By Isabella Sutherland - Military Strategy & Intelligence Team
Over one hundred and fifty arson and explosive plots across Europe have been linked to Russia between February 2022 and Februry 2026, and very few carried out by Russian nationals [1]. Since Russia's full-scale invasion of Ukraine in February 2022, Western security services have documented a sharp increase in Russian intelligence operations conducted through criminal proxies, disposable agents, and deniable intermediaries. R v Roussev & Others and R v Dylan Earl & Others together demonstrate that traditional UK counter-espionage frameworks were not designed to address remotely directed intelligence networks and task-based criminal operatives.
Available evidence suggests that Russia’s accelerated use of criminal proxies in the UK is enabled by multiple interacting factors, including the structural degradation of professional HUMINT capacity through mass coordinated diplomatic expulsions; depletion of Russian intelligence in Ukraine; the ideological contrast from Cold War-style long-term communist recruitment with Putin’s Russia, and the technological infrastructure which has made remote proxy control operationally viable at scale. The 2022 invasion was an accelerant rather than the origin of a new tradecraft.
Double Depletion
Russia’s professional HUMINT presence in the UK had begun to decline before 2022. The Salisbury poisoning triggered the expulsion of 23 Russian diplomats in 2018, the largest of its kind since the Cold War, removing a significant layer of embassy-based intelligence officers. Following the full-scale invasion in 2022, a coordinated Western response expelled over 700 Russian officials across more than 34 countries. The overwhelming majority were intelligence officers using diplomatic cover; this huge capacity cannot be quickly or easily replaced [2].
The Ukraine war introduced a compounding depletion. Russia’s intelligence services including the FSB, SVR, and GRU have been substantially redirected toward the war effort, consuming intelligence resources which could have otherwise been deployed in Western Europe [3]. These combined factors made proxy substitution both preferable and increasingly attractive. [al1]
Why ideology cannot fill the gap
Two main enabling conditions explain why proxy actors seem to have become one of the main instruments of Russia in the UK instead of rebuilding its network of professional officers after the mass expulsions.
First is ideology. The Cold War model of espionage depended on Western recruits motivated by a genuine commitment to Soviet communism. Putin’s modern statist nationalist anti-Western ideological framework may not hold the same appeal [4]. This is not a temporary gap, but a seemingly increasingly entrenched [al2] feature of post-Soviet Russia; money, coercion, and criminal leverage now substitute this void.
Second is technology in the era of the ‘Gig Economy’ defined by a free-market, predominantly online system where short-term positions common and organisations buy workers for temporary engagements [al3] [5]. Encrypted messaging platforms like Telegram, cryptocurrency payments, and remote tasking are central to this on-demand workforce. It creates the operational infrastructure for control over proxy actors without physical presence. Russian handlers direct the local actors anonymously through digital channels, making attribution difficult and the handler-agent relationship difficult to trace. Without this infrastructure, [al4] the expulsion of embassy-based officers would have significantly reduced Russian capability.
The Hitman and the Arsonist
Six Bulgarian nationals, the so-called ‘Minions Ring’, led by Orlin Roussev and directed through Russian intermediary and fugitive Wirecard executive Jan Marsalek, operated in a networked structured utilising fake passports in a layered principal-agent system. The group conducted semi-professional surveillance on journalists, politicians, and military facilities across the UK and Europe between 2020 and 2023, compiling reconnaissance on targets whom they planned to kidnap and kill.[al5] The defendants were recruited and tasked over Telegram, motivated by reward sums of nearly €1 million. No Russian nationals were directly involved in UK operations. This case demonstrates a structured operation purpose-built for intelligence collection and the closest contemporary example to traditional espionage.

The case of Dylan Earl takes a slightly different form. It was a task based, financially motivated operation with less sophistication. The 20 year old from Leicestershire with international criminal links was recruited on Telegram by a Wagner Group handler and tasked to organise arson attacks on London warehouses storing humanitarian aid and Starlink equipment for Ukraine, and to plan the kidnapping of a prominent Russia dissident. He recruited further assisting agents, none of whom had previously met, creating a layered principal-agent system in which the Russian connection was several steps removed from the physical act. The March 2024 arson caused over £1m damage. Earl and his co-defendant Jake Reeves became the first people convicted under the National Security Act 2023 for activity linked to a foreign state. This new legislation was explicitly designed to capture actors whose operations fall short of traditional espionage. Counter Terrorism Policing described this as a clear example of a Russian-state linked organisation using British proxies to carry out serious criminal activity on its behalf [6].
Frameworks need fixing
These cases reveal a core tradecraft shift to the absence of Russian nationals physically present in UK operations. No professional intelligence officers; no embassy infrastructure; no ideological commitment.
The National Security Act 2023 represents a genuine institutional acknowledgement of this shift. By extending criminal liability to actors who assist foreign states without formal intelligence roles, it closes a significant legislative gap posed by the proxy model. However, prosecution after the fact is not the same as disrupting recruitment further up the chain. Traditional counter-espionage frameworks built around identifying and expelling professional officers are necessary but no longer sufficient alone. The UK must engage with digital platforms and financial infrastructure through which proxy recruitment operates and pursue closer cooperation with the private sector, especially at a time when transatlantic intelligence-sharing is under unprecedented strain. The Intelligence and Security Committee’s Russia Report 2020 warned that the UK had failed to fully assess the scope of Russian interference, prosecutions since the full-scale invasion suggest that this assessment remains incomplete [7].
Russia’s shift towards criminal proxies is not a temporary adaptation to temporary Western pressure, but the path of least resistance to modernising effective tradecraft. It is a structural response to an irreplaceable HUMINT deficit, a post-ideological recruitment environment, and a digital infrastructure purpose-built for deniable covert action. With the escalation of the Ukraine war, comes the parallel escalation of the ‘shadow war’ which cannot be won by expelling diplomats alone.
[1] Courthouse News Service. (2025, October 24). Men sentenced over London arson attack masterminded by Russia as part of a wider sabotage campaign. Men sentenced over London arson attack masterminded by Russia as part of a wider sabotage campaign | Courthouse News Service
[2] Riehle, K. P. (2024). Soviet and Russian Diplomatic Expulsions: How Many and Why? International Journal of Intelligence and CounterIntelligence, 37(4), 1238–1263. https://doi.org/10.1080/08850607.2023.2272216
[3] Congressional Research Service. (2025). Russia’s foreign intelligence services (IF12865). Congress.gov. Russia’s Foreign Intelligence Services | Congress.gov | Library of Congress
[4] Snegovaya, M., & McGlynn, J. (2025). Dissecting Putin’s regime ideology. Post-Soviet Affairs, 41(1), 42–63. https://doi.org/10.1080/1060586X.2024.2386838
[5] Richterova, D., Grossfeld, E., Long, M. & Bury, P. (2024). Russian Sabotage in the Gig-Economy Era. The RUSI Journal, 169(5), 10–21. Full article: Russian Sabotage in the Gig-Economy Era
[6] Counter Terrorism Policing. (2025, October 28). Men jailed for London warehouse arson. Counter Terror Business. Men who organised Russia-backed arson at London warehouse jailed | Counter Terrorism Policing
[7] Intelligence & Security Committee of Parliament. (2020). Russia (HC 632). Her Majesty’s Stationery Office. HC 632 – Intelligence and Security Committee of Parliament – Russia
No comments.