Shadow Report on Systemic Gaps in Lithuania’s Security Model and Their Consequences for People, Democratic Institutions and the European Union

29
Ящерица под фонарём и тень динозавра

Gaps in VSD Activities and Institutional Accountability in the Context of Lithuanian National and European Security

Period covered: 2020–2026

Prepared on the basis of open-source intelligence (OSINT) and a comparative analysis of the annual assessments by VSD and AOTD

26 September 2026

Executive Summary

Lithuania’s model of public reporting on national security systematically narrows security to the activities of hostile states, military threats, intelligence activities, cyberattacks, migration and political influence. These threats are real. The problem is that this framework, which is narrow from the outset, leaves human security, the resilience of state institutions, the protection of activists in exile, public health, the environment, food, social cohesion and political safeguards against abuses by Lithuania’s own security agencies outside the central focus of analysis.

The seven annual assessments by VSD and AOTD for 2020–2026 create an impression of continuous state activity, yet provide little basis for assessing the effectiveness of the agencies charged with protecting Lithuania’s national security. The reports do not publish indicators of operations prevented, the numbers of substantiated and erroneous suspicions, the outcomes of earlier forecasts, the quality of protection afforded to specific groups or an independent assessment of the agencies’ own failures. The scale of threats is described in the language of probability, while the institutional responsibility of particular agencies remains blurred.

This shadow report substantiates the conclusion that the persistent shift of attention from specific and verifiable gaps in state protection to broad, potential and insufficiently defined categories of threats creates a semblance of combating threats and a smokescreen of information noise. Meanwhile, systemic measures to identify, investigate and remedy actual vulnerabilities remain fragmentary or publicly unconfirmed, creating risks not only to Lithuania’s national security but also to the security of the European Union.

Open sources do not yet provide direct evidence of an overarching intent on the part of VSD to knowingly mislead the public. However, the recurring selection of topics, the absence of public self-assessment and the failure to acknowledge certain significant VSD failures in protecting Lithuania’s national security allow this to be viewed not as a coincidence but as a consistent institutional choice requiring urgent independent cross-border scrutiny.

Taken together, the established failures have a pan-European dimension. Lithuania’s territory and infrastructure have been used to send incendiary devices to other European states; Lithuanian companies and transport chains feature in investigations into the circumvention of European sanctions; vulnerabilities in state information systems create a risk of cross-border data compromise; opaque migration and intermediary mechanisms may be used to regularise the status of individuals and legitimise capital linked to Russian and Belarusian authoritarian structures; the lack of a publicly verifiable system for protecting organisations operating in exile creates more favourable conditions for foreign regimes to persecute people within the European Union. As a result, Lithuania is turning from a state that presents itself as the front line of European security into a source of exported threats to Europe’s security. The situation requires immediate and decisive corrective measures at both national and European levels.

Key Findings

  • Official reports describe the adversary in considerably greater detail than the state’s own capacity and success in protecting people.

  • There are no transparent criteria for distinguishing between a victim of a foreign intelligence operation, a person subjected to pressure or a recruitment attempt, and an agent who knowingly cooperates. Official reports effectively conflate these fundamentally different categories. This leads to the stigmatisation of potential victims, deters them from seeking help and creates additional opportunities for transnational repression, blackmail and forced recruitment.

  • The growth of the Belarusian diaspora is used as a counterintelligence context without providing denominators, data on the prevalence of recruitment or an assessment of the risk of collective stigmatisation.

  • The Pegasus case reveals a gap between the publicly declared protection of the opposition and the absence of a visible state response to confirmed spyware infection or attempted infections of devices belonging to representatives of the Russian and Belarusian opposition in Vilnius.

  • Comprehensive national security must be assessed through UNDP’s seven interrelated dimensions of human security, with traditional military and intelligence aspects of security complementing rather than displacing them.

  • Accumulated institutional weaknesses already have cross-border consequences and are turning Lithuania’s unaddressed vulnerabilities into a security risk for the European Union as a whole.

Scope and Method

The report compares the annual public threat assessments by VSD and AOTD for 2020–2026, official statements by state bodies, international research on digital surveillance and the United Nations human security framework. The analysis distinguishes between established fact, substantiated analytical assessment and a hypothesis requiring further evidence.

 

Level of assertion

How it is used in the report

Established fact

Confirmed by a primary document, an official statement or a technical study

Analytical conclusion

Follows from a comparison of several facts, but allows for an alternative explanation

Hypothesis

Requires internal documents, testimony from officials or an independent investigation

 

Framework of the Seven Dimensions of Human Security

UNDP’s 1994 Human Development Report shifted the focus of security from territory and armaments to people and identified seven interrelated dimensions. The United Nations continues to use this framework: economic, food, health, environmental, personal, community and political security. This is not a substitute for defence and counterintelligence, but a test of whether Lithuania’s state policies protect people’s lives, dignity and freedom.

 

Dimension

What should be assessed in Lithuania

What is largely absent from VSD and AOTD reports

Economic

Income, employment, energy poverty, exploitation of migrants, household resilience

The impact of threats on people and the unequal distribution of costs

Food

Food availability and affordability, dependence on imports, logistics, reserves and protection of vulnerable groups

A systematic assessment of access to food and the resilience of supply chains

Health

Access to treatment, pandemics, mental health, hospital preparedness, assistance to refugees

The impact of security and repression on people’s health

Environmental

Water, pollution, climate, the Belarusian nuclear power plant, the Neris and Viliya, cross-border accidents

Community participation, long-term harm and environmental diplomacy

Personal

Violence, surveillance, Pegasus, transnational repression, gender-based violence, witness protection

Measurable results in protecting specific individuals

Community

Cohesion, minorities, diasporas, hate speech, prevention of collective stigmatisation

Risks created by the very securitisation of communities

Political

Rights, participation, oversight of intelligence and security services, judicial protection, media and opposition freedom

VSD accountability, errors, effective appeals and democratic oversight

1. Gaps in the State Threat Assessments by VSD and AOTD

1.1. A Narrow Agency-Specific Model of Security

The official assessments are not comprehensive reports on the state of Lithuania’s national security. They are a joint public product of the intelligence services, prepared in accordance with state-approved intelligence requirements. It is therefore natural that the document sees the world through the eyes of intelligence services. The problem arises when this agency-specific product effectively becomes the main public account of the country’s security.

In the official reports, it is considerably easier to find descriptions of the intentions of Russia, Belarus and China than answers to the key questions of national security: how well Lithuania’s residents are actually protected, which threats were missed, which decisions proved wrong, who was held accountable for them and what measures the state took to remedy the identified shortcomings. The reports provide no systemic and verifiable answers to these questions.

1.2. Unverifiable Probabilities

The reports use the categories likely, highly likely and almost certainly, to which percentage ranges are assigned. Until 2024, a four-level scale was used; since 2025, a six-level scale has been used. The method for calculating the percentages is not disclosed. There is no explanation of whether they result from a formalised model, a consensus expert assessment or an editorial decision. Nor is any subsequent evaluation of forecast accuracy published.

The figures create an impression of measurability, but the reader cannot verify the underlying data, the weight assigned to sources or alternative hypotheses. This is particularly dangerous when a probabilistic conclusion is applied to a specific individual.

1.3. No Audit of Their Own Errors

The annual reports contain virtually no section on past errors. For example, in 2023, Russia’s military setbacks and sanctions were expected to gradually reduce the Kremlin’s financial capacity to support Lukashenko. By 2024, it was acknowledged that the Russian economy had proved more resilient than expected and that Belarus had received unprecedented military support. Revising an assessment is legitimate; the shortcoming lies in the absence of a direct explanation of why the earlier forecast proved weak and how the methodology was changed.

1.4. Substituting Striking Incidents for an Assessment of Scale

The reports cite individual cases involving espionage, recruitment, radical groups and arrests, but almost never provide a denominator. The reference to 62,167 Belarusian citizens in Lithuania is accompanied by examples of individual recruits, Litvinism and an Active Club cell, yet no information is given on what proportion of the diaspora consists of confirmed agents or members of radical networks. The existence of a phenomenon takes the place of an assessment of its prevalence.

1.5. Conflating the Victim with the Threat

The political opposition, independent journalists and NGOs are simultaneously recognised as targets of the KGB and treated as an environment in which foreign intelligence services may seek agents. The reports offer no transparent criteria for distinguishing between a victim, a recruitment target, a person acting under coercion and a person knowingly acting as an agent. This uncertainty creates a risk that a person’s vulnerability to the KGB will be turned against them in immigration or judicial proceedings.

For counterintelligence assessment, these are four fundamentally different situations. The first involves a person about whom a foreign service is gathering information or whom it has merely selected as a target of an attack, hybrid operations and transnational repression. The second involves the target of a recruitment attempt who has refused, informed the authorities or has not yet made a decision. The third involves a person acting under threats to relatives, blackmail, dependency or other forms of coercion. The fourth involves a person who knowingly and voluntarily carries out assignments for a foreign service. Contact with a representative of the KGB or FSB, the mere fact of pressure or the existence of a vulnerability does not prove knowing cooperation.

Conflating these categories itself creates vulnerability and additional risks for victims of transnational repression. If reporting a recruitment attempt may lead to a person being designated a threat or refused asylum or a residence permit, that person has a rational incentive to remain silent. The foreign service then uses fear of the Lithuanian authorities as an additional lever: it convinces the target that voluntarily seeking help will only make their situation worse. As a result, VSD loses an early warning signal, the victim is left to face the pressure alone, and the KGB or FSB gains increasingly favourable conditions for subsequent blackmail and recruitment.

A sound model must be based not on the binary distinction between “safe” and “an agent”, but on behaviour, intent, freedom of choice and assistance provided. Voluntary and timely reporting, refusal to carry out an assignment and cooperation in preventing harm must lead first and foremost to protection and safe support. Coercion requires an individual assessment and measures to relieve the pressure. A finding that a person knowingly acts as an agent must be based on individualised evidence: acceptance of an assignment, concealment, a systematic pattern of conduct, transmission of information, remuneration or other confirmed actions, rather than solely on their biography, family ties, previous service or the mere fact of contact.

1.6. No Assessment of Harm Caused by the State’s Own Actions

The public assessments contain no systemic analysis of erroneous VSD decisions: false-positive assessments, the consequences of secret evidence, the inability to appeal effectively, the collective stigmatisation of the Belarusian and Russian diasporas and the use of unreliable information from authoritarian states. Without analysing the harm it causes, the state assesses security from only one side.

2. Selective Coverage of Threats and Gaps in Accountability

Official reports shape the public agenda through repetition, volume and the selective allocation of attention. Readers are offered dozens of pages on the adversary’s intentions, radicalisation, migration and individual suspected agents, yet there is no comparable information on failures of state protection, response times, investigation outcomes or the effectiveness of preventive measures. This creates a picture that serves institutional interests: the threat is constantly growing, the need to expand the service’s powers goes unquestioned, and the effectiveness of its activities remains virtually unverifiable and beyond independent assessment.

The proposition that there is deliberate avoidance of addressing actual gaps must be formulated precisely. Open-source materials demonstrate a persistent effect of shifting attention and a lack of full public accountability. The recurrence of the same structure over many years, the selective visibility of some risks and the invisibility of others provide grounds for speaking of an institutional choice of priorities rather than an isolated editorial error.

2.1. Selective Disclosure and the Significance of Silence

VSD and AOTD regularly publish anonymised examples of successful counterintelligence work stripped of operational details: identified recruitment methods, arrests of suspects, exposed networks, disrupted operations and actions by partner services. Secrecy requirements therefore do not in themselves explain the complete absence from the reports of even minimal information on responses to certain serious threats. Where successful work has been carried out without public disclosure, the services have a tried and tested way of making its existence known without disclosing sources, methods or identities.

Persistent silence on the Pegasus spyware case and other similar incidents therefore has evidentiary significance. It does not justify a categorical assertion that no action was taken without public disclosure, but it shifts the burden of explanation to the state: why a serious threat affecting people in Vilnius and their sensitive contacts was not reflected even in anonymised form; whether an inquiry and assessment were carried out; whether potential secondary targets were warned; and what measures prevented a repeat of the attack. If the state publicly describes successes but systematically fails to report on reviews of failures, there are reasonable grounds to suspect a tactic of removing inconvenient threats from public discussion.

2.2. Not Only Intelligence but Also the Absence of an Embedded Security Culture

The problem is not limited to a particular intelligence or security service having missed an attack. National security requires mandatory interagency security protocols for institutions and officials working with diplomatic, intelligence, personal and other sensitive information. Such protocols must include threat modelling, secure devices and communication channels, multi-factor authentication, access segregation, incident logging, digital forensics, notification of affected individuals, checks for secondary compromise and independent audits of compliance.

Lithuania’s National Audit Office has conducted system-wide cybersecurity audits, including a 2022 audit covering the period 2019–2021. It would therefore be inaccurate to claim that no audits have ever been conducted in Lithuania. The problem is different: no regular system of independent checks of the security of each individual institution handling sensitive information has been found in the public domain, with published assessments of compliance, deadlines for remedying vulnerabilities and subsequent verification of results. A general assessment of the national system does not replace testing the actual security of the Ministry of Foreign Affairs, the Ministry of the Interior, the Migration Department, VSD and other institutions.

The hacking of Ministry of Foreign Affairs correspondence, which became known in 2021, indicated possible access by a Russia-linked group to the ministry’s email and a leak of correspondence; Lithuania’s president publicly spoke of signs that classified information had been leaked. An official Ministry of Foreign Affairs email address had also previously been used in a sender-spoofing attack. These incidents point not only to an external threat, but also to inadequate prevention, access control, detection of compromise and public auditing of the consequences.

Careless handling of sensitive information by state bodies must therefore be assessed as a threat to national security in its own right. When a report describes the adversary’s capabilities in detail but does not examine whether the ministries themselves comply with mandatory protection rules, a description of the external enemy takes the place of responsibility and protection. The absence of publicly verifiable protocols and data on their actual implementation cannot automatically be equated with a complete absence of internal instructions; it does, however, mean that the state has not demonstrated their adequacy or implementation.

