Introduction
Europe is facing growing concerns over what governments and security officials describe as an intensifying campaign of Russian hybrid activity. The alleged operations range from cyberattacks and sabotage to drone incidents, information manipulation and interference with critical infrastructure.
French President Emmanuel Macron said on September 18, 2026, that Russia’s hybrid attacks against France and Europe were intensifying. He ordered his government to prepare measures to strengthen the protection of critical infrastructure, particularly facilities linked to national security and defence.
The warning comes amid a broader series of incidents across Europe that governments have attributed to Russia or associated actors. European officials have increasingly described these activities as part of a wider strategy designed to create disruption without necessarily triggering a conventional military confrontation.
The European Union says Russia’s hybrid activities have intensified since the full-scale invasion of Ukraine in 2022. The bloc has identified sabotage, cyberattacks, foreign information manipulation, interference with democratic processes and attacks on critical infrastructure among the activities of concern.
What Are Russian Hybrid Attacks?
The term “hybrid warfare” describes activities that combine different methods of exerting pressure on another country.
Unlike conventional warfare, hybrid operations do not necessarily involve tanks, missiles or large military formations crossing a border.
Instead, they can involve cyber operations, disinformation campaigns, sabotage, espionage, drone activity, electronic interference and other forms of disruption.
The European External Action Service says hybrid threats involve coordinated harmful activities intended to undermine a state or institution and can combine multiple methods. It lists cyberattacks, foreign information manipulation, sabotage, damage to undersea infrastructure and airspace violations among the forms of activity Europe has been dealing with.
The challenge for European governments is that individual incidents can sometimes appear unrelated.
A cyberattack against a government network may look different from damage to infrastructure or an information campaign on social media. Security agencies, however, increasingly examine whether such incidents form part of a coordinated strategy.
Macron Warns That the Threat Is Increasing
France has become one of the latest European countries to publicly warn about the changing security environment.
Macron said on September 18 that Russia’s hybrid threat toward France and Europe had intensified.
He ordered the development of a plan to strengthen protection for critical infrastructure and defence-related sites.
The French president pointed to a combination of cyber and drone-related incidents as examples of the evolving threat.
Macron also said such activities were intended to weaken European support for Ukraine.
France’s response is significant because critical infrastructure includes systems that are essential to the functioning of modern societies, including energy networks, communications, transport facilities and other strategic services.
Europe Is Seeing Multiple Forms of Disruption
European officials are not dealing with just one type of threat.
The EU says the broader pattern includes:
- Cyberattacks against government and infrastructure networks
- Sabotage of critical infrastructure
- Foreign information manipulation
- Attempts to interfere with democratic processes
- Drone and airspace incidents
- Damage involving undersea infrastructure
- Electronic interference
- Other forms of covert disruption
The EU Council says Russia and its proxies have conducted persistent hybrid campaigns against EU member states and partners.
This variety makes the threat particularly difficult to address.
Traditional military forces are designed primarily to respond to conventional attacks. Hybrid operations can instead target computer systems, public confidence, infrastructure and political institutions.
Cyberattacks Remain a Major Concern
Cybersecurity is one of the most important components of Europe’s response to the hybrid threat.
In July 2026, the European Union publicly accused Russia of maintaining a malicious cyber ecosystem involving intelligence services, cybercriminal groups, hacktivists and private companies.
The EU said Russian-linked cyber activity had targeted government networks and critical infrastructure in several European countries. It specifically mentioned France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and Finland.
According to the EU, the activities included cyber espionage and disruptive operations.
The bloc imposed restrictive measures on nine individuals and four entities connected to the activities it identified.
The EU also emphasized cooperation with NATO and the United Kingdom in responding to the threat.
Why Critical Infrastructure Is Important
Critical infrastructure is an attractive target in hybrid campaigns because modern economies depend heavily on interconnected systems.
Energy grids, telecommunications networks, transport systems, ports, airports and public-sector computer networks all play important roles in daily life.
