Britain must remain on high alert to the threat posed by Russia, with Western officials warning that Vladimir Putin has demonstrated both the willingness and the capability to authorise hostile operations on UK soil.
The warning follows a series of increasingly direct threats from Moscow over Britain’s military and political support for Ukraine. Officials believe the Kremlin is seeking to pressure countries backing Kyiv while avoiding a direct confrontation with Nato.
“Russia’s appetite to conduct hybrid operations is very clear, including sabotage and cyber,” one official said. “Our assessment remains that Putin wants to avoid a direct confrontation with Nato, but there is a risk of miscalculation.”
Hybrid operations can include cyber attacks, espionage, sabotage, disinformation and the use of criminal proxies. The UK Government has described such activity as covert or deniable action falling short of open armed conflict but intended to damage Britain or its allies.
The warning also reflects Russia’s previous actions in Britain. Officials pointed to the 2006 poisoning of former Russian intelligence officer Alexander Litvinenko in London and the attempted murder of Sergei Skripal and his daughter in Salisbury in 2018 as evidence of Moscow’s readiness to conduct dangerous operations abroad.
Defence manufacturers and other companies supporting Ukraine are considered potential targets for sabotage, while British infrastructure and public institutions remain vulnerable to cyber attacks and influence operations.
The Government has taken new steps to respond. In July, Britain and the European Union announced their first joint package of sanctions aimed at Russian cyber networks and alleged proxy groups. The measures targeted 24 individuals and organisations, including senior members of Russia’s military intelligence service, the GRU.
The UK also joined European allies in attributing an attempted attack on Poland’s energy infrastructure to Russia’s Federal Security Service. Officials said the failed operation could have left as many as 500,000 people without electricity during winter.
At least 2,100 UK victims of the Lumma Stealer malware were identified in the six months before the sanctions were announced, according to the National Crime Agency. The malicious software is used to steal credentials and other sensitive information from compromised devices.
The Government has additionally introduced the National Security (State Threats) Act 2026, giving the Home Secretary new powers to designate foreign state-linked organisations involved in activities such as sabotage, espionage and interference. Supporting or materially assisting a designated body can now constitute a criminal offence.
The warnings come as Britain has increased surveillance of Russian activity around its waters. Ministry of Defence figures published in August showed that Royal Navy ships and aircraft spent 21 days monitoring Russian movements in UK waters and the North Atlantic during July, a 25 per cent increase on the same period last year.
Four Royal Navy vessels were involved, tracking Russian warships and submarines as well as vessels associated with the so-called shadow fleet used to transport sanctioned oil. One Russian frigate was monitored while escorting a tanker through the Dover Strait.
Officials said the heightened rhetoric from Moscow should not be mistaken for evidence that Russia has abandoned its wider objectives in Ukraine. They believe the Kremlin is attempting to weaken European unity, undermine public support for Kyiv and create pressure on governments through threats and disinformation.
Russia is also expected to intensify attacks on Ukrainian energy infrastructure ahead of winter, with officials warning that strikes on power stations could be used to place further pressure on the civilian population.
The assessment is that Putin remains reluctant to launch a direct attack on Britain or another Nato member, but that covert operations and the possibility of an unintended escalation mean complacency would be dangerous.
