Lyce · Hybrid Watch

hw_b7ec73d2263912dd

Danish intelligence identifies concrete Russian preparations for sabotage against defence-sector companies.

On 5 September 2026, Denmark’s Security and Intelligence Service (PET) publicly confirmed that it was observing concrete Russian planning and preparation for sabotage operations inside Denmark. PET assessed the overall Russian sabotage threat to Denmark as high. The intelligence service said the activity was aimed primarily at companies belonging to the Danish defence industry and companies directly connected to military assistance for Ukraine. PET described Russian intelligence services as recruiting intermediaries through social-media platforms, gaming services and messaging applications such as Telegram. Recruits can initially be given seemingly minor assignments, including photographing companies, warehouses, transport vehicles and access routes. These tasks can serve as reconnaissance or preparation for later sabotage activity while distancing Russian handlers from the eventual operation. PET subsequently reiterated that Russian willingness to undertake sabotage in Denmark was increasing and could eventually expand from defence companies toward critical infrastructure and other essential societal functions. On 7 October, Reuters reported that Danish intelligence had concluded Russia had attempted sabotage acts against Danish defence companies, confirming that the threat involved operational activity rather than only a theoretical scenario. PET did not publicly identify the individual companies or provide dates for every operational step, meaning this should remain one campaign-level entry rather than being split into invented individual incidents. The Russian attribution itself, however, comes directly from Danish counterintelligence and can therefore be recorded as Officially attributed.

Occurrence
2026-09-05
Publication
2026-09-05
First observed
2026-10-10T04:30:13.070Z
Review status
Not assessed
Countries
DK
Updated
2026-10-10T04:30:13.070Z

Attribution

Official

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2026-09-05T15:09:26Z

    On 5 September 2026, Denmark’s Security and Intelligence Service (PET) publicly confirmed that it was observing concrete Russian planning and preparation for sabotage operations inside Denmark. PET assessed the overall Russian sabotage threat to Denmark as high. The intelligence service said the activity was aimed primarily at companies belonging to the Danish defence industry and companies directly connected to military assistance for Ukraine. PET described Russian intelligence services as recruiting intermediaries through social-media platforms, gaming services and messaging applications such as Telegram. Recruits can initially be given seemingly minor assignments, including photographing companies, warehouses, transport vehicles and access routes. These tasks can serve as reconnaissance or preparation for later sabotage activity while distancing Russian handlers from the eventual operation. PET subsequently reiterated that Russian willingness to undertake sabotage in Denmark was increasing and could eventually expand from defence companies toward critical infrastructure and other essential societal functions. On 7 October, Reuters reported that Danish intelligence had concluded Russia had attempted sabotage acts against Danish defence companies, confirming that the threat involved operational activity rather than only a theoretical scenario. PET did not publicly identify the individual companies or provide dates for every operational step, meaning this should remain one campaign-level entry rather than being split into invented individual incidents. The Russian attribution itself, however, comes directly from Danish counterintelligence and can therefore be recorded as Officially attributed.