Russia Fired the Master Spy and Hired the Gig Worker

Moscow runs two recruitment engines, money for the willing and hostages for the unwilling, and Germany is the front line: DHL parcel fires, the Rheinmetall assassination plot, and drones mapping critical infrastructure. The MO, the tradecraft, and what it reprices.

A hooded figure with a glowing phone among shipping containers at night, a distant fire on the port skyline

In 2024, a warehouse in east London holding supplies bound for Ukraine was set on fire. The man who organized it was not a Russian intelligence officer. He had no diplomatic cover, no years of language training, no false identity built at great expense over a decade. He was a British national who had made contact with Wagner over Telegram. Six men were later jailed. No Russian diplomat was expelled over it, because there was no Russian in the country to expel.

That single fact is the most important shift in European security you are probably not pricing in. Russia has quietly retired its most expensive intelligence product and replaced it with a disposable one, recruited by the thousand over encrypted apps, and the change rewrites the risk map for every port, pipeline, rail line, data center, and logistics hub on the continent. It also reaches further than money can explain, because the second engine driving it is not greed. It is fear. And in one country above all, the abstract threat has already become a concrete campaign of fires, drones, and foiled assassinations: Germany.

The master spy has been made redundant

For most of the twentieth century, Russian human intelligence came in two grades. Legals operated under diplomatic cover: attachés and protocol officers who were really officers of the SVR or GRU. Illegals were the crown jewels, operatives inserted under wholly false identities, trained for years to pass imperceptibly as locals. Kim Philby, still revered inside Russian intelligence, was the archetype. The model was patient, expensive, and vulnerable to exactly one thing: expulsion. Catch the officer, declare him persona non grata, and the network degrades.

Since the full-scale invasion of Ukraine in 2022, Europe has expelled Russian intelligence officers at industrial scale, including, in Britain's case, an undeclared military intelligence officer posing as a defense attaché. The Russian ambassador to London left this year. On paper, that looks like the West winning the counter-espionage fight. It is not, because Moscow changed the product. As the exiled Russian intelligence historian Andrei Soldatov, sentenced in absentia to four years this year for his journalism, has documented, the Kremlin now leans on a third category of agent: local, disposable, hired for a single task, and discarded. You cannot expel a gig worker you have never met. That is the entire point.

Two engines: greed and fear

The disposable model runs on two separate recruitment engines, and conflating them is the analytical mistake most coverage makes.

The first engine is inducement. Russian handlers broadcast what are effectively job ads to strangers, promising fast, easy money for small tasks. One investigation found millions of sabotage-related "job postings" pushed through short-lived Telegram accounts that vanish before they can be traced, and the net has widened from Ukraine across the whole European Union. The people who answer are, by design, the vulnerable and the naive: refugees, migrants, petty criminals, the broke, and, increasingly and deliberately, teenagers. Britain's Counter Terrorism Policing has described children as young as 13 being drawn in, and MI5's director general Ken McCallum has publicly warned of Putin's "henchmen" trying to strike inside the UK through proxies. Many recruits genuinely do not know they are working for the Kremlin. They think they have found a shady side hustle.

The second engine is coercion, and it is the one that should worry strategists more. Where inducement fishes for the willing, coercion manufactures agents out of the unwilling by seizing something they cannot afford to lose. The lever is almost always the same: family or property inside Russia's reach. Anyone with a parent in occupied Donetsk, a child in Russia, a flat in Mariupol, or a business the FSB can touch is a potential recruit whether they want to be or not, because the service can threaten the hostage and demand the service. This is the vector that turns the millions of Ukrainians displaced by the war, and the wider Russian-speaking diaspora, into a coercible population. It does not require the target to be greedy, gullible, or sympathetic to Moscow. It only requires them to love someone the FSB can reach.

The hostage economy

The clearest illustration came this August, when Mykhailo Puryshev, a Ukrainian volunteer famous for evacuating some 200 civilians from besieged Mariupol in a battered red van in 2022, announced he was traveling to Russia. He said the FSB had called him from his own son's phone and threatened to conscript the young man into the Russian army, and send him to the front against Ukraine, unless Puryshev cooperated. A Mariupol native, he had four children, two of them living in Russia from a previous marriage. "The first option is that I am friends with them, they don't touch my son... but I am betraying my country and my children. The second option is that I don't cooperate, and they will simply kill my son," he said, before posting a final video captioned, "I have arrived in Russia for the sake of my son." Whatever one concludes about the individual case, the mechanism is textbook: the family is the leverage, and the leverage is the recruitment.

