From Sabotage to Assassination: Russia’s Escalating War on Europe’s Defense Industry

From Sabotage to Assassination: Russia’s Escalating War on Europe’s Defense Industry

The Italian opposition is seeking to draw the government’s attention to the explosion at the KNDS Ammo Italy plant in Colleferro in the context of possible Russian sabotage. In particular, opposition lawmaker Carlo Calenda called on the government to clarify whether Italy faces a concrete risk of hybrid attacks by Russia. He pointed to the extensive coverage of the explosion in

Russian media and called for an assessment of intelligence, parliamentary oversight

or a clear statement from Prime Minister Giorgia Meloni.

On August 13, an explosion occurred at the KNDS Ammo Italy plant in Colleferro, near Rome. The incident took place in the propellant-pressing department after a fire. The blast raised questions about possible Russian involvement because the plant produces ammunition, some of which is supplied to Ukraine by European states. Italian Defense Minister Guido Crosetto said the Italian government currently has no information indicating Russian involvement in the explosion. Meanwhile, the Velletri prosecutor’s office says the investigation remains open to all possibilities.

Suspicions of possible Russian involvement in the explosion at the KNDS Ammo Italy plant in Colleferro should not be dismissed as unfounded without proper examination, because

Russian intelligence services have previously carried out sabotage operations in EU countries against facilities linked to arms supplies to Ukraine. The most illustrative and large-scale example is the 2014 explosions at ammunition depots in Vrbětice, Czech Republic, for which Czech law-enforcement authorities established the involvement of Russian military intelligence and Unit 29155.

The Italian authorities should ensure a full examination of suspicions concerning possible

Russian sabotage at the ammunition plant in Colleferro. The opposition’s calls for an intelligence assessment and stronger parliamentary oversight are justified, as this would make it possible to rule out or confirm external

interference and ensure public confidence in the results of the investigation.

The explosion at the Italian ammunition-production facility in Colleferro

demonstrates the vulnerability of European defense infrastructure amid Russia’s hybrid

war against Europe. Plants, warehouses, and logistics hubs involved in the production or supply of weapons to Ukraine are strategically important and could potentially become targets of Russian operations. Incidents at such

facilities therefore require not only a technical investigation but also a mandatory assessment by

counterintelligence agencies.

Developments in recent years show that the Russian hybrid threat is not limited to

sabotage at defense enterprises. Moscow combines such actions with cyberattacks, espionage, and information operations, creating multidimensional pressure on European states. This approach makes it possible simultaneously to inflict material damage, collect intelligence, undermine

citizens’ trust in state institutions, and deepen a sense of instability and chaos in European society.

Attempts to damage such facilities may potentially be aimed not only at an individual state, but also at weakening the entire European system of military support for Ukraine.

Regardless of the Italian investigation’s final conclusions, Europe should proceed from the assessment

that Russia has created a system of intelligence and sabotage operations directed against states that support Ukraine. The use of agents, proxy structures, and covert networks to attack defense enterprises indicates that the Kremlin has moved

toward a long-term campaign of pressure on Europe’s defense-industrial base. Effective countermeasures against this

threat are possible only through coordinated EU and NATO action and stronger protection of critical sectors of the economy.

German security services uncovered an operation by Russian military intelligence aimed at assassinating the founder of the German drone company Donaustahl, which supplies UAVs to Ukraine. According to Bundestag member Bastian Ernst, the plans against Stefan Thumann were already well advanced; he was reportedly to be killed with a nerve agent similar to the notorious Novichok.

Shortly before Christmas 2025, 39-year-old Stefan Thumann was informed by German security authorities about a Russian intelligence operation targeting him. He added that the war in Ukraine had become his ‘personal war.’ In March 2026, German law-enforcement authorities detained two Russian ‘disposable agents’ who had been surveilling the businessman. German security agencies regard the Thumann case as a striking example of the escalation of Russia’s hybrid war. According to CNN, in 2024 the United States disrupted a Russian plot to assassinate Armin Papperger, chief executive of the German defense giant Rheinmetall.