Circulating frightening scenarios does not in itself increase resilience or protect Lithuania. A warning works only when institutions and individuals are given a specific threat model, know their own vulnerabilities, understand who is responsible for addressing them and can verify whether protective measures have been implemented. If a report states that the adversary is dangerous but does not show which weaknesses have been identified within the state, what has been remedied and what remains undone, it generates anxiety and emotional reactions instead of strengthening security.

2.3. The Internal Threat and Data Theft through Government User Accounts

Cybersecurity cannot be reduced to protecting the external perimeter. Excessive access rights, weak oversight of user activity, compromised accounts, a lack of behavioural monitoring and the ability to extract information in bulk without immediate blocking pose no less of a threat. The same risk model also encompasses deliberate disclosure of information by an employee, negligence, social engineering and the use of stolen access credentials. These scenarios require different evidence and different responses.

In 2026, it became known that more than 600,000 extracts containing, among other things, personal identification codes and property information may have been unlawfully obtained from the Centre of Registers’ Real Property Register and Register of Legal Entities. According to law enforcement authorities, access took place from abroad through the systems of other institutions; the head of the Criminal Police Bureau confirmed the use of Migration Department accounts. It was subsequently reported that the access credentials of two of its employees had been compromised. The bulk extraction had continued since January and was detected only in April. Data relating to the family of Lithuania’s prime minister were also among those affected.

Without further evidence, this incident cannot be described as a deliberate leak by Migration Department employees. It nevertheless demonstrates the same institutional risk: access privileges held by state institutions became a channel for the large-scale extraction of sensitive information, and the anomalous activity was not stopped in time. The figure of more than 600,000 refers to the number of extracts, not necessarily the number of distinct individuals; public reports cited an estimate of approximately half a million people affected.

Following detection, the Migration Department’s accounts at the Centre of Registers were blocked, passwords were changed, existing access rights were restricted and two-factor authentication was introduced. A claim that no action at all was taken would therefore be inaccurate. The shortcoming in the response lies elsewhere: as of 26 September 2026, no final public report was found in the open sources examined that established the recipient and ultimate location of the extracted data, the criteria for selecting individuals, the possible use of the information by foreign intelligence services or criminal groups, the secondary risks to affected people and the individual measures taken to reduce harm.

For national security, it is not enough to close the technical channel after the theft. An operation to neutralise the consequences is needed: establish which categories of individuals were selected and why; separately assess the risks to intelligence officers, military personnel, diplomats, judges, politicians, activists and their families; warn people at heightened risk; change vulnerable identifiers and identity verification procedures; monitor attempts at coercion, fraud and physical surveillance; and conduct an independent review to establish the responsibility of the Centre of Registers, the Migration Department and oversight bodies for the incident. Until these findings are published, at least in anonymised form, the state has not demonstrated that the consequences of the incident have been contained or that similar situations will not recur in the future.

2.4. Garsų pasaulis and the Failure to Vet the Supplier of Lithuanian Passports

A separate structural risk emerged in the case of the Lithuanian company Garsų pasaulis, which had produced secure blank passports for Lithuanian citizens for many years and had been selected to participate in the New Belarus passport project. A joint investigation by the Belarusian Investigative Center and 15min established the company’s links to GP Holographics and Viktor Chevtsov, a Belarusian businessman and oligarch whom the investigators describe as a financial partner of the Lukashenko regime.

According to the investigation, Garsų pasaulis and the Belarusian state monopoly Golograficheskaya Industriya established the joint venture GP Holographics in Vilnius. Viktor Chevtsov was among its co-owners. Although Garsų pasaulis claimed to have severed ties after the start of the full-scale war in 2022, journalists established that the shareholding had been transferred to Chevtsov through an intermediary, while the related entities continued to share an address, an administrator and an accountant. Only after the public scandal and journalistic investigation did VSD deem the company unreliable in September 2024; the Identity Documents Personalisation Centre terminated the contract for the production of Lithuanian passports. Another state contract was subsequently terminated.

The company’s history of international contracts also contained serious warning signs. In 2018, Garsų pasaulis was declared the winner of a tender worth approximately US$13.5 million to produce biometric electronic passports for Kyrgyzstan. In February 2019, Kyrgyzstan’s State Committee for National Security launched a criminal investigation, after which the conclusion and performance of the contract were effectively blocked. In the ensuing international arbitration, Kyrgyzstan alleged that the company’s success in the tender was linked to corruption and the bribery of officials. However, the arbitral tribunal found the evidence presented insufficient and dismissed the corruption allegations as unproven. It is therefore incorrect to describe this episode as an established corruption scandal. The verifiable facts are the opening of an investigation, the making of serious allegations and the emergence of an international dispute — that is, the existence of reputational and due diligence indicators that the Lithuanian authorities should have assessed before authorising the company to produce documents of strategic importance, but for unclear reasons failed to identify.

Terminating the contracts removed future contractual access but did not answer questions about the past. No comprehensive public review has been found in the public domain establishing who authorised the company to produce documents over many years and on the basis of what vetting; what information was held by VSD, the Ministry of the Interior, the Identity Documents Personalisation Centre and procurement committees; whether the influence of Viktor Chevtsov and the Belarusian partners was examined; whether security technology could have been compromised; which batches, materials and production logs were examined; who was held accountable through disciplinary action; and whether the rules for approving strategic suppliers were changed. Dismissing a manager or terminating a contract is no substitute for establishing the entire chain of decisions.

If the state cannot publicly rule out the compromise of passport infrastructure, it must proceed on the basis of a conservative risk scenario: conduct an independent technical and counterintelligence examination, identify the security elements to which connected persons may have had access, assess the need to replace particular security features, check subcontractors and ultimate beneficial owners, notify parliamentary oversight bodies and publish anonymised findings. This is the standard of action necessary to rule out such a possibility on a demonstrable basis.

2.5. Elfanta and the Lack of Transparency in Checks on Links to the Russian Defence Industry

In December 2023, The Insider identified the Lithuanian company UAB Elfanta as a participant in a supply chain through which Austrian-origin washers and plugs for lathes were exported to the Russian company Unimatic. The publication linked Unimatic to supplies to enterprises in Russia’s military-industrial complex, including the tank-gun manufacturer Plant No. 9. Elfanta responded that it carried out warehousing operations and processed customs documentation but did not collect information on the final recipient of the goods.

Monika Kasčiūnienė worked for many years as a payroll accountant at Elfanta. She is the wife of Laurynas Kasčiūnas, chair of the parliamentary Committee on National Security and Defence and, from 25 March to 11 December 2024, Lithuania’s Minister of National Defence. This employment was publicly declared at least in 2016 and 2020. The Ministry of Defence stated that her duties were unrelated to logistics and that the latest shipments referred to had taken place on 14 January and 4 February 2022, before Russia’s full-scale invasion and the subsequent expansion of EU sanctions.

This episode created an obvious risk of a conflict of interest, vulnerability to influence and reputational harm. When a close relative of the chair of the parliamentary security committee, and subsequently the minister of defence, works for a company mentioned in an investigation into supplies to the Russian defence sector, the state must conduct and document checks into the nature of the work, access to information, the company’s clients and beneficial owners, re-export chains, potential levers of pressure and the need for the official to recuse himself. Such checks protect state decision-making from hidden influence and reasonable doubts. The public sources examined did not establish that such a comprehensive review had been carried out and that its findings had been published, at least in anonymised form.

No final report has been found in the public domain on whether, following the publication, Customs, the Financial Crime Investigation Service, the prosecution authorities or VSD examined Elfanta’s specific shipments, the final recipient, the legality of the transactions at the time they took place, the possible continuation of the relationships after February 2022 and the need to review the risk assessment or Kasčiūnas’s clearance. This is not a question for VSD alone: sanctions enforcement and the investigation of violations are shared among several institutions. The structural gap is the absence of a publicly verifiable outcome and a single risk owner in a situation involving the immediate circle of a senior security-sector official.

There are grounds to suspect that the institutional model did not change structurally after this episode. The annual assessments by VSD and AOTD describe Russian methods of circumventing sanctions and the role of foreign intermediaries, but no dedicated systemic study of Lithuania’s corporate sector was found in the open-source materials examined: which companies registered in Lithuania, warehouses, customs intermediaries and carriers are part of supply chains serving the Russian defence industry; how many such links have been identified; how many checks have been initiated; which assets have been frozen; how many case files have been referred for investigation; and what legal consequences have followed.

According to publicly available registry data, Elfanta is undergoing liquidation as a result of bankruptcy: bankruptcy proceedings were opened by Vilnius Regional Court on 24 February 2025, and the decision took effect on 4 March. Bankruptcy in itself is not a sanction for assisting Russia’s military-industrial complex. No confirmation has been found in open sources that the former management or owners were held criminally or administratively liable, or subjected to sanctions, specifically in connection with the supplies to Unimatic. It is therefore necessary to establish whether the response ended with the ordinary bankruptcy of the legal entity or whether the state examined the personal responsibility of the decision-makers.

Possible corporate succession requires a separate examination. The closure or bankruptcy of one company does not eliminate the risk if the same owners, managers, employees, telephone numbers, addresses, warehouses, clients, customs authorisations or assets move to another legal entity acting as its successor. This scenario must be examined through a comparison of data from the Register of Legal Entities, beneficial ownership information, customs declarations, employment transfers, related companies and asset movements before and after bankruptcy, rather than through assumptions.

2.6. Restrictions on Property Purchases and the Risk of Revealing Sensitive Zones to Hostile Intelligence Services

In 2026, the Ministry of Foreign Affairs proposed prohibiting Russian and Belarusian citizens from purchasing property in areas near facilities important to national security and military training grounds. Similar initiatives had previously been promoted by representatives of the conservative parliamentary group and the parliamentary Committee on Foreign Affairs. Airfields, training grounds, airports and energy facilities were among those publicly named. The stated aim is to hinder surveillance, sabotage and the establishment of footholds near critical infrastructure.

The intended purpose of such a mechanism is to hinder surveillance, preparations for sabotage and the establishment of footholds near critical infrastructure. Its practical application, however, will inevitably require access to information on restricted zones for a broad and effectively unlimited range of persons and entities: notaries, estate agents, property owners, buyers, banks, valuers, insurance companies, cadastral and municipal officials, lawyers and parties to legal proceedings. Without such access, they will be unable to verify whether a transaction is permissible or to fulfil their statutory duties.

The mechanism thus creates an intelligence vulnerability of its own. If information on protected zones is published as a map or a list of cadastral plots, or becomes available through an ordinary enquiry about whether a transaction is permissible, the system will become a tool for identifying sensitive facilities by inference. Successive enquiries about neighbouring plots will make it possible to determine the boundaries of a restricted zone and locate a facility even where its purpose and exact location are officially classified. Additional sources of information may include refusals by notaries, registry extracts, bank decisions, property listings, administrative correspondence and litigation. Taken together, these data will allow the KGB, FSB or entities acting through intermediaries to reconstruct a map of sensitive infrastructure with ease, without direct access to classified information.

Signs of Simulated Effectiveness by Lithuania’s VSD

  1. Activity is measured by the number of threats described rather than the number of consequences prevented.

  2. Successful operations by state bodies receive publicity, while missed threats are rarely examined in the annual report.

  3. The secrecy of sources simultaneously obstructs fact-checking and shields the service from scrutiny of the quality of its analysis and the effectiveness of its work.

  4. Broad risk categories allow new groups to be classified as risk groups without publishing data on the prevalence of the problem.

  5. Responsibility is distributed among VSD, AOTD, the police, the prosecution authorities, the Ministry of Defence and other bodies, so failures often have neither a clear institutional owner nor, consequently, anyone held personally accountable for them.

3. Gaps in the Protection of Civil Society in Exile

3.1. Pegasus targeting activists and journalists in Vilnius

On 30 May 2024, Citizen Lab and Access Now published a technical investigation into the use of Pegasus spyware against seven Russian- and Belarusian-speaking journalists and opposition activists in Europe. The targets included an independent Russian journalist and a member of Belarusian civil society who were living in Vilnius. The Belarusian activist’s device was infected around 25 March 2021, Freedom Day. The Russian journalist’s device was targeted in an attempted infection around 15 June 2023.

The researchers identified indications of a common operator in at least several cases but were unable to publicly identify the state responsible.

From a national security perspective, the central question is different: two people under the protection of Lithuanian jurisdiction were targeted with one of the most dangerous digital espionage tools. Pegasus can access messages and other data on a device, as well as its microphone and camera, putting at risk not only the victim but also their contacts, sources, organisations and opposition networks.

3.2. Lithuania’s public response

In response to an enquiry from LRT, Lithuania’s Ministry of National Defence declined to disclose whether it had information about the attacks and whether Lithuanian institutions had used Pegasus. No public statement by VSD or the prosecution service concerning a separate investigation into the Pegasus attacks against two people living in Vilnius was found in the open sources reviewed up to 26 September 2026. These cases involved one confirmed infection and one confirmed attempted infection. Nor did the sources reviewed for that period contain public statements concerning the identification of the operator, an assessment of the possible exposure of information about their contacts, or the provision of state protection to those affected.

This does not prove that no action was taken confidentially. However, national security also encompasses trust and the prevention of further attacks. Even if operational details could not be disclosed, the state could have publicly confirmed that an inquiry had been opened, informed the victims of their status, provided guidance to other potential targets, and reported on inter-agency coordination. The absence of such a visible response constitutes a distinct gap in public accountability on security matters and leaves unanswered the question of what measures VSD took in response to the Pegasus attacks against a journalist and a member of Belarusian civil society in Lithuania.

3.3. What the Response by the State, and VSD in Particular, Should Have Included

  • Independent digital forensic examination and preservation of evidence on the devices.
  • Identification of the possible operator, the attack infrastructure and the jurisdictions in which the Pegasus licence was in force.

  • Assessment of the compromise of the victims’ contacts, organisations, sources and events.

  • Notification of all individuals who may have become secondary targets.
  • Examination of possible involvement or assistance by authorities of EU Member States.
  • A public report to the extent compatible with protecting the confidentiality of the investigation.
  • Parliamentary and independent oversight of the use of commercial spyware within Lithuania.

