By Jim Shimabukuro (assisted by ChatGPT)
Editor
How sabotage, cyber intrusion, drones, and information campaigns pressure Ukraine’s supporters below the threshold of open war.
An airport employee found an explosive device attached to a drone in the secure cargo area of Leipzig/Halle Airport on the night of August 4. The device did not explode. A month later, Germany publicly attributed the attempted attack to Russia, citing police work, the pattern of the operation, and intelligence. Criminal proceedings were still open. Leipzig handles freight as well as Ukrainian cargo aircraft. The attack brought a weapon onto German soil near a transport hub without a Russian unit crossing a border or Moscow claiming responsibility (Saxony State Chancellery, 2026; Federal Government of Germany, 2026).
That is a vivid example of a hybrid attack: an adversary uses a mix of covert violence, cyber operations, economic leverage, deception, political interference, or military pressure to achieve a strategic result while complicating attribution and the victim’s response. The term describes a campaign and its method, rather than a lesser category of harm. A fire on a freight aircraft could kill people; a disabled railway could derail a passenger train. NATO says such campaigns blend overt and covert, military and civilian means. Their speed and reach have grown through connected infrastructure and digital networks (NATO, n.d.-a).
On September 24, Denmark’s Defence Intelligence Service warned that Russia would probably mount more frequent attacks with greater consequences in the coming months, potentially including destructive cyberattacks and sabotage that risks casualties. It separately assessed a limited military attack on a NATO neighbor as a “low but growing risk.” The service saw no sign of an impending outright invasion. NATO Secretary General Mark Rutte urged calm and continued support for Ukraine. Those positions address different questions: preparation for an escalating campaign and the present ability to defend the alliance (Danish Defence Intelligence Service [DDIS], 2026; Cook & Moulson, 2026).
An old practice with new reach
Covert action, sabotage, propaganda, proxies, and pressure on trade have accompanied wars for centuries. During the Cold War, intelligence services spread forged documents, funded intermediaries, and conducted clandestine operations. Russia’s seizure of Crimea in 2014 gave today’s label its defining European example: armed personnel without national insignia operated alongside local proxies, disinformation, and conventional forces waiting nearby. Moscow initially denied the identity of the soldiers. The later full-scale invasion of Ukraine in 2022 made clear that covert pressure and overt war can be phases of the same contest (NATO, 2014; NATO, n.d.-a).
One earlier digital warning came from Estonia in 2007. During a dispute over the relocation of a Soviet-era war memorial, waves of traffic knocked government, banking, and media websites offline. NATO described it as a major attack on the country’s electronic infrastructure and accelerated its cyber-defence work. The public record of the disruption is firm; assigning every participating computer and its political direction to a single command is much harder. This episode anticipated the attribution problem that now accompanies attacks on power systems and websites (NATO, 2007).
The newer features are practical. A recruiter can find a courier on Telegram without sending an intelligence officer across a border. A payment can travel in cryptocurrency. A parcel can cross several jurisdictions before a timer starts a fire. A small drone can carry explosives into an airport. A hacker can probe a utility from afar, while a fake institute distributes polished commentary in multiple languages. These tools lower cost, widen the pool of intermediaries, and stretch investigations across states. The Royal United Services Institute, drawing on a CSIS (Center for Strategic and International Studies) incident database, reported 34 serious arson or sabotage incidents attributed to the Russian campaign in 2024, up from 12 in 2023 and two in 2022. Those are counted cases within a defined dataset, rather than a tally of every suspicious outage or drone sighting (Redlowska et al., 2026).
The freight network becomes a target
The earlier Leipzig case shows how an operation can cross borders while hiding in ordinary commerce. Lithuanian prosecutors reported in March 2026 that four parcels containing improvised incendiary devices were dispatched from Vilnius on July 19, 2024. Two went by DHL air freight toward Britain; two traveled by DPD road freight toward Poland. One ignited at Leipzig airport on July 20 before transfer to a cargo aircraft. Another burned in a truck in Poland the following night. A third ignited at a Birmingham warehouse. The fourth failed and was seized. Investigators said they also found test parcels sent toward the United States and Canada and intercepted two similar consignments in Amsterdam (Prosecutor General’s Office of Lithuania & Lithuanian Criminal Police Bureau, 2026).
