In August 2026, the Financial Times reported on attempts by Colombian illegal armed groups to acquire advanced expertise in the operational use of drones from the war in Ukraine. Ukrainian recruitment structures had also identified and rejected applicants with links to organised crime.
The significance of these cases goes beyond the individuals involved. They point to a broader mechanism: the transfer of battlefield-derived capabilities into criminal or illegal armed networks.
The value of such expertise is already evident in Colombia. According to figures cited by the Financial Times, illegal armed groups carried out 264 drone attacks between 2024 and 2025.
For Poland and the wider European security community, however, the Colombian case matters less for where it occurred than for what it demonstrates.
Capabilities developed or refined on the modern battlefield can be deliberately acquired, adapted and transferred into criminal environments.
There is no basis for equating combat experience with a propensity for criminal activity. The risk lies elsewhere: established criminal organisations may deliberately seek out a relatively small number of individuals whose specialist skills are useful to them.
Organised crime does not require thousands of such people. A handful of individuals may be enough to adapt existing TTPs — tactics, techniques and procedures — improve operational planning and then pass that knowledge to others within the network.
The effect can be disproportionate to the number of specialists involved.
For corporate security leaders, this changes the analytical question. Assessing the likelihood of a threat remains essential, but it is no longer sufficient on its own. Security functions also need to consider how the capability and operating methods of a potential adversary may evolve.
Not just more crime, but greater operational capability
Much of the European debate around the potential post-war security environment has focused on the diversion and illicit trafficking of firearms.
That risk requires continued attention, but it is only one part of the picture.
The war is creating a substantial pool of practical experience in contemporary methods of warfare. Many of the capabilities involved are transferable beyond a military setting and extend far beyond weapons handling.
They may include the use of UAS, including FPV platforms, reconnaissance and surveillance, counter-surveillance, operational security (OPSEC), secure communications, small-team coordination, operational planning and the adaptive use of commercially available dual-use technology.
The individual skills matter. The ability to transfer them matters even more.
Modern criminal networks do not need to develop every capability internally. They can recruit specialists, purchase services, use encrypted communications and digital tools, exploit legitimate businesses and draw on existing commercial infrastructure.
In its June 2026 report, Decoding the EU’s most threatening criminal networks – Issue 2: The blueprint of criminal opportunism, Europol describes the most threatening criminal networks as highly adaptive structures able to exploit technological, financial, social and geopolitical change. Digital platforms, encrypted communications, artificial intelligence, cryptocurrencies and legitimate business structures are increasingly part of that environment.
The long-term consequence of the war may therefore be more than an increase in the scale of criminal activity.
The more significant change may be qualitative: an increase in the operational capability of parts of the criminal environment.
Why Poland matters
For Poland, this is not simply a theoretical question for the distant post-war future.
In February 2026, Marek Boroń, Commander-in-Chief of Police, publicly discussed the need to prepare for security conditions that may follow the end of the war. Among the risks he highlighted were the potential growth of organised crime, illicit firearms trafficking and criminal interest in individuals with experience gained during the conflict.
That should not be interpreted as suggesting that demobilisation itself will produce higher crime levels. The more relevant issue is that, once the conflict ends, the number of people in civilian environments with specialist knowledge, experience and technical skills may increase — and some of those capabilities may attract the attention of existing criminal networks.
The institutional response is also evolving.
Plans to establish a new national investigative structure were first announced by the Polish Police in November 2025. A more detailed concept for the Narodowe Biuro Śledcze Policji (NBŚP) followed in June 2026. The proposed bureau is intended to combine experience in tackling conventional organised crime with capabilities relating to cybercrime and other emerging threats. Its planned remit also includes the identification and disruption of criminal activity involving unmanned aerial systems.
Poland’s geography adds to its relevance. The country remains one of the principal transit points for people, goods and equipment connected with Ukraine, and some changes in the regional security environment may become visible there earlier than in EU Member States further from the Union’s eastern border.
Some of these shifts are already visible
Not every relevant development belongs to a future post-war period.
