Key Points
- Two Latvian men, aged 32 and 36, were arrested on suspicion of trespassing at RAF Molesworth in Cambridgeshire after an abandoned vehicle was discovered near the base perimeter.
- The arrests followed a conference attended by NATO intelligence professionals, where former British defence attaché to Moscow John Foreman warned about the growing threat of sabotage, espionage, arson, cyberattacks and other hostile activities.
- RAF Molesworth hosts the US intelligence operations centre for Europe and Africa and the NATO Intelligence Fusion Centre (NIFC), making it an important facility for allied intelligence cooperation.
- The suspects were released on bail on Friday while Counter Terrorism Policing investigated their possible motives. Their nationality does not establish any connection to Russia or another foreign state.
- The incident has renewed concerns about the security of British military installations following previous incidents involving RAF Brize Norton and a separate investigation concerning RAF Fairford.
- General Sir Richard Barrons called for stronger protection against emerging threats, including drones, while NATO’s former assistant secretary general for intelligence and security, David Cattler, stressed the need to establish whether any intelligence or operational information had been compromised.
- The Ministry of Defence said the security of defence sites remained under constant review, with measures including physical barriers, patrols, surveillance, monitoring and counter-drone capabilities.
The report leads with the arrests and the significance of the security incident, followed by the investigation, expert assessments, wider security concerns and background.
- Key Points
- What happened at RAF Molesworth?
- Why is RAF Molesworth strategically important?
- What warning did John Foreman give about Russian sabotage?
- What might hostile actors seek to achieve by entering military bases?
- How does the Molesworth incident compare with other UK military security breaches?
- Are British military bases prepared for drone and hybrid attacks?
- What has the Ministry of Defence said about protecting military sites?
- What questions remain unanswered in the investigation?
- What is the background to growing concerns about military-site security?
- How could the Molesworth incident affect the UK public and defence sector?
- What is the prediction for the next stage of the RAF Molesworth case?
Mosco News Daily (MND) October 10, 2026 – Two Latvian men have been arrested on suspicion of trespassing at RAF Molesworth, a strategically important British military installation used by US and NATO intelligence organisations. The arrests came hours after former defence attaché to Moscow John Foreman warned at an intelligence conference about the growing threat of hostile activity against Western military facilities. Police are investigating the circumstances and possible motivation behind the incident, but no confirmed evidence presented in the supplied report establishes that the suspects acted on behalf of Russia or any other foreign power. The incident has renewed questions about the protection of sensitive defence sites across the United Kingdom.
What happened at RAF Molesworth?
According to reporting by Dan Sabbagh, defence and security editor at The Guardian, the two men were discovered inside the perimeter of RAF Molesworth during the early hours of Thursday, 8 October 2026. The investigation began the previous evening after Ministry of Defence Police patrols found an abandoned vehicle near the facility.
Police subsequently identified a small breach in the perimeter fence. The men, both Latvian nationals living in the United Kingdom, were arrested at approximately 2am. Reports identify their ages as 32 and 36. Specialist explosive ordnance disposal officers also carried out checks connected with the abandoned vehicle before it was removed for further examination.
The incident was investigated by Counter Terrorism Policing London, working alongside the Ministry of Defence Police and Cambridgeshire Constabulary. The investigation was examining why the men had entered the restricted area and whether their actions were connected to any criminal activity or other offence.
In an update published on 9 October, the Metropolitan Police confirmed that both men had been released on bail under strict conditions while enquiries continued. Commander Helen Flanagan, head of Counter Terrorism Policing London, said investigators were still seeking to establish their potential motivation.
The arrests were made under suspicion of trespass-related offences and entering a prohibited place for a purpose prejudicial to the United Kingdom. The supplied reporting also describes their subsequent arrest under the National Security Act 2023.
These are allegations under investigation, not findings of guilt. Their nationality alone provides no evidence that the men were working for Russia or any other state.
Why is RAF Molesworth strategically important?
RAF Molesworth is a significant military intelligence facility in Cambridgeshire, north of London. Although it is an RAF site, it is operated by the United States Air Force and supports American and NATO intelligence activities rather than functioning primarily as a conventional flying airbase.
The installation houses the US intelligence operations centre for Europe and Africa, alongside the NATO Intelligence Fusion Centre. The latter supports the alliance by collecting, assessing and sharing intelligence that can inform military planning and decisions.
As reported by the Associated Press in its 9 October coverage, the base hosts intelligence personnel associated with US Africa Command as well as the NATO Intelligence Fusion Centre. Its importance therefore extends beyond the immediate locality, connecting British territory to wider allied intelligence and security operations.
David Cattler, NATO’s former assistant secretary general for intelligence and security, explained the significance of the intelligence centre in comments reported by The i Paper.
