A Norwegian publication has questioned whether Europe’s accusations of Russian sabotage rest on evidence or political expectation. The argument, made by Italian commentator Thomas Fazi in an article published by on 8 October 2026, is that warnings from the European Union and Nato may shape public opinion before investigations have established every fact.
That is a legitimate concern in any fast-moving security case. Intelligence assessments can change, evidence may remain secret and official statements can come before a trial. But the wider suggestion that Europe’s accusations are merely political conjecture runs into a record of criminal proceedings, technical cyber investigations and sanctions aimed at named Russian units, companies and individuals.
The important distinction is between what has been proved in court, what authorities have formally assessed and what remains under investigation. The evidence is not identical in every case. Nor does one documented incident establish Russian responsibility for every fire, cyberattack or GPS disruption reported across Europe. It does, however, make the claim that European accusations have no evidentiary basis too broad.
A warehouse fire became a prosecution case
One of the clearest examples is the arson attack on 20 March 2024 at a warehouse in Leyton, London. The site held aid intended for Ukraine, including Starlink equipment.
The United Kingdom’s Crown Prosecution Service said the organisers acted in coordination with the Wagner private military company, which has been linked to the Russian state. Prosecutors relied on material including surveillance footage and digital evidence.
Those allegations belong to a specific criminal case; they do not automatically prove every wider accusation about Russian activity in Europe. A prosecution case is also not the same as a final conviction. But the existence of a defined location, date, alleged participants and identifiable visual and digital material contradicts the sweeping idea that European authorities are relying only on political messaging.
A separate investigation followed the discovery in early August 2026 of a drone carrying explosives near a Ukrainian An-124 transport aircraft at Leipzig Airport. German authorities said the inquiry produced evidence pointing to Russian involvement in a possible hybrid operation. The incident was linked to tighter security measures and to the closure of the Russian House in Germany.
The Leipzig case must be treated differently from a completed trial. Its significance is narrower but concrete: investigators were examining a particular device, aircraft and site, rather than responding only to a general prediction about what Moscow might do. The strength of the evidence remains a matter for the relevant German legal and investigative processes.
Cyber attribution follows a different trail
Digital attacks rarely leave the kind of immediately visible evidence found in a video recording or a seized device. German and Czech cybersecurity specialists and government agencies nevertheless officially linked attacks on logistics systems and government servers in 2024 to APT28, also known as Fancy Bear. Western governments identify the group with Russian military intelligence.
The public explanations referred to technical indicators including digital signatures, the infrastructure used in the attacks and characteristics of the malware and programme code. Such an attribution is not the same as a criminal conviction. Intelligence sources may remain confidential, and agencies commonly disclose only part of the technical record.
That limitation does not turn the assessment into a political guess. Cyber investigators generally compare several elements: the tools deployed, server infrastructure, operating methods, target selection and the timing of an operation. The conclusion is cumulative, and its level of confidence may differ from the standard of proof required in court. It is nevertheless based on a technical process rather than simply on the existence of political tension.
This is where Fazi’s argument has its strongest point and its greatest limitation. Governments can overstate an early assessment, and an attribution can be revised as new information emerges. But the fact that the public cannot inspect every source does not show that no technical analysis exists.
Sanctions name structures, not just a country
The EU’s response has also gone beyond general warnings. On 16 December 2024, the Council of the EU imposed sanctions on Russian military intelligence unit 29155 and people associated with it. The council cited alleged involvement in foreign operations, including explosions and cyberattacks.
A sanctions decision does not prove that every act of sabotage in Europe was directed by that unit. It does show that EU governments identified a particular structure and used a formal legal instrument against it. The designation carries legal and economic consequences, but it is not automatically a judicial finding on every incident connected with it.
On 20 May 2025, the Council also sanctioned Russia’s Main Radio Frequency Centre, linking its activities to electronic warfare, including the jamming and spoofing of GPS signals. The EU said such activity created risks for the Baltic region and civil aviation.
The same package included Russian fishing companies whose activities the EU associated with surveillance of critical infrastructure and potential risks to undersea cables. Those measures, too, require careful interpretation. A sanctions designation is not a criminal verdict. It is nevertheless more specific than a general political accusation: it names organisations, describes alleged capabilities and imposes formal restrictions.
What Fazi’s warning does — and does not — establish
Fazi, an Italian commentator who regularly writes for eurosceptic media, argues that repeated warnings about possible Russian false-flag operations could prepare the public to blame Moscow before direct evidence becomes visible. His article questions whether official statements are influencing the interpretation of events before all the circumstances are known.
That risk cannot be dismissed in principle. Early information may be incomplete; intelligence services can alter their assessments; and public accusations can affect how later evidence is understood. The public debate should therefore distinguish between a political warning, an intelligence assessment, a technical finding and evidence tested in court.
But doubt about the timing or transparency of one statement does not establish that the wider pattern is fabricated. In Britain, an arson investigation produced a prosecution case involving surveillance and digital material. In Germany and the Czech Republic, agencies published technical assessments of cyberattacks. The EU imposed sanctions on named Russian units, companies and associated individuals over alleged hybrid activity.
None of these examples proves Russian responsibility for every fire, cyberattack, GPS disruption or suspected act of sabotage in Europe. They do show why the claim that Europe’s accusations have no evidentiary foundation is too broad. The unresolved question is more precise: how strong is the attribution in each individual case, and how much of the underlying evidence can governments and prosecutors disclose without exposing sources, weakening security or damaging investigations that are still under way?