The attempt by Russian intelligence services to organize the assassination of Donaustahl founder Stefan Thumann indicates a Kremlin shift toward physical attacks against representatives of the defense-industrial sector of NATO countries.

Particularly alarming is the information about the possible use of a nerve agent such as Novichok, which Russian intelligence services have previously used in the attempted assassination of Sergei Skripal and his daughter in the United Kingdom.

If reports that an assassination attempt against Stefan Thumann using a Novichok-type agent was being prepared are ultimately confirmed by the German investigation, this should be interpreted not simply as another Russian assassination operation, but as a qualitative escalation of Russia’s covert war against Europe.

In practical terms, this would demonstrate a readiness to use chemical weapons on NATO territory

This is the most serious aspect. The OPCW explicitly states that poisoning a person with a nerve agent constitutes the use of a chemical weapon under the Chemical Weapons Convention.

Therefore, if a Russian intelligence service genuinely planned to use Novichok against Thumann in Germany, this would amount to more than an assassination plot. In political and legal terms, it would mean preparation for the use of a chemical weapon on the territory of a NATO member state.

This would significantly raise the seriousness of the incident compared with ordinary sabotage, arson, or even a killing carried out with conventional weapons.

A return to the ‘Salisbury model’

The most important parallel is the 2018 attempted assassination of Sergei Skripal in the United Kingdom. The British public inquiry, whose findings were released in December 2025, concluded that the Novichok operation was carried out by GRU officers and that responsibility lay with the Russian state. British citizen Dawn Sturgess died after secondary exposure to the substance.

The possible plot against Thumann can therefore be interpreted as an especially important signal: after Salisbury, Moscow may not have abandoned the use of nerve agents as an instrument of overseas covert operations.

If confirmed, Salisbury would cease to look like an exceptional operation and instead become part of a recurring operational pattern.

But the target has fundamentally changed

This is where the Thumann case may be particularly important for contemporary European security.

Skripal was a former Russian military-intelligence officer whom Moscow regarded as a traitor. Alexei Navalny was a domestic political opponent of the Kremlin; the OPCW confirmed the presence in his biological samples of a cholinesterase inhibitor with structural characteristics associated with Novichok-family agents.

Thumann represents an entirely different category of target: a German businessman whose company produces military technology for Ukraine.

If this version is confirmed, it would therefore suggest a potential evolution:

‘traitors and political opponents’ → executives of the Western defense-industrial complex.

This would represent a major change in Russia’s target set.

Novichok has not only a physical but also a psychological effect

There are far simpler ways to kill a single individual. The choice of such a distinctive substance may therefore carry additional significance.

Since Salisbury, Novichok has become a kind of signature weapon closely associated with Russian intelligence services. Its possible reuse could serve a strategic intimidation function.

The potential audience for such a signal is therefore not limited to Thumann, but includes a much broader group of executives at Rheinmetall, KNDS, Saab, and other companies involved in producing weapons for Ukraine. Recent reports of threats against European defense-industry executives indicate that European services already treat their personal security as a distinct concern.

Moscow may be testing NATO’s ‘gray zone’

Russia understands the distinction between an overt military attack and a covert intelligence operation. A Russian missile strike on a German defense facility would create an obvious NATO crisis. The covert poisoning of a company executive creates a far more difficult problem of attribution and proportional response.

Such operations can therefore be viewed as testing the limits of what is tolerated below the threshold of open war: sabotage → assassination attempt → use of a toxic agent → denial of responsibility → testing NATO’s response.

It is particularly significant that other Russian operations are continuing in parallel. On August 18, 2026, a German court handed down a verdict in a case involving parcels containing GPS trackers as part of an operation that German authorities linked to Russian intelligence and reconnaissance of potential future sabotage targets.