Inside Ukraine, the same coercion is aimed at minors and dressed up as something else. Ukraine's SBU says Russian operatives frequently impersonate Ukrainian law enforcement, posing as officers of the SBU or National Police, to pressure civilians into committing arson, sabotage, and attacks, so the recruit believes he is helping his own side, or fears his own side, rather than knowingly serving Moscow. Russian services have recruited Ukrainian teenagers to plant devices and mark targets on Ukrainian soil; Ukraine's Prosecutor General has framed the recruitment of children for acts of war as a war crime in its own right. The scale prompted the SBU to launch a Telegram chatbot, "Burn the FSB Agent," for citizens to report recruitment approaches; it logged more than 1,300 reports between mid-December 2024 and April 2025 alone. As the analyst Keir Giles put it, "Russia will reach out and recruit anybody it can, because that is now very much cheaper and easier thanks to online access."

The tradecraft

The tasking follows a deliberate escalation, and understanding it is how you spot it. Recruits are typically vetted with something trivial and testable first: photograph a rail yard, film activity at a port, scrawl graffiti, drop a parcel. It proves reliability, filters the informants, and quietly implicates the recruit before the serious asks arrive. From there the jobs climb: reconnaissance and target-marking, testing the security of shipping and logistics, casing a factory or an executive's home, and finally planting incendiary or explosive devices. The pattern is consistent, surveillance first and strike second, with the same disposable recruit sometimes used for both stages.

The handling is built for deniability. There is usually no face-to-face contact and no traditional handler relationship to unravel; instructions arrive over encrypted chat from an account the recruit cannot identify, and payment moves in small tranches through cryptocurrency brokers, informal cash desks, and fragmented bank transfers designed to stay beneath detection thresholds. The recruit is a cutout who does not know the chain above him, which is precisely why arresting him rarely leads anywhere. The one durable weakness, as Western investigators note, is financial: the payment chain is fragmented but it is not invisible, and following the money remains the most productive way to climb from a disposable agent toward the network that hired him.

The wave is physical, and Germany is the front line

None of this is theoretical, and no country has absorbed more of it than Germany, Europe's largest economy and, after the United States, Ukraine's most important arms supplier. In July 2024, a parcel containing an incendiary device ignited at the DHL freight hub at Leipzig/Halle Airport shortly before it was due to be loaded onto an aircraft. It was not an isolated fire. Polish prosecutors described a series of self-igniting packages that struck couriers in Poland, Germany, and a DHL depot in the UK as "test runs" for a plot to down cargo flights bound for North America; Western officials attributed the campaign to the GRU, and Lithuania later prosecuted a network it said organized the DHL and DPD parcel attacks on orders from Russians tied to military intelligence. Germany's federal prosecutor took up the Leipzig case on suspicion of a foreign-intelligence background, though Berlin itself stopped short of naming Moscow at the time.

It did not stay quiet for long. Overnight on 4-5 August 2026, the campaign returned to the same airport with a heavier weapon: an explosives-laden drone was discovered on the apron beside Ukrainian An-124 heavy-lift transports and defused, forcing the airport to close. German investigators reportedly recovered DNA from the device with indications linking it to the 2024 DHL parcel plot, and US intelligence tied the drone to the GRU. On 1 September 2026, Interior Minister Alexander Dobrindt announced that police work, the pattern of the offense, and intelligence findings together pointed to Russian responsibility. Berlin summoned the Russian ambassador, and Foreign Minister Johann Wadephul ordered the Russian consulate general in Bonn closed, effective 18 September, and the lease on the Kremlin-linked “Russian House” cultural center in Berlin terminated. It was a notably firm step, Berlin moving from suspecting foreign sabotage to formally naming Moscow for an attack on German soil. Read the arc: the same site, the same campaign, upgraded in two years from an incendiary parcel slipped into the freight stream to a bomb-carrying drone on the tarmac. The surveillance flights and the sabotage are not parallel stories. They are phases of one kill chain.

