> ## Content Index
> Fetch the complete content index at: https://www.adriadefense.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Russian Plots Put European Defense Executives at Risk
- URL: https://www.adriadefense.com/russian-plots-put-european-defense-executives-at-risk/
- Published: 2026-08-20T10:00:17.000Z
- Updated: 2026-08-20T10:00:17.000Z
- Description: The suspected Russian plot against Donaustahl CEO Stefan Thumann exposes a wider security risk for European defense executives supporting Ukraine.
- Author: C.P. 
- Tags: Analysis, Germany, Russia, Ukraine, defense industry, Hybrid Warfare, Donaustahl, Micael Johansson, Christo Grozev, Stefan Thumann, Emilian Gebrev, Industry

German defense entrepreneur **Stefan Thumann** has withdrawn from public view after German security authorities reportedly assessed that Russian intelligence was preparing an attack on his life. Thumann leads Donaustahl GmbH, a German defense startup developing drones and related weapons and supplying equipment to Ukraine.

The case goes beyond the security of one company. From the 2015 poisoning of Bulgarian arms businessman **Emilian Gebrev** to the disrupted 2024 plot against Rheinmetall Chief Executive Officer **Armin Papperger**, Russian and suspected Russian operations have repeatedly reached individuals connected to Europe's defense industry and support for Ukraine.

That pattern raises a question as Europe expands weapons production: governments are investing heavily in protecting factories, supply chains and critical infrastructure, but are the people running strategically important defense companies receiving comparable protection?

## German prosecutors confirm Russian-directed surveillance

Germany's Federal Public Prosecutor has confirmed the underlying surveillance operation, although the publicly disclosed allegations against the suspects concern intelligence activity rather than attempted murder.

German authorities arrested Romanian citizen Alla S. in Rheine, North Rhine-Westphalia, on March 24, 2026\. Spanish authorities simultaneously detained Ukrainian citizen Sergey N. in Elda, Alicante, under a European arrest warrant.

According to federal prosecutors, Sergey N. began surveilling a person in Germany in December 2025 on behalf of a Russian intelligence service. The target was involved in supplying drones and related components from Germany to Ukraine.

Investigators allege that Sergey N. researched the target online and recorded video of the target's workplace. After he moved to Spain, Alla S. allegedly continued the assignment no later than March 2026 and recorded the target's registered address with her phone.

Federal prosecutors assessed that the surveillance was probably intended to prepare additional intelligence operations against the target.

The official announcement did not publicly identify Thumann. Subsequent German reporting identified the Donaustahl chief as the person under surveillance.

## German intelligence reportedly identified an assassination objective

The reported assassination objective goes beyond what German prosecutors have publicly charged.

Die Zeit reported on August 5 that German security authorities believe the Russian state may have been preparing an attack on Thumann's life. The surveillance reportedly included his private address, workplace and information available about him online.

German authorities had received information from a foreign partner service that helped them identify the operation, according to Die Zeit. The investigation ultimately led authorities to the alleged surveillance network.

The distinction between the evidence and the intelligence assessment is important. German prosecutors publicly allege Russian-directed surveillance against a person supplying drone equipment to Ukraine. The conclusion that the operation was preparing an assassination comes from German security assessments reported by Die Zeit rather than an attempted-murder charge currently disclosed against the suspects.

Thumann has since withdrawn from public visibility. The effect demonstrates how a hostile intelligence operation can impose costs even when an attack never takes place.

## Donaustahl shows why smaller defense companies can become targets

Donaustahl is not Rheinmetall. That may be precisely why the case deserves attention.

Europe's defense technology sector increasingly includes small companies developing drones, artificial intelligence, electronic warfare, autonomous systems and other technologies shaped by battlefield experience in Ukraine. These businesses can acquire military significance considerably faster than traditional defense companies.

Donaustahl has developed military unmanned systems, avionics, warheads and its Adaptive Loitering Munition Platform family. Its work has been connected to Ukraine and to operational experience generated by the war.

A startup can therefore become strategically relevant before its corporate security organization reaches the level associated with a traditional defense prime.

That creates a different vulnerability. At a large corporation, technical knowledge, customer relationships and decision-making authority are distributed across substantial management structures. At a founder-led defense technology company, several of those functions can remain concentrated around a small number of people.

An executive or chief engineer can consequently represent more than corporate leadership. That individual may also hold technical knowledge, military relationships, supply-chain information and authority over production and investment decisions.

## Sign up for AdriaDefense – CEE & SEE Defense News, Analysis

Daily defense news, analysis and industry intelligence from Central and Eastern Europe and Southeast Europe.

Subscribe 

Email sent! Check your inbox to complete your signup. 

No spam. Unsubscribe anytime.

## Gebrev poisoning established an earlier defense-industry precedent

One of the clearest precedents occurred in Bulgaria in 2015.

Emilian Gebrev, owner of Bulgarian arms company EMCO, was poisoned in Sofia together with his son and a senior company employee. All survived.

