Russia's Escalating Hybrid Attacks Against Europe: Strategic Intent and Countermeasures
Executive Summary
Unable to secure a military breakthrough on the Ukrainian front, Russia is expanding the theater of conflict by applying grey-zone pressure targeting the European rear. Incidents such as the drone discovery at Leipzig Airport, the fire at a Starlink base station in Poland, and drone threats originating from the Mediterranean are individually below the threshold for invoking NATO's Article 5. However, they are designed to cumulatively and substantially drive up Europe's security costs. The EU's unanimity requirement for sanctions, Hungary and Slovakia's dependence on Rosatom, and Germany's delayed attribution of responsibility serve as valuable data points for Russia to test the limits of Europe's response. With peace negotiations currently deadlocked, a baseline scenario of a gradual increase in sporadic pressure is highly likely. Consequently, accumulating actionable measures at the level of individual member states and the NATO Secretariat is a more realistic alternative than establishing a unified European response standard. South Korean companies should manage their exposure in air cargo and energy logistics bound for Europe, while simultaneously exploring opportunities to enter Europe's expanding procurement markets for air defense and drone detection.
I. Analysis of the Current Situation
Russia's Escalating Hybrid Attacks Against Europe: Analysis of the Current Situation
1. Background and Developments
Germany's Leipzig/Halle Airport is a key hub for European air cargo logistics [6]. It is known as a frequent takeoff and landing site for transport aircraft carrying military supplies and materials bound for Ukraine [2][6]. On the night of August 4, a drone carrying explosives was discovered near the airport's cargo area [2][6]. The explosive device consisted of 600 grams of Semtex explosive packed inside a vegetable soup can [3], possessing enough explosive power to destroy everything within a 10-meter radius [3].
Around the same time, a cargo aircraft sustained minor damage after colliding with an unidentified flying object [2][6]. The drone was discovered in a secure area near cargo planes bound for Ukraine [2][8]. Immediately following the incident, the airport completely suspended night operations [2][8]. Although Russia's involvement was suspected from the beginning, the German government did not immediately attribute the attack [6], hesitating due to potential diplomatic repercussions [2][6]. It was not until September 1, a month after the incident, that Berlin officially named Russia as the perpetrator [6]. Symbolic diplomatic measures followed, such as the closure of a Russian consulate general [6]. However, these did not include substantive actions to sever economic ties with Russia [6].
The response trajectory of the Baltic states differs significantly from that of Western Europe. Due to their geographical proximity to Russia, they have been the first and most frequently exposed to hybrid threats [4]. In Estonia, a drone crashed into the chimney of the Auvere power plant, located 2 kilometers west of the Russian border, in late March [4]. Through such incidents, the Baltic states have accumulated rapid response capabilities [4]. The Swiss newspaper Neue Zürcher Zeitung (NZZ) points out that this gap in accumulated experience leads to a divergence in threat perception between Western Europe and the Baltic states [4][10].
2. Current Situation
In Poland, a fire broke out at a base station for the Starlink satellite communication system [9][12]. Krzysztof Gawkowski, Poland's Minister of Digital Affairs, defined the incident as "sabotage" [12]. He stated that the fire disrupted internet access for several organizations, including the Ukrainian military [12]. Previously, Prime Minister Donald Tusk had warned of Moscow's potential for hybrid warfare [12].
In the Mediterranean, the threat of ship-launched drone attacks has emerged as a new dimension. The U.S. Central Intelligence Agency (CIA) warned that Russia is preparing drone attacks targeting Europe, using vessels in the Mediterranean as launch platforms [17]. The Spanish newspaper El Mundo reported that Spain, France, and Italy are the targets of this warning [15]. Brussels also confirmed its awareness that hybrid attacks are actively underway on its territory [15]. France initiated a plan to protect critical infrastructure one day before an emergency summit chaired by President Emmanuel Macron [15].
On September 24, the Danish Defence Intelligence Service (DDIS) assessed that Russia is highly likely to intensify its hybrid campaign against NATO and the West in the coming months [8][16]. This assessment is based on the judgment that Russia is increasingly willing to take risks as the security situation in Ukraine deteriorates [8]. The same report stated that there is a "low but growing risk" of Russia launching a limited military attack against a NATO member state within months [16]. Mentioned scenarios include long-range strikes on infrastructure supporting Ukraine or limited incursions into neighboring countries [16].
German Foreign Minister Johann Wadephul stated at a UN Security Council meeting that Russia's hybrid attacks have "reached a new level" [7]. This statement reaffirmed that the German government had already attributed the Leipzig Airport drone incident to Russia [7].
3. Key Actors and Positions
The German Governmentis maintaining a cautious balance between attributing responsibility to Russia and taking substantive measures against it. While it took the symbolic step of closing a consulate general, it ruled out substantive responses such as severing economic relations [6]. This suggests that managing diplomatic repercussions remains its priority.