The escalation ladder runs to assassination, and no longer against one man. US and German intelligence foiled a Russian plot to kill Armin Papperger, chief executive of Rheinmetall, Germany's largest arms maker, which a senior NATO official confirmed on the record was one of a series of Russian plans to kill European defense-industry executives. In 2026, Die Zeit revealed the second named case: Stefan Thumann, CEO of the Bavarian startup Donaustahl, which supplies reconnaissance and strike drones to Ukraine. Allied intelligence warned Berlin of a credible assassination plan in December 2025; two suspected low-level agents, a Ukrainian man and a Romanian woman who had surveilled his home, were arrested and charged with foreign-intelligence activity, and Thumann has lived in hiding since, changing location every few weeks under guard. Note who the foot soldiers were: not Russians, but a disposable surveillance team recruited from exactly the populations described above. German prosecutors have separately charged individuals with scouting US military installations in Germany for potential sabotage.

The rail network is in the target set too. In November 2025, an improvised charge detonated under the Warsaw-Lublin line, the artery for aid moving toward Ukraine, as a freight train passed; Prime Minister Donald Tusk called it an "unprecedented act of sabotage," and Poland identified the suspects as two Ukrainian citizens working with Russian intelligence, recruited, once again, from the population Moscow can reach. And then there are the drones over Germany itself: for two years, waves of unidentified drones have systematically overflown German critical infrastructure and military sites, from Schleswig-Holstein to power plants, ports, and government facilities, in what officials describe as deliberate mapping rather than stray hobbyist flights, with sightings repeatedly disrupting major German airports. By late 2025 the German government was publicly assessing that the country's critical infrastructure faces serious threats daily, from drones, cyberattacks, and arson combined. The trend line behind all of it points one way: a CSIS database of Russian sabotage and subversion in Europe found attacks nearly tripling from 12 in 2023 to 34 in 2024, after roughly quadrupling the year before, and an Associated Press tally has catalogued around 145 incidents linked to the campaign since the 2022 invasion.

The children, and the next hire

The willingness to burn through the young is not incidental; it is the model working as intended. The case of Laken Pavan, a Canadian teenager, shows both engines at once: by his account to Polish prosecutors he traveled to Donetsk expecting to do humanitarian work, was detained by the FSB, interrogated with a bag over his head, and told to spy or be killed, then tasked to travel Europe photographing sites. He confessed to hotel staff and was jailed in Poland. Coercion produced the agent; disposability defined his value.

Soldatov's forward warning points at the next and more dangerous labor pool: veterans of the war in Ukraine, returning brutalized and, in his words, with little to lose, who "would be much more aggressive and would care much less about the risks they take." Today's proxies are mostly amateurs with poor tradecraft and a high arrest rate. A pipeline of combat veterans comfortable with demolitions and weapons is a capability upgrade, and the war is manufacturing that pipeline in real time. When the fighting slows, that labor supply does not evaporate. It looks for work.

Why this breaks the tools built to stop it

Western deterrence against Russian intelligence was engineered for state officers: surveillance, expulsion, prisoner swaps, the quiet diplomacy of declared and undeclared personnel. None of it bites on a Telegram cutout. The disposable model attacks the one thing the entire Western response depends on, attribution. If the person with the accelerant is a local teenager or a coerced refugee paid in crypto by an account he cannot name, the chain back to Moscow is deniable by design. You can convict the arsonist. You cannot expel the embassy, sanction the ministry, or invoke the treaty article, because you cannot prove, to the standard those responses require, who gave the order. It took Germany two years, and a DNA trail, to formally name Moscow over Leipzig. This is hybrid war optimized for the gap in the West's operating system: the space below the threshold that triggers a hard response, executed by people cheap enough, or coerced enough, to lose in bulk.

What it means for money

Here is where the security story becomes an investment story, and where most coverage stops one step too soon.

1. European physical-security risk is repricing structurally. The target set for cheap sabotage is critical national infrastructure: energy nodes, undersea cables, ports, rail, water, telecom, and the unglamorous logistics real estate that moves military and civilian goods. For holders of European infrastructure, utilities, ports, and industrial exposure, "geopolitical risk" is no longer confined to headlines from the front. It is a warehouse in the portfolio catching fire, a freight line under an explosive charge, a cargo hub with a drone on the tarmac. That raises the standing operating cost of physical assets across the continent, more guards, fencing, monitoring, redundancy, and downtime, on a multi-year basis rather than as a one-off shock.