Timers were concealed in massage cushions, with additional combustible material hidden in consumer-product containers. Prosecutors say coordinators linked to Russian military intelligence divided transport, storage, activation, and payment among people who often did not know one another. Recruits from several countries, frequently vulnerable people, were approached through acquaintances and Telegram and offered cryptocurrency. A joint team from Lithuania, Poland, Germany, the Netherlands, and Britain identified 22 people; five were sent to court in Lithuania in the case described in March. Charges and investigative attribution are serious evidence, but the accused retain the presumption of innocence. The sequence also demonstrates why investigators should resist the easy inference that every perpetrator’s passport identifies the state directing the operation (Prosecutor General’s Office of Lithuania & Lithuanian Criminal Police Bureau, 2026).
In August 2026, the same airport faced the explosive-drone attempt. Saxony’s investigators said an employee discovered the drone near the southern runway in a secure freight area. Germany attributed the attempted attack to Russia on September 1, distinguishing a political intelligence judgment from an unfinished criminal case. It summoned the Russian ambassador, announced closures and restrictions, and consulted NATO and EU partners. The public account does not establish the device’s precise intended target, its operator’s identity, or a completed explosion. It does establish why civilian transport nodes tied to Ukraine’s supply system have become strategically valuable targets (Saxony State Chancellery, 2026; Federal Government of Germany, 2026).
Poland offers a second transport example. In November 2025, an explosive charge damaged a track at Mika on the Warsaw–Lublin route, while another action damaged infrastructure near Puławy. A passenger train with 475 people had to brake sharply. Prime Minister Donald Tusk said two Ukrainian citizens cooperating with Russian services were identified, and Polish prosecutors charged two suspects with sabotage on behalf of Russian intelligence; the suspects had left Poland. Tusk warned against turning the suspects’ nationality into hostility toward Ukrainian refugees. That political consequence was itself useful to Moscow: a railway operation could endanger travelers, disrupt aid, absorb police resources, and corrode support for Ukraine at once (Chancellery of the Prime Minister of Poland, 2025; National Public Prosecutor’s Office of Poland, 2025).
In September 2026, Romania’s intelligence service reported that it had prevented another suspected sabotage operation. A Russian citizen living in Romania had been watched since February, the service said, after an intermediary directed him to photograph military bases, communications centers, critical infrastructure, and Ukrainian Antonov cargo aircraft. The published account identifies reconnaissance and a prevented operation; it does not disclose a completed attack or a detailed planned device. It shows the early stage of a chain in which someone first maps vulnerable targets and transport schedules, then passes the material onward. Romania said it saw a pattern similar to operations it had interrupted in 2024 and 2025 (Romanian Intelligence Service, 2026).
The Danish assessment sees a change from earlier attacks designed chiefly to frighten the public and weaken aid to Ukraine toward operations meant to stop material support from reaching it, including defence firms and rail transport. This is its intelligence judgment, not proof that every recent mishap has that purpose. Ordinary accidents, criminal acts, and unauthorized drones still occur. Specific incidents require their own evidence (DDIS, 2026).
The digital and political fronts
A cyber operation can interrupt a service without a visible blast. In July 2026, Britain and EU states attributed a December 2025 attempt on Poland’s power grid to a unit of Russia’s Federal Security Service. Britain’s National Cyber Security Centre said that, had the attack succeeded, as many as 500,000 civilians might have lost electricity. Its joint advisory also described the unit’s scanning of poorly secured routers across critical sectors. A failed intrusion is still a warning about access and intent; the half-million figure is a counterfactual risk estimate, not a blackout that occurred (National Cyber Security Centre [NCSC], 2026a).
Other online disruption has a looser connection to the Kremlin. The NCSC reported that Russian-aligned hacktivist groups have overloaded British local-government and infrastructure websites in protest over support for Ukraine. It described these groups as ideologically motivated and outside direct state control. Their traffic floods can make essential services unavailable, but calling every such attack an intelligence-service order would exceed the evidence (NCSC, 2026b).
