Russia escalates hybrid attacks on pro-Ukraine Europe

European officials say Russia is waging an intensifying hybrid campaign of sabotage, cyberattacks and drone operations against EU and NATO members that provide military and economic support to Ukraine[1][5][10][12]. Analysts at the Netherlands-based International Center for Counter-Terrorism (ICCT) estimate that Moscow has planned or carried out at least 151 hostile operations in Europe since the full-scale invasion began in 2022, largely targeting states funneling arms and aid to Kyiv[11][12]. A broader open-source tracker cited in a recent U.S. congressional report has logged nearly 500 suspected hybrid incidents across the continent, underscoring how what diplomats once called “gray-zone” activity has evolved into a persistent shadow war on European soil[1][15].

On the physical side of the campaign, investigators have linked Russian military intelligence and affiliated networks to a series of sabotage plots and attacks on infrastructure and logistics hubs[1][3][5]. Research by Germany’s DW, drawing on court files and intelligence briefings, found that between January 2022 and July 2025, 110 acts of sabotage and attempted attacks were carried out in Europe—mostly in Poland and France—by individuals with ties to Russia, with 89 successful and 21 foiled[3]. In recent months, European media and officials have reported explosives or incendiary devices planted on cargo aircraft and rail lines, including an explosives-laden drone discovered near a Ukrainian cargo plane at Leipzig/Halle airport in Germany, alongside suspected sabotage in Poland and unexplained fires and blasts at defense facilities supplying Ukraine across several countries[2][4][10]. PBS reporting highlights attempted arson near the British prime minister’s residence, firebombing of Latvian warehouses storing aid, and a foiled assassination plot against a German arms manufacturer, as well as drones crossing into NATO territory and destroying property[7].

The cyber dimension of Russia’s hybrid war mirrors this escalation, with operations aimed at both disruption and long-term access to European critical infrastructure[1][5]. A recent congressional research report cites an April 2025 cyberattack on a Norwegian dam that briefly opened floodgates, and a December 2025 campaign against 30 energy facilities in Poland, as emblematic of Moscow’s willingness to blend cyber means with physical risk to public safety[1][2]. Romanian and Bulgarian authorities have also faced waves of distributed denial-of-service (DDoS) and other disruptive attacks on election systems, government portals and infrastructure, which officials and researchers attribute to pro-Russian hacker groups acting in concert with state objectives[1]. A CSIS database, tracking major cyber incidents with losses above one million dollars, records hundreds of Russian-linked operations against European and U.S. targets, ranging from espionage intrusions and website defacements to more destructive sabotage campaigns, reinforcing concerns that the cyber front could be scaled up rapidly in a crisis[5].

Beyond direct attacks, European governments warn that Russia is using disinformation, political interference and electronic warfare to shape public opinion and strain cohesion inside the EU and NATO[1][6][13]. Think-tank analyses from Carnegie Europe and ICCT identify coordinated propaganda about energy prices, migration and alleged “war fatigue” as part of a broader influence strategy targeting electorates in countries supplying Ukraine, often amplified by state media and proxy outlets[11][12]. A report published by the Royal United Services Institute (RUSI) documents more than 200 suspected hybrid incidents between 2014 and 2024—86% since early 2022—including sabotage, disinformation and electromagnetic attacks such as GPS jamming against aviation and maritime traffic[8]. Western intelligence has also blamed Russian actors for damaging or severing critical underwater infrastructure like power cables and data links in the Baltic Sea, activity cataloged in recent congressional and NATO briefings as attempts to test how far Moscow can go below the threshold of overt war[1][8][13].

European leaders have become more public in calling out this pattern as a “hybrid war” and pledging a coordinated response, but the policy toolkit remains a work in progress[6][10][12]. Germany’s interior minister recently framed the attempted drone bombing at Leipzig/Halle airport as part of a broader sequence of hybrid actions and warned that the country should expect further attacks as it continues to support Ukraine[10]. Across the EU, governments are tightening laws on foreign interference, boosting funding for counterintelligence and critical infrastructure protection, and pressing for faster information-sharing on sabotage attempts, while NATO has expanded its hybrid warfare support to member states facing sustained pressure[1][6][12][15]. However, analysts caution that the sheer variety of tactics—from cyber intrusions and disinformation campaigns to drones launched from “shadow fleets” at sea that disrupt civil aviation and probe air defenses—makes it difficult to develop simple deterrence measures[5][9][14].

For defenders, the emerging lesson is that Russia’s campaign treats Europe’s digital networks, physical infrastructure and information space as a single battlespace, demanding an integrated security posture rather than siloed responses. Security teams at critical infrastructure operators, defense manufacturers, logistics firms and government agencies are being urged by European and U.S. experts to harden industrial control systems, improve monitoring for anomalous activity around energy sites and transport hubs, and rehearse incident response plans that assume a blend of cyber and physical triggers[1][5][8][15]. Governments and platforms are also expanding efforts to track and demote coordinated disinformation, while civil-aviation authorities and militaries invest in better drone detection and attribution capabilities[6][9][14]. As Russia’s hybrid operations grow more frequent and more brazen, officials argue that the most effective countermeasure may be rapid attribution and public exposure—making clear to citizens which attacks are part of a broader campaign against states that choose to keep supporting Ukraine[1][6][10][12].

References

  1. Russian Hybrid Warfare Activities in Europe
  2. [PDF] Russian Hybrid Warfare Activities in Europe – Congress.gov
  3. www.dw.com · en · russian-network-for-conductingRussia maintains network for hybrid warfare in Europe – dw.com
  4. Europe calls out Russia’s ‘hybrid war’ in public. But how can it make …
  5. Russia’s Shadow War Against the West
  6. Where and how Putin could expand his war in Europe beyond …
  7. European countries confront Russian sabotage and …
  8. Unnatural Disasters: The Next Front in Russia’s Hybrid War
  9. Russian drones and the shadow fleet | AP News
  10. The Russian Military Campaign Against Europe: Defining …
  11. Russia Linked to 151 Hybrid Warfare Operations in Europe …
  12. Is Russia’s alleged hybrid war on EU a genuine threat? – RTÉ
  13. Russian sabotage operations in Europe
  14. In Russia’s Long Drone Shadow
  15. Russia Escalates Hybrid Warfare Campaign Across Europe, U.S …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply