ROME – We still do not know what caused the explosion that severely damaged the ammunition plant in Colleferro, some 30 kilometres south-east of Rome, last Thursday. Investigators will have to determine whether it was an industrial accident or whether something else lay behind the fire and subsequent blast.
But there is one thing we do know: in the hours after the explosion, the pro-Russian online ecosystem quickly turned what had happened into propaganda material.
- A European plant producing ammunition, embedded in the Italian — and broader Western, Nato — defence industrial chain and connected to Europe’s effort to support Ukraine going up in flames is fertile ground for propaganda, automated or semi-automated, and disinformation.
- The distinction is essential. Celebrating an explosion, or exploiting it for propaganda purposes, does not mean having caused it. But the speed with which episodes of this kind are absorbed into the Kremlin-friendly information ecosystem says something broader about how Moscow, and the networks that amplify its narratives, view Europe’s vulnerabilities today.
What happened: The explosion occurred past week, on August 13th, at the former Simmel Difesa plant, now KNDS Ammo Italy, in the industrial area between Colleferro and Artena, not so far from Rome. The facility produces medium- and large-calibre ammunition for land and naval systems, as well as solid propellants also used by the aerospace sector.
- According to initial reports, the fire appears to have started in the powder-pressing department before triggering a violent explosion that was felt kilometres away. There were no casualties: workers on site reached designated safety areas, while the authorities have opened an investigation into the cause.
This, however, is not just any industrial plant. Colleferro is part of a European ammunition supply chain whose strategic importance has grown substantially in recent years. KNDS has expanded European artillery ammunition production capacity, while the Italian facility also produces modular charges for 155mm shells — precisely the kind of industrial capability that the war in Ukraine has transformed from a largely commercial matter into an element of European security.
A direct question: How should an incident affecting a node in Europe’s military production network be interpreted on a continent where sabotage, covert reconnaissance, cyber attacks, information manipulation and hybrid operations conducted through intermediaries have become part of the security landscape?
Not only Colleferro. Just three days earlier, on August 10, a fire followed by explosions hit an ammunition and explosives storage and processing facility operated by the Bulgarian company EMCO in Belitsa, forcing the evacuation of around 300 people. Bulgarian authorities said the fire originated in a vehicle that caught fire during a fuel delivery, with the flames subsequently spreading towards an ammunition depot. There were no reported casualties in that case either.
- The timing alone proves nothing. But the name EMCO inevitably makes the episode sensitive: the company belongs to Bulgarian businessman Emilian Gebrev, who survived a poisoning attempt in 2015 that European authorities and investigations have linked to Russian military intelligence operatives.
- Even more significant is what happened a few days earlier in Germany. At Leipzig/Halle Airport — a major logistics hub also used by Ukrainian Antonov aircraft and integrated into Nato’s strategic airlift capabilities — a drone equipped with explosives and a detonator was discovered. Germany’s federal prosecutors are investigating the case as a possible attack on national security. Interior Minister Alexander Dobrindt has explicitly placed it within the broader landscape of hybrid threats; US intelligence cited by international media has also raised suspicions of Russian involvement, although Berlin has so far made no formal attribution.
- Within the space of just a few hours, also on August 13, a series of incidents hit Rotterdam, home to Europe’s largest port: a transformer fire, a major power outage, an emergency shutdown at ExxonMobil’s Botlek refinery and, shortly afterwards, an explosion at Gunvor Energy’s refinery and terminal, which killed one worker and injured six others.
Yes but… Three incidents do not automatically make a campaign. And it would be methodologically wrong to draw a straight line connecting Leipzig, Belitsa and Colleferro. But it would be equally wrong to examine each of them as though it had occurred in a strategic vacuum.
The grey zone comes home. For years, European intelligence services have warned that the confrontation with Moscow does not stop at the Ukrainian battlefield.
- Hybrid warfare thrives precisely on ambiguity: it combines military and non-military tools, overt and covert action, cyber attacks, sabotage, disinformation, economic coercion and operations carried out through proxies, whenever possible keeping confrontation below the threshold that would trigger a conventional military response. This is the grey zone between peace and war, where establishing not only who acted, but even whether an attack took place, can take weeks or months.
