Russia Escalating Hybrid Attacks across Europe

Since Russia’s full-scale invasion of Ukraine in February 2022, Russia has escalated its use of hybrid, asymmetric warfare across Europe, far beyond the former Soviet Union, where Russia historically focused its aggression. These tactics fall under a Russian military strategy known as New Generation Warfare (NGW). Insikt Group assesses that Russia is likely to escalate NGW tactics over the next two years, potentially culminating in a full-scale NGW campaign. Europe-based private and public sector entities are very likely at risk of physical and cyber sabotage as Russia deploys NGW tactics. Critical infrastructure entities in Europe are at high risk of being targeted, potentially resulting in data loss, physical damage to facilities, or injury or death of personnel.

Russian hybrid and sabotage activity is nothing new; asymmetric responses to perceived provocations by Russia’s adversaries date back to at least the Soviet Union, when such tactics were called “active measures.” These tactics differ from conventional, kinetic warfare. They do not involve troops moving across a country’s border or a state’s military dropping bombs on an adversary’s capital city. Instead, they are a complex kit of psychological, cyber, and physical tactics meant to achieve several key aims:

These tactics fall broadly under a strategy Russian military officials in 2013 termed “New Generation Warfare” (NGW). Insikt Group assesses that Russia started using NGW tactics in Ukraine during and after it annexed Crimea in February 2014; however, since Russia’s full-scale invasion of Ukraine in February 2022, Russia has escalated its use of these tactics across Europe, far beyond the former Soviet Union, where Russia historically focused its aggression.

The very rules of war have changed. The role of nonmilitary means of achieving political and strategic goals has grown and, in many cases, they have exceeded the power of force of weapons in their effectiveness.

Valeriy Gerasimov, Chief of the General Staff of the Russian Armed Forces
Quoted from the 2013 article in Military-Industrial Kurier, where Gerasimov laid out the New Generation Warfare strategy

A bomb disposal specialist in a heavy protective suit walking beside a tracked EOD robot on an airfield tarmac next to a runway sign.
Figure 1: On the evening of August 4, 2026, an explosive quadcopter struck the wing near the fuel tank of an Antonov An-124 cargo aircraft in Leipzig, Germany, in what we assess is the first instance in Europe of a sabotage drone carrying military-grade explosives near critical infrastructure (Source: NPR)

Russia Using Varied Tactics, from Arson to Airspace Violations

Russia has used various tactics while employing NGW tactics across Europe, from influence operations to airspace incursions to physical sabotage operations.

Influence Operations: Russia has consistently launched influence operations to manipulate public opinion across Europe, and particularly in states Moscow likely views as Kyiv’s core European supporters: the UK, France, Germany, and Poland. These operations include Doppelgänger, Operation Overload, Operation Undercut, and CopyCop. They have often involved impersonating national and pan-European media outlets to disseminate Kremlin propaganda.

Example
CopyCop Campaign Expansion (Late August 2026): The CopyCop disinformation network expanded further, continuing to impersonate localized news and fact-checking outlets across Europe — especially in France and Norway — using AI-generated text and voice clones.

Airspace Incursions: Starting in September 2025, suspected violations of NATO airspace by what are likely Russian drones or jets reached unprecedented levels. Insikt Group tracked 30 such violations between September 2025 and January 2026, compared to 23 suspected or confirmed violations between March 2022 and August 2025. The most commonly targeted countries have been Poland and Romania; however, violations have occurred outside of Russia’s historic sphere of influence, including in Germany, the UK, Denmark, and Norway.

Example
Estonian Border Incursion (September 1, 2026): Estonian defense forces tracked multiple Russian drones near the Estonian border, including one that breached southeastern Estonian airspace. Ground air defenses went on high alert, and NATO F-16 jets stationed at Estonia’s Ämari Air Base were scrambled.

Territorial Waters Violations and Undersea Cable Targeting: Russia has increasingly used violations of NATO territorial waters and targeting of undersea cables to test NATO’s resilience, collect intelligence, and keep NATO in a reactive, defensive posture.

Example
Neptun Deep Gas Field Drone Interception (August 20, 2026): Romanian authorities intercepted and destroyed an explosive-laden Russian surface maritime drone detected near the Neptun Deep offshore gas project in the Black Sea. Authorities determined the incident was meant to threaten offshore energy infrastructure and test NATO maritime response protocols.
An aerial view of a large commercial building engulfed in intense fire with thick black smoke billowing into the sky above a parking lot.
Figure 2: The Polish Government attributed a fire at the Marywilska 44 shopping center in Poland on May 12, 2024, to Russian intelligence services (Source: Reuters)

Physical Sabotage Operations: Russia-nexus individuals and entities have increasingly used physical sabotage operations to degrade critical infrastructure in NATO territory, propagate a narrative that Western states cannot protect their populations from threats, and harm NATO’s ability to collectively respond to Russian aggression. These attacks often target civilian or dual-use critical infrastructure that directly or indirectly supports either European collective defense or Europe’s material support for Ukraine.

Example
Leipzig/Halle Airport Drone Incident (August 2026): On September 1, 2026, the German government publicly blamed Russia for the alleged sabotage plot at Leipzig/Halle Airport, describing it as part of a broader pattern of hybrid activity in Europe. German police recovered drones carrying military-grade hexogen explosives designed to cause damage to cargo infrastructure. The Halle Airport is a key military and logistics hub for German military support for Ukraine.

