Over the course of the past three months, Russian services have aggressively employed proxies to conduct targeted operations in both Ukraine and supportive nations. This past week, we saw Ukraine take a page out of the same playbook in targeting a Russian naval officer. On August 13, Capt. 1st Rank Robert Shageev of the Russian Navy was killed by an IED hidden in a trash can in Sevastopol. The individual arrested and charged with the assassination is 32-year-old Margarita Reut, a Russian national.
Why target Shageev?
On March 21, 2014, Shageev surrendered Ukraine’s only submarine, Zaporizhzhia, when Russia occupied Crimea and blockaded Sevastopol’s Striletska Bay. He later switched sides and joined the Russian Navy and, at the time of his death, served as deputy commander of the 4th Separate Submarine Brigade in the Black Sea. Ukrainian sources state the brigade is known to have been responsible for numerous Kalibr missile strikes against Ukrainian infrastructure and civilian targets.
The Ukrainian hand
On the morning of August 13, 2026, an improvised explosive device estimated at roughly 500 grams TNT equivalent detonated from a trash can on Stoletovsky Prospekt in Sevastopol. Shageev died at the scene. Russian authorities state that a Russian civilian woman, Margarita Reut, was detained nearby with the remote control.
The Russian security services claim that Reut acted on Ukrainian special-services instructions, received cryptocurrency payment, planned to leave the country afterward, and expressed no remorse.
The Proxy: Margarita Reut
A review of publicly available Russian media information detailed how she had a short-lived travel agency, worked as a biologist producing floral vaginal suppositories, and allegedly worked as an escort. Numerous Western media outlets led with headlines and ledes that inferred a honey trap involving Reut and Shageev was in play, given her alleged employment as an escort. No available information connects Reut to Shageev. It is probable she had never crossed paths with Shageev and was provided targeting information on where and when to plant the IED. This is indicative of a modicum of operational surveillance on Shageev having been conducted by the sponsors of the assassination.
What is documented, within the Russian-language press, is her 2025 arrest for making a public outburst against the Russian army following a Ukrainian drone attack.
Her presence in proximity to the explosion allowed bystanders to identify her as an individual possibly involved and led to her arrest. At the time of her arrest, she had the remote in her possession. This clearly indicates Reut had been provided only with limited training.
Russia operations
While the target of Reut’s operation was a Russian naval officer, let there be no doubt that Russian services are running numerous campaigns inside Ukraine and across NATO. In early August, a drone with an explosive device was found in proximity to a Ukrainian transport plane lying on the tarmac. The U.S. intelligence community assessed that Russia was the probable sponsor.
Looking back a bit further, we see numerous examples over the past three months.
- In August, Polish authorities detained a Russian-recruited suspect tasked with killing a Ukrainian-American dual citizen in Warsaw.
- In June, the Security Service of Ukraine disrupted two women preparing a remote IED under a Ukrainian serviceman’s car near Maidan Nezalezhnosti; one built the device from video instructions after being recruited with promises of easy money.
- The same month, a Kyiv resident was arrested after receiving an advance on a $100,000 bounty to assassinate GUR spokesman Andrii Yusov with an FPV drone.
- A separate June shooting in eastern Poland killed a Russian dissident artist critical of the Kremlin; Polish officials treat it as a probable directed political assassination.
Proxy operations
Why proxy operations? Proxies provide plausible deniability and expand the threat radius beyond the battlefield. Russia’s modus operandi is predictable, and the SBU (Ukrainian Security Service) detailed it to this writer in February 2025 in Ukraine. Security services, through human or virtual targeting, engage individuals with no connection to government entities. Motivation mixes ideology, debt, and cash or crypto. Direction arrives through cut-outs or messaging apps.
This is not a new method. In the Second World War, both Allied and Soviet services directed local civilians and lightly trained recruits for deniable sabotage and selective killings in occupied territory. The same structure of cut-out direction and non-professional executors produced secondary risk for associates of the targets. In Vietnam, both the Phoenix Program and Viet Cong assassination campaigns relied on local proxies to identify and eliminate officials and collaborators.
Everyone has a role in defense
The difference between successful and thwarted attacks is often less about proxy sophistication than about the quality and timing of defensive intelligence. When indicators are collected early, plots are disrupted. When they are missed or arrive too late, the attack succeeds. Detecting a lone actor or lightly handled proxy is harder than detecting a large-scale military effort. The potential attacker pool is vast. Defensive analysis therefore depends on prioritization of indicators: anomalous contacts, unexplained financial movements, surveillance patterns, sudden interest in a target’s movements or locations, and input from the citizenry.
Targeting and operational methodology patterns are no different from terrorist targeting. Protective measures, route variation, and scrutiny of anomalous contacts are table stakes. The adage, “See something, say something,” still applies. An airport bus driver discovered the Leipzig drone. Bystanders identified Reut.