3.4. The Recurring Gap between Warning and Protection

The infection of activists with Pegasus spyware in Lithuania is not an isolated example. In March 2024, Leonid Volkov was beaten with a hammer near his home in Vilnius; VSD linked the assault to Russian intelligence services only after the attack. In 2026, Lithuanian authorities and their partners reported international networks that had been preparing to murder activists and arranging parcels containing incendiary devices to be sent from Vilnius. These investigations demonstrate the ability of law enforcement bodies to uncover complex networks, but at the same time raise the question of why protection is often strengthened only after an attack or after victims themselves discover a tracking device, and why the scope and results of VSD’s preventive work aimed at averting such threats are not publicly demonstrated.

3.5. The Case of Andrei Shimanovich and VSD’s Double Standard in Risk Assessment

An investigation by Buro Media, conducted with the participation of the Lithuanian project Siena and cybersecurity experts, established that the Belarusian entrepreneur Andrei Shimanovich had been married to Olga Sheiman, the daughter of Viktor Sheiman. Viktor Sheiman is a long-standing associate of Alexander Lukashenko and is included on the European Union’s sanctions lists; the EU’s statement of reasons for the sanctions cites his responsibility for the unresolved disappearances of opponents of the regime and politically motivated repression. The investigators found numerous trips made jointly by Andrei Shimanovich and Viktor and Sergei Sheiman, but expressly noted that no documentary evidence had been found of Andrei Shimanovich’s involvement in the Sheiman family’s business.

Shimanovich was a co-founder and public representative of mSpy, a software product that enables covert reading of messages and monitoring of geolocation, photos, calls and user activity. The investigation also linked him to the Belarusian company Mobyrix, the Lithuanian company Appvillis and other entities that developed applications with access to sensitive data. The existence of such technical capabilities does not in itself prove cooperation with intelligence services or criminal activity. However, the combination of the covert surveillance industry, a cross-border corporate structure, the processing of sensitive data and close family ties to a senior figure in an authoritarian regime constitutes an obvious set of factors requiring enhanced scrutiny.

Nevertheless, in 2023, Shimanovich obtained a temporary residence permit in Lithuania as a start-up entrepreneur without difficulty and renewed it in 2025. According to the Migration Department’s official response, the competent state authorities were consulted before both decisions, and the department received no substantive information that would preclude issuing a residence permit. Only after the journalistic investigation was published did the Migration Department again ask VSD, the National Cyber Security Centre and the criminal police to assess the risks associated with Shimanovich and the software applications developed by his companies.

This case should be compared not with abstract migration policy but with the practice of designating large numbers of other Belarusians as threats to national security. According to the final figures, 1,428 Belarusian citizens received this designation in 2023, 598 in 2024 and 1,634 in 2025. The official questionnaire specifically requires applicants to disclose previous military service, employment in state institutions and contacts with public authorities. In publicly described cases, participants in the 2020 protests were designated threats because of compulsory military service long ago, military education or previous employment in Belarusian state structures, without publicly presented evidence of current intelligence activity.

A structural asymmetry emerges: a socially vulnerable applicant must rebut a suspicion arising from a biographical fact in the distant past or from family ties, while a Belarusian entrepreneur developing espionage tools, with resources, a European company and publicly established links to the family of an official under sanctions, passes vetting despite being in the covert surveillance business. This demonstrates inconsistency in VSD’s criteria, weak scrutiny of economic and technological links and the risk that the system produces false-positive decisions concerning readily accessible targets while overlooking more complex and well-resourced networks.

3.6. The Mantas Danielius Case and the Systemic Lack of Protection for Belarusian Human Rights Organisations in Exile

The case of the Lithuanian lawyer Mantas Danielius illustrates the most dangerous form of transnational repression: the infiltration of organisations of political exiles by a trusted local professional. According to prosecution and court materials, Danielius presented himself as a volunteer, visited the premises of Belarusian opposition organisations, in particular the Belarusian human rights organisation Our House in exile, and collected information about their activities, projects, funding sources, participants and meetings. Our House publicly stated that it had used his legal assistance. On 20 September 2024, Vilnius Regional Court found him guilty of espionage on behalf of Belarus and sentenced him to nine years’ imprisonment.

The criminal investigation and conviction constituted a significant state response, so it would be inaccurate to claim that the authorities completely ignored the Danielius case. However, uncovering and punishing one agent is not equivalent to restoring security within the compromised environment.

After the criminal proceedings were concluded, the state did not conduct a comprehensive assessment of the harm caused to Our House and other affected organisations. The full extent of the information transmitted was not established, potentially affected individuals were not systematically informed, possible secondary infiltration was not checked, the organisations were not provided with assistance in reviewing their rules on access, data storage and communication, no permanent channel of contact with counterintelligence was established, and the implementation of protective measures was not verified. In other words, the state punished the identified agent but took no systemic action to address the consequences of his activities or to establish a mechanism for preventing similar infiltration. Consequently, the task of restoring security remained essentially with the affected organisations themselves, which have neither the powers nor the resources of a counterintelligence service.

This is where the structural gap becomes apparent. VSD publishes general warnings about recruitment and invites citizens to report suspicious contacts, but a generic guidance leaflet cannot replace the development and practical implementation of a dedicated security protocol for high-risk organisations, including Our House.

A human rights organisation should not have to perform counterintelligence functions on its own: identify agents, conduct operational checks on lawyers, staff and volunteers, establish their possible links to foreign intelligence services, investigate leaks or provide witness protection. An NGO’s duty is to take reasonable steps to protect data, follow internal procedures and report incidents promptly. The state’s duty is to conduct a professional threat assessment, provide a secure communication channel, appoint a permanent contact person, offer methodological and technical support, help address the consequences of infiltration and verify the implementation of protective measures.

Following the Danielius case, no such systemic protection scheme was established for Our House or other high-risk organisations. Institutional protection consisted mainly of isolated recommendations, and responsibility for practical resistance to hostile foreign intelligence and transnational repression therefore remained largely with their potential victims.

After confirmed infiltration, state assistance must extend beyond the organisation’s leader. The information collected may have affected staff, applicants, donors, partners, families of political prisoners and people remaining in Belarus. Secondary risks therefore need to be mapped: who was mentioned in documents and correspondence, which trips and meetings became known, which accounts and devices need to be checked, and who needs new communication channels, legal assistance, physical protection or a warning about possible pressure.

After the Danielius case came to light, the affected organisations, including Our House, faced not only a lack of systemic state support but also public blame from Lithuanian human rights defenders for the agent’s successful infiltration. In an LRT article dated 7 October 2022, Vytis Jurkonis, director of Freedom House’s Lithuanian office, stated that the heads of Dapamoga and Our House should “acknowledge their irresponsible mistake”, raising the question of who had admitted Danielius into the Belarusian community and why his activities had not been recognised in time.

Framing the issue in this way replaces an analysis of the state’s duties and failures with blame directed at the injured party — classic victim-blaming. A human rights organisation can and should observe reasonable internal security measures, but it lacks the powers, operational capabilities and access to non-public information needed to identify a professional agent of a foreign intelligence service. Responsibility for counterintelligence detection, checking warning signals, alerting potential targets and protecting those affected lies primarily with VSD and other competent Lithuanian state bodies, not with women human rights defenders in exile.

Donors, partners and civil society organisations must not use successful intelligence infiltration as grounds for publicly ostracising its victims. Such a practice creates an additional chilling effect: organisations become afraid to report suspicions and incidents because revealing infiltration may result in accusations, reputational damage and the loss of partner support rather than assistance. As a result, responsibility is shifted from the foreign intelligence service and the state that failed to provide timely protection to the organisation targeted by a professional intelligence operation.

Lithuania needs a dedicated system to protect organisations in exile from transnational repression. It must operate before an incident, after the first warning signal and after an agent has been exposed, rather than ending with criminal proceedings alone. The absence of a publicly verifiable protocol means that potential targets do not know what assistance they are entitled to receive, who is responsible or how to verify that the consequences have been addressed.

3.7. The Black Book of Belarus and Belaruski Hajun: Widespread Harm Following the Compromise of Sources

Two further cases show the heavy cost of the lack of preventive protection for digital projects in Lithuania that work with people inside Belarus. Almost from its inception, the Black Book of Belarus was infiltrated at a very senior level by Artur Gaiko, an officer of Belarus’s GUBOPiK. An investigation by Mediazona established that for around ten months he had access to the internal chats and bots of the main and regional channels, through which approximately 8,500 users who were in Belarus at the time had contacted the project. He could also see messages from other protest initiatives. The team established his identity in July 2021 but removed him from all chats only three weeks later, while a public warning to sources with a full description of the scale of the risk appeared more than a year later.

The compromise had tangible human consequences. Informant Artyom Parkhamovich, who supplied information to the project, was detained; in February 2022, he and his colleague Alexei Bychkovsky were each sentenced to eleven years’ imprisonment on multiple charges. A Belarusian GUBOPiK officer’s prolonged access to messages, Telegram profiles and internal discussions put thousands of people who had contacted the project at risk. According to figures published by the Viasna Human Rights Centre in October 2023, at least 32 people had been convicted of supplying data to the Black Book of Belarus chatbot. The situation called for immediate warnings to those whose data might have reached the security forces and coordinated evacuation of the most vulnerable sources. The available material does not establish the extent to which these measures were taken.

On 5 February 2025, unknown individuals gained unauthorised access to the bot chat of the Belaruski Hajun project, to which residents of Belarus sent photographs and information about Russian military equipment. The project’s founder, Anton Motolko, acknowledged that access had resulted from his own human error and warned that identifiable senders were at risk. The data obtained included users’ unique Telegram IDs; the project had previously reported that around 30,000 people had provided it with information. The first detention became known the very next day.

According to Mediazona’s estimate, based on the list of individuals involved in ‘extremist activity’ and data from human rights defenders, 335 people are believed to have been convicted in the ‘Hajun case’ between March 2025 and January 2026; 142 were sentenced either to imprisonment in a penal colony or to restriction of liberty with placement in an open-type correctional facility. These figures are a journalistic estimate, as the Belarusian authorities do not publish a complete register of cases and sentences. Nevertheless, the scale of the repression makes the compromise of a digital project a cross-border incident involving the protection of life and liberty, rather than merely an internal error by a non-governmental organisation.

Both projects had organisational and personal links to the Belarusian exile community operating in Lithuania. The Lithuanian authorities were aware of the KGB’s broader campaign against the Belarusian diaspora and opposition structures, but no public system of mandatory consultation, auditing of high-risk projects and emergency response to the compromise of sources has been demonstrated.

Following the Hajun hack, Dmitry Bolkunets and Ruslan Khazin contacted Lithuanian law enforcement authorities, citing the project’s alleged connection to BNR100 Consortium, a legal entity registered in Lithuania. The police and prosecution authorities refused to initiate a pre-trial investigation; on 3 June 2025, Vilnius Regional Court issued a final decision dismissing the complaint, citing the absence of objective evidence that a crime had been committed on Lithuanian territory, by Lithuanian citizens or by persons permanently residing in the country.

But the narrow question of territorial criminal jurisdiction does not exhaust the state’s duty to protect activists, journalists and human rights defenders. Even if the hack occurred outside Lithuania, VSD, the police, the National Cyber Security Centre and data protection authorities should have assessed the risk to organisations and administrators in Lithuania, helped preserve digital evidence, determined the extent of the data leak, arranged for sources to be notified securely, assisted in evacuating people at high risk and checked whether similar vulnerabilities existed in other projects. The public sources examined did not establish the extent to which these measures were implemented; no publicly verifiable outcome of a systemic response has been published.

These cases reveal a recurring pattern: the state expects a small, underfunded organisation to build highly effective counterintelligence capabilities, digital forensics, staff vetting, a system for warning thousands of sources and cross-border evacuation arrangements on its own. After a failure, responsibility remains with the project and its victims. For Lithuania, as a country providing refuge to centres of Belarusian civil society, protecting such organisations’ infrastructure must be regarded as part of national and human security.

3.8. The Peramoha Plan and the Absence of an Independent Review of Its Compromise

The Peramoha mobilisation plan, created by BYPOL, an association of former Belarusian security and law enforcement officers, used a Telegram bot to collect information about people willing to participate in resistance to the Lukashenko regime. BYPOL’s leaders publicly claimed that hundreds of thousands of participants had registered. For the Belarusian security and law enforcement authorities, even launching the bot, completing a questionnaire and providing contact details became grounds for charges of participation in an ‘extremist formation’ and lengthy prison sentences in Belarus. Human rights defenders documented criminal cases, lengthy sentences and regular video recordings in which detainees, often showing signs of beatings and torture, spoke about registering for the plan.

There were, however, several possible ways of identifying people. GUBOPiK created fake bots and links under the name Peramoha, sent out assignments in BYPOL’s name to conduct surveillance or retrieve a cache, and detained those who responded. In other cases, a person could have been identified through a seized phone, analysis of a Telegram account, a coerced confession, information from acquaintances or the Belarusian authorities’ own operational work. In August 2023, pro-government channels claimed that the plan’s database had been hacked, and detentions followed, but the precise content of the data obtained was not published.

In May 2024, the organisers lost control of the main chatbot. A political mailing was sent through it to registered participants; the Belarusian security and law enforcement authorities soon claimed to have detained several recipients. BYPOL later announced that the plan had been closed for security reasons, specifically citing the loss of access to the bot. Open-source materials do not establish who controlled the bot, whether the entire set of registration data was exposed or whether the reported detentions were indeed a direct consequence of the mailing. But the loss of control over a channel linked to people inside a repressive state is itself a critical incident requiring an independent expert examination and an immediate protective response.

The Peramoha plan was organised primarily from Poland, so it cannot automatically be asserted that every technical incident affecting it fell within Lithuania’s criminal jurisdiction or that VSD knew in advance of a specific compromise. However, the network of Belarusian democratic structures, their staff and participants operate across borders, including from Lithuania, and VSD publicly acknowledges active KGB operations against this community. Under these conditions, Lithuanian counterintelligence should not limit itself to a formal public warning to ‘be careful’: it needs a mechanism for sharing warning signals with the Polish authorities and other partners, as well as protection for administrators, organisations and potential secondary targets located in Lithuania.

