Sabotage and lone wolves. Who are the individuals under close scrutiny in Italy?

From the Tallinn fire to cyber-attacks against Western infrastructure, there is a growing reliance on intermediaries, criminal groups and operations that are difficult to attribute. Striking without exposing oneself is becoming part of the strategy to destabilise the West’s enemies. This is also the case in our country 

25 AUG 26
Translated by AI
Image of Sabotage and lone wolves. Who are the individuals under close scrutiny in Italy?
In recent months, there have been several alleged incidents and attacks on European defence factories and industrial facilities. The latest occurred during the night between Friday 14th and Saturday 15th August, when a building used by the Estonian company Milrem Robotics on Betooni Street in Tallinn caught fire. The following day, the Latvian security service opened a criminal investigation, alleging that three Latvian citizens had started the fire in Estonia, and also charging the three with an offence under Latvian law that punishes aiding a foreign state in an act directed against national security. According to an investigation published yesterday by The Telegraph, the Kremlin is said to have launched a new campaign of sabotage against factories producing weapons destined for Ukraine, using intermediaries and local criminal groups precisely to make it more difficult to trace the operation back to its source. The mechanism is that of so-called ‘plausible deniability’ – the ability for a state to benefit from a hostile operation without there being sufficient evidence to attribute it directly to that state. It is one of the hallmarks of contemporary hybrid warfare: the aim is not necessarily to provoke an attack obvious enough to warrant a military response, but to exert pressure, gather intelligence on the adversary’s reaction and exploit the political divisions that the incident may cause. Russia is not the only country to use such tactics: in the same weeks, hackers believed to be linked to Iran targeted a small British power station and several water infrastructure management systems in the United States. The incidents did not cause widespread damage, but they highlighted the vulnerability of Western critical infrastructure.
The issue of groups that could potentially be recruited by those seeking to sow instability has also emerged in Italy, following the explosion on 13 August at the KNDS Ammo Italy factory in Colleferro. In this specific case, the Velletri Public Prosecutor’s Office is also investigating the possibility of sabotage, although the Italian government has so far found no evidence to link the incident to Russia. However, Italy’s cautious approach does not mean that the authorities do not regard the threat of Russian ‘below-the-threshold’ operations as a real one. In its latest report, Italian intelligence identified Moscow as the main external threat to Europe and considers hybrid warfare to be one of the tools through which Russia seeks to weaken Western countries. And Italy has already made explicit attributions in some cases: in February, Foreign Minister Antonio Tajani attributed a series of cyber-attacks against the Foreign Ministry, the Italian Embassy in Washington and websites linked to the Milan-Cortina Olympics to Russia.
But establishing who can organise and actually carry out a single act of sabotage is much more difficult. In some cases, the links between circles within the opposing camp and the network of influence of countries hostile to the West are public knowledge. On 14 December last year, for example, the Intifada Social Centre in Casal Bruciato, Rome, hosted an event dedicated to the Donbas, featuring the screening of a Russia Today documentary in the presence of the North Korean Ambassador to Italy, Ri Kwang Hyok, and representatives from the Russian Embassy in Italy. According to a source interviewed by Il Foglio who is familiar with the matter and prefers to remain anonymous, however, these anti-Western circles alone do not seem sufficient to explain the scale of the phenomenon. Intelligence agencies are also monitoring anti-European groups and cross-party political communities that may contribute to the circulation of certain narratives. There are extremist factions, on both the right and the left, but there are also so-called ‘lone wolves’ – individuals who decide independently to carry out an act after having been exposed for a long time to propaganda campaigns, extremist content or narratives hostile to Western institutions. According to Il Foglio’s source, this is why the intelligence services are monitoring online influence operations with renewed interest – operations that do not necessarily result in a direct order or explicit recruitment, but which may seek to gradually alter the information environment in which users make their decisions. An algorithm that continues to suggest content consistent with previous searches can amplify a narrative without it being immediately apparent who introduced it into the system. According to another qualified source within internal security, this type of investigation becomes even more relevant in the run-up to general elections: influence operations are a ‘self-perpetuating’ system, and once a narrative has been introduced, it is no longer necessary for its originator to intervene directly. Users share it, algorithms amplify it, new content is produced based on previous interactions, and the propaganda ends up taking on a life of its own. The pressure can be “complex and coordinated at all levels”, whilst the identity of the person actually carrying out a single action may remain unclear. And what about the money? These days, all it takes is to guarantee “200,000 likes” on an Instagram post to get a teenager to pull off a “stunt” – which is no stunt at all.