A disruption does not necessarily have to cause physical destruction to create economic or social consequences.
For example, a major cyberattack could interrupt services or force an organisation to shut down systems temporarily.
Similarly, interference with transport infrastructure could create delays and additional costs.
European governments are therefore increasingly treating infrastructure resilience as a national security issue.
Drone Incidents Add a New Dimension
Drones have become another major concern for European security authorities.
Recent incidents involving drones near sensitive locations have raised questions about surveillance, disruption and potential sabotage.
Macron referred to an attempted drone attack at Leipzig airport in Germany in August as an example of the evolving threat, with Germany attributing the incident to Russia.
Polish Prime Minister Donald Tusk has also warned that Russia could use drones or rockets in hybrid attacks against NATO countries supporting Ukraine.
According to Tusk, intelligence from NATO, Ukraine and the United States indicated that Russia was targeting border crossings and other logistical infrastructure.
These claims are part of an increasingly tense security environment along NATO’s eastern flank.
Poland Faces Particular Security Concerns
Poland has become one of Europe’s most vocal countries regarding potential Russian threats.
Its geographical position makes it an important logistical route for assistance reaching Ukraine.
Poland also borders Ukraine and Belarus, while Russia’s Kaliningrad region lies nearby.
Tusk has warned that Russia could attempt to stage incidents that appear accidental in order to test NATO’s response and create disagreement among member states.
The Polish government has therefore been closely monitoring drone activity and other incidents near its territory.
These concerns are shared by other countries along NATO’s eastern flank, where governments have increased surveillance and air-defence preparations.
The Baltic Region Remains Highly Alert
The Baltic states are another area of particular concern.
Estonia, Latvia and Lithuania have repeatedly highlighted the risks posed by Russia because of their geography and history.
NATO says Russia’s hostile activities toward members and partners, including airspace violations, cyberattacks and sabotage, have increased in frequency.
Recent drone incidents have further increased attention on airspace security.
NATO has been adapting its approach to air and missile defence as the number of aerial threats increases.
The alliance is also strengthening its ability to respond to activities that do not fit neatly into traditional categories of military aggression.
NATO Strengthens Its Cyber Defence
NATO has publicly condemned Russian malicious cyber activity.
In July 2026, the North Atlantic Council said Russia was using a cyber ecosystem to target NATO allies and partners.
The alliance said these activities threatened Allied security and included attacks on critical national infrastructure and government entities.
NATO also said it had strengthened its cyber posture by integrating cyber effects into Alliance operations and activities.
The alliance has emphasized that cyber defence is now an essential part of modern collective security.
That reflects the changing nature of conflict, where an attack may begin in cyberspace rather than with a conventional military strike.
Information Warfare and Disinformation
Another important element of hybrid activity is information manipulation.
Social media platforms allow false or misleading narratives to spread rapidly across borders.
A successful influence campaign does not necessarily need to convince everyone of a particular claim.
It can instead attempt to create confusion, increase distrust or deepen disagreements within a society.
The EU identifies foreign information manipulation and interference as a significant component of hybrid campaigns.
It has also warned that attempts to interfere with democratic processes can undermine public confidence in institutions.
European governments are therefore increasing efforts to identify and counter coordinated information campaigns.
Why Ukraine Is Central to the Situation
The war in Ukraine remains central to the current European security environment.
European governments have provided military, economic and humanitarian support to Ukraine since Russia launched its full-scale invasion in February 2022.
Russia has repeatedly criticized Western support for Kyiv.
European officials increasingly argue that hybrid operations can be used to pressure governments and societies without directly confronting NATO forces on a conventional battlefield.
EU foreign policy chief Kaja Kallas said in September that Europe had experienced a steady increase in hybrid attacks since Russia’s full-scale invasion of Ukraine.
European governments therefore view support for Ukraine and protection against hybrid threats as closely connected security issues.
Kaja Kallas Warns of Further Provocations
Kallas has been among the European officials warning about the potential for additional Russian hybrid activity.