In July 2026, Europol announced the disruption of a criminal network moving wholesale quantities of methamphetamine and cocaine from Western Europe towards Slovakia and Ukraine. Poland was being used as a logistical hub on what Europol described as an emerging trafficking corridor connecting Western, Central and Eastern Europe.
One operation does not demonstrate a structural transformation of Europe’s criminal markets. It does, however, show how quickly criminal networks can adapt routes, logistics and operating models to changing geopolitical conditions.
A different mechanism has been identified by Poland’s Internal Security Agency.
According to the Agency, Russian intelligence services systematically recruited individuals from Latin America through Telegram, including people with military experience, to conduct reconnaissance of selected targets, carry out sabotage and document the results. A Colombian national connected with such activity was also identified in relation to attacks conducted in Poland.
This was not a conventional organised-crime case. From a security perspective, however, it illustrates something equally important: operational capabilities can themselves become an asset that different actors seek to acquire.
Those actors may be criminal organisations, but they may also include state-linked or proxy structures involved in hybrid activity. In practical terms, the boundaries between criminal, counter-intelligence, sabotage and corporate security threats may therefore become less distinct.
What does this mean for corporate security?
At this point, the issue stops being primarily geopolitical.
Europol has found that 86% of the EU’s most threatening criminal networks make use of legitimate business structures. These structures can support operations, obscure activity, facilitate money laundering and reduce the visibility of criminal networks.
For companies, one of the most immediate concerns remains insider threat.
Access to a warehouse, terminal, shipping documentation, transport schedules, access-control systems, information on an executive’s movements or internal security procedures may be considerably more valuable to a criminal organisation than attempting to overcome physical security directly.
The risk is not limited to people already inside the organisation. Employees and contractors with useful access, knowledge or permissions may become recruitment targets, and criminal groups may seek opportunities to place individuals where they can support future operations.
Reconnaissance is another important area.
Commercially available drones, imaging systems, open-source intelligence (OSINT) tools and other dual-use technologies make it possible to observe facilities, transport routes, logistics processes and security arrangements at a fraction of the cost once associated with such activity.
If those tools are combined with experience in OPSEC, secure communications, counter-surveillance and operational planning, the result is not simply a broader toolkit. It is a higher level of operational maturity.
Some traditional assumptions about how criminal actors behave, communicate and expose themselves to detection may therefore become progressively less reliable.
This also has direct implications for senior personnel and executive protection.
Better reconnaissance can help an adversary identify routines, home and work locations, travel patterns, frequently used routes and the way protective arrangements operate. Effective executive protection should therefore place increasing emphasis not only on responding to immediate threats, but also on identifying early signs of hostile interest and changes in the protected person’s environment.
Similar considerations apply to supply chains.
EUDA has repeatedly highlighted the exploitation of legitimate supply chains by organised crime. Corruption, intimidation of employees, sophisticated concealment methods, increasingly diverse routes and emerging technologies all play a role.
Criminal networks with greater operational capability may be better able to identify weaknesses beyond conventional physical security. Business processes, access management, subcontractor relationships, information flows and the organisation of logistics may all represent exploitable vulnerabilities.
This is particularly relevant to transport, logistics, energy, critical infrastructure, the defence sector and companies involved in supporting or eventually rebuilding Ukraine.
For corporate security leaders, the question should therefore not be limited to:
How likely is this threat to occur?
An equally important question is:
What capabilities might a potential adversary possess several years from now — and is the organisation’s current security posture designed with that type of adversary in mind?
Ukraine’s reconstruction will increase Poland’s relevance
According to the joint assessment published in February 2026 by the Government of Ukraine, the World Bank Group, the European Commission and the United Nations, Ukraine’s reconstruction and recovery needs are estimated at almost USD 588 billion over the next decade.
The scale of future movements of capital, materials, equipment, personnel and contractors will be substantial. Poland, because of its location and existing logistical role, is likely to be directly involved in a significant share of the transit, logistics and support activity associated with reconstruction.
Flows of that scale also create opportunities for fraud, corruption, infiltration of legitimate companies, economic crime and exploitation of supply chains.
