Allied Intelligence — 2026-05-03
MI5 and European Intelligence Services Track Expanding Iran and Russia Proxy Operations Across Europe
The Soufan Center reported that MI5 Director General Ken McCallum has tracked more than 20 potentially lethal Iran-backed plots in the UK in 12 months, while Dutch intelligence service AIVD issued parallel warnings about escalating threats from Russia and China. The report cited a 254 percent increase in Russian GRU-linked proxy incidents across France, Germany, UK, Moldova, Georgia, and Estonia from 2023 to 2024. Specific incidents named include Iran-linked attacks on Jewish targets in London, Belgium, and the Netherlands, and alleged Russian GRU-backed arson plots targeting UK Prime Minister Starmer. The assessment concluded that Iran has adopted Russia's low-cost proxy methodology for deniable operations across Europe.
AnalysisThe shared operational logic, deniable, sub-threshold actions that impose political costs while limiting retaliation exposure, marks a structural shift, not episodic escalation. Iran's adoption of Russia's low-cost proxy model is the more consequential development: Tehran has chosen ambiguity as a force multiplier, not an operational byproduct. Per a single Soufan Center synthesis of public statements, European services are tracking parallel campaigns sharing methodology rather than confirmed joint direction, making formal attribution of a coordinated Iran-Russia operation before August 2026
genuinely uncertain. Attribution of individual state-sponsored hybrid operations is very likely before August 2026, given the quarterly disclosure cadence across six or more national services, though the documented escalation may reflect improved Western collection as much as increased adversary tempo.
1 sources
- Europe Expanding Hybrid Threat: Taking a Page from the Proxy Playbook - Soufan Center
View in full brief →