The most dangerous conclusion: a possible lowering of Russia’s threshold for using especially hazardous means

If information about a plan to use Novichok against Thumann is confirmed, it would indicate that Russian intelligence services may be prepared to use means classified under international law as chemical weapons not in an exceptional operation against a defector, but as an instrument in a campaign against Europe’s defense-industrial complex.

This would represent a different level of threat.

The assessment can be formulated as follows:

The possible preparation by Russian intelligence services of an assassination attempt against the head of a German defense company using a Novichok-type nerve agent indicates a potential lowering of Moscow’s threshold for employing especially dangerous means in covert operations on NATO territory. If confirmed by the investigation, this would amount to a qualitative escalation: a method previously used against defectors and domestic opponents of the Kremlin may have been transferred to a new category of targets – executives of Europe’s defense-industrial complex. This would mean that Moscow is increasingly blurring the distinction between domestic physical-elimination operations and its covert war against states providing military support to Ukraine.

An even stronger strategic conclusion follows: Thumann + Papperger + sabotage against defense infrastructure should be analyzed not separately, but as a possible single campaign against Europe’s defense-industrial complex, in which Moscow attacks three components simultaneously – production, supply chains, and people.

The attempt to eliminate the head of a company producing drones for Ukraine demonstrates an expansion of Russian pressure methods to include the physical elimination of representatives of the Western defense sector who provide the Ukrainian military with military technologies.

The danger lies in the creation of a precedent in which Moscow treats NATO territory not only as a space for espionage, but also as an operational area for sabotage and lethal action. Warnings issued by German security services to businesses point to growing risks for European companies connected with defense production. The purpose of such operations may be not only to remove individual people, but also to intimidate defense-sector executives and employees, disrupt operations, and weaken the EU’s ability to support its partners.

The exposure of plans to assassinate Stefan Thumann indicates targeted activity by Russian intelligence services against executives of European defense companies.

Russia is deliberately expanding the practice of special operations that go beyond conventional intelligence activity and create direct security risks for NATO countries, testing the Alliance’s readiness to respond. Preparations for assassination attempts involving the possible use of toxic substances in Europe demonstrate the willingness of Russian intelligence services to export methods of physical elimination beyond Russia. The absence of a firm and coordinated NATO response could be interpreted by the Kremlin as a signal that such operations will not entail sufficiently serious consequences for Russia, increasing the risk of further escalation.

If Russian intelligence services do not face an adequate response to attempts to attack Europe’s defense-industrial complex, Moscow may broaden its target set to the EU civilian sector. Software developers, microelectronics manufacturers, logistics operators, and energy companies whose activities matter to European defense capabilities could come under threat. In that case, Russian hybrid activity would cease to be primarily a defense-sector problem and would directly affect the security and everyday lives of EU citizens.

Stronger counterintelligence and personal protection for European defense-company executives alone are insufficient to deter further Russian action. The West should move toward a systemic policy for countering Russian intelligence services, including broader sanctions against Russia’s defense-industrial complex, its financial intermediaries, and structures that support Russian intelligence activity. At the same time, Moscow should clearly understand that organizing terrorist attacks against the defense sector of NATO countries will carry concrete and tangible consequences for Russia.

The August 13, 2026 explosion at the KNDS Ammo Italy facility in Colleferro near Rome cannot at this stage be classified as Russian sabotage. Available open-source information contains no evidence of direct involvement by Russian intelligence services. At the same time, the nature of the facility, its role in European ammunition production, and the documented history of Russian sabotage against European defense infrastructure mean that the possibility of external interference should be subject to a separate counterintelligence review.

The Colleferro incident

KNDS Ammo Italy is also among the companies involved in European mechanisms for expanding ammunition production. (AP News)AP News

Serious accidents have occurred at the same site before: in 2007, an explosion killed one person and injured 13. The nature of the facility therefore creates a significant baseline risk of industrial accidents. (Euronews)euronews

This is precisely why post hoc reasoning must be avoided: the plant’s strategic importance and Russian sabotage activity do not, by themselves, prove external interference.