That does not make reconstruction itself a security problem. It does mean that the associated risks need to be considered before those flows reach their full scale.
The Western Balkans: a warning, not a template
The experience of the Western Balkans shows that the effects of armed conflict on organised crime can persist long after hostilities end.
Weapons left outside effective control following earlier conflicts continue to feature in Europol’s assessments of Europe’s illicit firearms market, while routes from the region remain a focus for European law-enforcement activity.
That does not mean Ukraine should be expected to follow the same trajectory.
Nor is there currently a basis for claiming that weapons from Ukraine are entering European criminal markets on a mass scale. At the same time, the OSCE, INTERPOL, UNODC and countries across the region are strengthening their ability to detect, trace and disrupt the potential illicit movement of firearms, ammunition and explosives from conflict zones.
The Western Balkans are therefore useful as a warning, not as a prediction.
They show why risks associated with uncontrolled weapons, trafficking networks and the transfer of specialist expertise need to be assessed before a conflict ends, not only after the consequences become visible.
Professional security analysis must also distinguish clearly between threats already supported by evidence and scenarios that may materialise in the future.
The most important change may be adversary capability
The Colombian case shows that the transfer of battlefield-derived expertise can begin while a conflict is still under way.
Europol’s assessments, meanwhile, show how quickly modern criminal networks can acquire specialist capabilities, exploit legitimate businesses and adapt their operating models to technological and geopolitical change.
Poland’s geography, the intensity of cross-border movement and its role in the wider logistics system connected with Ukraine mean that some of these developments may become visible there relatively early.
For corporate security, however, the conclusion reaches well beyond firearms trafficking or future demobilisation.
The post-war challenge may not simply be a greater volume of organised crime, but criminal networks operating with more advanced capabilities.
A security system designed solely around known scenarios and familiar patterns of criminal behaviour may remain effective against today’s threat environment while proving less effective against an adversary operating differently several years from now.
Security functions should therefore monitor not only how often particular incidents occur, but also how adversaries are changing their technologies, methods of reconnaissance, communications, planning and operational expertise.
The final question is broader than the future scale of organised crime:
will governments and the private sector recognise the change in adversary capability early enough — before new methods, expertise and operating models become an established part of Europe’s security environment?
Sources and further reading
- Financial Times, “Colombian narcos head to Ukraine for drone expertise”, 6 August 2026.
- Europol, Decoding the EU’s most threatening criminal networks – Issue 2: The blueprint of criminal opportunism, 26 June 2026.
- Europol, Decoding the EU’s most threatening criminal networks, 5 April 2024.
- Europol, Leveraging legitimacy: How the EU’s most threatening criminal networks abuse legal business structures, 18 December 2024.
- Europol, Emerging drug trafficking corridor from Western to Eastern Europe disrupted, 7 July 2026.
- Europol, materials on trade in illegal firearms and explosives and operations targeting firearms trafficking from the Western Balkans into the European Union.
- Polish Police, W strukturach Policji powstanie Narodowe Biuro Śledcze, 6 November 2025.
- Polish Police, Narodowe Biuro Śledcze Policji – nowy filar bezpieczeństwa Polski, 16 June 2026.
- Polsat News, “Wzrośnie przestępczość”. Polska policja szykuje się na koniec wojny w Ukrainie, interview with Commander-in-Chief of Police Marek Boroń, 20 February 2026.
- Polish Internal Security Agency, Działał na rzecz obcego wywiadu przeciwko RP. 21 lipca br. Kolumbijczyk usłyszał zarzuty.
- European Union Drugs Agency, European Drug Report 2026: Trends and Developments.
- OSCE, materials relating to strengthening Ukraine’s capacity to prevent and combat the illicit trafficking of weapons, ammunition and explosives.
- INTERPOL / UNODC, Project iARMS V – Countering illicit arms flows stemming from conflict zones.
- Government of Ukraine / World Bank Group / European Commission / United Nations, Fifth Rapid Damage and Needs Assessment (RDNA5), 23 February 2026.