No public independent review was found in open sources that would establish, for the Lithuanian side, whether any infrastructure components or people with administrative access were located in Lithuania; whether those registered included residents of Lithuania and their contacts in Belarus; what data the KGB and GUBOPiK may have obtained; who was warned; what measures were taken after access to the bot was lost; and whether other projects with a similar architecture were checked. The absence of such a report leaves activists without a clear assistance protocol and makes it impossible to verify whether the causes of the risk have been addressed.

Human rights defenders and political activists in exile can observe basic digital hygiene, minimise data and report incidents. But they are not professional counterintelligence officers and should not have to identify infiltrators, attribute KGB operations, conduct forensic examinations of servers and devices, coordinate an international investigation and protect witnesses on their own. This falls within the mandate of state authorities, particularly VSD. Transferring these functions to activists in exile both reduces the quality of protection and enables the state to evade responsibility after a foreseeable failure.

The Peramoha case calls for an examination of the causes, rather than blame directed at those affected: why so much data was collected, who had access and on what basis, whether data minimisation and automatic deletion were used, how consent was withdrawn, whether an independent audit was conducted before launch, what contingency plan existed in case the bot was lost, and who was responsible for notification and evacuation. Only publication of anonymised findings and verification that the new rules are being implemented can demonstrate that the next initiative of this kind will not repeat the same cycle and that hundreds more Belarusians will not end up behind bars as political prisoners.

3.9. The Case of Andrei Stryzhak: Abuse of Power within the Aid Infrastructure

In July 2025, Belarusian women activists publicly accused Andrei Stryzhak, co-founder and head of the BYSOL solidarity fund affiliated with Sviatlana Tsikhanouskaya, of sending unsolicited photographs of exposed genitals and other sexualised messages. The first published accounts by two women were accompanied by screenshots of their correspondence. Stryzhak himself acknowledged that he had sent sexualised content without the recipients’ explicit consent.

This behaviour by the head of the fund affiliated with Sviatlana Tsikhanouskaya continued for several years. Some women also reported that, in the event of refusal, conflict or public disclosure, Andrei Stryzhak, who lives in Lithuania, threatened to use his connections to have them designated threats to Lithuania’s national security. This concerns the possible use of purported access to state mechanisms as a means of coercing Belarusian women in Lithuania into sex and suppressing complaints by victims of sexual violence.

The lack of transparency in Lithuania’s procedure for designating a person a threat to national security makes the situation particularly serious. The non-disclosure of the grounds, assessments based on hypothetical risks and limited opportunities for an effective appeal made such blackmail credible. For Belarusian women in exile, the consequences could include losing their residence permits, being unable to remain legally in Lithuania and risking return to Belarus, imprisonment and, consequently, torture. Such a serious threat could have forced those affected to remain silent for years and avoid approaching Lithuania’s state authorities.

The internal inquiry commission established by BYSOL recorded 12 verified cases and described the behaviour identified as systematic. Seven cases involved the sending of unwanted messages, and in five of these the recipients were BYSOL beneficiaries. The commission’s published summary confirms the multiplicity and systematic nature of the incidents.

This case has a direct human security dimension. The head of one of the largest aid funds in Lithuania, affiliated with Sviatlana Tsikhanouskaya, held institutional status, had access to resources and sensitive data, and exercised considerable influence over the environment on which former Belarusian political prisoners, women activists, female staff and other vulnerable people depended. Even in the absence of a direct threat to withhold assistance, such a power imbalance creates dependency: a female recipient may reasonably fear that an objection, refusal of sexual contact, cessation of communication or public complaint will affect funding, recommendations in migration matters, reputation and access to other support structures in Lithuania.

BYSOL’s structure included the Lithuanian legal entity Labdaros ir paramos fondas BYSOL, alongside organisations in Poland and the United States. Questions of governance, safeguarding female beneficiaries, processing sensitive data, preventing conflicts of interest and implementing the commission’s decisions therefore cannot be treated solely as an internal conflict within the Belarusian opposition. They concern the obligations of legal entities, donors and supervisory authorities in several states, including Lithuania.

Sexual harassment in itself does not fall within VSD’s exclusive mandate. It should be addressed by the police, equality bodies, labour inspection authorities, data protection authorities, bodies supervising foundations and independent mechanisms providing assistance to those affected. However, VSD’s counterintelligence role arises where an organisation’s head has access to sensitive data on Belarusian political prisoners and activists; where compromising material creates opportunities for blackmail and pressure against Belarusian women in exile in Lithuania; where alleged connections with Lithuanian state authorities, particularly VSD, are used to intimidate women and coerce them into unwanted sexual contact; or where an internal crisis may be exploited by the KGB or FSB for recruitment, pressure and information operations.

The state is not required to know in advance about every instance of sexualised behaviour. It is, however, required to establish a safe system for reporting the combination of harassment, organisational dependency, threats of retaliation through immigration procedures and possible abuse of connections with security authorities. Such a channel must be confidential, independent of political intermediaries and separate from migration decision-making. A victim’s report must not automatically increase the risk of an adverse change to her immigration status.

In this situation, the state’s protection framework proved fragmented. The public sources examined did not establish that any institution had carried out a comprehensive assessment of the combined issues of sexualised behaviour, dependency among beneficiaries, concentration of power in the founder’s hands, access to sensitive data and threats to use national security mechanisms against women making complaints. Nor was publicly verifiable information found showing that VSD had examined reports of the possible use of its name and alleged links with the service to intimidate women, assessed the risk of sensitive data leaks or offered those affected a secure communication channel.

An independent investigation with the informed consent of the women taking part, confidential psychological and legal assistance, a prohibition on retaliation, an audit of access to personal data, an examination of the possible use of organisational and state channels, and a public anonymised report on addressing the structural causes are required. Funding organisations must monitor the implementation of these measures, rather than limit themselves to protecting the fund’s reputation or ensuring continuity of payments.

According to publicly available information, a comprehensive interagency response in Lithuania has not been publicly confirmed. The sources examined did not establish that VSD investigated reports of threats to use the procedure for designating a person a threat to national security, examined possible contacts and transfers of information, or assessed the counterintelligence implications of the fund leadership’s access to data on vulnerable people. This does not mean that such actions definitely did not occur; it means that there is no publicly accountable outcome allowing verification of protective measures for those affected, remediation of the identified vulnerability and prevention of similar situations in the future.

3.10. Possible Trading in Humanitarian Legitimisation by Lithuania’s Ministry of Foreign Affairs and Financial Infrastructure at Heightened Risk of Corruption

Two reports published in 2023 point to the same systemic risk: humanitarian funds, letters of recommendation and migration procedures of Lithuania’s Ministry of Foreign Affairs under Gabrielius Landsbergis could have been used not only to assist genuine victims of repression but also to confer legitimacy on individuals and capital associated with questionable financial, sanctions-related and political risks that had not been assessed. Each report requires further verification in its own right. The overlap in participants, institutions and the alleged mechanism provides sufficiently strong grounds for a full transnational investigation into the matters described.

The Proposed Financial Model of a Possible Corruption Scheme

In the covert video recording ‘How Propaganda Tricked BYSOL’, the interlocutors presented themselves as representatives of a fictitious Russian entrepreneur who wanted to establish a charitable foundation in Lithuania as a ‘laundromat’ for questionable funds, conceal his own involvement and use it for transactions involving Russian funds and ‘grey’ cryptocurrency funds. Andrei Rudanov, the Lithuanian lawyer of the BYSOL fund affiliated with Sviatlana Tsikhanouskaya (headed and founded by Andrei Stryzhak, mentioned above), took part in the conversation and discussed the organisational model of such a ‘laundromat’ foundation, nominal Lithuanian management, the absence of the actual client from formal documents, the documentation of payments to individuals purportedly presented as victims of repression in Belarus, and the preparation of explanations for banks in the event of Russian or other problematic funds being received.

Andrei Rudanov also supplied a cost estimate for the proposed financial model of a foundation intended to launder Russian funds of questionable origin in Lithuania and, consequently, within the European Union. It envisaged approximately €400,000 in annual expenditure, including €54,000 for the services of the director general, €48,000 in remuneration for Rudanov himself, and €15,000 for office premises. In the recording, he separately states the amount of donor support received by BYSOL in 2022—€2,046,378, excluding national funding—and draws a parallel between BYSOL and other foundations that were to be established with the involvement of Andrei Stryzhak and individuals connected to Sviatlana Tsikhanouskaya’s structures.

The cost estimate does not prove that money laundering actually took place. However, it has evidentiary value as a tangible trace of possible preparations to establish financial and organisational infrastructure for corruption and the laundering of funds of questionable Russian origin. The discussion took place after the start of the full-scale war, the introduction of expanded sanctions, and the sharp increase in the risk of charitable organisations being used to circumvent banking and sanctions controls.

The content of the conversation reinforces the significance of the document. After being informed about the Russian and “grey” funds, Rudanov discussed the visibility of the ultimate beneficial owners, European banks’ sensitivity to large and recurring transfers, and the need to prepare documentation and supporting explanations in response to bank enquiries. The remarks made by Lithuanian lawyer Andrei Rudanov in this video provide sufficient grounds to investigate possible facilitation of the concealment of beneficial owners, sham charitable activity, the laundering of Russian capital of questionable origin in Lithuania, the circumvention of financial controls, and tax abuse.

Possible conflict of interest involving the Lithuanian Ministry of Foreign Affairs (then headed by Gabrielius Landsbergis)

The same recording states that his wife, Irina Rudanova, had worked at the Lithuanian Ministry of Foreign Affairs for eleven years, held the position of Third Secretary of the Consular Section in Belarus, dealt with Schengen and national visas, and was responsible for these matters at the Lithuanian consulate in Minsk in 2019–2021. The conversation mentioned the possibility of obtaining a humanitarian visa for the fictitious Russian businessman’s secretary under the guise of a “victim of political repression by the Belarusian regime”.

A family connection does not in itself prove interference in visa decisions. However, an obvious conflict of interest arose from the combination of the Lithuanian lawyer’s advice on laundering illicit Russian funds in Lithuania under the guise of ‘assistance to victims of political repression in Belarus’ and on concealing the foundation’s actual organiser, the discussion of a humanitarian visa for a person with no established history of persecution, and the adviser’s family connection to an employee of the consular system. This warning sign required an immediate internal inquiry by the Ministry of Foreign Affairs: examination of records of approaches made to the authorities, visa decisions, correspondence, possible access to official information and the involvement of connected individuals in preparing applications. There is no public information indicating that such an inquiry was conducted.

The transcript also indicates that the metadata of the cost estimate submitted by Andrei Rudanov listed Klara Weger, Head of Resource Management at the International Centre for Migration Policy Development (ICMPD), as a co-author. The document itself described the financial model of a foundation discussed in the context of receiving questionable Russian funds and possibly concealing the actual organisers and beneficial owners.

The presence of a name in the metadata does not automatically establish authorship, knowledge or involvement on the part of Klara Weger or ICMPD: the information could have been retained from a previously used template, transferred automatically or modified by another user. However, the position held by the person named, the file’s provenance and the content of the cost estimate provided sufficient grounds for an immediate, thorough technical and financial examination. The original file, its creation and editing history, the authors’ user accounts, correspondence, contracts, the document’s circulation and possible links between the proposed foundation and ICMPD should have been examined. There is no publicly available information indicating that such an inquiry took place.

The absence of publicly available information about whether such a review was conducted leaves a number of fundamental questions for the Lithuanian Ministry of Foreign Affairs and the VSD unanswered: whether the possible involvement of ICMPD staff in the preparation of the financial model described above was examined; whether it was investigated whether funding from national governments or the European Commission was envisaged; whether the possible use of ICMPD’s institutional reputation to lend legitimacy to a fund potentially serving as a vehicle for money laundering was assessed; and whether the risk of European migration infrastructure being involved in the laundering or legitimisation of funds of questionable Russian origin within the European Union was examined.

We were unable to identify, in publicly available sources, any information indicating that such a technical, financial, or institutional review was conducted, or any information about its results. The involvement of Klara Weger or ICMPD therefore cannot be considered established. At the same time, the absence of public information about any review of the identified digital trail raises a separate question about the effectiveness of financial and institutional oversight by the Lithuanian Ministry of Foreign Affairs and the VSD.

The Actual Case of Belarusian Businessman Eduard Apsit

On 30 June 2023, the Belarusian Investigative Center published an investigation into assistance provided to relatives of the Belarusian businessman Eduard Apsit in obtaining humanitarian residence permits in Lithuania. According to the Center, Apsit transferred more than €94,000 to the Dutch entity of the BYSOL fund affiliated with Sviatlana Tsikhanouskaya. BYSOL co-founder Yaroslav Likhachevsky approached Freedom House’s Lithuanian office for letters of recommendation, citing financial support for the fund. Freedom House then acted as an intermediary with the Lithuanian authorities to regularise the residence status of Apsit’s relatives. The businessman’s mother and his wife’s parents received humanitarian residence permits. Freedom House representative Vytis Jurkonis confirmed that it had acted as an intermediary.

The applicant’s profile contained clear indicators of heightened risk. Companies linked to the Apsit family featured in a Latvian investigation into the alleged laundering of €73 million through ABLV Bank. Journalists also reported on their government contracts in Russia and Belarus and possible business links to Yevgeny Prigozhin’s structures. These circumstances ruled out relying solely on the intermediary’s reputation or the fact of a large donation. An independent examination of the source of funds, the beneficial owner, business and political ties, and the genuine grounds for each applicant’s humanitarian status was required. The publicly available material did not establish that such an independent review had been carried out and that its findings had been recorded in a verifiable form.

A private organisation is entitled to submit a letter of recommendation but has no authority to establish whether persecution has occurred, assess a threat to national security or make a migration decision. Responsibility for independently verifying the circumstances claimed, the sources of funds and possible sanctions-related and criminal risks lay with the Ministry of Foreign Affairs, the Migration Department and VSD.