At the same time, according to Italian media, the Velletri prosecutor’s office is examining the broader context of the incident, including possible parallels with explosions at defense facilities in Bulgaria. The rapid activation of Russian and pro-Russian information outlets after the explosion has also attracted attention. Azione leader Carlo Calenda called on the government to brief parliament on a possible ‘hybrid attack.’ (RaiNews)RaiNews

However, Moscow’s information exploitation of the event is not evidence of its involvement in the event itself. Russian information structures may exploit an accident regardless of its origin. An information operation and physical sabotage should therefore be treated as two separate analytical hypotheses.

Suspicion of a possible Russian operation does not arise in a vacuum. European law-enforcement and intelligence authorities have established precedents for Russian sabotage against arms-supply chains.

The strongest evidentiary example remains the 2014 explosions at depots in Vrbětice, Czech Republic. In 2024, the Czech National Centre against Organized Crime said it considered GRU responsibility proven. The investigation established the involvement of Unit 29155 personnel and concluded that the operation was intended to obstruct the supply of weapons and ammunition to areas where Russian forces were operating. Czech law-enforcement authorities explicitly characterized Vrbětice not as an isolated episode but as part of sustained Russian sabotage activity in the EU and Ukraine. (Policie České republiky)Policie České republiky

This is crucial to the assessment of Colleferro: Russia has already demonstrated both the capability and intent to physically destroy ammunition on European territory that was intended for its adversaries.

Since the full-scale invasion, this model has broadened. NATO publicly characterizes Russian sabotage, cyberattacks, and other hostile operations against Alliance members as a growing threat. (NATO)NATO

From attacks on facilities to attacks on people

A particularly important element of the threat assessment is the shift in Russian focus from physical infrastructure to key individuals in the defense-industrial complex.

In 2024, U.S. and German services disrupted a Russian plot to kill Rheinmetall CEO Armin Papperger. In January 2025, NATO official James Appathurai confirmed that the plot was viewed in the context of a broader Russian sabotage campaign. (Reuters)Reuters

Even more illustrative is the case of Donaustahl founder Stefan Thumann. According to German media, security authorities warned him in late 2025 about a Russian operation targeting him. In 2026, individuals suspected of conducting surveillance of the businessman were detained; Bundestag member Bastian Ernst said the case involved preparations for an assassination attempt using a Novichok-type nerve agent. (JUX)JUX

Details about the planned method of killing currently derive largely from media reporting and statements by individual politicians rather than publicly released German criminal-case materials. Nevertheless, the broader trend is consistent with previously uncovered operations against defense-industry executives.

It is therefore possible to identify the potential emergence of a three-tier Russian model of pressure on Europe’s defense-industrial complex:

Destruction of production capacity and stockpiles.
The objective is to physically reduce the availability of ammunition, components, and weapons.

Disruption of logistics and production chains.
Even localized sabotage can halt production, trigger inspections at other facilities, force reviews of security procedures, delay contracts, and generate additional costs.

Pressure on human capital.
Surveillance, threats, or preparations for assassination attempts against company executives can create an intimidation effect far broader than the physical removal of a single individual.

The third component may be strategically the most dangerous.

Moscow’s strategic objective may extend beyond the physical destruction of weapons

If Vrbětice, the Papperger plot, the Thumann case, and other European episodes are treated as elements of a single trend, Russia’s objective may be less about destroying a specific batch of ammunition than about increasing the systemic cost of European military support for Ukraine.

The threat of sabotage forces companies to spend more resources on physical security, cybersecurity, counterintelligence procedures, personnel vetting, and production redundancy. Threats to executives create additional costs for personal security and insurance.