Bulgarian prosecutors subsequently charged three Russian citizens with attempted murder. Investigations linked the operation to personnel associated with Unit 29155 of Russia's Main Intelligence Directorate, or GRU, which has been connected to covert Russian operations elsewhere in Europe.

Gebrev's position makes the case particularly relevant to the threat against Thumann. His business had supplied defense equipment to Ukraine, while investigators examined his arms business and Russia's interest in defense supply networks as possible factors behind the operation.

The wider GRU network associated with covert operations in Europe was also connected to the 2018 poisoning of former Russian military intelligence officer Sergei Skripal and his daughter Yulia in Salisbury, United Kingdom.

The Salisbury operation involved the Novichok nerve agent and demonstrated that Russian intelligence services were prepared to conduct a potentially lethal operation on NATO territory.

## Papperger plot brought the threat to Europe's largest defense groups

The security problem returned to the defense industry in a particularly direct form in 2024.

Western intelligence uncovered a Russian plot to assassinate Rheinmetall CEO Armin Papperger. Rheinmetall had become one of the most important European industrial suppliers supporting Ukraine while expanding ammunition, armored vehicle and other weapons production.

The significance of the case extends beyond Papperger.

NATO Deputy Assistant Secretary General James Appathurai said in January 2025 that threats against industry leaders, including the Rheinmetall chief, formed part of a broader Russian sabotage campaign. He placed the case alongside arson, attacks on property and other hostile activity inside NATO countries.

The Papperger and Thumann cases also demonstrate that corporate size does not define the potential threat.

One target led one of Europe's largest defense groups. The other leads a comparatively small German drone company.

Their common denominator is more important: both companies became relevant to European military support for Ukraine.

## Saab incident shows why executive security is receiving attention

A security incident involving Saab Chief Executive Officer Micael Johansson has added to concerns around European defense executives, although there is no public evidence establishing it as a Russian intelligence operation.

In August 2026, two Russian citizens were found camping near a property connected to Johansson in Sweden. Johansson already had personal protection because of his position at Saab, according to Swedish public broadcaster SVT.

Johansson's security personnel confronted the pair before police became involved. Swedish authorities subsequently investigated suspected unlawful intrusion and preparation for aggravated theft.

The incident should not be presented as an assassination attempt or confirmed espionage operation. Its significance lies elsewhere: security surrounding European defense executives has reached a point where an unusual encounter involving Russian nationals near the protected location of a major arms company CEO immediately generates counterintelligence concerns.

Saab's role reinforces that sensitivity. The Swedish company produces combat aircraft, missiles, sensors, command systems and other military equipment while Sweden and other European states continue supporting Ukraine.

## Christo Grozev case reveals a wider Russian targeting environment

Defense executives are not the only people facing this security environment.

Bulgarian investigative journalist Christo Grozev spent years identifying Russian intelligence personnel and exposing operations attributed to Russian security services, including investigations surrounding the poisoning of Russian opposition leader Alexei Navalny.

Grozev previously lived in Vienna but left Austria after authorities warned him about a threat to his security. Evidence subsequently disclosed through investigations into a Russian-linked espionage network showed discussions concerning surveillance, kidnapping and killing him.

The case differs from Gebrev, Papperger and Thumann because Grozev is an investigative journalist rather than a defense executive.

It nevertheless demonstrates the broader operational environment. People considered strategically damaging to Russian interests can face surveillance well beyond Russia's borders, including inside European Union and NATO states.

The implications are particularly relevant to counterintelligence. Surveillance that initially appears limited to addresses, travel or daily routines can provide information required for intimidation, kidnapping or physical attack.

## Russian media give the Thumann allegation limited prominence

Russian domestic media reviewed by AdriaDefense have treated the Thumann case differently from German and independent Russian-language reporting.

Lenta.ru reported the investigation but placed greater emphasis on Sergey N. being a Ukrainian citizen than on the suspected assassination operation against Thumann. The Russian intelligence connection and reported assassination objective were presented as allegations originating from Germany.

AD searches of several other major Russian state and Kremlin-aligned outlets did not identify comparable substantial coverage giving prominence to the alleged assassination plan.

That finding should be treated cautiously. Search results cannot demonstrate that an outlet never mentioned a story, and limited coverage is not evidence about whether the underlying German assessment is correct.

It does, however, reveal a difference in emphasis. Highlighting the alleged operative's Ukrainian citizenship can produce a substantially different impression from German reporting centered on prosecutors' allegation that he conducted surveillance on behalf of a Russian intelligence service.

Independent Russian-language media have given greater prominence to the alleged Russian operation and the reported assassination objective.

The distinction reinforces the importance of separating three elements of the case: what German prosecutors publicly allege, what German intelligence reportedly assesses and how different media environments present those findings.

## Why defense executives can become strategic targets

Targeting an executive can produce effects extending beyond the individual.

Senior defense industry leaders can combine access to sensitive programs, relationships with government customers, knowledge of supply chains and authority over production and investment decisions.

