While attention is focused on cyberattacks and drones over European airports, Russia's Foreign Intelligence Service continues to play the oldest game in espionage — recruiting people. Sweden's Security Service (Säpo) has reported the exposure of an operation that has been coordinated by Russian foreign intelligence for a long time, and its key instrument was not malicious code, but an ordinary person with access to information.
Why specifically a diplomatic mission
The agent worked at one of the foreign diplomatic missions in Sweden — Säpo does not disclose which one. This is no coincidence: diplomatic institutions provide access to informal conversations, draft positions, and contacts with officials before decisions become public. For intelligence services, this is cheaper and more effective than any cyber operation.
The agent's tasks were down-to-earth: to gather information about how decisions are made in Sweden — who influences whom, where disagreements exist, which topics cause public division. This is not about stealing secret documents, but about understanding the decision-making mechanism in order to then subtly apply pressure to it.
What exactly they tried to discredit
According to the Swedish security service, the operation was aimed at four directions:
- Sweden's political positions;
- its work in NATO and the EU;
- support for Ukraine;
- the country's military capabilities.
This is not a random set of targets, but a logical map: Sweden over the last two years has transformed from a neutral country into a NATO member and one of Ukraine's military donors. Each of these four topics is a point where public polarization can provide Moscow with real leverage.
"Russian intelligence and security services continue to prioritize traditional intelligence work through recruiting people as agents," said Christopher Wedelin, deputy head of Sweden's Security Service.
According to him, the security service was able to track the agent's activities in detail — his meetings and their content. This means that the operation was most likely conducted under the control of Swedish counterintelligence long before its formal exposure, rather than being stopped at the last moment.
Practical conclusion
The story demonstrates a simple fact: the most expensive cybersecurity measures cannot help if the vulnerability is a person with legal access. Sweden, which in 2024 abandoned years of military non-alignment and joined NATO, now officially names Russia, China, and Iran as the main intelligence threats.
The question is not whether Moscow will attempt to repeat such a scheme in other EU countries that support Ukraine — but how many such agents in diplomatic institutions remain undiscovered.