Moldova shows a campaign aimed at a country’s political choice. In June 2026, the EU sanctioned six people for actions it said helped destabilize the country, including Russian-funded vote-buying and disinformation around its September 2025 parliamentary election. The Council identified a paid rally staged to simulate popular backing, party operatives who encouraged bribery, and a coordinator who used church networks to influence parishioners. These were EU sanctions findings, not a claim that every opposition voter or critical argument was manufactured abroad. The mechanism was to make a domestic election vulnerable to concealed foreign financing and organized false signals of public support (Council of the European Union, 2026).
The war in Ukraine also tests this boundary. Russian missile and drone strikes inside Ukraine are direct acts of war, regardless of whether they are paired with false explanations online. Ukrainian strikes on Russian military and energy targets are part of the armed conflict as well. “Hybrid” becomes useful when it identifies the coordinated covert, political, or transnational component, especially pressure against countries supporting Ukraine. It should never soften the description of an explosive attack or make an unproven attribution sound settled.
What AI actually changes
AI has a documented role in producing and circulating influence material. An August 2026 OpenAI investigation found accounts very likely originating in Russia that used ChatGPT to write English-language posts and replies promoting a purported Israeli “expert community,” the International Burke Institute. Operators asked the model to conceal linguistic clues to their Russian origin. The site contained copied and falsely attributed academic work and a sovereignty index flattering Russia while criticizing Western states. OpenAI says the articles and index were not made with its models; the identified AI use was mainly promotion on X, Facebook, LinkedIn, Substack, and Telegram. Its observed audience was limited. This is a concrete account of cheaper multilingual distribution and identity disguise, rather than proof of mass persuasion (OpenAI, 2026).
The EU’s 2026 foreign-information report describes AI-generated posts, images, video, and voice cloning in Russian and Chinese influence operations, including campaigns that flood online spaces with material likely to be retrieved by search or AI systems. These uses can expand volume and speed and make fabricated speakers sound plausible. The evidence does not show that AI designed the Leipzig explosives, autonomously selected rail targets, or directed the people who placed incendiary parcels. Drones, timers, encrypted messaging, and cryptocurrency are technologically important here, but none is itself proof of an AI-guided attack (European External Action Service [EEAS], 2026).
AI also affects the defenders: analysts can sort reports, compare video, detect coordinated accounts, and identify unusual network behavior. These are supporting tools, subject to human verification and the possibility of false positives. The decisive question in a public attribution remains the chain from device or account to operator, coordinator, and state direction. A convincing synthetic clip cannot supply that chain.
The uncertain line between attack and war
Russia benefits when a victim must decide quickly whether an incident is an accident, a private crime, a state-directed attack, or the beginning of a military campaign. A drone can drift across a border, be jammed, or be launched intentionally. A cut undersea cable may result from a dragging anchor or deliberate sabotage. A suspected act cannot be made certain by repeating it alongside stronger cases. Germany’s Leipzig judgment illustrates political attribution based on several strands of evidence even as prosecutors continue criminal work (Federal Government of Germany, 2026).
Nor is Article 5 a rigid explosives threshold. NATO says a sufficiently grave cyber or hybrid operation may amount to an armed attack, decided case by case. An attacked ally requests or consents to collective action; each ally then decides what assistance it deems necessary, which need not be military. Article 4 allows consultations when an ally considers its security threatened. NATO invoked Article 5 after the September 11 attacks, demonstrating that an attack need not be delivered by a uniformed army. Attribution, effects, intent, and alliance judgment matter more than whether the instrument was a missile or a computer network (NATO, n.d.-b).
Denmark’s September assessment describes a possible escalation beyond covert sabotage: an isolated long-range strike on infrastructure vital to Ukraine aid, with Russia claiming that Ukrainian jamming caused the missile or drone to hit NATO territory, or an attack using Ukrainian-made drones as a false flag. It also sketches a small incursion by troops without insignia. These are scenarios in an intelligence forecast, not reported events. Denmark considers a full invasion highly unlikely at present and says it would require visible preparation. The danger of the gray area is that a state might misjudge how allies will respond to a limited strike (DDIS, 2026).