Freedom House’s recommendation and support from the BYSOL fund affiliated with Sviatlana Tsikhanouskaya could not substitute for state vetting by the Ministry of Foreign Affairs or VSD, or create a presumption of trustworthiness on humanitarian grounds. In this case, there was a clear substitution of mandates: private intermediaries with a financial interest effectively established the applicants’ status as trusted individuals, while the state authorities did not demonstrate an independent and verifiable assessment of the information submitted. As a result, the intermediary’s reputational standing and the size of the donation may have carried more weight within Lithuania’s state institutions than a substantiated history of persecution and an objective risk assessment.

Double Standards

The case demonstrates a double standard. Ordinary Belarusian applicants were designated threats to national security because of military service long ago, relatives in Belarus or other general biographical characteristics. At the same time, the family of a major donor whose companies featured in a money-laundering investigation and reports on links to Yevgeny Prigozhin’s structures gained access to influential intermediaries capable of influencing decisions by the Lithuanian state.

Even if each individual decision was formally lawful, this asymmetry creates a market of unequal access to humanitarian protection. The risk posed by a person begins to be assessed not only on the basis of verifiable facts but also according to their ability to make a large donation to structures affiliated with Sviatlana Tsikhanouskaya, obtain a letter from an international organisation and mobilise political connections. In such a system, humanitarian status can be transformed from a protection mechanism into a resource whose accessibility is influenced by intermediaries and mechanisms that create corruption risks within Lithuania.

The Overlap between the Alleged Method and the Case That Actually Occurred

The covert recording and the Belarusian Investigative Center’s investigation are separate materials in terms of their form, but they describe a similar sequence of actions and an overlapping institutional environment.

The covert recording demonstrates the alleged method:

  • establishing a foundation in Lithuania with formally independent Lithuanian management to receive questionable Russian funds and subsequently move them within the European Union;

  • excluding the actual initiator and the real client from official documents;

  • using the status of a victim of political repression to regularise the status of questionable individuals and legitimise payments and financial transactions;

  • assessing the extent to which banks would be able to identify the beneficial owners;

  • preparing formal explanations to pass banking checks without difficulty;

  • discussing the possibility of obtaining humanitarian visas in Lithuania through the mediation of Lithuania’s Ministry of Foreign Affairs for people who had presented no history of political persecution.

The Center’s investigation describes a sequence that actually occurred:

  • Eduard Apsit’s transfer of more than €94,000 to the Dutch entity of BYSOL, affiliated with Sviatlana Tsikhanouskaya;

  • an approach by Yaroslav Likhachevsky, co-founder of the BYSOL fund affiliated with Sviatlana Tsikhanouskaya, to Freedom House’s Lithuanian office seeking support in the form of recommendations;

  • Freedom House’s intermediation with Lithuanian state authorities, particularly Lithuania’s Ministry of Foreign Affairs;

  • the granting of humanitarian residence permits to Apsit’s mother and his wife’s parents;

  • serious financial, criminal and political risk indicators associated with companies linked to Apsit, including their mention in an investigation into the alleged laundering of €73 million in Latvia and in reports on possible links to Yevgeny Prigozhin’s structures.

The overlap between the two reports produces a set of specific, mutually reinforcing indicators of a possible replicable model of corruption in Lithuania:

a large donation to a fund affiliated with Sviatlana Tsikhanouskaya → access to the influential intermediary Freedom House → humanitarian legitimisation through a recommendation in an intermediary letter from Lithuania’s Ministry of Foreign Affairs under Gabrielius Landsbergis → an application to the migration authorities → a migration decision in which it was not publicly disclosed how VSD assessed the financial, sanctions-related and corruption risks.

The situation concerns a possible corrupt model of trading in humanitarian legitimisation in Lithuania through Lithuania’s Ministry of Foreign Affairs. It therefore requires an examination not only of the decisions concerning the Apsit family but also of all cases in which humanitarian residence permits were obtained through Lithuania’s Ministry of Foreign Affairs.

The Need for a Transnational Investigation

The examination cannot be limited to one applicant or one fund. A name-by-name cross-check is required of:

  • recipients of humanitarian visas and residence permits in Lithuania obtained through Lithuania’s Ministry of Foreign Affairs;

  • applications and letters of recommendation from Freedom House, BYSOL and other intermediaries affiliated with Sviatlana Tsikhanouskaya;

  • donations to BYSOL’s Dutch entity and legal entities linked to Tsikhanouskaya in Lithuania, Poland, the United States and other countries;

  • the dates of donations, recommendations and migration decisions;

  • the grounds of persecution claimed;

  • applicants’ alternative citizenships, residence permits and sources of income;

  • the actual senders and beneficiaries of payments;

  • the advisers, intermediaries and officials involved;

  • subsequent corporate and financial links.

Such an investigation must be transnational because the bank accounts, legal entities, donors, intermediaries and state decisions span several jurisdictions. A joint international investigation team and formalised data exchange are required between the Lithuanian prosecution authorities, the Financial Crime Investigation Service, VSD, the Ministry of Foreign Affairs, the Migration Department and the competent authorities of the Netherlands, Poland, the United States and other states concerned, as well as Eurojust, Europol and national financial intelligence units.

The Gap in the Publicly Verifiable Response by VSD and Other Lithuanian State Authorities

The investigations made public in 2023 constituted a specific early warning requiring an interagency response. However, open sources contain no information indicating that VSD, the Ministry of Foreign Affairs, the Migration Department, the prosecution authorities or the Financial Crime Investigation Service:

  • cross-checked donors, recommended individuals and recipients of humanitarian documents by name;

  • requested banking and corporate data from the Netherlands and other jurisdictions;

  • examined the possible conflict of interest within the Ministry of Foreign Affairs;

  • examined the provenance and metadata of the financial cost estimate;

  • checked the sources of large donations to BYSOL and other structures affiliated with Sviatlana Tsikhanouskaya;

  • reviewed migration decisions previously taken;

  • established uniform rules for recording intermediation;

  • published anonymised findings of the examination;

  • changed procedures so that a donation could not influence access to humanitarian status.

The absence of a publicly reported outcome, anonymised statistics, procedural decisions and corrected procedures means that the state has not demonstrated that the identified risk has been addressed.

National security is weakened not only when a particular person is proven to be working for a foreign intelligence service. It is also undermined when private intermediaries with a financial interest acquire opaque influence over state decisions to regularise the status of questionable individuals, a large donation becomes a means of acquiring reputational legitimacy in Lithuania, and humanitarian protection mechanisms can be used to regularise the status of individuals and legitimise capital whose links and risks have not been assessed.

Against the backdrop of large numbers of ordinary Belarusians being designated threats to national security, the state’s failure to demonstrate a visible and verifiable outcome of an examination of such a specific chain of events points to the risk of systemic double standards and another gap in VSD accountability. The state takes a harsh approach to people without political or financial resources, while where large donations, influential intermediaries and international structures are involved, the publicly verifiable risk assessment remains insufficient. Such selectivity creates a risk that Lithuania’s national security system may become an instrument of unequal access, transnational corruption, political patronage and possible circumvention of financial controls.

3.11. The Nasha Niva Case: Selective Lowering of Journalistic Standards and Media Amplification as a Security Risk

Separate monitoring of Nasha Niva’s publishing practices in Lithuania identified the repeated dissemination of unsubstantiated allegations, rumours and negative interpretations concerning certain representatives of Belarusian civil society in exile. The distinctive feature of this case is not a general lack of professional capacity within the editorial team. On other subjects, Nasha Niva demonstrates the ability to conduct complex journalistic investigations, establish links between individuals and organisations, verify documents, cross-check sources and maintain a high standard of evidence.

The systematic lowering of evidentiary requirements concerning a specific group of actors therefore cannot convincingly be explained solely by professional errors, a lack of resources or generally weak editorial procedures. This selectivity is apparent in the publication of serious allegations against people and organisations independent of Sviatlana Tsikhanouskaya’s political centre under a lower standard of verification than the outlet is capable of applying in other cases. Unverified claims are repeated, carried from one publication into another and gradually turned into persistent negative reputational labels.

This persistent and targeted publishing practice raises a legitimate question about the deliberate construction of a negative reputation for certain actors. It does not prove that the activity was commissioned for political or intelligence purposes, but it requires an examination of at least two possible explanations:

  • a politically motivated smear campaign serving the interests of structures linked to Sviatlana Tsikhanouskaya;

  • influence by Belarusian intelligence services or the use of the editorial environment as part of transnational repression against Belarusian civil society in exile.

It is impossible to establish which of these explanations reflects reality solely by analysing publications. It is necessary to examine editorial contacts and conflicts of interest, the origins of recurring allegations, the role of anonymous sources, possible coordination of publications, the transfer of materials to political structures and state authorities, and the subsequent use of these publications in donor, migration and counterintelligence decisions.

The Mechanism of Harm

An unsubstantiated allegation repeatedly disseminated by an influential Belarusian media outlet operating from Lithuania may become raw information for:

  • a non-public VSD assessment;

  • a Migration Department decision;

  • refusal of asylum or a residence permit;

  • termination of donor funding;

  • exclusion from professional and human rights networks;

  • public ostracism;

  • the fabrication of a new charge by Belarusian security and law enforcement authorities;

  • an increased risk of detention, deportation or transnational persecution.

A defamatory publication thus ceases to be solely a matter of media ethics. It may trigger a chain of state, financial and reputational consequences that are virtually impossible to remedy once the initial allegation has been disseminated.

This mechanism is particularly dangerous in Lithuania, where decisions to designate a person a threat to national security may be based on a non-public VSD assessment. The person affected often does not know the original source of the allegation, has no access to the materials used and cannot effectively refute information already circulating among editorial teams, political intermediaries, donors and state authorities.

VSD’s Duties

VSD should not determine the permissible content of journalistic publications or interfere with lawful editorial activity. However, the service has a duty to respond when a systematic information campaign may be an instrument of foreign influence, transnational repression, political pressure or preparations for decisions affecting national security.

In such a situation, VSD should have:

  • identified the original sources of the most serious allegations;

  • checked whether supporting documents and independent testimony existed;

  • assessed the interests and possible connections of anonymous sources;

  • checked for coordination between publications, political structures and subsequent migration or donor decisions;

  • established whether materials had been supplied to the editorial team by Belarusian state authorities, intermediaries linked to them or individuals with a political interest;

  • checked whether Nasha Niva publications had been used in official assessments by VSD or the Migration Department;

  • distinguished journalistic error and political criticism from a deliberate information operation;

  • ensured protection for people targeted by a confirmed hybrid attack or transnational repression.

A state authority is not entitled to use a media publication as stand-alone evidence of a threat to national security. It must establish the original source of the information, examine that source’s interests, find independent corroboration and disclose the substance of the allegation to the person affected to an extent sufficient for an effective appeal.

If the examination reveals indications of defamation, unlawful processing of personal data, persecution, coordination with a foreign intelligence service or knowing facilitation of transnational repression, VSD must refer the materials to the competent law enforcement and supervisory authorities. Any measures must be based on law, evidence and due process, rather than becoming administrative pressure on the media for criticism.

Remedying the Entire Chain of Consequences

The Nasha Niva case also concerns the early warning system. If an allegation of links to intelligence services or other dangerous activity migrates from a publication into a donor, migration or counterintelligence decision, correcting a single article is not enough. A mechanism is needed to correct the entire information chain.

A rebuttal, clarification or editorial correction must be sent to all state authorities, donors and organisations that received or used the original material. Otherwise, an unsubstantiated claim continues to operate as a hidden sanction even after it has lost its factual basis.

The open sources examined contained no information indicating that VSD had systematically investigated the origins of such allegations, assessed the possibility of political or intelligence coordination, examined their use in migration decisions or established a mechanism for remedying the consequences. Therefore, at the publicly verifiable level, a potentially dangerous information chain remains without independent scrutiny: a publication becomes an accepted fact about someone’s reputation, that reputational fact becomes a non-public signal to the state, and that non-public signal becomes a decision that the person affected is practically unable to challenge.

Possible political coordination, the involvement of Belarusian intelligence services and the use of publications in mechanisms of transnational repression should have been examined by VSD. There is no publicly verifiable information that such an examination was conducted or that the people affected were protected.

3.12. Large-Scale Migration Decisions and False Positives in SIS Alerts

Official Migration Department statistics show sharp fluctuations in the scale of restrictive decisions concerning Belarusian citizens. The final figure for 2023 was 1,428 people, for 2024 it was 598, and for 2025 it was 1,634. Thus, over three calendar years, 3,660 Belarusian citizens were designated threats. This total is the sum of the annual figures, rather than an established number of unique individuals over the entire period: the published data do not rule out the same person being counted more than once in different procedures or years.

Year

Belarusian citizens

Nature of the official figure

2023

1,428

Final annual number of people designated threats

2024

598

Final annual number of people designated threats

2025

1,634

Final annual number of people designated threats

Legally, a Lithuanian authority’s decision that a person poses a threat and the entry of an alert in the Schengen Information System (SIS) are not the same thing. However, the Migration Department officially states that all persons covered by such decisions are banned from entering Lithuania. Under Article 24 of Regulation (EU) 2018/1861, a decision to refuse entry or stay, based on an individual assessment and a finding of a threat to public policy, public security or national security, provides grounds for an SIS alert. Lithuanian decisions can therefore have cross-border effects throughout the Schengen area. Public reporting, however, does not disclose precisely how many Lithuanian decisions in 2023–2025 led to the creation, amendment or deletion of SIS alerts.

The problem is not the physical capacity of the database. The risk lies in a lower signal-to-noise ratio. If alerts enter the common European system primarily on the basis of citizenship, compulsory military service long ago, previous employment in a state institution, relatives in Belarus or another biographical connection, without specific information about current conduct, intent and capacity to cause harm, this creates false-positive matches and an additional burden on other states’ border, migration, police and consular authorities.

Such information noise does not prove that a particular intelligence operative will automatically escape detection. But it increases the risk of errors in prioritisation: officers have to check more weak signals, their attention and focus are dispersed, and alerts based on specific hostile activity enter the same stream as decisions whose quality cannot be independently verified. At the same time, an individual may face refusals and checks in several states even though the original Lithuanian decision is based on a non-public, hypothetical assessment and is unrelated to criminal prosecution or proven espionage.

