caught him filming drone tests. Investigators from the DGSI, France's domestic intelligence agency, found a 55-second video on his phone that had been sent to a Russian number (Le Monde).
A separate Molotov-cocktail attack hit the same factory days earlier, according to Le Monde, but investigators have not publicly established a link between the detained man and the arson. The reconnaissance file is strong. The full chain from Russian tasking, to filming, to arson by the same person has not been proven.
Who owns the problem
Latvia's VDD, the state security service, has warned that young people are increasingly recruited through TikTok, Discord, Telegram and gaming platforms such as Roblox (Baltija.eu). The recruitment surface is widening faster than the authority to act against it.
Under EU treaty law, national security remains the responsibility of each member state (TEU Article 4). National services investigate. National prosecutors charge. Europol can connect police intelligence across borders (Europol). Eurojust can bring prosecutors together, and its SIRIUS project helps them obtain Telegram chats and account data that these cases depend on (Eurojust SIRIUS).
But coordination is not command. No single EU body can take a counter-sabotage case from first detection to prosecution across the bloc. That matters for small member states as much as for large ones: Malta depends heavily on EU-level sharing when a threat crosses borders, but the first legal move still belongs to national authorities.
The platform gap makes this harder. Telegram is not on the Commission's list of Very Large Online Platforms under the Digital Services Act, the EU law that governs online content and systemic platform risks. It therefore avoids the extra systemic-risk oversight that applies to the biggest platforms (Commission VLOP list). The recruitment channel sits outside the regulatory machinery built for exactly this kind of coordinated harm.
A sabotage recruiter behaves like an EU-wide actor while every legal response starts locally. Europe has coordination tools, but no single authority owns the pattern early enough. Recognition still depends on a national officer linking a photograph of a rail yard, taken by someone who thought they had found easy money, to the Telegram chat that ordered it.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 7/7/2026, 2:52:09 AM
- Pipeline run:
- eu_pipeline_20260707_005006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication