European Intelligence Agencies Warn of Imminent, Decisive Russian Action Against NATO: A Situational Analysis and Policy Recommendations
Executive Summary
Intelligence agencies from European countries including Poland, the Czech Republic, Latvia, and Sweden have warned that Russia is preparing a hybrid drone and missile attack against NATO member states, disguised as an accidental incident. This is assessed as a political calculation aimed at testing the threshold for invoking NATO's Article 5 and thereby weakening the alliance's collective defense resolve. However, threat assessments differ among intelligence agencies regarding the timing and nature of the potential attack, with Baltic security chiefs stating there is no specific evidence of an imminent assault. EAI assesses a 50% probability that the current pattern of gray-zone pressure combined with physical provocations will continue for the next 6 to 12 months. Using this as a baseline, EAI proposes common policy responses valid across optimistic, baseline, and pessimistic scenarios: securing defense procurement channels, managing logistics and infrastructure risks, and establishing robust information verification systems.
I. Situational Analysis
European Intelligence Agencies Warn of Imminent, Decisive Russian Action Against NATO: A Situational Analysis
1. Background and Developments
The Baltic states and Poland, due to their shared borders with Russia and Belarus, have been on the front lines of hybrid threats [4][6]. In Estonia, a drone crashed into the chimney of the Auvere power plant, just 2 km from the Russian border [4][6]. Since then, the Baltic states have been developing their own rapid response systems [4]. Drone incursions and sabotage of defense facilities have also occurred in countries like Germany and Slovakia [2]. An incident in Slovakia involving remote-controlled traffic cameras revealed a new layer of threat separate from physical drone incursions: supply chain vulnerabilities in existing civilian infrastructure [6].
Against this backdrop, CIA Director John Ratcliffe visited Moscow on August 25, using intelligence agency channels rather than official State Department channels [2]. His route began at Joint Base Andrews, transited through Riga, Latvia, and bypassed Russian airspace—closed since 2022—before landing at Moscow's Vnukovo Airport [2]. In Moscow, he met with Sergey Naryshkin, Director of Russia's Foreign Intelligence Service (SVR) [2]. The contact is understood to have been a warning to Russia to refrain from escalating against the three Baltic states [2]. This pattern of activating intelligence channels while physical provocations continue has led to the recent warnings from European intelligence chiefs.
2. Current Situation
In a speech to the lower house of parliament on September 17, Polish Prime Minister Donald Tusk, citing intelligence assessments, stated that Russia was planning a hybrid drone and missile attack targeting countries that support Ukraine [9][12][13]. He described the intelligence as "very consistent and convincing" [9]. Tusk noted that such an attack would be disguised as "accidental" [12]. He explained that the objective is to paralyze, or at least weaken, the resolve of NATO members to invoke the relevant article in the event of an attack on a member state [12]. He warned that even if a drone or missile were to land on the territory of an eastern flank country and cause actual destruction, Moscow's official narrative would portray it as a complete coincidence, arguing that no NATO response is necessary [11]. According to the Polish assessment, this is effectively an attempt to prove that "Article 5 is theoretical, not practical" [1].
French President Emmanuel Macron described Tusk's warning as "valid and well-founded" [1] and subsequently convened a related meeting on Friday [1]. In an interview with The Guardian, Michal Koudelka, Director of the Czech Security Information Service (BIS), mentioned increased drone activity and the possibility of a false flag operation as potential Russian actions [3]. The intelligence chiefs of the Czech Republic, Latvia, and Sweden, in separate interviews, presented various scenarios ranging from an expansion of sabotage and influence operations to the possibility of a physical attack [5]. However, Baltic security chiefs have drawn a line, stating there is no specific evidence of an imminent attack [3]. Assessments of the nature and timing of the threat diverge even among intelligence agencies [5].
3. Key Actors and Positions
As a frontline state on the eastern flank, Poland is the most active actor in sounding the alarm. By publicizing the intelligence assessment in a parliamentary address, the Tusk government aims to simultaneously rally domestic defense posture and raise awareness among NATO allies. This coincides with Poland's judgment that the war in Ukraine has entered its "most decisive phase" [8].
Intelligence agencies in the Czech Republic, Latvia, and Sweden agree on the existence of the threat but maintain cautious differences regarding its imminence and form [5]. The three Baltic states, confident in the rapid response systems they have built, have been reluctant to endorse the possibility of an imminent, full-scale attack [3]. Germany continues its practice of refraining from attributing blame to Russia in individual sabotage incidents, indicating that the threat perception gap between the eastern flank and Western European countries persists [2][6].
France is the most prominent case of a key Western European nation responding swiftly, with President Macron publicly endorsing Tusk's warning and immediately convening a meeting [1]. The United States is sending dual signals, using the CIA director's backchannel to Moscow to demand de-escalation [2]. This creates a structure where there is a time lag and contradiction between official announcements and actual actions [2]. European officials believe Russia will deny official involvement in any such provocations, adopting a strategy of disguising them as accidents [11][13].
4. Key Issues
The first issue is the timeline of the threat. While some European intelligence chiefs suggest the possibility of a test provocation within "months, not years" [1][7], the counterargument that there is no specific evidence of an imminent attack also persists [3]. The second issue is the threshold for invoking NATO's Article 5. The shared interpretation of Poland and France is that Russia's strategy is focused on testing the alliance's cohesion by evading an Article 5 invocation under the guise of an accidental incident [1][11][12]. The third issue is the asymmetry in response speed. The gap between the immediate alarms raised by eastern flank countries and the cautious reluctance of Western European nations to assign blame acts as a structural factor constraining a unified NATO response [2][6].