On September 15, she told the European Parliament that Europe had seen an increase in hybrid attacks since Russia’s full-scale invasion.
She cited several recent security incidents, including a Russian warship firing flares at a Danish helicopter and NATO aircraft shooting down a drone over Lithuania.
Earlier in September, Kallas warned that attacks could increase around Russia’s parliamentary elections.
Her comments reflected growing concern that European countries could face additional provocations during politically sensitive periods.
The Challenge of Proving Responsibility
One of the most difficult aspects of hybrid warfare is attribution.
Governments may believe that an incident is connected to a foreign state without immediately having enough evidence to publicly establish responsibility.
Attackers can use intermediaries, criminal groups, anonymous online accounts or covert operatives.
This creates a difficult balance for governments.
They must investigate carefully while also deciding when to publicly attribute an incident.
Attribution matters because governments may impose sanctions, expel diplomats or take other measures based on their assessment of responsibility.
Incorrect attribution could create diplomatic complications.
At the same time, delaying a response could allow repeated attacks to continue.
Why Hybrid Attacks Are Difficult to Deter
Traditional military deterrence often depends on the threat of a clear and proportionate response.
Hybrid operations create a more complicated problem.
A cyberattack, sabotage incident or disinformation campaign may not immediately reach the threshold associated with an armed attack.
This can make it difficult for governments to decide how strongly to respond.
European security officials have increasingly argued that repeated low-level attacks can produce significant cumulative effects.
The goal may be to create uncertainty and make governments spend resources defending against a large number of relatively small incidents.
Europe Is Building Greater Resilience
European governments are responding by investing in resilience.
This includes stronger cybersecurity, improved infrastructure protection, better intelligence-sharing and greater cooperation between civilian and military agencies.
The European Council adopted conclusions in March 2026 calling for stronger EU capabilities to prevent, deter and respond to hybrid campaigns.
The Council identified sabotage, malicious cyber activity, information manipulation, election interference and the instrumentalisation of migration among the challenges facing Europe.
The objective is not simply to stop every individual incident.
It is also to make European societies harder to disrupt.
The EU Wants Better Coordination
Hybrid threats cross national borders, which means individual countries can struggle to respond alone.
A cyber campaign may target organisations in several countries at the same time.
A disinformation operation can spread across multiple languages.
Infrastructure such as energy networks, telecommunications cables and transport routes can connect several countries.
The EU has therefore emphasized greater coordination between member states.
The bloc has also worked with NATO and other international partners to exchange information and coordinate responses.
NATO’s Eastern Flank Is Being Strengthened
NATO says it has significantly reinforced its eastern flank since Russia’s annexation of Crimea in 2014 and its full-scale invasion of Ukraine in 2022.
The alliance says Russia’s hostile activities, including cyberattacks, sabotage and airspace violations, have increased in frequency.
NATO has increased its readiness and deployed additional capabilities in eastern member states.
The alliance describes these measures as part of a broader effort to protect its members and maintain credible deterrence.
A New Security Environment for Europe
Europe’s security environment is now considerably different from the period before 2022.
Governments are no longer focusing only on traditional military threats.
They must also protect digital systems, energy networks, communication infrastructure and democratic institutions.
This creates a much wider definition of national security.
A government may need cybersecurity specialists, intelligence officers, police, military personnel and infrastructure operators to work together when responding to a single incident.
The boundaries between domestic security and international security have become increasingly blurred.
Protecting Democratic Institutions
Democratic institutions are another area of concern.
Elections can be targeted through hacking, foreign influence operations, fake online content or attempts to undermine trust in electoral systems.
The EU has specifically identified attempts to undermine democracy and electoral processes as part of the hybrid threat environment.
Protecting elections therefore involves more than securing ballot boxes.
Authorities must also protect voter information, political organisations, government systems and public communication channels.
Media literacy and public awareness can also help people recognize misleading information.
