Romania Says It Foiled a Russian Sabotage Operation: Targets Included NATO Bases and Ukrainian Antonov Cargo Aircraft
Baltic Security Monitor | Analytical Brief As of 8 September 2026, 20:00 EEST
Romania's domestic intelligence service, SRI, said on 8 September that it had, together with domestic and international partners, prevented a sabotage operation on Romanian territory that it directly attributes to coordination by the Russian Federation. According to SRI, a Russian citizen residing in Romania had been under surveillance since February 2026 as part of an investigation involving DIICOT prosecutors, the organized-crime police, Romanian military intelligence, and partner foreign services. The suspect photographed and filmed communications centers, Romanian military bases used by NATO allies, headquarters of national defense, public-order, and national-security institutions, and critical infrastructure. According to the service, an intermediary — with whom the suspect communicated via encrypted messaging apps — instructed him to collect imagery of targets of strategic military interest, explicitly including Ukrainian Antonov cargo aircraft during their presence on Romanian territory.
SRI assessed the activity as following the same pattern used by Russian-coordinated sabotage networks previously disrupted in Romania in 2024 and 2025 — meaning this isn't the country's first such case, but part of a recurring scheme. Romanian police and prosecutors added a significant evidentiary detail: the 40-year-old suspect allegedly collected and transmitted photographs of Romanian and allied military equipment, troop movements, and activity at bases in Cluj, Constanța, Călărași, Ilfov, and Bucharest between February and July. He was detained on 8 September on suspicion of preparing acts of sabotage; prosecutors are seeking 30 days of pre-trial detention. The criminal allegations remain subject to the presumption of innocence. Reuters independently confirmed SRI's statement and attribution; Russia's embassy in Bucharest had not responded to Reuters at the time of publication.
The notable part isn't another warning about Russian hybrid activity — there have already been several this week alone, from Denmark to Germany. What's new is that Romania disrupted a concrete operation and officially attributed it to Russia, rather than issuing a general threat assessment: the case has moved from an intelligence finding into an active criminal proceeding with a named detainee.
BSM analysis: the same target as Leipzig, on the other end of Europe
The choice of Antonov aircraft as a surveillance target isn't incidental, and it draws a direct parallel to an event BSM already covered this week: on the night of 5 August, a drone carrying a suspected explosive charge was found beside a Ukrainian An-124 at Leipzig/Halle Airport, and Western intelligence assessments later linked the device to the Russian government. Leipzig/Halle has served as Antonov Airlines' primary European base since 2022 and regularly handles NATO military and logistics flights. The Romanian case shows the same target-selection logic applied at a different point in Europe: strategic airlift is a scarce capability used to move oversized military and industrial cargo, meaning reconnaissance against it threatens not one specific airport, but the entire air-logistics chain sustaining Ukraine.
The fact that SRI explicitly links this case to two previously disrupted operations from 2024 and 2025 confirms this isn't an isolated episode but a persistent, recurring pattern of Russian-coordinated sabotage networks operating specifically inside Romania — a country that is simultaneously a NATO frontline state, a Black Sea security actor, and an important logistics corridor supporting Ukraine.
Why it matters for Ukraine and the Baltic region
Romania is simultaneously a NATO frontline state, a Black Sea security actor, and an important logistics corridor supporting Ukraine. Ukrainian heavy-lift Antonov aircraft are particularly relevant because strategic airlift is a scarce capability used to move oversized military and industrial cargo. The case therefore points to a threat model aimed not simply at influencing European politics but at identifying the physical military-logistics infrastructure sustaining Ukraine.
For the Baltic and Nordic region, the case reinforces a pattern BSM has already documented in the German and Danish cases: suspected Russian networks using relatively low-profile intermediaries to conduct reconnaissance against military, defense-industrial, and logistics targets ahead of potential sabotage. Because foreign partner services participated in the investigation, further arrests or the identification of cross-border links could reveal a wider European network rather than an isolated Romanian case.
Bottom line
SRI says it prevented a sabotage action but has not disclosed the planned method, final target, intended timing, or whether explosives or other attack equipment had already been acquired. The next indicator to watch is precisely that — details that may emerge as the criminal proceeding unfolds — along with whether further detentions surface a wider cross-border network. The case also strengthens the evidentiary basis for treating protection of Ukraine-support logistics as a counter-intelligence and counter-sabotage mission, not merely a conventional force-protection problem.
Baltic Security Monitor (osint-baltic.com) — an analytical publication covering security on NATO's north-eastern flank. All OSINT indices are calculated by an automated indexing system based on open sources.