For this reason, the large volume of decisions should be treated as grounds for an independent audit of the quality of VSD’s work, rather than as a measure of its effectiveness in itself. It is necessary to establish how many decisions were based on specific actions and how many on general biographical characteristics; how many led to an SIS alert; how many alerts produced a meaningful hit in another state; how many decisions were overturned by a court or the authority itself; how many records were corrected or deleted; how many files were referred for criminal investigation; and how many individuals were actually linked to intelligence, sabotage, sanctions-related or other hostile activity.

Until these data are published, it cannot be asserted that thousands of decisions correspond to thousands of identified agents or genuine threats. Nor can it be asserted that all the decisions are wrong. The criticism that can be substantiated is the lack of public quality control: the state reports the volume of restrictions but does not demonstrate their accuracy, effectiveness or impact on the common European security mechanism.

Required measure: an independent international audit of decisions and associated SIS alerts for 2023–2025, involving the Migration Department, VSD, Lithuania’s SIRENE Bureau and the data protection authority. The audit should use an anonymised sample and examine the individualised nature and proportionality of the grounds, the proportion of false-positive decisions, the outcomes of appeals, the time taken to update and delete data, and the operational value of these alerts for other Schengen states.

4. Sabotage, Sanctions Circumvention and Gaps in State Resilience

4.1. Lithuania as an Operational Base for Russian Sabotage

In July 2024, four parcels containing improvised explosive-incendiary devices were sent from Vilnius via DHL and DPD. One device activated at a logistics centre in Leipzig shortly before it was due to be loaded onto a cargo aircraft; another caught fire at a warehouse in Birmingham. A joint investigation team from Lithuania, Poland, Germany, the Netherlands and the United Kingdom identified 22 suspects in Lithuania and Poland. According to the prosecution authorities and Eurojust, nationals of several states, often in socially vulnerable circumstances, were used for individual tasks; communication took place through Telegram, and payments were made partly in cryptocurrencies.

Uncovering the network is an important law enforcement achievement, but a criminal case is no substitute for a public interagency review. It has not been publicly explained how the devices were manufactured, transported and dispatched from Vilnius, which indicators the services and carriers missed, whether other shipments and contacts of the same individuals were checked, which screening procedures were changed or who verified their effectiveness. The key national security question is not only whether the perpetrators have been detained but also whether the conditions that enabled Lithuania to be used as a logistics hub for a Russian sabotage operation have been eliminated.

4.2. The IKEA Arson Attack and the Absence of a Public Review of Early Detection

The prosecution authorities classified the arson attack on the IKEA store in Vilnius on 9 May 2024 as a terrorist offence committed in the interests of Russia’s military and intelligence services. On 24 November 2025, one of the perpetrators, who had been a minor at the time of the offence, was convicted. The investigation into other participants was conducted separately. The case materials also indicated preparations for another attack in Riga, which was prevented following the perpetrator’s arrest in Lithuania.

The verdict addresses the criminal responsibility of individual perpetrators but does not show whether early warning signals existed, whether other potentially recruited teenagers were assessed or whether the arson attack, parcels and other operations were examined together as a single infrastructure. An anonymised after-action review is needed: a chronology of detection, missed indicators, interagency cooperation, changes to procedures and independent verification of their implementation in Lithuania.

4.3. Systematic Recruitment of Disposable Agents

Official materials from sabotage cases show that a foreign service can divide an operation among perpetrators of different nationalities who do not know the overarching plan. Recruitment exploits economic vulnerability, criminal connections and young people, using Telegram, small payments and cryptocurrency. This calls into question a risk model that relies excessively on citizenship, previous service or family ties.

The state should analyse behaviour and infrastructure rather than ethnic or migration profiles: digital recruitment channels, intermediaries, financial flows, component suppliers, recurring addresses and logistics routes. Mass screening of migrants’ backgrounds can coexist with a failure to detect an actual sabotage network if the service is looking for a suspicious category of people while the adversary chooses a perpetrator of any nationality who is suited to the task.

4.4. State Reserves Built without Reference to the Main Risks

Lithuania’s National Audit Office found that Lithuania’s state reserves had been built without sufficient consideration of the most significant risks and without adequate justification based on scenarios for managing those risks. The audit also identified a danger that stocks would not reach recipients in time during a crisis or war.

This is a direct gap between military planning and human security. The public assessment system should show adequacy standards for food, water, fuel, medicines and autonomous power supplies, their regional distribution, delivery times, stock rotation and provision for vulnerable groups. The mere existence of stocks does not mean readiness if their composition is not linked to scenarios and the logistics have not been tested in practical exercises.

4.5. Shelters and the Physical Protection of the Population

According to the 2025 state audit, around 361,000 residents of Lithuania had no allocated place in shelters, and approximately 200,000 had no allocated place in collective protection facilities. The audit also highlighted problems with modernising the warning system and the accessibility of facilities for people with reduced mobility.

The number of premises in a register is not an indicator of actual protection. Municipal data are needed on actual capacity, the time required to open facilities, ventilation, water, sanitation, backup electricity, communications and accessibility. Unannounced inspections and publication of the proportion of facilities that can actually accommodate people within the prescribed time are required. Otherwise, the state demands that the population view the military threat as existential while failing to provide basic physical protection for a substantial proportion of residents.

4.6. Lack of Readiness in the Civil Resistance System

An audit of citizens’ preparation for unarmed civil resistance identified insufficient coordination, uneven access to training across municipalities and the need to adapt programmes for people with disabilities. Planning for changes and a new coordination mechanism began after the audit.

The concept of total defence remains incomplete without a clear allocation of responsibilities among the state, municipalities and NGOs. No uniform procedures have been published for the participation of migrants, foreign nationals, organisations of exiles and independent volunteers; requirements for protecting their data; arrangements for admission to training; safeguards against political discrimination; or a mechanism for assisting people with disabilities. Civil resistance cannot be reduced to patriotic messaging without accessible practical training and a coordinator whose work can be scrutinised.

4.7. Undersea Cables and Infrastructure Resilience

In November 2024, a telecommunications cable between Lithuania and Sweden was damaged. Lithuanian prosecutors opened a pre-trial investigation on suspicion of terrorism, and the incident formed part of a series of instances of damage to undersea infrastructure in the Baltic Sea. In January 2025, NATO announced the Baltic Sentry mission to strengthen the protection of critical infrastructure.

Investigating the cause of the damage does not in itself address Lithuania’s resilience. The number of independent international links, the time required to switch to backup connections, the dependence of state registers, the payment system and emergency services, the results of exercises simulating simultaneous damage to several lines, and the procedures for retaining and integrating AIS, satellite surveillance and port control data need to be disclosed in a safely aggregated form. Attribution may remain uncertain, but redundancy and recovery must be verifiable and transparent to the public.

4.8. GPS and GNSS Signal Jamming and Spoofing

The Lithuanian Transport Safety Administration warned of satellite signal jamming and spoofing in the Baltic region and issued a navigational warning for Lithuanian waters. VSD links the increase in such interference to Russia’s use of electronic warfare equipment in the Kaliningrad region.

There is no unified public dataset on the number and geographical distribution of incidents, dangerous close encounters involving aircraft and vessels, the availability of independent backup systems at airports and ports, or the impact on rescue, medical and military services. A common register of GNSS incidents, a uniform methodology for assessing harm and mandatory exercises simulating prolonged loss or deliberate spoofing of navigation signals are required.

4.9. Rerouting Trade through Intermediary Countries

Bank of Lithuania data record an almost mirror-image shift in export destinations after the start of the full-scale war. Comparing 2021 with the third quarter of 2022, Russia’s share of Lithuania’s total exports fell by 4 percentage points, while the share of other CIS states rose by 4.2 percentage points. The Bank of Lithuania itself raised the question of whether these states had become an intermediate route for delivering goods to Russia.

The Bank of Lithuania’s initial analysis did not establish that the decline in direct exports automatically meant that the same goods had been rerouted through other CIS states. When broken down into broad product categories, the decline in exports of machinery, equipment, chemical products and plastics to Russia did not fully match the growth in the same categories in other markets. The correspondence between aggregate figures is a serious risk indicator requiring further examination.

However, the absence of statistical proof at the level of broad commodity codes does not prove the absence of a scheme. The analysis did not establish the end user, subsequent re-export transactions, the link between seller and intermediary, the origin of payments, the movement of goods after crossing the border or the use of a new legal entity. The Bank of Lithuania later itself described CIS states as a possible instrument for circumventing sanctions and reported that in 2022 the value of payments to CIS states, Georgia and Turkmenistan more than doubled, incoming payments almost doubled, and transactions with Kazakhstan increased by more than 80 per cent. Among the possible explanations, the Bank explicitly identified the search for new payment methods to continue cooperation with existing partners in Russia and Belarus.

In May 2023, the Association of Lithuanian Banks presented more detailed risk indicators. Comparing the first quarter of 2022 with the first quarter of 2023, exports from Lithuania to Kyrgyzstan increased by a factor of 19.3, to Armenia by a factor of 10, to Georgia by a factor of 3, to Kazakhstan by a factor of 1.6 and to Tajikistan by a factor of 1.4; growth was also recorded for Uzbekistan, Azerbaijan, Türkiye, Serbia, Moldova and the United Arab Emirates. The Association warned that Lithuania risked acquiring a reputation as a grey zone of the European Union whose companies transported goods to states friendly to Russia and Belarus for possible subsequent re-export.

 

Indicator

Publicly established trend

What remains unchecked

Russia’s share

A fall of 4 percentage points

Which goods and end recipients disappeared from the direct route

Other CIS states

An increase of 4.2 percentage points

Subsequent re-export and the actual end user

Payments involving Kazakhstan

An increase of more than 80 per cent

Purpose of payments, intermediaries and links to Russian clients

Exports to Kyrgyzstan

An increase by a factor of 19.3

Commodity codes, intermediary companies and the subsequent movement of goods

Exports to Armenia

An increase by a factor of 10

End use and links to sanctions-related chains

 

VSD’s annual assessments lack a comprehensive analysis of the specifically Lithuanian link in the chain: a list of high-risk sectors and companies, the volume of suspicious re-exports, the number of files referred, the results of checks, end recipients, criminal justice consequences and an assessment of the re-emergence of the same networks.

Against this backdrop, restrictions on broad categories of Russian and Belarusian citizens create an impression of toughness but do not replace checks on commodity codes, beneficial owners, payments, routes and end use. If the state demonstrates political strictness through restrictions on individuals while failing to show proportionate effectiveness against commercial chains that actually supply the Russian market, such a policy becomes a diversion and a semblance of combating the problem. It shifts attention away from complex investigations into businesses and intermediaries circumventing European economic sanctions towards easily administered symbolic bans.

The risk is that Lithuania will become a grey gateway — and, in the event of deliberate and systematic facilitation, a black gateway — for circumventing European sanctions. This threatens more than the country’s reputation. Re-exports of industrial equipment, electronics, vehicles and dual-use goods may support Russia’s war economy and directly weaken the European Union’s collective security. Concealing the scale of the problem, the absence of public reporting on the progression of investigations, and the replacement of oversight with symbolic restrictions and a semblance of work by VSD must be regarded as a separate threat to national and European security.

4.10. Sanctions Circumvention: The Gap between Warning Signals and Legal Consequences

According to FNTT, in 2024 the number of reports relating to sanctions restrictions on Russia and Belarus rose to 305, compared with 193 the previous year. Financial institutions submitted 66 reports of possible sanctions circumvention, while the analysis of 23 of them was publicly reported. At the same time, the service granted 392 exemptions or authorisations relating to the non-application of particular restrictions. In 2024–2025, proceedings were initiated against several companies and individuals, searches were conducted with OLAF’s support, and vehicles and goods worth around €1.5 million were seized.

However, public reporting does not make it possible to trace the progression of enforcement: how many warning signals were checked, how many cases were opened, how many were closed, how many charges were brought, which convictions and confiscation orders became final, who received exemptions and how the end user was verified. Without such statistics, it is impossible to assess whether networks circumventing European economic sanctions are being dismantled or whether, after one legal entity is closed, its activities move to a successor company and continue through the same or new schemes.

 

Public indicator

Required examination

305 reports in 2024

How many were checked and how many led to investigations

66 specific warning signals

Why analysis of 23 was publicly reported

392 exemptions and authorisations

Recipients, criteria, end user and follow-up oversight

Criminal investigations

Charges, convictions, confiscations and closed cases

Closed companies

Owners, managers, addresses, assets and new legal entities

 

4.11. Centralisation of State IT Systems as a Single Point of Failure

The National Audit Office found that around €100 million had been spent on shared infrastructure and centralised public-sector IT services in 2015–2024, but sufficient evidence of the expected benefits of centralisation had not been presented. Following the mass extraction of data from the Centre of Registers, this finding takes on national security significance.

It is necessary to examine whether centralisation has created a common point of compromise: whether agencies’ data are segregated, whether a single user account can be used to make bulk queries across several registers, whether isolated backups exist, how administrators and contractors are monitored, and whether recovery tests and insider-threat simulations are conducted. Savings from combining systems should not be assessed separately from the concentration of harm in the event of a compromise and the risks to national security.

4.12. A Unified Register of Consequences and Remedial Action for VSD’s Failures

For every serious incident, the state should publish an anonymised follow-up record: what happened; when the authority became aware; which institutions were responsible; which indicators were missed; how many people and systems were affected; what investigation was opened and how it concluded; whether anyone was held accountable; which rules were changed; who verified their implementation; and whether a similar incident recurred.

Lithuania’s problem is not a lack of information about threats. The state describes the adversary in considerable detail after an incident. The systemic gap lies between warning, prevention, investigation of root causes, protection of those affected and verifiable remediation of the vulnerability. A criminal case against an individual perpetrator does not prove that the state system has learned a lesson and ruled out a recurrence of the threat in the future.

5. Preliminary Assessment across the Seven Dimensions of Human Security

5.1. Economic Security

Official VSD and AOTD assessments periodically include separate sections on economic and energy security. They examine the Belarusian Nuclear Power Plant, energy dependence, strategic infrastructure, Russia’s war economy, sanctions circumvention, supplies of dual-use goods, foreign investment and attempts by hostile states to use companies registered in Lithuania to obtain technologies.

