Russia’s ‘spook gangster’ tactics for recruiting spies to target UK military sites

Russia is refining its “disposable spy” model to plot more “sophisticated and deadly” sabotage attacks against Britain and its allies, intelligence experts have warned. 

Moscow relies on so-called “gig-economy saboteurs” by recruiting amateur, low-level operatives to conduct its hybrid warfare campaign of infrastructure attacks, physical assaults and intimidation as Vladimir Putin seeks to inflict a cost on Europe for its support of Ukraine. 

However, sources told The i Paper that hostile intelligence services known to be active in the UK – including Russia, Iran and China – are evolving their recruitment tactics to broaden the scope and tempo of attacks, as well as looking to infiltrate state institutions from armed services to government departments. 

The Kremlin is widely held to be behind a dramatic escalation in “grey zone” activity across the UK and Europe – ranging from surveillance and arson attacks on defence manufacturing facilities to offensive drone operations such as the failed explosive UAV attack on Leipzig airport last month.

The number of hybrid warfare incidents attributed to Russia has risen by 60 per cent in the first 10 months of 2026 compared with the same period last year.  

‘If someone can firebomb a warehouse, why not train them to pilot a drone?’

Intelligence agencies and counter-terrorism forces are increasingly concerned that Moscow is now also evolving its sabotage and espionage tactics to identify more accomplished operatives as it trawls criminal networks and social media platforms for individuals willing to carry out illegal acts in return for payments ranging from as little as £5 for graffiti to £10,000 for an assassination or large-scale arson.  

The use of these individuals, who are often but not always recruited among eastern European and Russian-speaking diaspora communities, has coined the phrase “disposable spies” or “single-use operatives” on the basis of their criminal background, financial motivation, and the risk that their activities often result in detection or arrest. 

Dragonfly Intelligence from Dow Jones, which monitors hostile state activity, said it had tracked 351 individuals arrested in connection with suspected Russian-origin hybrid warfare attacks since 2022 who had a criminal background and no prior experience of intelligence work. Of that total, 73 – 21 per cent – were detained in the past 10 months. 

One European intelligence source said: “The utility of the ‘single-use’ operative model is strongly proven for the Russians. The next question for them is how to improve that model.  

“An obvious route is to take those individuals who have shown some aptitude and see how they might be used in more precise or higher-value activities. If someone has shown they can firebomb a warehouse and get away with it, why not train them to surveil an airbase or pilot a drone?” 

‘More sophisticated or deadly attacks’

In a recent study, the International Centre for Counter-Terrorism (ICCT), a think-tank based in The Hague, found that the main motivation for grey zone operatives was money, and that the Kremlin’s readiness to pay was leading to the formation of “organised networks” capable of taking on more lethal missions at the behest of their Russian controllers. 

The ICCT warned: “Moscow often begins with petty criminals – petty thieves, minor drug dealers, or indebted individuals – whose initial role is limited to low-level acts. Yet repeated recruitment can lead these actors to build more structured criminal groups. 

“These groups may then evolve into organised networks that serve Moscow’s interests more systematically… and potentially enabling more sophisticated or deadly attacks.” 

Western countries, including Britain, have responded to such threats with increased interventions under tightened legislation such as the UK’s National Security Act designed to counter subversion by hostile or adversary states such as Russia, Iran and China. 

Among those currently facing charges in the UK are a 31-year-old Swindon man who denied allegations that he plotted with Russian intelligence to sabotage drone manufacturing sites. Earlier this week, a Royal Navy sailor specialising in warfare intelligence appeared in court charged with preparing to spy for Russia. 

The mass expulsion of Russian intelligence operatives from western countries in the wake of the Salisbury nerve agent poisonings in 2018 is widely regarded as having forced Moscow’s hand into replacing its retinue of professional spies. In Europe, a “spook-gangster nexus” of espionage officers working hand-in-glove with organised crime groups provide services from recruiting low-level operatives to money laundering and conducting cyber attacks. 