Offensive Cyber Operations: Russian cyber activity directed at European targets has typically emphasized access-oriented operations, including attacks on internet-facing firewalls, virtual private networks (VPNs), email services, and web portals. These operations are likely intended to enable intelligence collection, operational reach, and long-term access rather than immediate disruption. Russian cyber activity has been broad in scope, targeting multiple regions and sectors.

Example
Distributed Denial-of-Service (DDoS) and Access Operations in Norway (August 30, 2026): Russia-nexus cyber threat actors launched coordinated cyberattacks against Norwegian public sector infrastructure, forcing key government portals offline. Norwegian authorities termed the campaign a targeted effort to degrade Norway’s infrastructure in retaliation for Norway’s military support for Ukraine.
Select Metrics Related to Russian Hybrid Warfare in Europe

Airspace Incursions:

  • 30 suspected violations between September 2025 and January 2026
  • 23 suspected violations between March 2022 and August 2025

Physical sabotage operations:

  • Four-fold increase between 2023 and 2024; 2025 is consistent with 2024
  • Most commonly targeted states between January 2018 and June 2025: Germany, Estonia, Latvia, Lithuania, Poland

Russia Likely to Escalate Aggression in Near-Term, Potentially into Full-Scale NGW Campaign

Insikt Group assesses that Russian hybrid warfare in Europe has thus far been largely opportunistic, despite employing increasingly aggressive tactics. Over the next two years, Russian President Vladimir Putin is likely to escalate aggression across Europe, potentially coalescing the above-described tactics into a full-scale NGW campaign.

Putin likely sees fractured European unity and inconsistent US assistance to European collective defense efforts as offering him a finite window of opportunity prior to the 2028 US Presidential election, which could result in a US President more willing to commit US military and political resources to bolstering Europe’s defensive capabilities.

In contrast to Russia’s current hybrid warfare campaign — which we assess is largely opportunistic — a full-scale NGW campaign is likely to involve more frequent incursions and violations, multiple tactics used concurrently to strain NATO resources, and escalated aggression as detailed in the chart below. Russia would still be unlikely to seek permanent damage to European critical infrastructure or mass civilian harm, as Russia likely does not want to risk invoking NATO’s Article 5 common defense clause.

Indicators of Full-Scale NGW Campaign in Europe, Implications, and Recommendations

Indicators of NGW Campaign
Implications for Public & Private Entities
Recommendations

Influence Operations

Convergence of narratives across propaganda outlets

Public Sector: Increased political polarization; reduced public trust in government

Private Sector: Brand damage if firms are named in influence operations

Ensure communication response protocols are in place

Ensure information environment monitoring is attuned to Russia-nexus narratives

Airspace Incursions

More frequent incursions that last longer and target strategic sites

Lower altitude incursions, perhaps with transponders turned off
Public Sector: Forced closure of critical infrastructure sites

Private Sector: Disruptions in business operations
Strengthen counter-measures around critical sites

Ensure joint civil-military air incident protocols are in place, including aviation alerts

Territorial Waters Violations & Targeting of Undersea Cables

More frequent violations by state-linked vessels

Non-compliance with escorts or hails
Public Sector: Intermittent communications degradation

Private Sector: Operational losses for telecommunications, finance, and other key sectors, should undersea cables be cut
Map out alternative sea routes in case primary routes are disrupted

Ensure port-state coordination and physical hardening of cable landing sites

Sabotage Operations

More frequent and aggressive operations, including arson, vandalism, use of bombs, and rail disruptions

Targeting of civilian sites, such as shopping malls or residential neighborhoods

Concurrent sabotage operations and airspace violations to maximize disruption
Public Sector: Reduced Public confidence in the government’s ability to protect critical infrastructure; emergency services could be strained if sabotage operations escalated significantly

Private Sector: Facility loss or damage; threat to worker safety; supply chain interruption
Expand insider threat and contractor vetting

Ensure physical security measures are in place, including perimeter detection, anti-drone measures, and so on.

Enhance public-private partnerships and rapid liaison channels with law enforcement and intelligence services

Offensive Cyber Operations

Campaigns targeting strategic pressure points (for example, logistics, transportation hubs, defense supply chains, and so on)

Intrusions and DDoS activity spikes during politically significant events
Public Sector: Degraded public confidence in the reliability of institutions

Private Sector: Elevated risk of disruption for key logistics, transport, rail, and aviation systems
Enforce phishing-resistant multi-factor authentication

Coordinate with the national Computer Emergency Response Team (CERT) and National Counterintelligence and Security Center (NCSC)

Infographic titled "Indicators of a Full-Scale New Generation Warfare Campaign in Europe," detailing five categories of hybrid threats—Influence Operations, Airspace Incursions, Territorial Waters Violations, Sabotage Operations, and Offensive Cyber Operations—along with their associated signals, public and private sector implications, and recommended security measures.

In February 2026, Insikt Group published an in-depth assessment of how Russia employs New Generation Warfare tactics across Europe and what escalated aggression might look like. This report includes indicators of escalated aggression and recommendations for European public and private entities.

Preparing for Russia's New Generation Warfare in Europe

About Insikt Group®

Recorded Future’s Insikt Group, the company’s threat research division, comprises analysts and security researchers with deep government, law enforcement, military, and intelligence agency experience. Its mission is to produce intelligence that reduces risk for customers, enables tangible outcomes, and prevents business disruption.