He said its contribution was not limited to producing intelligence reports. It also helps NATO members establish a shared understanding of security threats, which is necessary when 32 allied nations must assess information and make decisions together.
That role means a security incident at Molesworth raises questions beyond the integrity of the physical perimeter. Investigators must also establish whether the intrusion involved attempts to obtain sensitive information, interfere with equipment or identify weaknesses that could be exploited later.
Cattler stressed the importance of distinguishing between a physical security breach and an actual compromise of intelligence or operations. The former had occurred, but the available information did not establish that the latter had been attempted.
He identified three central questions for investigators: what the individuals intended to do, what they actually did, and whether anyone directed or supported their actions.
What warning did John Foreman give about Russian sabotage?
The incident took place against a backdrop of concern among defence and intelligence professionals about the growing range of threats facing Western military installations.
John Foreman, a former British defence attaché to Moscow, spoke at a two-day conference at Molesworth attended by NATO intelligence professionals. According to The i Paper, discussions included the importance of maintaining intellectual and cognitive superiority over Russia, alongside conventional and nuclear military capabilities.
Foreman said he had warned participants about the importance of recognising threats that extend beyond traditional military confrontation.
He identified sabotage, espionage, arson, assassination, bribery, corruption and cyberattacks as areas of concern. His warning was particularly striking because the arrests occurred later on the same day.
Foreman told The i Paper that he had been discussing the threat in the morning before learning of the arrests that evening. He described the incident as a reminder that security arrangements at military installations needed to continue improving.
He also said he had been informed that protection at Molesworth had recently been strengthened. The measures reportedly included armed Ministry of Defence Police officers, US personnel, guard dogs and arrangements intended to reduce the risk of attacks involving vehicles or explosives.
Foreman’s assessment was that Russia could have an incentive to use unconventional methods because of the West’s advantages in conventional military power, intelligence and economic resources.
He argued that as Russia’s relative disadvantage compared with Western countries widened, the possibility of increased risk-taking could not be discounted.
However, his comments represented an assessment of the wider threat environment, not evidence identifying the suspects’ intentions. Neither the arrests nor the men’s Latvian nationality establishes a Russian connection.
Latvia has a substantial ethnic Russian population, as Foreman noted, but ethnicity and nationality cannot independently demonstrate an individual’s political loyalties or involvement in espionage.
What might hostile actors seek to achieve by entering military bases?
Foreman suggested that an unauthorised entry into a military installation could serve several possible purposes, even if no immediate physical attack followed.
One possibility is reconnaissance: examining the perimeter, identifying surveillance blind spots or assessing the speed and effectiveness of security responses. Information gathered during such an operation could potentially be useful for planning a later intrusion.
Another possibility is espionage, including attempts to observe sensitive facilities, identify personnel movements or locate equipment of intelligence value.
Foreman also raised the possibility of attempts to install listening devices, interfere with satellite communications or identify weaknesses in communications and security systems. These were examples of potential hostile objectives, not confirmed actions at Molesworth.
The distinction matters because an investigation must establish what actually happened rather than assume the most serious possible explanation.
A person crossing a restricted perimeter may have committed an offence, but determining whether the incident was linked to espionage, sabotage, criminal activity or another motive requires evidence. Investigators would need to examine the circumstances of entry, material recovered, digital evidence, communications and any relevant connections.
The available reporting does not establish that the suspects accessed intelligence buildings, obtained classified material or interfered with military systems.
For that reason, the central question remains whether the incident was an unauthorised entry without a wider operational objective or part of a more organised activity.
How does the Molesworth incident compare with other UK military security breaches?
The arrests have renewed attention on earlier incidents at British military installations, particularly those used by American forces.
What happened at RAF Brize Norton?
Last year, activists associated with Palestine Action allegedly entered RAF Brize Norton in Oxfordshire and damaged two military aircraft. The incident reportedly caused millions of pounds in damage.
The episode raised questions about perimeter protection and the ability of individuals to reach valuable military equipment inside a secure installation.
A military source quoted by The i Paper criticised the apparent security shortcomings at Brize Norton and described the incident as part of a wider pattern of concern about Royal Air Force base protection.
The source also referred to the 2012 attack on Camp Bastion in Afghanistan, during which Taliban fighters killed two US Marines and injured 17 people. The comparison was offered as an example of the consequences that can follow when the security of a military installation fails.
However, the incidents differ in circumstances and should not be treated as evidence of a common organisation or motive. The Brize Norton case involved alleged activist action, while the purpose of the Molesworth intrusion remains under investigation.
What is known about the RAF Fairford investigation?
RAF Fairford in Gloucestershire has also faced heightened scrutiny following a separate security incident in September.