A UK government source said Moscow remains adept at seeking out the weak points of individuals it may wish to target in persuading them to act on its behalf.

“It’s financial. It’s embarrassment. It’s some sort of moral compulsion,” the source said. “Maybe [someone] sympathises with Russia rather than Ukraine or something. Maybe there’s some duress: good old fashioned ‘you don’t want these pictures turning up to your mum and dad’ or something like that. There’s many reasons for it.”

Consequently, Britain and other western governments have built in multiple safeguards in an attempt to block the Kremlin’s preferred routes to those with sensitive information.

Dark web portals used by intelligence services to elicit information with promises of anonymity are in fact routinely monitored by law enforcement agencies such as the NCA and the FBI. Similarly, public servants with access to sensitive information must agree to routine vetting of their finances to flag unusual or large payments and work email accounts potentially used to share classified material can be tracked.

Several experts pointed out that Russia and other adversaries have at the same time never lost sight of “old school” intelligence goals such as recruiting sources within rival agencies as well as in walks of life from the military to politics. 

Arkadiusz Nyzio, a security specialist at the Jagiellonian University in Krakow, said: “Innumerable precedents demonstrate that Russian espionage remains oriented toward penetrating the decision-making ranks of the state and acquiring high-value human sources within critical sectors of public life.” 

Dr Nyzio pointed to the arrests and prosecutions in the last three years of intelligence officials in Germany, Sweden and Austria for spying for Russia as proof of Moscow’s enduring ability to penetrate its western adversaries. 

He said Russia was in effect running its “traditional” espionage operations aimed at recruiting high-value agents in parallel with its “disposable spy” operation, while at the same time keeping open the possibility that a small proportion of its “gig-economy” saboteurs may be worthy of development.

Dr Nyzio said: “Russian intelligence services do not necessarily need to protect every one of these recruits with the same care they would devote to a carefully selected, trained and equipped intelligence asset in a more traditional espionage operation. They can afford to lose many of them while identifying and developing those who prove particularly valuable.”

Chinese online recruitment plot

From the point of view of hostile espionage services operations to set up conventional spy networks used to target rival agencies or political parties are time-consuming and expensive, requiring substantial payment to recruits and undertakings to exfiltrate and rehome agents if necessary. 

Matthew Ince, associate director for global risks at Dragonfly Intelligence, points out that the same services are consequently looking for short cuts in obtaining such high-level intelligence. 

In June, the so-called Five Eyes intelligence sharing alliance comprising the UK, the US, Australia, Canada and New Zealand issued a rare joint bulletin warning of an operation by Chinese military spy agencies to use western networking sites and online job platforms to target serving government and military personnel with access to classified information. 

The bulletin warned of an “aggressive online recruitment strategy” whereby Chinese intelligence officers were posing as employees of think-tanks or headhunting firms seeking foreign policy or defence analysts. Candidates within government ministries or armed services with security clearances were then being pressured to provided “non-public” information as part of a bogus recruitment process. 

Social engineering

Ince pointed out that there was little chance of hostile states using the “disposable spy” model to attempt to convert an individual paid to conduct an arson attack or scrawl racist graffiti into the sort of high-level operative needed to infiltrate a government ministry or a military intelligence cell. 

But he said countries like Russia were actively exploring multiple avenues, from using criminal intermediaries to identify potential targets to adopting technology, to destabilise and degrade western institutions.

He added: “The Five Eyes bulletin was an example of the way this type of grooming and social engineering activity [to obtain intelligence] can now happen increasingly through more digital means. AI just amplifies the scale at which these types of synthetic operations can be carried out.

“Given the extent to which we know Russia and Iran have history of carrying out malign influence and interference operations in the UK, I think it’s plausible they would be using those types of tactics as well.” 

Original source Russia’s ‘spook gangster’ tactics for recruiting spies to target UK military sites

Back to home