II. In-depth Analysis
European Intelligence Agencies Warn of Imminent, Decisive Russian Action Against NATO: An In-depth Analysis
1. Analysis of Root Causes
The recent warnings are rooted in the stalemate on the Ukrainian front. Prime Minister Tusk noted that the Kremlin's primary objective is to destroy Ukraine's economy and logistics [8]. He pointed out that a parallel objective is to weaken the alliance's resolve through attacks on NATO member states [8]. This is premised on the judgment that Russia, facing difficulties in achieving a military breakthrough on the battlefield, has shifted its focus to external pressure tactics.
The logic presented by Tusk is straightforward: even if a Russian drone or missile lands on the territory of an eastern flank country, Moscow is expected to frame it as an "accidental" incident [12][13]. The official narrative would be designed to eliminate the grounds for a NATO response, even if actual destruction occurs [11]. The purpose is to test the conditions for invoking NATO's Article 5. The Polish interpretation is that this is an attempt to prove that Article 5 is "theoretical, not practical" [1]. In essence, the core of this warning is not about a specific military operation itself, but about a political calculation designed to test whether NATO's collective defense mechanism will actually function in an ambiguous situation.
For this calculation to be viable, a precondition must exist: there must already be fissures in the attribution practices of NATO member states. Germany has maintained a cautious stance on blaming Russia for individual incidents on its territory [6]. In contrast, bordering countries like the Baltic states and Romania tend to immediately point to Russia and activate rapid response systems when incidents occur [6]. This perception gap between Western Europe and the eastern flank countries could be seen by Moscow as a fissure worth testing.
2. Structural Context
Political Structure: NATO's decision-making structure is based on consensus. The invocation of Article 5 is a political judgment, not an automatic trigger. This means that if threat perceptions differ among member states, the response itself could be delayed or neutralized. At the EU level, sanctions against Russia are also hampered by a unanimity requirement and the energy dependence of Hungary and Slovakia on Russia, causing the pace of decisions to converge on the level of the most reluctant member state [6]. These structural constraints provide an incentive for Russia to act "below the Article 5 threshold."
Security Structure: Russia's pattern of provocation consistently targets the threshold below the invocation of NATO's Article 5. A combination of drone incursions, sabotage of defense facilities, and infiltration of infrastructure supply chains has spread across Europe [2][6]. The remote-controlled traffic camera incident in Slovakia revealed a layer of vulnerability separate from physical drone incursions: the supply chain weakness of civilian infrastructure equipment itself [6]. This suggests that gray-zone pressure is not a single type of activity but is proceeding on multiple levels simultaneously.
Intelligence Channel Structure: While this pressure campaign has been underway, a separate intelligence channel has been active between the United States and Russia. The CIA director's visit to Moscow in August was conducted through intelligence channels, not official State Department ones, and is understood to have been a warning to refrain from escalating against the three Baltic states [2]. The time lag and contradictions between official diplomatic announcements and actual physical movements show that US signals to Russia are not being consolidated into a single, coherent message [2].
3. Historical Precedents and Comparative Cases
The three Baltic states have accumulated experience with hybrid threats long before this recent warning. The drone crash at Estonia's Auvere power plant occurred just 2 km west of the Russian border [4][6]. This incident prompted the Baltic states to establish their own rapid response systems [4]. This experience shows that Tusk's warning is not a sudden judgment but rather an extension of a pattern of gray-zone provocations that has built up over several years.
Recent moves by the Baltic Sea states to form a joint task force to counter hybrid threats fall within the same context [4]. However, the fact that this body has not yet finalized its organizational structure, budget, or command system shows that the Baltic states' threat perception has not yet translated into institutional response speed at the Western European level [4]. Considering Germany's practice of refraining from attributing blame to Russia in individual incidents, some assess that this task force is relatively likely to remain a consultative body for information sharing [4].
The recent statements by the intelligence chiefs of the Czech Republic, Latvia, and Sweden are also consistent with past cases. They have pointed to the possibilities of sabotage operations, influence campaigns, and false flag operations [3][5]. These are not significantly different from the types of provocations seen repeatedly across Europe since the outbreak of the war in Ukraine. What is new in the current warnings, however, is the specific mention of the timeline. The emergence of the phrase "months, not years" sets these warnings apart from previous ones, as it indicates that intelligence agencies are presenting a significantly narrowed time horizon for the threat [1][3][7].
4. Key Variables Shaping Future Developments
First, a key factor is whether the divergence in assessments among intelligence agencies will persist. Baltic security chiefs have drawn a line, stating there is no specific evidence of an imminent attack [3]. In contrast, Poland and some other intelligence chiefs emphasize the possibility of action within months [1][3]. If this assessment gap does not narrow, preparations for a unified NATO-level response could be delayed.
Second is whether the attribution practices of Western European countries, including Germany, will change. If Germany continues to maintain a cautious stance in individual incidents, the establishment of the rapid joint response system demanded by the eastern flank countries will be constrained [4][6].
Third is the consistency of U.S. signaling toward Russia. As demonstrated by the CIA Director's unofficial visit to Moscow, a discrepancy exists between Washington's official announcements and its actual course of action[2]. If European allies interpret this inconsistency as a source of uncertainty regarding U.S. security commitments, it could heighten the demand for Europe to mount its own responses to Russia’s gray-zone provocations.
Fourth is the rigidity of the EU's sanctions decision-making structure. As long as the structural constraints of the unanimity requirement and the energy dependence of Hungary and Slovakia on Russia remain unresolved, any response measures, should a provocation actually occur, are likely to converge on the level of the most reluctant member state [6].
3 credits are required from here
The body beyond the scenario analysis is available with credits.
Sign in to continue reading*This text is an AI translation of an original written in Korean. Some translations or nuances may be inaccurate.
This report is an in-depth analysis planned by an EAI researcher, grounded in sophisticated AI-assisted research, and finalized by the EAI researcher.