Estonia formally accused Russian security services Tuesday of ordering an Aug. 15 arson attack on a Tallinn defense-robotics facility that supplies unmanned ground vehicles to Ukraine. The government said three Latvian citizens suspected of carrying out the attack have been arrested and transferred to Estonia, turning an initially unexplained industrial fire into a direct allegation of Russian sabotage inside a NATO member.
Prime Minister Kristen Michal said the Estonian Internal Security Service, known as KAPO, reached the attribution after assessing collected intelligence. The government called the fire deliberate and preplanned, while the Associated Press reported that Kremlin spokesman Dmitry Peskov rejected the accusation as unfounded and unsupported by evidence.
The public record establishes an arson investigation, arrests and cross-border transfers. It does not disclose the intelligence behind Estonia’s conclusion or identify the Russian service allegedly directing the operation, so the underlying attribution cannot yet be independently examined.
From industrial fire to state attribution
The fire began overnight at a building used by Milrem Robotics in Tallinn’s Lasnamäe district. Responders quickly contained it, and no one was injured. In its initial Aug. 18 public notice, Estonia’s Prosecutor General said investigators were treating arson and possible sabotage as lines of inquiry but had not established a motive.
Latvia’s State Security Service opened a case on Aug. 16. It detained two Latvian citizens the next day and a third on Aug. 18, searched seven homes and vehicles, and seized data-storage devices and objects investigators said might have been used to start the fire. The Latvian agency said the inquiry involved suspected assistance to a foreign state in action directed against another country, as well as property destruction by arson.
Estonia said Latvia transferred the three suspects on Sept. 17 and 18. They remain in custody while the criminal investigation continues. The distinction between intelligence attribution and a criminal verdict remains essential: Estonian authorities say Russian services commissioned the operation, but the suspects have not been convicted and prosecutors are still developing the evidentiary record.
Why Milrem became a target
Milrem Robotics develops tracked, remotely operated ground vehicles used for military logistics, reconnaissance and other tasks. Estonia’s government statement said the company supplies THeMIS vehicles to Ukraine in cooperation with European Union countries. That connection places Milrem within the European industrial network supporting Kyiv, even though the damaged building was in Estonia rather than on the battlefield.
Michal characterized the attack as part of a wider effort to frighten European governments and weaken their support for Ukraine. Foreign Minister Margus Tsahkna summoned Russia’s chargé d’affaires and said Estonia would respond by working with allies, tightening pressure on Moscow and continuing assistance to Kyiv. The Financial Times reported that Tsahkna wants NATO members to attribute suspected attacks publicly, arguing that silence could invite escalation.
Estonian officials have not said the fire halted production or changed Ukrainian operations. The significance lies in the alleged method: recruiting intermediaries to attack a defense supplier in an allied capital while distancing the suspected sponsor from the act.
Hybrid pressure below open warfare
European officials use “hybrid” for coercive activity combining sabotage, cyber operations, disinformation and pressure on critical infrastructure without becoming a conventional military attack. Small teams and inexpensive tools can impose security costs and political anxiety while complicating how governments should respond.
NATO Deputy Secretary General Radmila Shekerinska said in an Aug. 31 speech that allies were confronting arson attempts, sabotage, cyber activity and attacks on infrastructure alongside more visible airspace violations. She specifically cited cooperation between Estonia and Latvia in identifying suspects connected to an attack on a robotics facility, weeks before Tallinn issued its formal attribution.
Such incidents test alliance policy because collective-defense commitments were designed around armed attacks, while covert operations may be ambiguous in origin, scale and effect. Public attribution can expose a pattern and support sanctions or prosecutions, but it also raises the need for credible evidence and proportionate responses. Estonia has not said the Milrem fire meets NATO’s Article 5 threshold, and the alliance has not announced a collective-defense decision in this case.
The evidence remains partly classified
Estonia’s confidence rests on KAPO intelligence and preliminary information gathered in the criminal investigation. The official account says the method matches other sabotage carried out in Europe on Russia’s behalf, but it does not publish communications, financial trails or command links connecting the suspects to a Russian handler.
That is not unusual in an active counterintelligence case. Disclosing collection methods could compromise sources or future prosecutions. Still, Peskov’s denial and the absence of publicly testable evidence mean outside readers must distinguish Estonia’s authoritative government judgment from a proven court finding. The arrests verify that investigators identified alleged perpetrators; they do not, by themselves, establish who commissioned them.
The next important evidence may emerge through charging documents and court proceedings. Prosecutors will need to show how the suspects were recruited, what they understood about the mission and whether money, messages or travel records tie the alleged arson to a foreign service. Intelligence may inform that case, but admissible evidence will determine individual criminal responsibility.
Security implications extend beyond Estonia
KAPO Director General Margo Palloson warned that defense companies and organizations supporting Ukraine face elevated risk and should strengthen both physical and cyber protections. The Milrem case demonstrates why those layers intersect: a company may protect sensitive networks yet remain vulnerable through buildings, contractors, suppliers or people recruited across borders.
Estonia’s attribution marks a sharper phase in the investigation, but it does not close it. What is established publicly is that a facility burned, no one was hurt, three suspects were detained through Latvian-Estonian cooperation and Tallinn now assigns responsibility to Russian security services. What remains unresolved in public is the chain of command behind the attack and whether forthcoming evidence will sustain that attribution in court. Those answers will shape whether the case becomes a durable example of allied deterrence or another contested episode in Europe’s widening confrontation with covert pressure.