That concentration becomes more significant at smaller companies. A founder can simultaneously serve as chief executive, technical decision-maker and principal interface with military customers, making the individual difficult to replace quickly.

The economics of disruption may also favor attacks against people.

Damaging a protected ammunition plant or weapons factory can require access, explosives and the ability to overcome increasingly sophisticated physical security. Surveillance, intimidation or an attack against an individual can potentially require fewer resources while still disrupting corporate activity.

Assassination does not have to be completed for an operation to have an effect.

Persistent surveillance or a credible threat can force executives to change travel patterns, reduce public appearances, increase security expenditure and limit how openly they interact with customers and partners.

Thumann's withdrawal from public visibility illustrates that effect. Once a credible threat emerges, the company and the state must devote resources to protecting the individual regardless of whether the planned operation progresses further.

## Europe's defense startups create a new security challenge

The problem could grow as European governments deliberately expand the number of companies entering defense.

Europe wants faster innovation, greater private investment and more startups working on drones, autonomous systems, artificial intelligence, electronic warfare and other technologies. Ukraine has accelerated that process by demonstrating how quickly commercially derived technology can acquire battlefield importance.

Security structures do not necessarily develop at the same speed.

A company can become strategically relevant faster than its security organization matures.

That gap matters because traditional defense primes have security departments, established relationships with intelligence authorities, controlled facilities and experience handling sensitive personnel. A startup entering defense from the commercial technology sector may initially have none of those advantages.

The vulnerability extends below chief executives.

Chief engineers, software developers, weapons designers and specialists responsible for unique manufacturing processes can hold knowledge that is difficult to replace. In some companies, losing a handful of people could create greater disruption than losing physical equipment.

This changes the definition of a strategically important defense asset.

## Europe may need to redefine defense-industrial resilience

European defense-industrial resilience has traditionally focused on production capacity, secure supply chains, stockpiles, cybersecurity and critical infrastructure.

The cases involving Gebrev, Papperger and Thumann suggest that definition may now be too narrow.

Protecting people does not mean placing every defense executive under permanent police guard. Governments instead face the challenge of identifying individuals whose positions create vulnerabilities with national security consequences.

Threat assessments could consider a company's importance to critical weapons programs, support for Ukraine, possession of sensitive technology and dependence on a limited number of executives or specialists.

Governments and companies could then divide responsibility.

Companies remain responsible for normal corporate and physical security. Intelligence and law-enforcement authorities possess capabilities that private security departments do not, particularly when a threat involves foreign intelligence services.

Closer cooperation could include rapid threat notifications, counter-surveillance support, travel-security guidance and protection against exposure of home addresses and other personal information.

For Central, Eastern and South-Eastern Europe, the issue is particularly relevant.

The region contains ammunition plants, explosives manufacturers, drone developers, repair facilities and logistics infrastructure connected directly to Ukraine. Russian intelligence services have already demonstrated sustained interest in the networks supporting those activities.

There is also a deterrence component.

Stopping an operation protects its immediate target. Identifying the network behind it, prosecuting operatives and credibly attributing state involvement can increase the political and operational costs associated with future activity.

Europe's defense buildup is creating more than new factories and production lines. It is also creating a larger group of executives, engineers and entrepreneurs whose decisions and expertise have strategic military consequences.

If hostile intelligence services increasingly treat those people as components of Europe's defense supply chain, European security policy may eventually have to do the same.

---

## Questions about Russian threats to European defense executives

### Was Russia preparing to assassinate Donaustahl CEO Stefan Thumann?

German prosecutors publicly allege that suspects conducted surveillance against a German supplier of drones and components to Ukraine on behalf of a Russian intelligence service. German security authorities reportedly assessed that the operation could have been preparing an attack on Thumann's life, but the publicly disclosed criminal allegations concern intelligence activity rather than attempted murder.

### Was EMCO owner Emilian Gebrev targeted by Russian operatives?

Gebrev was poisoned in Bulgaria in 2015 together with his son and a company employee. Bulgarian prosecutors later charged three Russian citizens with attempted murder, while investigations linked suspects in the operation to Russia's GRU.

### Did Russia plan to assassinate Rheinmetall CEO Armin Papperger?

Western intelligence uncovered a Russian plot against Papperger in 2024\. NATO subsequently confirmed that threats against defense industry leaders such as the Rheinmetall chief formed part of a wider sabotage campaign attributed to Russia.

### Why are European defense executives potential targets?

Executives and technical leaders can hold strategically important knowledge, government relationships and authority over weapons production. The vulnerability can be particularly concentrated at smaller defense technology companies where a limited number of people remain central to both technology and corporate decision-making.

The Thumann case is therefore more than an unusual security problem surrounding one German drone entrepreneur. Viewed alongside Gebrev and Papperger, it points to a broader vulnerability emerging as Europe rebuilds its defense-industrial base.

Factories can be guarded, networks hardened and supply chains diversified. The next phase of European defense resilience may require governments and companies to pay equal attention to the people without whom those systems cannot operate.