Such analysis is necessary but rests on a narrow understanding of economic security. The economy is viewed primarily as a sphere of external influence and a collection of strategic assets that must be protected from Russia, Belarus and China. At the same time, there is almost no assessment of the economic security of Lithuania’s residents themselves or of the consequences of state security policy for the labour market, the tax base, investment and the state’s technological resilience.

Official reports do not provide systematic answers to the following questions:

  • how migration and counterintelligence decisions affect the labour market;

  • what labour shortages arise after workers leave;

  • how much tax revenue the state loses;

  • how many companies scale back their operations or relocate them to another country;

  • how legal uncertainty affects investment and technology sectors;

  • to what extent energy poverty, housing costs and insecure employment increase the population’s vulnerability;

  • whether a migrant’s dependence on a non-public VSD decision creates additional conditions for exploitation, blackmail and recruitment;

  • what economic harm is caused by erroneous or overly broad decisions designating a person a threat to national security.

Economic vulnerability is mentioned primarily as a possible channel for recruitment by foreign intelligence services. However, poverty, insecure employment and dependence on an employer and immigration status are not treated as threats to security in their own right that the state has a duty to reduce. As a result, the causes of vulnerability are overlooked, and an economically vulnerable person is transformed from someone to be protected into a target of suspicion and attack.

This contradiction is clearest in the treatment of Belarusian citizens. Lithuania initially made a deliberate effort to attract workers, entrepreneurs and technology companies dependent on migration decisions. The state facilitated their relocation, presented it as an economic success and used Belarusian workers to fill labour shortages. After these people had become part of the economy, begun paying taxes, established businesses and brought their families over, the state tightened migration restrictions and placed them in a situation of pronounced legal uncertainty.

The Scale of Economic Integration

Indicator

Earlier available data point

Latest available data point

Employed Belarusian citizens

around 13,000 as at 1 January 2022

around 48,000 in Q4 2023; 46,600 as at 1 January 2025

Transportation and storage

around 9,600 heavy truck drivers at the beginning of 2022

33,100 sector employees, including 32,800 drivers, as at 1 January 2025

Construction

no comparable figure by citizenship published

5,600 workers from Belarus as at 1 January 2025

Information and communication

631 employees at the beginning of 2022

3,500 employees as at 1 January 2025

Highly skilled employment

895 employees at the beginning of 2022

5,200 employees as at 1 January 2025

Valid residence permits held by Belarusian citizens

steady growth after 2020

peak: 62,844 as at 1 April 2024; 47,872 as at 1 September 2026

Work-based residence permits

no comparable earlier figure published

33,203 valid permits as at 1 September 2026

The indicators refer to different statistical snapshots and are not always fully comparable in methodological terms. Nevertheless, they show the scale of Belarusian workers’ integration into Lithuania’s economy and the need to assess the consequences of migration decisions not only for individuals but also for entire sectors, the tax base and the state’s technological resilience.

The Structural Role of Belarusian Workers

Belarusian workers have become a significant part of sectors with chronic labour shortages. At the beginning of 2025, 33,100 Belarusian citizens worked in transportation and storage, 5,600 in construction and 3,500 in information and communication. According to the Bank of Lithuania, at the end of 2023, employed and registered unemployed Belarusian citizens accounted for 3.2 per cent of the country’s total labour force.

Around 88 per cent of those employed held medium-skilled jobs, primarily as drivers and construction workers. A further 11 per cent held highly skilled positions, mainly in information technology, communications, engineering and the natural sciences. Their economic significance lay not only in their overall numbers but also in filling vacancies and skills gaps that Lithuania’s labour market could not quickly address using its own resources.

The transport sector is also particularly dependent on workers from third countries, including Belarusian citizens.

The Technology Ecosystem Created by the State

The presence of Belarusian information technology professionals resulted from deliberate state policy. In 2021, 43 Belarusian companies had already begun relocating to Lithuania, and around 40 more were considering doing so. Later reports referred to approximately 80 companies that had relocated or were in the process of relocating. Those named included EPAM Systems, Wargaming, Flo Health, Coherent Solutions, Godel Technologies and Itransition.

According to data for 2024, Wargaming Vilnius had around 878 employees, revenue of approximately €83.5 million and paid around €11.2 million in taxes. This example shows that migration decisions concerning individual employees can affect not only the particular foreign national but also an export and technology ecosystem developed with state support.

The state initially invested political and administrative resources in attracting these companies, then began applying increasingly broad and opaque security criteria to their employees. The absence of an assessment of the consequences of this policy shift indicates a lack of coordination between migration, economic and counterintelligence strategies.

Policy Tightening and Outflow

The turning point becomes apparent after 2024. The number of Belarusian citizens holding valid residence permits fell from 62,844 in April 2024 to approximately 57,500 in January 2025 and 47,872 in September 2026. The decline from the peak was around 24 per cent.

According to the Employment Service, the inflow of workers from Belarus decreased by approximately 4,200 people in 2025. At the same time, the number of Belarusian citizens designated threats to national security rose from 598 in 2024 to 1,634 in 2025.

These processes occurred simultaneously. Some people may have left as a result of decisions by VSD and the Migration Department, while others may have left because of restrictions on submitting documents, border closures, company relocations, the economic cycle, family circumstances or moves to other EU states.

For this very reason, an official analysis of the causes of the outflow is needed. Without it, it is impossible to establish what proportion of the decline is linked to the identification of genuine threats and what proportion resulted from general legal uncertainty and the broad application of restrictive measures. No such state analysis was identified in the publicly available sources.

The scale of migration decisions also raises questions about the quality of threat assessments and possible alerts in the Schengen Information System. These consequences are discussed in subsection 3.12.

Unmeasured Losses in Tax Revenue and Workforce Capacity

The precise tax impact of current security policy cannot be determined from the published data. VMI and Sodra do not publish a complete annual data series on Belarusian citizens’ taxes and social contributions, broken down by sector, occupation and the consequences of migration decisions.

The absence of such a calculation is a governance problem in Lithuania in its own right. Lithuania takes large numbers of decisions on national security grounds but does not publish an assessment of their aggregate fiscal, workforce and sectoral consequences.

It is not known:

  • how many taxpayers left the country following negative decisions;

  • how many vacancies remained unfilled;

  • how many companies scaled back their operations or relocated them to another country;

  • how many decisions were overturned by the courts;

  • how many people designated threats were actually linked to hostile activity;

  • what economic harm was caused by erroneous or overly broad decisions;

  • whether the security outcome achieved is commensurate with the economic harm inflicted on Lithuanian companies.

Economic Vulnerability as a Result of Security Policy

A person’s heavy dependence on a migration decision makes them more vulnerable to exploitation, blackmail and recruitment. A worker who fears losing their residence permit is less likely to report employer misconduct, corruption, unlawful financial transactions or a suspicious contact. Opaque security policy may therefore itself create conditions favourable to foreign intelligence services and unscrupulous intermediaries.

A situation in which approaching state authorities does not guarantee protection but may lead to additional scrutiny of the person reporting and a deterioration in their immigration position is particularly dangerous. Such a system reduces people’s willingness to report genuine threats and undermines the trust necessary for counterintelligence.

An economic audit of migration decisions does not imply recognising an unconditional right for anyone to remain in Lithuania. Its purpose is to assess the quality of the state’s risk management. Anonymised data are needed on the number of refusals and revocations, the grounds for decisions, the occupations and sectors of the people affected, the taxes they paid, subsequent filling of vacancies, company closures or relocations and the outcomes of judicial appeals.

For each set of restrictive decisions, the state should compare:

  • the established national security risk;

  • the actual protective outcome;

  • the economic harm and loss of workforce capacity;

  • the number of erroneous decisions;

  • the results of judicial review;

  • the likelihood of new vulnerabilities arising as a result of the restrictive policy itself.

Without these data, it is impossible to determine whether the current system identifies actual agents and participants in hostile activity or predominantly pushes out drivers, construction workers, engineers and developers with Belarusian passports who are already integrated into Lithuania’s economy.

The problem is not a complete absence of economic issues from VSD’s reports. The problem lies in the one-sided analysis: VSD assesses how external adversaries may exploit Lithuania’s economy but scarcely assesses how the security authorities’ own decisions affect employment, the tax base, investment, workforce resilience and people’s ability to resist exploitation and recruitment.

A national security policy whose effectiveness is neither weighed against the economic harm caused nor tested against measurable outcomes can itself weaken the state’s economic resilience and pose a threat to Lithuania’s national security.

5.2. Food Security

Public assessments pay almost no attention to access to food, supply resilience, strategic reserves, dependence on imports of fertilisers and energy, or the ability to protect vulnerable families during a crisis. A military scenario without a food-supply scenario is an incomplete model of resilience.

5.3. Health Security

The reports primarily treated the COVID-19 pandemic as a source of disinformation and cyber risks. Much less attention was paid to the preparedness of the healthcare system, chronic illnesses, mental health, the consequences of prolonged stress, healthcare for refugees and continuity of treatment in an emergency.

5.4. Environmental Security

The Belarusian Nuclear Power Plant is described as an external threat, but environmental security extends beyond nuclear risk. It includes water and air quality, the transboundary Neris/Viliya river basin, the participation of local communities, climate risks and preparedness for pollution. Military and political confrontation must not obstruct mechanisms for cross-border warnings, environmental diplomacy and water diplomacy.

5.5. Personal Security

This includes infiltration by spyware such as Pegasus, attacks, surveillance, transnational repression, human trafficking, gender-based violence and witness protection. A state report should measure not only the threat but also the outcome of protection: how many people received a risk assessment, physical protection, secure communications, legal assistance and notification of a digital attack.

5.6. Community Security

Community security requires protecting diasporas and minorities from collective stigmatisation. When the presence of individual agents turns an entire community into a suspect environment, the state inadvertently advances the objectives of authoritarian regimes’ information operations: mistrust, isolation and conflict between local residents and exiles. It obstructs successful integration and creates ethnic bubbles and ‘ghettos’, while also contributing more broadly to polarisation and radicalisation in society.

5.7. Political Security

Political security includes freedom of expression, media independence, the ability to engage in opposition activity, judicial protection and oversight of intelligence services. Secret materials must not deprive a person of an understanding of the substance of the allegations and an effective means of appeal. A security service whose errors cannot be scrutinised itself becomes a source of institutional risk and a threat to the country’s national security.

6. Conclusion: The Cross-Border Consequences of Lithuania’s Security Gaps for the European Union

The report’s findings reveal a recurring governance cycle rather than a set of isolated errors. The state publicly describes the external adversary but does not ensure comparable transparency about its own failures; investigates individual perpetrators but rarely publishes an analysis of the causes; terminates a particular contract or blocks a particular company but does not publicly demonstrate that the structural vulnerability has been remedied; formally warns organisations and activists of danger, yet in publicly verifiable practice a substantial share of counterintelligence and data-protection tasks remains with the organisations and activists themselves.

This cycle already extends beyond Lithuania’s domestic policy. Incendiary parcels prepared and dispatched from Vilnius endangered European aviation, logistics centres and people in other states. Sanctions circumvention networks help sustain Russia’s military industry and thus the war against Ukraine. Compromised data and insufficient protection of exiles create infrastructure for transnational repression within the European Union. Vulnerabilities in undersea communications, navigation and centralised state systems may affect neighbouring countries and shared European communications, transport and payment chains.

The weaknesses of VSD and the entire interagency security framework can therefore no longer be regarded solely as Lithuania’s internal problem. If the state does not publicly and verifiably demonstrate that it has identified, fully investigated and remedied its own vulnerabilities, there remains a risk that its territory, companies, state systems and logistics infrastructure will serve as channels through which threats reach other European states. In this limited but practically significant sense, Lithuania’s systemic security gaps themselves become a source of threats to European security.

This conclusion does not mean that Lithuania acts as an adversary of the European Union or deliberately creates such threats. It means that a prolonged lack of a publicly verifiable institutional response, together with the consequences of remediation that cannot be verified, themselves become an independent risk factor. Political declarations about being on the front line of security cannot compensate for insufficiently verifiable VSD results in controlling sabotage logistics, sanctions-circumvention chains, access to state data and the protection of people persecuted by foreign regimes.

The situation concerning VSD in Lithuania requires decisive and immediate measures. At the national level, an independent parliamentary investigation into systemic failures, a mandatory interagency review of every major incident, an audit of VSD’s activities and methodology, personal accountability for failure to implement corrective measures and a public register of their implementation are required. At the European Union level, there is a need for an independent assessment of cross-border consequences, the involvement of Europol, Eurojust, OLAF, ENISA and competent European oversight mechanisms in examining sanctions-related, sabotage, digital and repressive chains, and monitoring of the implementation of recommendations against specific deadlines.

Intervention must be lawful, independent and proportionate. It must not supplant Lithuania’s democratic institutions or expose operational sources.

Its purpose is to ensure external oversight where internal mechanisms have failed for years to demonstrate verifiable and systematic remediation of vulnerabilities. Postponing action until the next act of sabotage, mass data leak, attack on an exile or cross-border incident means accepting a risk whose consequences will be borne not only by Lithuania’s residents but also by other European societies.

7. Recommendations

Consolidated Checklist of Mandatory Measures

This checklist brings together the measures needed to address the identified gaps in national security. Each item must culminate in a verifiable outcome, rather than a formal decision: established facts, clearly assigned responsibility, protection for those affected, elimination of the structural cause and independent confirmation of implementation.

7.1. Independent Oversight and Mandatory Remediation of Systemic Failures

☐ Establish an independent parliamentary commission on systemic national security failures, with access to classified materials, powers to summon officials and a duty to publish anonymised findings, deadlines and the persons responsible for remedial action.

☐ Conduct an independent European assessment of cross-border risks associated with sabotage logistics, sanctions circumvention, state information systems and transnational repression, with the involvement of competent EU mechanisms.

☐ Create a single public register of serious incidents: date of detection, responsible institutions, missed indicators, scale of harm, progress of the investigation, measures taken, implementation deadline and the outcome of an independent follow-up review.

