Russia has intensified efforts to disrupt Danish companies involved in supplying military equipment to Ukraine, according to Denmark’s national security and intelligence service, as Copenhagen warns that Moscow is increasingly concentrating its hybrid activities on targets with a direct connection to weapons production.
Josefine Christensen, a lead analyst with the Danish Security and Intelligence Service, PET, said on October 7 that Russian operations had moved from extensive planning earlier in 2026 toward more active implementation during the summer. Reuters reported her comments from a homeland security conference in Copenhagen.
The reported shift is important because it places defense production closer to the center of Russia’s suspected hybrid campaign in Europe. Rather than focusing only on broad disruption or political pressure, Danish intelligence says Moscow is increasingly seeking targets whose disruption could affect the supply of military equipment to Ukraine.
From broad disruption to defense production
According to Christensen, Danish intelligence assessed that earlier Russian efforts had not succeeded in discouraging NATO countries from continuing military support for Ukraine. The focus has consequently moved toward targets capable of producing a more direct effect on the battlefield, particularly weapons production.
The distinction matters for European defense industries. Companies supporting Ukraine increasingly form part of a distributed production network rather than operating solely through traditional government arsenals. Components, drones, electronics, ammunition and other equipment can involve multiple private suppliers across several countries.
That structure can also create more potential points of vulnerability. Smaller manufacturers may not have the same physical security, counterintelligence resources or cybersecurity budgets as major national defense contractors.
Danish intelligence has previously warned that Russian sabotage activity can rely on intermediaries and proxies rather than personnel directly identifiable as Russian intelligence officers. PET says Russian-linked actors can recruit individuals to identify targets and carry out physical sabotage, making attribution more difficult.
A growing concern for Danish defense companies
The latest warning follows a series of Danish intelligence assessments that have identified Russian sabotage as a growing security concern.
In September, Danish reporting based on PET statements said Russian security services were actively preparing sabotage against parts of Denmark’s defense industry, particularly companies connected to military support for Ukraine. The warnings included concerns over attempts to obtain information about factories, access arrangements and security conditions.
PET’s broader public assessment says Russia is showing an increased willingness to use physical sabotage in Europe. It identifies disruption of supplies to Ukraine and the creation of fear within Western societies as possible objectives. The agency also says Russian-linked individuals have been associated with sabotage incidents elsewhere in Europe.
At the same time, the publicly available Danish material does not establish that a particular named Danish defense factory has been physically damaged by a Russian operation. PET’s public sabotage assessment says it was not aware of specific instances of Russian physical sabotage in Denmark.
That distinction is important. The latest intelligence reporting indicates that Danish authorities believe Russian sabotage operations are being conducted or prepared against defense-related targets, but publicly available information does not provide a detailed incident list, identify affected companies or establish the extent of any physical damage.
Russian targeting of Europe’s drone supply chain
One element cited by Danish intelligence is a list published by Russia’s Defense Ministry in April identifying European companies that Moscow said were involved in producing drones or drone components for Ukraine.
The Russian publication included companies and facilities in several European countries. Russian officials presented the companies as connected to Ukraine’s military-industrial supply chain, while subsequent reporting noted that at least one listed address appeared to be a residential property rather than an obvious production site.
The list does not by itself demonstrate that an attack will occur against any company named in it. Its relevance to the Danish warning is that Russian authorities have publicly drawn attention to European businesses involved in supplying Ukraine, while Danish intelligence is reporting increased Russian interest in defense production.
For companies operating in the European defense supply chain, that creates a security problem beyond traditional military threats. Facilities that previously might have been treated primarily as commercial manufacturing sites can become potential targets for espionage, disruption, cyber operations or physical sabotage.
Denmark’s warning fits a wider NATO threat assessment
The Danish assessment is not isolated from the broader European security picture.
The Danish Defence Intelligence Service, DDIS, has previously assessed that Russia is conducting hybrid warfare against NATO and the wider West, including sabotage and destructive cyber operations. Its assessment says Russia has used individuals who are not directly connected to Russian intelligence services to conduct sabotage, partly because this can make attribution more difficult.
DDIS has also warned that Russia is likely to increase its hybrid activities against NATO. Its assessment describes sabotage as one of several tools that can be used below the threshold of open armed conflict.
That approach creates a difficult problem for European governments. A conventional military attack against a NATO member would present a fundamentally different response problem from an unexplained fire, intrusion, cyberattack or industrial accident that authorities later determine may have been deliberately caused.
The ambiguity can itself be useful to an attacker because it can delay attribution and complicate decisions over how strongly to respond.
The defense industrial base becomes part of the security perimeter
The Danish case also illustrates a wider change in the European defense environment.
European governments are increasing defense spending and expanding production capacity after years of relatively limited investment. Denmark, for example, has substantially increased defense spending and has allocated significant resources for military assistance to Ukraine. The Danish government said in February that defense spending was expected to reach about 3.5 percent of GDP in 2026 and that approximately DKK 70 billion had been allocated through the Ukraine Fund’s military framework for 2023 to 2028.
Those investments are intended to increase military capacity, but they also expand the physical and digital footprint that adversaries can seek to disrupt.
For defense manufacturers, resilience therefore increasingly involves more than maintaining production equipment and inventories. Security measures can include access control, employee vetting, protection of industrial networks, monitoring of suspicious reconnaissance activity and coordination with national security agencies.
This is particularly relevant to the growing European drone sector. Drone production can be distributed among relatively small companies and suppliers, creating a network that can be harder to protect uniformly than a small number of traditional military production complexes.
Moscow rejects the allegations
Russia has repeatedly rejected Western allegations that it conducts sabotage or hybrid warfare operations in Europe. The Russian Embassy in Copenhagen rejected the latest Danish accusations, according to Reuters, while Moscow has previously characterized similar claims as unfounded.
No public evidence released with the latest Danish warning establishes the full operational details of the alleged activities. The Danish intelligence assessment therefore remains the central basis for reporting the development.
The significance of the warning is less about a single confirmed attack than about the reported change in Russian targeting priorities. If defense production and companies supporting Ukraine are increasingly treated as operational targets, European governments will have to protect a much larger part of the defense supply chain.
For Denmark, that means private factories and suppliers supporting Ukraine are increasingly part of the country’s national security picture. For NATO more broadly, the same issue extends across borders because modern defense production depends on interconnected suppliers rather than isolated national arsenals.
The available evidence does not establish the scale of any physical damage to Danish defense companies. It does, however, show that Danish security agencies consider the threat of Russian-directed or Russian-linked sabotage serious enough to require increased attention from the defense industry and government.