2. The insurance model has a hole at the attribution seam. Attribution is the load-bearing beam of war-risk, terrorism, and political-violence coverage, because policies turn on whether an event was war, terrorism, ordinary crime, or a state act. The disposable-proxy model is engineered to blur exactly that line, and the Leipzig arc, two years from parcel fire to formal state attribution, shows how long the answer can take. Expect coverage disputes, tightening exclusions, rising premiums on European property, aviation, and marine risk, and a drift toward self-insurance and government backstops. Where attribution collapses, someone eats the loss, and the fight over who is itself a market.

3. The insider-threat and vetting problem just widened. The coercion engine means the risk is not only at the perimeter. Any organization employing people with close family or property inside Russia or occupied territory now carries a coercion surface that standard background checks were never designed to detect, because the recruit may be a loyal employee with a gun to a relative's head rather than a plant. For operators of ports, defense supply chains, energy, and transport, this pushes spending toward continuous insider-threat programs, access compartmentation, and support structures that give a coerced employee somewhere to turn other than compliance.

4. The counter-hybrid buildout is a durable tailwind, and it is already commercial. Every incident strengthens the case for spending that never shows up in the tank-and-jet budget lines: physical and perimeter security, counter-drone systems, insider-threat, open-source and financial-intelligence tooling, and critical-infrastructure monitoring. This is not a forecast. In 2026, Rheinmetall and Deutsche Telekom announced a partnership to build a civilian counter-drone and sabotage-defense shield for German critical infrastructure, pooling sensors, jammers, interceptors, and lasers, a direct commercial response to the incursions. That is the shape of the trade: the advantage accrues to the players who detect, attribute, and harden, and to the financial-intelligence layer that follows fragmented crypto payment chains, rather than to the ones who shoot. Governments cannot expel their way out of this, so they will build domestic counter-sabotage capacity instead, a multi-year, politically durable spending trend that flows to the vendors of protection.

The bottom line

Russia did not lose the spy war when it lost its embassies. It got cheaper, more deniable, and harder to hit, and it built two engines to feed the machine: money for the willing, and hostages for the unwilling. In Germany, the abstraction is already a campaign: parcel fires and a bomb-carrying drone at Leipzig, an explosive charge under the rail artery to Ukraine next door, executives of Rheinmetall and Donaustahl under death threats, and drones methodically mapping the infrastructure, while the next wave of labor hardens at the front. For strategists, the lesson is that deterrence built for the Cold War does not fire on a gig-economy threat, and vetting built for spies does not catch a coerced employee. For investors, the lesson is narrower and more useful: the cost of protecting the physical world in Europe is on a structural climb, the insurance framework that priced that world is cracking at the attribution seam, and the money will move, steadily and unglamorously, toward whoever can see the threat coming, follow its money, and harden the target. Watch the protection layer, not the front line.


Sources & Further Reading


Disclaimer

AlphaBriefing is an independent intelligence publication. The content in this article is produced for informational and educational purposes only. Nothing published by AlphaBriefing constitutes financial, investment, legal, tax, or regulatory advice, nor should it be construed as a solicitation or recommendation to buy, sell, or hold any security, asset, or financial instrument.

All views expressed are those of the author at the time of writing and are subject to change without notice. Markets are volatile and unpredictable; past performance is not indicative of future results. Any investment involves risk, including the possible loss of principal.

AlphaBriefing and its principals, employees, or contributors may hold positions in securities or assets mentioned in this article. Readers should conduct their own due diligence and consult qualified financial, legal, and tax advisors before making any investment decisions.

Information in this article is drawn from public sources believed to be reliable at the time of publication. AlphaBriefing makes no warranty, express or implied, as to the accuracy, completeness, or timeliness of any information herein.

© AlphaBriefing. All rights reserved.

Operated by veterans. Driven by discipline. Built for the early mover.
AlphaBriefing provides financial commentary and market analysis for informational purposes only. We do not offer personalized investment advice. All content is opinion-based and should not be considered a recommendation to buy or sell any security. Past performance is not indicative of future results. Investing involves risk, including the potential loss of principal. Individual results may vary. We value your privacy. Any data collected is used to improve your experience and to provide relevant updates about our services.
©2025 AlphaBriefing. All rights reserved. | Privacy Policy | Legal Disclaimer