Romania says it foiled Russian-coordinated sabotage operation targeting military sites
The intelligence service’s allegation puts infrastructure protection under scrutiny; the reviewed evidence does not establish a completed attack.
Romania’s intelligence service said on September 8 that it had prevented a sabotage operation coordinated by Russia, according to Sky News. The service alleged that a Russian citizen had documented military bases used by NATO allies and other sensitive sites. The account describes an intercepted operation, rather than a confirmed destructive attack.
Sky reported that the suspect had been monitored since February and that prosecutors were questioning a 40-year-old Russian man. The attribution to Moscow remains the Romanian service’s assessment in the reporting reviewed. Further prosecutorial findings would be needed to establish criminal responsibility and clarify the relationship between reconnaissance and any intended acts of sabotage.
National investigation, allied security concerns
NATO’s published policy places primary responsibility for responding to hybrid threats with the country being targeted. The alliance can provide assistance, including tailored support teams requested by members. Its January 2026 explanation also describes intelligence sharing and analysis intended to help governments understand hostile activity. These arrangements explain the wider security framework without independently substantiating Romania’s allegation.
The same NATO policy treats sabotage, deception and cyber activity as methods that can be used to destabilise societies and blur the boundary between peace and war. It says hybrid actions could lead to an Article 5 decision, but that is a potential political response rather than an automatic consequence of an intelligence announcement. The Romanian report does not establish that such a collective-defence decision has been taken.
Earlier responses provide context
Britain has separately used sanctions against Russian intelligence activity. In July 2025, its Foreign, Commonwealth and Development Office announced measures targeting three GRU units and 18 military intelligence officers over a sustained campaign of malicious cyber operations. The British statement identified communications, political institutions and energy infrastructure among sectors Russia had targeted. Those earlier findings concern other conduct and provide no proof against the person under investigation in Romania.
The immediate issue is therefore the evidence emerging from the Romanian investigation. Public findings that distinguish surveillance, preparation and attempted damage would help establish what was prevented and who directed it. Existing NATO assistance mechanisms and earlier British sanctions illustrate tools governments can use in response to hostile activity. Applying those tools to this case would require decisions grounded in its own facts, rather than assuming that similarities to previous operations establish responsibility.