The Role of Ordinary Citizens
Although hybrid warfare is often discussed as a government-level security issue, ordinary citizens can also play a role in resilience.
People can improve their digital security by using strong passwords, enabling multi-factor authentication and keeping devices updated.
They can also verify suspicious claims before sharing them online.
Cybersecurity awareness is particularly important because attackers frequently attempt to exploit human behaviour.
A convincing phishing email or fraudulent message can provide access to systems even when an organisation has sophisticated technical defences.
Businesses Also Face Growing Risks
Private companies are increasingly part of the security picture.
Energy providers, telecommunications companies, transport operators, banks and technology firms operate infrastructure that governments and citizens depend on.
A cyberattack against a private organisation can therefore have consequences beyond the company itself.
Governments are increasingly working with businesses to improve information-sharing and incident response.
Companies are also investing in backup systems and contingency plans designed to keep essential services operating during attacks.
Could Hybrid Attacks Become More Frequent?
European officials clearly expect the threat to remain significant.
Kallas has warned of continuing Russian hybrid activity, while Macron has said the threat has intensified.
NATO has also described Russian hybrid actions as an increasing security challenge.
However, the exact scale and form of future incidents cannot be predicted with certainty.
Hybrid operations are deliberately flexible.
They can change according to political circumstances, technological developments and opportunities identified by those conducting them.
This means European governments are preparing for a range of possible scenarios rather than one specific type of attack.
Europe’s Response Will Depend on Coordination
The effectiveness of Europe’s response will depend heavily on cooperation.
Individual countries can improve their national defences, but hybrid campaigns frequently cross borders.
Information-sharing between intelligence services can help identify patterns.
Coordination between NATO and the EU can improve responses to threats affecting both military and civilian infrastructure.
Cooperation with the private sector can strengthen protection of essential networks.
The objective is to ensure that an incident in one European country does not become an opportunity for wider disruption.
France Plans Stronger Infrastructure Protection
Macron’s latest announcement reflects the growing emphasis on resilience.
France plans to strengthen protection of critical infrastructure and defence-related facilities in response to what the president described as intensified Russian hybrid activity.
The move comes as European governments increasingly treat infrastructure security as part of national defence.
Protecting physical sites, computer networks and communications systems requires different technologies and expertise.
France’s response could therefore involve closer cooperation between civilian authorities, security agencies and infrastructure operators.
The Broader European Picture
The current concerns are not limited to France or Poland.
The EU has documented Russian-linked cyber activity affecting several member states.
NATO has reported increasing hostile activities toward its members and partners.
Countries in northern and eastern Europe remain particularly alert to airspace and infrastructure incidents.
At the same time, western European governments are strengthening cybersecurity and counter-sabotage capabilities.
This suggests that hybrid security has become a continent-wide issue.
Final Thoughts
Russian hybrid attacks against Europe are becoming an increasingly important security issue in 2026.
European governments and institutions describe a broad range of activities, including cyberattacks, sabotage, information manipulation, drone incidents and interference with critical infrastructure.
French President Emmanuel Macron said on September 18 that Russia’s hybrid attacks against France and Europe had intensified and ordered preparations to strengthen the protection of critical infrastructure.
The European Union has also documented Russian malicious cyber activity targeting government networks and critical infrastructure in several member states.
NATO has responded by strengthening its cyber posture and reinforcing its eastern flank, while EU institutions are developing broader mechanisms to counter hybrid campaigns.
The central challenge is that hybrid attacks operate below or around the traditional boundaries of warfare. They can disrupt societies without necessarily producing the unmistakable signs of a conventional military conflict.
For Europe, the response therefore involves more than military strength. Cybersecurity, infrastructure protection, intelligence cooperation, public awareness and resilience are all becoming important parts of national and collective security.
As European governments continue supporting Ukraine, the issue of hybrid attacks is likely to remain a major part of the continent’s security debate. The coming months will test how effectively European countries can coordinate their responses, protect critical systems and reduce the impact of activities designed to create disruption and uncertainty.
