Testing the Threshold: Russia’s Escalating Hybrid Campaign in Europe

Russia is escalating a hybrid campaign to test the resilience of European states and the North Atlantic Treaty Organization’s (NATO) without triggering collective defense measures under Article 5. Incident data show the campaign accelerating and expanding into suspected sabotage of defense-industrial, energy, and transport infrastructure. We assess Russian hybrid activity will likely remain elevated through the winter, combined with a battlefield offensive in Ukraine. 

On September 13, a Russian drone struck a Kyiv-Warsaw train two kilometers from the Polish border. Shortly before, a train carrying former U.K. Prime Minister Boris Johnson and European security advisers crossed at the same point. Some analysts concluded Russia intended to harm the officials, while others saw the incident as a warning shot. We assess the strike’s significance does not depend on intent but rather capability, as Russia showed it can strike at NATO’s edge while senior Western figures are in transit. Four days later, Polish Prime Minister Donald Tusk, citing intelligence ⁠agencies, warned Russia is planning drone and missile attacks on Ukraine’s allies. The attacks are likely to be framed as accidents but are designed to probe NATO’s resolve.

The Sahaidachnyi Security Center’s Everywhere War Tracker recorded 182 officially attributed or pattern-consistent incidents in European countries, including joint European/NATO threats, between September 23, 2025, and September 23, 2026. The annual total accounts for more than a third of all incidents logged since 2022. 

  • August 2026 was the most active month on record, with 28 incidents, more than double the monthly average of the prior nine months. 
  • Sabotage, absent in July, accounted for around ten incidents from early August to mid-September indicating a recent escalation. Moscow commonly denies involvement, but the U.S. Office of the Director of National Intelligence identifies sabotage and military intimidation among Russia’s gray-zone tools.

Figure 1 – Russian-linked hybrid incidents in Europe by month (January 15, 2022, to September 18, 2026): The chart shows 491 incidents across European countries and joint European/NATO threats, covering all incident types, both officially attributed to Russia and fitting the pattern. (Source: Sahaidachnyi Security Center, Everywhere War Tracker)

Spillover along NATO’s borders has grown more dangerous:

  • September 15, Lithuania: NATO jets shot down an explosive-carrying drone that entered Lithuanian airspace from Belarus, the first such shootdown in the country.
  • September 14, Poland: The Polish military recovered a Russian Gerbera-2 drone off Poland’s northwestern coast; prosecutors later confirmed it carried a live warhead.
  • September 8-9, Ukraine-Moldova border: Drones struck the Starokazache crossing on the Ukrainian side, killing two civilians and forcing Moldova to close the Tudora checkpoint.
  • July 30, Poland: A Russian Kh-101 cruise missile crashed into a field about 100 kilometers from the Ukrainian border.
  • July 24-26, Romania: Romanian F-16s shot down three suspected Russian drones on three consecutive days, the first time Romania has engaged an airspace intruder.

Suspected sabotage operations have concentrated on defense suppliers linked to Ukraine. Most incidents remain unattributed, but we assess the pattern likely reflects deliberate targeting of the supply chain:

  • September 11-12, Bulgaria: An explosion and fire struck an EMCO munitions depot, the company’s second incident in just over a month. Officials did not rule out outside interference but also cited lax storage and security.
  • August 30-31, Poland: Fires hit two defense-industrial sites within 24 hours, including a drone-components plant.
  • August 25, Slovakia: Police foiled a napalm arson plot against drone maker Skyeton. A Latvian and a Ukrainian were detained in Slovakia, and a second Latvian was arrested in Hamburg.
  • August 4, Germany: Authorities found an explosive-laden drone near a Ukrainian cargo plane at Leipzig/Halle airport. Germany attributed the attack to Russia.

Suspected sabotage incidents have also targeted energy and transport industries. On September 1, attackers targeted two German power substations. On September 15, objects placed at around 30 track locations paralyzed much of the Dutch rail network. We assess the September incidents likely signal an expansion of sabotage targets beyond defense supply chains to European energy and transport networks, which will likely remain vulnerable through the winter.

  • Western intelligence sources have previously warned the Kremlin is increasingly recruiting criminal groups, as proxies, for such attacks, and research found perpetrators often receive only a few hundred euros. We assess contractors and temporary staff represent points of vulnerability for companies in the sector.

We assess winter will heighten Europe’s vulnerability. Russia’s shift toward increasing ballistic missile deployments in Ukraine supports a winter battlefield push, and we assess pressure will likely extend beyond Ukraine’s borders. Kyiv authorities are already preparing to relocate vulnerable residents during prolonged heating outages. 

  • European Union underground gas storage stood at 65.4 percent on September 1, which is more than 16 percent below the five-year average and the lowest levels recorded for this date since records began in 2011. 
  • Any attack on energy infrastructure could compound price rises across the continent. Winter storms also offer cover for “accidental” cable damage. The Congressional Research Service cited news reports of at least six suspected Baltic cable incidents in December 2025 and January 2026 alone, a threat likely to be repeated this year.

Against the backdrop of a Russian winter offensive and expanded grey zine attacks, The Financial Times, citing sources close to negotiations, reported Moscow does not plan substantive negotiations before February 2027. Russia intends to enter talks from a position of strength, hybrid attacks aim to weaken western support for Ukraine and test escalation thresholds. Organizations should assess their exposure across NATO’s eastern flank, across European energy and connectivity dependencies.

How Concentric Can Help

Concentric’s intelligence and security teams are monitoring developments and stand ready to support your organization:

  • Monitoring Online Interactions: Concentric’s Active Monitoring team tracks mentions of executives, families, facilities, and events across surface, deep, and dark web sources. 
  • Risk Consulting Services: Concentric delivers site risk assessments, residential security assessments, and strategic reporting on the evolving threat environment.
  • Executive Protection Support: Concentric provides travel risk assessments, secure ground transportation, executive protection, and route planning for travel into Ukraine and border regions. 
  • Crisis Management: Concentric helps organizations set alert thresholds, build incident response protocols, and train executives and staff to respond with clarity under pressure.
  • Protecting Personal Information: Eclipse by Concentric™ removes personally identifiable information from tracking websites, reducing the online exposure adversaries use to target executives and staff.

For more information, please reach out to Concentric’s Global Intelligence team.

Related Posts