US charges allege Russian intel plot for killings and attacks across Europe

US prosecutors allege a Russian intel-linked network sought murders and infrastructure attacks in Europe against states supporting Ukraine, sharpening EU security and C-UAS priorities.

Share
European critical infrastructure security scene with power substation fencing and surveillance cameras at dusk.
European critical infrastructure security scene with power substation fencing and surveillance cameras at dusk.

Key facts

  • US prosecutors charged five alleged Russian intelligence-linked operatives with conspiracy to finance terrorism; three also face murder-for-hire conspiracy charges.
  • Indictment alleges recruitment for surveillance/killings in the US and discussions of attacks on European civilian and military infrastructure aligned with Ukraine.
  • Case cites a proposed Lithuania killing and suggested attacks on a warehouse or electrical substation; operations allegedly coordinated in Prague and Lithuania in 2024.

3 minute read

U.S. federal prosecutors have charged five individuals alleged to be working for Russian intelligence with conspiracy to finance terrorism and, for three defendants, conspiracy to commit murder for hire. The indictment, announced by the U.S. Department of Justice, describes a network that allegedly recruited operatives to conduct surveillance and targeted killings in the United States, and to plan attacks against civilian and military infrastructure in European countries that are aligned—or perceived to be aligned—with Ukraine. All five defendants remain at large.

According to the charging documents, the network most recently attempted to recruit a U.S.-based individual to surveil and kill a prominent Russian dissident living in the United States, offering roughly $40,000 to “eliminate” or “disappear” the target and discussing subcontracting the act to others. Separately, an alleged Russian intelligence officer is accused of offering $25,000 to kill a dissident in Lithuania, before proposing attacks against a warehouse or an electrical substation in “all the countries that are helping Ukraine.” The indictment also alleges operational coordination in Prague and Lithuania during 2024, underscoring a footprint that intersects multiple European jurisdictions and security services.

For Europe, the immediate implication is a higher assessed risk of directed sabotage and proxy violence against critical national infrastructure and defence-adjacent logistics, with energy nodes, depots, airports, and rail-linked supply chains likely remaining attractive targets because they deliver strategic effect below the threshold of conventional military escalation. The allegation that targeting logic extends to any state “helping Ukraine” broadens the threat envelope beyond frontline allies and into the full coalition of political, financial, industrial and military supporters.

The U.S. case also reinforces a wider European pattern of suspected Russian-linked hostile activity. POLITICO notes Germany’s explicit attribution to Moscow of an explosives-laden drone incident at Leipzig-Halle airport in August and identification of suspects with alleged ties to Russian military intelligence, alongside this week’s incidents in which NATO jets shot down a drone that entered Lithuanian airspace and a Russian frigate fired at a Danish military helicopter. While these events differ in attribution and legal posture, together they point to an increasingly crowded operational environment in which intelligence services, law enforcement, and armed forces must synchronize counter-sabotage, airspace/maritime security, and protective security for high-risk individuals.

For European procurement and aerospace stakeholders, the operational takeaway is that counter-UAS, perimeter surveillance, and rapid attribution tooling are becoming not only force-protection requirements but also civil-military critical infrastructure necessities, particularly around airports, ports, energy substations, and warehouses supporting Ukraine-related supply flows. The reputational and continuity risks for operators and integrators will rise in parallel with more frequent investigations, arrests, and sanctions actions tied to alleged Russian networks.

Source: POLITICO Europe