Beyond Europe and the next phase
The methods are not exclusively Russian. NATO identifies Chinese economic coercion, cyber activity, and disinformation among hybrid challenges to allied security. At sea, China’s coast guard and maritime militia have blocked and water-cannoned Philippine resupply vessels at Second Thomas Shoal, asserting control without a conventional naval battle. The geography, legal claims, and actors differ from Russia’s European sabotage. The common operational choice is to press a territorial or political claim with tools that make a military response costly and contested (NATO, n.d.-a; Asia Maritime Transparency Initiative, 2024).
The June 17, 2024 confrontation at Second Thomas Shoal puts detail behind that comparison. Chinese coast guard personnel, supported by maritime militia and naval units, surrounded and boarded a Philippine inflatable resupply boat; the researchers documented ramming, damaged equipment, and injuries. They recorded ten instances of force against resupply missions from 2021 to mid-2024, including water cannons and lasers. The vessels flew national flags and Manila publicly documented the encounters, so this was not a covert Russian-style sabotage operation. The ambiguity lay in the choice of coast-guard and militia instruments, the claim of law enforcement authority, and the calibrated force used around a mutual-defence treaty. The Philippines and China subsequently reached a provisional arrangement for resupply (Asia Maritime Transparency Initiative, 2024).
In the short term, the Danish warning points to more attempts against logistics, defence production, and critical services, alongside information campaigns intended to exploit the resulting anxiety. That forecast is credible enough to warrant preparation, but it does not identify the next target or establish that a NATO war is imminent. The longer trend depends on the course of the Ukraine war, Russia’s capacity to rebuild, and allied resilience. Cheap recruited labor and accessible drones may keep the pressure affordable; coordinated investigations, rapid repair, and public explanations can make each operation less effective (DDIS, 2026; Redlowska et al., 2026; NATO, 2026).
The hardest policy task is to respond at the right level while preserving trust in evidence. The Lithuanian parcel investigation required five national jurisdictions. Germany disclosed its Leipzig attribution while its criminal case remained open. Poland warned the public against blaming Ukrainians for alleged Russian-directed acts. These examples point to a durable answer: protect the transport and energy systems that carry aid, expose what investigators can substantiate, prosecute the people who execute attacks, and keep collective defence decisions available when effects warrant them. Hybrid campaigns depend on confusion about who acted and what happened. Accurate, timely accounts reduce that room for maneuver.
References
Asia Maritime Transparency Initiative. (2024, August 22). Shifting tactics at Second Thomas Shoal. Center for Strategic and International Studies. https://amti.csis.org/shifting-tactics-at-second-thomas-shoal/
Chancellery of the Prime Minister of Poland. (2025, November 18). PM Tusk in Parliament: Russia behind sabotage attacks in Poland. https://www.gov.pl/web/primeminister/pm-tusk-in-parliament-russia-behind-sabotage-attacks-in-poland
Cook, L., & Moulson, G. (2026, September 24). NATO chief calls for calm as intel agency warns Russia may ramp up hybrid attacks. Associated Press. https://www.chron.com/news/world/article/nato-chief-calls-for-calm-as-intel-agency-warns-22447315.php
Council of the European Union. (2026, June 15). Republic of Moldova: Council lists six individuals for actions destabilising the country. https://www.consilium.europa.eu/en/press/press-releases/2026/06/15/republic-of-moldova-council-lists-six-individuals-for-actions-destabilising-the-country/