The supplied report states that seven suspects were arrested in connection with a suspected plot involving the base. Subsequent reporting by The Washington Post said US B-1 bombers had been moved from Fairford after intelligence raised concerns about a possible Iranian drone attack. The report described the move as a precaution and did not establish that Iran had carried out an attack.
Authorities have explicitly cautioned against linking the Fairford and Molesworth cases without evidence.
Commander Flanagan said there was nothing in the investigation so far to suggest that the Molesworth incident was connected to the events at Fairford. She confirmed that police were continuing to work with defence police and Cambridgeshire Constabulary to determine why the men had been at the site.
The distinction is important because the timing of separate security incidents does not, by itself, establish coordination.
Taken together, the incidents have nevertheless prompted wider questions about whether military installations can adequately protect aircraft, equipment, personnel and intelligence infrastructure against different kinds of intrusion.
Are British military bases prepared for drone and hybrid attacks?
General Sir Richard Barrons, a co-author of the UK’s Strategic Defence Review, said Molesworth was a significant installation for military intelligence. He distinguished between gaining access to a site’s perimeter and reaching the buildings where sensitive activities take place.
Barrons nevertheless argued that the protection of British military bases needed to account for a wider range of potential threats, particularly drone attacks.
He said effective security required a combination of technology, cameras, sensors, trained personnel, dogs and counter-uncrewed aircraft systems, commonly known as counter-UAS capabilities.
The concern is that modern hostile activity does not necessarily involve a conventional assault on a base. Small drones, cyberattacks, surveillance and attempts to exploit weaknesses in physical security can present different challenges for military planners.
Barrons also highlighted the range of sensitive facilities across the UK, including nuclear installations, main RAF operating bases, intelligence centres and large Army bases holding substantial quantities of military equipment.
The risk is not limited to Molesworth. A weakness identified at one site could provide lessons for security planners responsible for other installations, even when the facilities have different functions and threat profiles.
Barrons said rising tensions involving Russia, NATO and Western support for Ukraine had increased the seriousness of the security environment. Arrangements that might have been considered sufficient during less tense periods could require strengthening.
His comments point to a broader defence challenge: protecting military installations against threats that may be difficult to detect in advance, while ensuring that additional security measures remain proportionate to the risks.
A further issue is that physical security and counter-drone protection require different capabilities. Strong perimeter fencing and regular patrols may help prevent unauthorised access, but they cannot independently address every potential cyber, electronic or aerial threat.
Similarly, drone-detection technology does not replace conventional security measures. Military planners must consider how these systems work together, how quickly personnel can respond to alerts and whether security teams can distinguish genuine threats from harmless activity.
The available information does not establish that a drone was involved in the Molesworth incident. Drone threats form part of the wider security discussion rather than a confirmed element of this particular investigation.
What has the Ministry of Defence said about protecting military sites?
The Ministry of Defence said it remained highly vigilant about potential threats against defence installations and continued to work closely with police and allied partners.
In its statement, the department said the protection of bases was subject to constant review and involved multiple layers of security.
These included physical barriers, patrols, surveillance, monitoring and counter-drone capabilities.
The statement indicates that the government regards military-site protection as an ongoing responsibility rather than a matter addressed through a single security measure. However, it did not provide a detailed breakdown of the arrangements at Molesworth or identify any specific changes being introduced as a direct consequence of the arrests.
The investigation will help determine whether any particular weakness needs to be addressed.
Security reviews following an incident can examine how an unauthorised entry occurred, whether surveillance systems detected it promptly, how patrols responded and whether procedures were followed. They can also assess whether existing arrangements are appropriate for the threats facing the installation.
The fact that a perimeter breach occurred does not, on its own, establish that every element of security failed. Investigators must determine the precise circumstances, including the point of entry, the timing of the intrusion and the effectiveness of the response.
The Ministry of Defence’s statement also needs to be considered alongside the concerns raised by Barrons and Foreman. Their assessments highlight the importance of reviewing security against evolving threats, while the official statement describes the broad measures already used to protect defence sites.
Neither source establishes that a particular security upgrade has been approved specifically because of the Molesworth incident.
What questions remain unanswered in the investigation?
The central unanswered question is why the two men entered RAF Molesworth.
Counter Terrorism Policing has said establishing their motivation remains a key line of enquiry. Investigators will need to determine whether the entry was connected to criminal activity, an attempt to obtain information or another purpose.
A second question concerns whether the men acted independently or received assistance. Cattler said investigators needed to establish whether anyone had directed or supported the individuals. No such direction or support has been established in the available reporting.
A third issue is whether the intrusion extended beyond the physical perimeter. There is a significant difference between entering a restricted area and accessing buildings, systems or information that could affect military operations.