Italy is focused to the problem. In recent years, the authorities’ attention has focused not only on the protection — including cyber protection — of critical infrastructure, but also on the intersection of intelligence, sabotage, influence operations and cognitive warfare.
- Defense Minister Guido Crosetto has proposed creating a roughly 5,000-strong civilian-military structure specifically dedicated to countering hybrid threats, identifying energy, airports, critical infrastructure, disinformation and cognitive warfare among the areas where the state needs stronger capabilities.
- The issue was also discussed at the latest meeting of Italy’s Supreme Defence Council, which described the hybrid threat posed by Russia and other hostile actors as a challenge to the security of Italy and Europe and to the integrity of democratic processes.
- Italy is now working on changes to its defence and security architecture that will make dealing with hybrid threats one of its operational priorities.
The problem, however, begins before any potential act of sabotage. One particularly sensitive area is the collection, through open sources, of information about military and dual-use infrastructure. In 2024-25, Italy’s “No Nato” movement compiled and circulated a dossier entitled Mettere nel mirino i presidi bellici — roughly, “Putting military sites in the crosshairs” — mapping installations, companies, universities and infrastructure deemed connected to Nato or to the defence supply chain in the Emilia-Romagna region.
- The document is public and that is precisely what makes the case interesting. The groups promoting the mapping described it as a tool to identify the military presence on Italian territory and organise a “concrete and structured response”. Related material encouraged the open-source reconstruction of sensitive infrastructure, including the route of Nato’s NIPS, the North Italian Pipeline System, in northern Italy, describing the techniques involved as relatively simple and replicable.
From Russia with love. None of this demonstrates a chain of command leading back to Moscow. Nor can anti-Nato activism automatically be equated with intelligence activity. But nor is it reasonable to exclude the possibility that observation and information-gathering around sensitive infrastructure may be exploited by foreign intelligence services. Europe already has judicial precedents.
- In Poland, members of networks linked to Russian intelligence have been convicted of monitoring military bases, ports, railway stations, airports and railway lines used for transfers to Ukraine, including by installing cameras along critical infrastructure.
- Italy has a different but equally significant case: Walter Biot, the Italian Navy officer convicted of passing classified documents to an official at the Russian embassy.
The point is more subtle. In hybrid warfare, the boundaries between propaganda, open-source collection, reconnaissance and operational activity are increasingly blurred, and a traditional chain of command is not always necessary for a state’s interests to be advanced. Moscow combines intelligence officers, intermediaries and ideologically aligned environments.
- The latter do not necessarily need to receive orders to generate information, identify vulnerabilities or amplify narratives useful to the Kremlin. The coexistence of direct operations, proxies and spontaneous convergence — and the difficulty of distinguishing between them from the outside — makes attribution, and therefore deterrence, one of the central challenges of grey-zone warfare.
Colleferro offers an almost perfect example of the other side of the same mechanism. Whatever ultimately caused the explosion, its outcome can immediately be exploited in the information space.
- An industrial accident can become evidence of Western vulnerability. A fire can be turned into a symbolic victory. Uncertainty itself becomes raw material: insinuations, celebrations, competing theories and suspicions can circulate far faster than a technical investigation can establish what actually happened. That is a feature of grey-zone warfare.
Europe’s changing security doctrine. This is also why Rome is not alone in rethinking its security architecture.
- Germany has just approved a plan to strengthen the powers of its BND and BfV intelligence services in response to cyber and hybrid threats. It comes as Berlin investigates the Leipzig drone case and other suspicious incidents around sensitive infrastructure.
- The shift goes deeper than simply tightening security around ammunition plants. Over recent decades, Europe has tended to keep separate domains that are now increasingly overlapping: terrorism, crime, counter-intelligence, cyber security and military defence. Hybrid warfare operates precisely across those seams.
The bottom line: A drone over an airport is a police matter until it becomes an intelligence matter. A social media profile is individual expression until it becomes part of a coordinated influence campaign. A photograph of a military site is public information until it becomes part of systematic reconnaissance. An explosion at an ammunition plant is an accident until evidence suggests otherwise.
- The challenge for democracies is not to reverse that principle: context should raise the level of scrutiny, not lower the threshold of proof. The point is not that every fire is automatically an act of sabotage. It is that Europe can no longer afford to rule out that possibility a priori.