Thus, even an unsuccessful Russian operation can produce a partial strategic benefit for Moscow.

This is an important feature of the campaign: its effectiveness is not necessarily measured by the number of factories successfully destroyed or executives killed. If the threat itself forces Europe’s defense sector to operate more slowly, at greater cost, and under persistent risk, Russia is already achieving part of its objective.

Colleferro as a test for Italy’s security system

For this reason, the investigation into the KNDS Ammo Italy explosion should include two parallel tracks.

Industrial and technical: establish the source of the fire, the sequence of detonations, the condition of equipment, compliance with safety procedures, and possible human or technological errors.

Counterintelligence: examine possible external interference, anomalous contacts involving personnel, attempts to penetrate the facility, cyberattacks, intelligence activity around the site, and possible links to known Russian networks.

The available information is insufficient to conclude that the Colleferro explosion was Russian sabotage. An industrial-accident explanation remains entirely plausible and should be treated as the baseline hypothesis until evidence indicates otherwise.

Ignoring the counterintelligence hypothesis would also be a mistake. Russian military intelligence has a documented history of attacks on European ammunition depots, while Western services have in recent years uncovered plots targeting defense-company executives.

The primary unit of analysis should no longer be an individual plant or an individual act of sabotage, but the entire European defense supply chain – production of explosives, ammunition and drones, transportation, warehouses, railway hubs, IT systems, component suppliers, and key personnel.

Russia’s potential strategic objective is not only the physical destruction of military products, but also an increase in the economic and security cost of producing them in Europe. Intimidation of management, higher insurance costs, stronger security measures, production delays, and the need to build redundancy into supply chains can create a cumulative effect.

The Papperger and Thumann cases point to an especially dangerous potential evolution: from sabotage of hardware to attacks on the human infrastructure of Europe’s defense-industrial complex. Executives, engineers, specialists in unmanned systems, explosives, microelectronics, and logistics may gradually become targets as important as factories and warehouses.

If this trend is confirmed, the next risk zone may be the civil-military periphery of the defense sector- electronics and software producers, telecommunications companies, logistics operators, energy companies, and other suppliers of critical components.

As a result, the Colleferro explosion matters regardless of the investigation’s final conclusion. If it was an accident, it demonstrates the physical vulnerability of a critical segment of European ammunition production. If external interference is established, the incident will become further evidence that Russia’s campaign against Europe’s defense-industrial complex has entered a new phase.

For the EU and NATO, the central conclusion is that protection of the defense industry can no longer be limited to guarding factory perimeters. It must encompass the enterprise, digital infrastructure, supply chain, and people as a single security system.

During the Cold War, the Soviet Union and the intelligence services of Warsaw Pact countries systematically prepared sabotage operations against Western military and critical infrastructure. There is, however, an important difference from the current situation: many of these plans were designed as ‘sleeper’ sabotage infrastructure for wartime activation, whereas proven Soviet assassination attempts specifically targeting Western defense-company executives in peacetime were far less common.

Sabotage against the defense industry was part of Soviet doctrine

Declassified U.S. assessments explicitly assumed that the Soviet Union possessed capabilities for large-scale sabotage against U.S. military facilities and bases in Europe. A 1954 U.S. intelligence estimate stated that Soviet sabotage capabilities against U.S. facilities abroad were particularly significant in France and Italy.

Italy itself was already an important theater of this confrontation at the beginning of the Cold War. Historical research based on declassified documents shows that in 1949–1950 French and Italian communist structures conducted ‘direct action’ campaigns aimed at obstructing weapons production in heavy industry and blocking deliveries of U.S. military materiel.

This does not mean that every such operation was directly controlled by Moscow: the activities of local communist parties, Soviet active measures, and operations conducted by the KGB or GRU themselves must be distinguished.

The KGB built infrastructure in Western countries for future sabotage operations

The Mitrokhin Archive is particularly revealing in this regard.