The available reports do not confirm that intelligence was compromised, that communications were disrupted or that equipment was damaged during the Molesworth incident.
The abandoned vehicle is another element of the investigation. Specialist officers conducted checks before the vehicle was removed for examination, according to reporting on the arrests. The results of those checks have not been established in the material available for this report.
The Associated Press also reported that police searched two properties in the Peterborough area as part of the investigation. Such searches can assist officers in examining evidence and reconstructing events, but their existence does not establish that the suspects were involved in espionage or a wider conspiracy.
Finally, the investigation must establish whether there is any relationship between this incident and other security events affecting British military facilities. Police have said that, so far, there is nothing to indicate a connection with the Fairford case.
Until investigators release further findings, claims about a Russian operation, a coordinated sabotage campaign or an attempted intelligence compromise must remain unproven.
What is the background to growing concerns about military-site security?
The Molesworth arrests come amid wider debate about how Western countries should protect military infrastructure in an increasingly complex security environment.
Traditional military threats remain relevant, but defence organisations must also consider espionage, sabotage, cyber operations, drones and other activities that can target vulnerabilities without resembling a conventional attack.
Foreman’s warning reflects concerns that hostile states may seek information or operational advantages through methods that are less costly than direct military confrontation. Such activity can be designed to test security arrangements, collect intelligence or create uncertainty, although the objective of any particular incident must be established independently.
The history of security incidents at military installations also shows why physical protection remains important. The alleged breach at Brize Norton, the earlier attack on Camp Bastion and the separate investigation involving Fairford illustrate different ways in which military sites can face security challenges.
These cases should not be treated as interchangeable. They involve different locations, circumstances and alleged activities. Their relevance lies in the broader requirement for military organisations to assess risks and learn from incidents without assuming that every event has the same cause.
Molesworth’s intelligence role adds another dimension. The NATO Intelligence Fusion Centre contributes to a shared understanding of threats across the alliance, meaning that protecting the facility is relevant to wider cooperation among NATO members.
The Ministry of Defence’s stated approach combines physical barriers, patrols, surveillance, monitoring and counter-drone capabilities. Experts have argued that these measures must be reviewed against changing risks and supported by appropriate technology and trained personnel.
The investigation into the two Latvian men will be important in establishing whether the incident exposed a specific vulnerability and whether any additional response is necessary.
How could the Molesworth incident affect the UK public and defence sector?
The immediate impact is likely to be on the assessment of security arrangements at Molesworth and other sensitive military installations. The extent of any changes will depend on the evidence gathered during the investigation and any subsequent security review.
For defence personnel, the incident could reinforce the importance of perimeter monitoring, reporting suspicious activity and ensuring that different security systems operate effectively together. It may also prompt further scrutiny of how military police and other security teams respond when an abandoned vehicle or suspected breach is identified.
For NATO and US defence organisations, the principal concern is whether the incident affected access controls, intelligence facilities or operational security. No such compromise has been confirmed, so any assessment of the consequences must remain conditional.
For the British public, the incident highlights the role of domestic security arrangements in protecting facilities that support international defence commitments. It also demonstrates why information released during an investigation needs to be distinguished from speculation about possible foreign involvement.
For policymakers, the wider issue is how to allocate resources between physical security, surveillance, cyber protection and counter-drone systems. Barrons’ assessment suggests that no single measure can address every potential threat.
A more comprehensive approach may involve reviewing the vulnerabilities of individual sites, improving the integration of detection systems and ensuring that security personnel can respond effectively to different types of incident. Whether these changes are required at Molesworth specifically will depend on the investigation’s findings.
What is the prediction for the next stage of the RAF Molesworth case?
The most immediate development to watch is the outcome of the police investigation into the suspects’ intentions and activities. Investigators may seek to establish whether the entry involved criminal conduct beyond unauthorised access, whether the abandoned vehicle is relevant to the incident and whether there is evidence of assistance from other individuals.
The release of both men on bail does not mean the investigation has concluded or that the allegations have been proved. Further police updates, if issued, may clarify the circumstances and any evidence uncovered.
A second likely area of attention is the security review of sensitive military installations. If investigators identify shortcomings in perimeter protection, surveillance or response procedures, the relevant authorities may consider additional measures. However, no specific changes should be assumed before they are announced.
The incident may also contribute to continued discussion among defence officials about the protection of intelligence centres and military assets against a combination of conventional and unconventional threats. Molesworth’s role in NATO intelligence cooperation makes the integrity of its facilities particularly important.
For the public and the defence sector, the key measure of progress will be whether authorities can establish what happened, determine whether any sensitive capability was affected and address any weaknesses identified.