☐ Set deadlines of 30, 90 and 180 days for critical measures; failure to meet a deadline must automatically trigger parliamentary scrutiny and individual accountability for failure to discharge official duties.

☐ Conduct a mandatory interagency review after every serious incident and verify not only that the perpetrator has been punished but also that the structural cause, secondary harm and risk of recurrence have been addressed.

☐ Introduce a protected reporting channel for employees and contractors of state authorities who report security failures, with a ban on retaliation, independent verification of reports and preservation of evidence.

7.2. Verifiability of Annual VSD and AOTD Assessments

☐ Supplement the annual threat assessment with a human security report covering UNDP’s seven dimensions: economic, food, health, environmental, personal, community and political security.

☐ Include a section on the accuracy of previous forecasts: which assessments were borne out, which were not, the reasons for errors and the changes made to the methodology.

☐ Publish performance indicators: the numbers of reports received, checks, confirmed cases, discontinued investigations, acquitted persons, overturned decisions, identified errors and actions actually prevented.

☐ Ensure parliamentary access to VSD’s and AOTD’s methodology for probabilistic assessments without disclosing operational sources, and establish independent quality checks on the data used.

☐ Consistently distinguish between a victim of foreign intelligence, a recruitment target, a person acting under coercion, an informant and a knowing agent; do not conflate these categories in reports or administrative decisions.

☐ Review public communications by security authorities for the risk of collective stigmatisation of diasporas, and assess the effects of securitisation on trust, integration and willingness to report genuine threats.

7.3. Protection of Organisations in Exile and Victims of Transnational Repression

☐ Adopt a mandatory interagency protection protocol for high-risk organisations in exile: a designated VSD contact, a secure communications channel, an urgent threat assessment, checks of devices and premises, training, witness protection and regular exercises.

☐ After every confirmed infiltration, work with the affected organisation to establish the extent of data exfiltration and secondary compromise, notify those affected and verify implementation of the plan to restore security.

☐ Conduct a retrospective assessment of the assistance provided to Our House, Dapamoga and other organisations following the Mantas Danielius case, and remedy the identified gaps in state support.

☐ Formalise the division of responsibility: an NGO must take reasonable measures to protect data and report incidents, while identifying agents, conducting operational checks and neutralising a foreign intelligence network remain the state’s responsibility.

☐ Prohibit blaming or ostracising an organisation that has fallen victim to professional intelligence infiltration without an independent analysis of its actions, available resources and the state support it received.

☐ Create a reporting mechanism for activists and applicants without the risk of an automatic deterioration in their immigration status: a report of pressure, recruitment or compromise must trigger protection and forensic assistance.

7.4. Pegasus and Commercial Spyware

☐ Establish an independent mechanism for recording and investigating the use of commercial spyware against people in Lithuania, involving the prosecution service, police, VSD and the National Cyber Security Centre.

☐ Publicly disclose, in anonymised form, what information state authorities received about Pegasus attacks on activists and journalists in Vilnius, what proceedings were opened and what protective measures were offered to those affected.

☐ Carry out technical attribution or document why it is not possible; establish the volume of extracted data, the persons affected indirectly and the consequences for organisations in exile.

☐ Establish a permanent state capacity to provide digital forensics for victims: secure receipt of devices, preservation of the chain of custody, urgent notification of high-risk contacts and assistance in restoring security.

7.5. Protection of Sources and High-Risk Civil Society Projects

☐ Conduct an independent review of the compromise of the Black Book of Belarus, Belaruski Hajun and the Peramoha plan: the chronology of warning signs, system architecture, administrative access, hacks, fake bots, loss of control and the response of Lithuanian authorities.

☐ Identify the sources exposed and the people subjected to detention, torture, criminal prosecution or other danger, and assess the timeliness of warnings, evacuation, legal assistance and digital support.

☐ For projects collecting information inside repressive states, introduce mandatory assessments of the impact on rights and security, data minimisation, segregation of access, logging, deletion deadlines, a simple procedure for withdrawing consent and external audits.

☐ Following a compromise, immediately activate an interagency team regardless of where the initial hack occurred: preserve evidence, disable compromised access, classify the exposed data and securely notify people at high risk.

☐ Make state and European funding for high-risk projects conditional on compliance with a minimum security standard and annual independent testing, including simulations of insider threats.

7.6. Quality of Migration Assessments and SIS Alerts

☐ Conduct an independent audit of decisions designating Belarusian citizens threats to national security in 2023–2025, distinguishing proven hostile activity from hypothetical risk, recruitment targets and victims of pressure.

☐ Establish how many decisions were based primarily on citizenship, compulsory military service in the distant past, previous employment in a state institution, family ties or contact with the KGB without evidence of voluntary cooperation.

☐ Compare decisions by VSD and the Migration Department with the outcomes of judicial appeals, reassessments and criminal investigations, and with threats actually prevented.

☐ Examine how many decisions resulted in SIS alerts, how many records were corrected or deleted, how quickly changes were communicated to other states and what operational value the alerts had.

☐ Establish an independent mechanism for reviewing individual threat assessments, with disclosure of the substance of the allegations to the person concerned to an extent sufficient for an effective appeal, and mandatory correction of the entire chain of national and European records after a decision is overturned.

☐ Prohibit designating a person a threat solely on the basis of general biographical characteristics without individualised information about their current behaviour, intent and capacity to cause harm.

7.7. Uniform Screening Criteria for People with Actual Risk Indicators

☐ Conduct a retrospective audit of decisions to issue and renew residence permits for Andrei Shimanovich, taking account of public information about surveillance technologies, mSpy and links to Viktor Sheiman’s family.

☐ Compare the depth of that scrutiny with the criteria applied to Belarusian protesters, former conscripts, volunteers fighting on Ukraine’s side and people with relatives in Belarus.

☐ Examine whether the same standards of proof and risk are applied to wealthy company owners, politically connected intermediaries and ordinary migrants without institutional support.

☐ Publish anonymised findings from the comparative audit, including the reasons for substantial differences between decisions and measures to eliminate discriminatory or selective practices.

7.8. Strategic Contractors and Passport Infrastructure

☐ Reconstruct the process of vetting, approving and renewing contracts with Garsų pasaulis and other suppliers that had access to passport infrastructure, security materials and Lithuanian citizens’ personal data.

☐ Establish which financial, corruption and counterintelligence indicators were available to VSD, procurement committees and state contracting authorities before the contracts were concluded, and why they did not influence the decision.

☐ Examine ownership structures, subcontractors, access to specifications, production waste, keys, equipment and technical infrastructure, as well as possible links to the Lukashenko regime.

☐ Publish an anonymised conclusion on the possible compromise of passport infrastructure and, where necessary, replace vulnerable security features without waiting for proof that an adversary has exploited them.

☐ Establish officials’ personal accountability and introduce enhanced vetting of strategic suppliers, including continuous monitoring of owners, subcontractors and corporate changes.

7.9. Humanitarian Visas, Recommendation Letters and Financial Conflicts of Interest

☐ Conduct an interagency cross-check, by individual name, of humanitarian visas and residence permits, recommendation letters from Freedom House and other intermediaries, donations to BYSOL entities, corporate links, alternative immigration statuses and documented grounds of persecution.

☐ Review the cases of Eduard Apsit’s family and comparable applications from 2020–2023: the origin of funds, financial and sanctions risks, the content of communications with the Ministry of Foreign Affairs and migration authorities, and the influence of private recommendations on state vetting.

☐ Obtain the originals of the covert recording and financial calculation, conduct audiovisual and computer forensic examinations, and check metadata, version histories, correspondence and the possible involvement of people linked to ICMPD, BYSOL and state authorities.

☐ Examine the possible conflict of interest between Andrei Rudanov’s consultancy work and Irina Rudanova’s consular work, including access to visa files, official logs and declarations of private interests.

☐ Create a secure log of external requests for exceptions to migration rules, recording the intermediary, grounds, verified sources, financial dependence and responsible official; publish anonymised statistics and the results of sample audits annually.

☐ Prohibit the use of a donation as evidence of humanitarian vulnerability, and introduce enhanced independent vetting of major donors and applicants linked to them.

☐ Where sufficient indicators exist, establish a joint investigation team through Eurojust, Europol and the financial intelligence units of the states concerned, with judicial oversight and protection of the rights of uninvolved persons.

7.10. Sanctions, Russia’s Defence Industry and Corporate Continuity

☐ Establish a continuously updated system for comparing declines in direct trade with Russia and Belarus against increases in exports and payments through intermediary states, at the level of commodity codes, companies, banks, routes and end users.

☐ Identify companies, goods and recipients linked to supplies of industrial equipment and dual-use goods to Russia’s defence industry, including scrutiny of Elfanta, Unimatic and other documented supply chains.

☐ Require exporters of higher-risk goods to verify the end user, include a prohibition on re-export to Russia and Belarus, confirm actual delivery and undergo subsequent sample checks.

☐ Publish an annual breakdown of the enforcement process: reports received, checks, investigations, exemptions, frozen assets, charges, convictions, confiscations, discontinued cases and monitoring of implementation.

☐ After the closure or bankruptcy of a higher-risk company, require checks for corporate continuity through owners, managers, employees, addresses, warehouses, licences, clients, assets and new legal entities.

☐ Examine conflicts of interest when close relatives of senior security-sector officials work for companies linked to Russia, Belarus or supply chains serving their defence industries; publish an anonymised outcome of the review.

☐ Assess restrictions on Russian and Belarusian citizens according to their demonstrated impact on sanctions-related chains, and repeal measures that create an appearance of toughness but do not affect the routes taken by goods, funds and corporate structures.

7.11. Internal Leaks and the Security of State Information Systems

☐ Adopt a single mandatory protocol for protecting sensitive information for VSD, AOTD, the Ministry of Foreign Affairs, the Ministry of the Interior, the Migration Department and other authorities, with an annual independent audit of actual implementation.

☐ Introduce an insider threat programme: minimum access privileges, separate approval for bulk data exports, multi-factor authentication, logging, anomaly detection and regular access recertification.

☐ Publish an anonymised final report on the mass extraction of data from state systems: the access route, categories of records, selection criteria, presumed recipient, secondary harm, notification of at-risk groups and a plan to mitigate the consequences.

☐ Independently assess whether the centralisation of state IT systems has created a single point of failure, an excessive concentration of administrative access and the ability to run bulk queries across several registers through one account.

☐ Conduct regular independent tests of recovery, segmentation, isolated backups and insider threat scenarios; confirm the remediation of critical findings through follow-up testing.

☐ Publish anonymised implementation indicators: multi-factor authentication coverage, detection and containment times, the number of affected persons notified, exercise results and the proportion of deficiencies remedied.

7.12. Sabotage Infrastructure and Critical Facilities

☐ Treat the IKEA arson attack, the dispatch of incendiary devices through DHL and DPD, recruitment of perpetrators through Telegram, criminal intermediaries and cryptocurrencies as possible elements of a single financing, logistics and command infrastructure.

☐ After each incident, publish an anonymised chronology, missed indicators, response times and specific changes to the work of carriers, warehouses, customs, police and counterintelligence.

☐ Establish a programme to identify one-off perpetrators based on behaviour and digital and financial infrastructure, rather than citizenship or ethnic origin.

☐ Before introducing restrictions on transactions near sensitive facilities, model the threat of reverse mapping and prevent disclosure of coordinates, zone boundaries, cadastral lists and statements of reasons that could reveal the locations of classified facilities.

☐ Screen transactions near strategic facilities on the basis of the ultimate beneficial owner, source of funds and actual user, regardless of citizenship, including legal entities, proxies, leases and other forms of control.

☐ Take account of access by notaries, registrars, estate agents, banks and valuers to information on protected zones, and establish a regime of minimum necessary access, logging and accountability for disclosure.

7.13. State Preparedness and the Resilience of Critical Infrastructure

☐ Link the composition and location of state reserves to publicly described risk scenarios, and test the practical delivery of food, water, fuel, medicines and self-contained energy sources to recipients annually.

☐ Publish the actual readiness of shelters and collective protection facilities in each municipality: effective capacity, time required to open them, ventilation, water, sanitation, backup power and accessibility for people with disabilities.

☐ Designate a single coordinator for civil resistance, allocate responsibilities among the state, municipalities and NGOs, and provide practical training for citizens, migrants, organisations in exile and people with disabilities.

☐ Conduct regular exercises involving simultaneous damage to undersea cables and other communications links; publish aggregate indicators of redundancy, failover and recovery times.

☐ Create a single state register of GNSS jamming and spoofing, assessing the impact on aviation, shipping, medical, rescue and military services, with mandatory exercises for prolonged signal loss.

☐ Publish follow-up reviews of public attribution of high-profile attacks, including alternative explanations, levels of confidence and grounds for revising the initial assessment.

7.14. Economic Resilience, Protection against Abuse and Monitoring of Outcomes

☐ Regularly assess the impact of migration and counterintelligence decisions on employment, tax revenue, labour shortages, company relocations and the resilience of the transport, construction, technology and manufacturing sectors.

☐ Compare economic harm and loss of workforce capacity with the numbers of confirmed threats, overturned decisions, false-positive assessments and actions actually prevented.

☐ Examine whether a person’s dependence on a non-public migration decision increases their vulnerability to exploitation, blackmail and recruitment, and reduces their willingness to report genuine threats to the state.

☐ Require foundations working with political prisoners and dependent aid recipients to have an independent supervisory body, an external complaints channel, a ban on retaliation, rules on data access and temporary restrictions on the powers of anyone subject to a duly justified investigation.

☐ Conduct an independent audit of BYSOL’s Lithuanian legal entity: the powers of founders and management, access to female beneficiaries’ data, implementation of the internal commission’s decisions and the transfer of powers following Andrei Stryzhak’s departure.

☐ Establish an interagency early-warning system for recurring abuses in high-risk organisations, allowing confidential or anonymous reporting, protection against retaliation and referral of information to the competent authority.

☐ For each recommendation, designate a responsible institution, a budget, a deadline, a measurable indicator and an independent reviewer; regard a measure as completed only after a documented follow-up review, rather than upon adoption of a new rule.

Sources

 

About The Author