The documents indicate that the KGB conducted reconnaissance of future targets, identified critical infrastructure nodes, and established covert caches of weapons, communications equipment, and explosives.

The FBI, analyzing the Mitrokhin materials, confirmed that in the 1950s and 1960s the KGB prepared for sabotage and infiltration into the West. Soviet services studied U.S. critical infrastructure and routes for infiltrating sabotage teams. Covert caches for such operations existed in Western Europe.

In other words, a system existed: target reconnaissance → agents → caches → explosives/weapons → sabotage team → activation during a crisis or war.

This closely resembles the modern concept of pre-positioning – creating sabotage capabilities in advance.

Military bases were not the only intended targets

The Soviet concept was considerably broader.

The KGB and GRU considered potential targets to include military bases and command centers, transport hubs, ports, railways, energy infrastructure, pipelines, telecommunications, ammunition depots, and enterprises critical to military production.

Declassified U.S. documents described the KGB and GRU as organizations with specially trained forces for operations against key political, military, and economic targets in the enemy rear.

Thus, contemporary Russian attention to Rheinmetall, KNDS, logistics companies, railways, or energy infrastructure has a historical Soviet antecedent.

Assassination attempts against defense-company CEOs are a different matter

The Soviet Union had a well-documented practice of assassination / executive action against defectors, émigrés, anti-Soviet activists, and others whom the regime regarded as particularly dangerous.

Soviet services were far more active in trying to penetrate Western defense companies, recruit employees, and steal technology than in killing their executives.

For example, in 1982 U.S. intelligence characterized Soviet acquisition of Western military technology as a centralized global program. The KGB and GRU penetrated companies, research centers, and government institutions in the United States, Western Europe, and Japan to obtain military technologies.

From Moscow’s perspective, this was logical: an engineer or executive who could be recruited was more useful alive than dead.

Papperger and Thumann may therefore represent an important evolution of the Soviet model

Cold War: Defense industry → espionage / recruitment / technology theft / wartime sabotage planning

Contemporary Russia: Defense industry → espionage + cyberattacks + sabotage + arson + disruption + assassination plots against executives

The contemporary Russian model is therefore not entirely new. Much of its organizational DNA derives from Soviet practice.

But Moscow appears to have changed one important parameter: sabotage tools that the Soviet Union largely reserved for war or an acute military-political crisis are now being used, or prepared for use, by Russia under conditions of formal peace with NATO.

This changes how Colleferro should be interpreted. If KNDS Ammo Italy is viewed not in isolation but through the lens of Soviet/Russian historical practice, three generations of the operational model emerge:

Cold WarRussia in the 2010sRussia after 2022
Defense plantsreconnaissance, penetration, sabotage planningphysical sabotagesabotage + proxies
Ammunitionwartime targetVrběticeEuropean production/supply chains
Technologyindustrial espionagecyber/agent penetrationcyber + HUMINT + sabotage
Company executivesprimarily intelligence targetspotential assassination targets
Operativesprofessional agentsGRU officersofficers + disposable agents
Thresholdprimarily war/crisis“gray zone”formal peace

The contemporary Russian sabotage campaign against Europe’s defense-industrial complex has clear conceptual parallels with Cold War Soviet doctrine, under which the KGB and GRU conducted advance reconnaissance of NATO military, industrial, transport, and energy facilities and created infrastructure for their destruction in the event of war. The fundamental difference lies in the threshold for use. Moscow is transferring part of a toolkit that, in the Soviet model, was largely intended for wartime into day-to-day confrontation with NATO. Reports of assassination plots against the heads of Rheinmetall and Donaustahl may indicate a further evolution of this doctrine: the object of physical coercion is no longer only defense infrastructure, but also the key human capital of Europe’s defense-industrial complex.This raises an additional KIQ: has Russia revived Soviet target lists and KGB/GRU methodology for NATO critical infrastructure and adapted them to the modern European defense industry?