The Polish Governmentmaintains a swift and explicit response posture, immediately defining the Starlink base station fire as sabotage [9][12]. Prime Minister Tusk's prior warning demonstrates that the Polish government treats the Russian threat as a constant security agenda item [12].
The Baltic Statesare the parties that have felt the threat most directly due to their geographical proximity. By developing rapid response systems, they have accumulated response experience ahead of Western Europe [4]. However, NZZ reports that the Baltic states paradoxically urge calm in response to Western Europe's alarmism [10].
The Danish Intelligence Service (DDIS)has presented Russia's increasing risk-taking propensity as an official assessment, urging the strengthening of NATO's alert posture [8][16].
The French Governmentconvened a summit led by President Macron and preemptively activated plans to protect critical infrastructure and defense facilities [9][15]. As France, along with Spain and Italy, was identified as a direct target of the CIA warning, it appears to be accelerating its response [15].
U.S. Intelligence (CIA)is playing a role in preemptively warning European counterparts about the possibility of ship-launched drone attacks in the Mediterranean [17]. The speed of assessment by U.S. intelligence, which raised the possibility of Russian involvement ahead of the German government, contrasts with the pace of political response within Europe [2].
Ukraineviews the expansion of these hybrid attacks in the same context as the escalating attacks on its own internet infrastructure. President Zelenskyy stated that Russia has expanded its targets to include Ukrainian data centers [11][14]. Attacks on data centers and internet service providers in the Kyiv region caused service disruptions for approximately 100,000 households [14].
Russiaofficially denies any involvement behind these incidents [11]. Foreign Minister Lavrov has adopted an offensive posture, counter-arguing that Europe is "fueling the war" [7].
4. Key Issues
The first issue is the political time lag in attributing responsibility. There was a one-month gap between the assessment of U.S. intelligence and the official attribution by the German government [2][6]. Critics argue that this delay fails to keep pace with the rapid normalization of physical threats [2].
The second issue is the structural characteristic of pressure applied below the threshold of invoking NATO's Article 5. It was confirmed that even the Leipzig incident did not reach the level required to trigger collective defense [6]. European security commentaries repeatedly observe that Russia is carefully calculating this threshold to calibrate the intensity of its provocations [13].
The third issue is the gap in response speed and perception among member states. The immediate responses of frontline states like the Baltic nations and Romania contrast sharply with the cautious approach of Germany and Western Europe [4]. This divergence is identified as a factor that complicates the establishment of a unified European red line.
The fourth issue is the diversification of targets. Attack vectors are no longer confined to a single type but are spreading across aviation infrastructure (Leipzig), satellite communications (Poland's Starlink), maritime routes (the Mediterranean), and power infrastructure (Estonia) [2][4][12][17]. This trend forces European nations to seek integrated defense systems rather than relying on individual infrastructure-level protections.
II. In-Depth Analysis of the Issue
Russia's Escalating Hybrid Attacks Against Europe: In-Depth Analysis of the Issue
1. Analysis of Root Causes
Russia's grey-zone pressure is directly linked to its military disadvantage on the Ukrainian front [4]. The stalemate in the ground war, where Russia has failed to secure a decisive breakthrough, has become prolonged. An NZZ opinion piece analyzes that Putin decided to escalate the war after failing to subdue Ukraine on the ground or force Ukrainians to surrender through drone and missile strikes [13]. This calculation aims to offset the lack of battlefield success by disrupting the rear.
The target of this calculation is not Ukraine itself, but the cohesion of Europe in supporting Ukraine. Leipzig Airport became a target because it serves as a critical transit hub for transporting military supplies to Ukraine [2][6]. The fire at the Starlink base station in Poland also directly targeted the communication network of the Ukrainian military [12]. Russia's objective is not to occupy European territory, but to continuously drive up the political and physical costs for Europe to support Ukraine.
At the same time, Russia is testing the threshold for invoking NATO's collective defense. The Danish Defence Intelligence Service assessed that Russia is increasingly willing to take risks as the security situation in Ukraine deteriorates [8]. This implies that Russia is measuring how far it can push provocations below the threshold of triggering NATO's Article 5. The case of Germany officially attributing the incident only a month after its occurrence, with measures limited to closing a consulate general [6], serves as useful data for Russia, effectively confirming the limits of Western Europe's response speed and intensity.
2. Structural Context
Political Structure: Unanimity Constraints and Divergent Stances Among Member States
EU sanctions against Russia require unanimous approval. Hungary and Slovakia remain dependent on the Russian state-owned nuclear energy corporation, Rosatom, for their energy needs [4][6]. This structure pulls the level of EU-wide response down to the lowest common denominator of the most reluctant member states [6]. NATO also limited its response to the Leipzig incident to reaffirming its commitment to defend member states, confirming the assessment that it did not reach the threshold for invoking collective defense [6]. This institutional vacuum is precisely what Russia exploits. While each individual incident is designed with an intensity too ambiguous to be classified as an act of war, their cumulative effect substantially drives up security costs across Europe.
Geographical Structure: The Threat Perception Gap Between the Baltic/Eastern Front and Western Europe
Frontline states, such as the Baltic nations and Romania, respond with immediate attribution to Russia and rapid response systems [4]. Conversely, Western European countries like Germany tend to hesitate in attributing responsibility due to concerns over diplomatic repercussions [2][6]. This gap stems from differences in experience shaped by geographical proximity. As seen in the drone crash at Estonia's Auvere power plant [4], the Baltic states have accumulated response manuals by handling similar incidents for years. Western Europe, having not undergone this learning curve, is suddenly facing a sharp increase in threats.
Dual Vulnerability of Security and Economic Infrastructure
The infrastructures targeted in this phase share the common characteristic of being civilian and commercial rather than military. These include air cargo (Leipzig), satellite communications (Poland's Starlink), traffic cameras (the Slovakian case, Report No. 4), and power plants (Estonia) [2][4][12]. Most of these infrastructures were not designed to be military-grade protected assets. With weak physical defense systems, they are left highly vulnerable to sabotage. France's initiation of a critical infrastructure protection plan [15] is a belated measure to fill this structural gap.
3. Historical Precedents and Comparative Analysis of Similar Cases
Continuity with Cold War Grey-Zone Operations
During the Soviet era, the KGB's "active measures" focused primarily on propaganda, the dissemination of forged documents, and political subversion. Today's Russian hybrid attacks represent an expanded version that integrates physical sabotage and cyber infiltration. However, they differ from the Cold War era in the nature of their targets. While Cold War operations targeted the political discourse, current attacks directly destroy or paralyze physical entities, such as air cargo, communication networks, and energy infrastructure.
Similarities with the Pre-Escalation Phase of the Ukrainian Front (2014–2022)
Around the time of the 2014 annexation of Crimea, Russia deployed forces with ambiguous attribution, such as the "little green men," in eastern Ukraine, expanding its de facto control while officially denying involvement. The drone and sabotage attacks occurring in mainland Europe today share a similar structure of deniability. While U.S. intelligence points to Russian government involvement [2], the German government withheld public attribution until it secured definitive proof [6]. This time lag itself yields strategic benefits for Russia.
The 2007 Cyberattacks on Estonia in the Baltic States
The large-scale cyberattacks targeting Estonia in 2007 are considered the first case to expose NATO's lack of clear response principles amid debates over state sponsorship. Although NATO subsequently established the Cooperative Cyber Defence Centre of Excellence (CCDCOE) in Tallinn, a corresponding organization for physical sabotage had not been set up prior to the current crisis. The ongoing discussions regarding "red lines"[1] can be seen as a belated attempt to fill the institutional gap that has remained unresolved since 2007.
4. Key Variables Shaping Future Developments
Level of Substantive Measures Following Germany's Attribution
Although Germany officially attributed the attack to Russia, it did not take substantive measures such as severing economic ties with Russia[6]. In the event of similar future incidents, whether Germany shifts beyond symbolic gestures to substantive responses will be a key variable shaping the overall response posture of Western Europe.
Possibility of Bypassing the EU's Unanimity Requirement for Sanctions
As long as Hungary and Slovakia's dependence on Rosatom[4][6] persists, tough EU-wide sanctions are structurally blocked. The key is whether individual state responses via a "coalition of the willing" that bypasses this requirement will expand.
Whether Warnings of Drone Attacks in the Mediterranean Materialize
If the vessel-launched drone attacks in the Mediterranean warned of by the CIA[17] actually occur, it would mean that the geographical scope of the threat has expanded from the Baltic and Eastern Europe to Southern Europe. Whether Spain, France, and Italy become actual targets will be a watershed for the next phase[15].
Explicit Redefinition of the Threshold for Invoking NATO's Collective Defense
If the "low but growing" risk of limited military attacks warned of by Danish intelligence[16] materializes, whether NATO redefines the conditions for invoking Article 5 to encompass hybrid attacks will determine the future effectiveness of its deterrence. Thus far, responses have remained limited to reaffirming member states' resolve to defend themselves[6].
3 credits are required from here
The body beyond the scenario analysis is available with credits.
Sign in to continue reading*This text is an AI translation of an original written in Korean. Some translations or nuances may be inaccurate.
This report is an in-depth analysis planned by an EAI researcher, grounded in sophisticated AI-assisted research, and finalized by the EAI researcher.