Danish Defence Intelligence Service. (2026, September 24). Assessment of the threat from Russia. https://www.fe-ddis.dk/globalassets/fe/dokumenter/2026/trusselsvurderinger/-assessment-of-the-threat-from-russia-.pdf
European External Action Service. (2026, March). 4th EEAS report on foreign information manipulation and interference threats. https://www.eeas.europa.eu/sites/default/files/2026/documents/EEAS%204th%20Threat%20Report_web.pdf
Federal Government of Germany. (2026, September 4). Entschlossenes Vorgehen gegen hybriden Angriff [Decisive action against a hybrid attack]. https://www.bundesregierung.de/breg-de/bundesregierung/bundeskanzleramt/reaktion-angriff-leipzig-2451522
National Public Prosecutor’s Office of Poland. (2025, November 21). Czynności w śledztwie dotyczącym aktów dywersji na kolei [Actions in the investigation of railway sabotage]. https://www.gov.pl/web/prokuratura-krajowa/dywersja3
National Cyber Security Centre. (2026a, July 13). UK and allies urge critical sectors to improve defences against Russian intelligence targeting. https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting
National Cyber Security Centre. (2026b, January 19). NCSC issues warning over hacktivist groups disrupting UK organisations and online services. https://www.ncsc.gov.uk/news/ncsc-issues-warning-over-hacktivist-groups-disrupting-uk-organisations-online-services
NATO. (2007, June 14). NATO to strengthen protection against cyber attacks. https://www.nato.int/en/news-and-events/articles/news/2007/06/14/nato-to-strengthen-protection-against-cyber-attacks
NATO. (2014, September 2). NATO and Russia: A new strategic reality. https://www.nato.int/en/news-and-events/events/transcripts/2014/09/02/nato-and-russia-a-new-strategic-reality
NATO. (2026, September 17). Prepare, protect, prevail: NATO publishes baseline requirements for resilience. https://www.nato.int/en/news-and-events/articles/news/2026/09/17/prepare-protect-prevail-nato-publishes-baseline-requirements-for-resilience
NATO. (n.d.-a). Countering hybrid threats. https://www.nato.int/en/what-we-do/deterrence-and-defence/countering-hybrid-threats
NATO. (n.d.-b). Collective defence and Article 5. https://nato.int/en/what-we-do/introduction-to-nato/collective-defence-and-article-5
OpenAI. (2026, August 25). Disrupting a new covert influence campaign from Russia. https://openai.com/index/disrupting-malicious-uses-of-ai-influence-campaign-russia/
Prosecutor General’s Office of Lithuania & Lithuanian Criminal Police Bureau. (2026, March 6). Case concerning terrorist acts organised and planned in different countries referred to court. https://www.prokuraturos.lt/lt/teismui-perduota-byla-del-skirtingose-valstybese-organizuotu-ir-planuotu-ivykdyti-teroro-aktu-with-text-in-english/12174
Redlowska, K., Popyk, M., & Keatinge, T. (2026, January 14). Responding to Russian sabotage financing. Royal United Services Institute. https://www.rusi.org/explore-our-research/publications/insights-papers/responding-russian-sabotage-financing
Romanian Intelligence Service. (2026, September 8). SRI, in cooperation with national and international partners, thwarted a sabotage operation coordinated by the Russian Federation on Romanian territory. https://www.sri.ro/articole/com-10-09-2026.html
Saxony State Chancellery. (2026, August 5). Ermittlungen durch Generalstaatsanwaltschaft Dresden und LKA Sachsen nach Sprengstofffund am Flughafen Leipzig/Halle [Investigation after explosives found at Leipzig/Halle Airport]. https://medienservice.sachsen.de/medien/news/1099150
###
Filed under: Uncategorized |
































































































































































































































































































































































































































































































































































Leave a Reply