TLP:CLEAR · Disclosure is not limited.
Europe: Russian-Linked Hybrid Pressure Widens, Airspace Risk Persists
Time window: Last 1 day · Audience: General analyst · Type: Situation report · DTG: 2026-09-23 04:14Z · Overall confidence: HIGH
BLUF
Russia is very likely sustaining a broad hybrid campaign against European states supporting Ukraine, with reported activity spanning sabotage, cyber operations, arson, disinformation, explosive drones and airspace incidents. A further hazardous incident affecting NATO territory or airspace is likely within 1 to 3 months, but open Russia-NATO kinetic conflict remains very unlikely in that period.
Executive summary
The reporting cycle adds evidence of Russian-linked activity across Germany, Lithuania, Poland, Romania, Norway and the NATO eastern flank. German authorities attributed an explosive-laden drone plot at Leipzig/Halle Airport to Russia, NATO aircraft shot down a drone over Lithuania on 15 September, and officials reported suspected Russian links to sabotage, cyber operations and fires affecting defence-related sites. Information operations are also active, including AI-generated videos, Kremlin narratives on TikTok, bots and fake websites. European governments are strengthening infrastructure protection and information-defence measures, but EU sanctions policy remains politically uneven after the planned delisting of Alisher Usmanov and Mikhail Fridman alongside an extension of sanctions on about 3,000 other individuals and entities.
Change from previous assessment
Since the 22 September brief, the core assessment that Russia is sustaining a coordinated hybrid campaign remains high confidence, but the evidence base has widened. New reporting adds the Romanian offshore-platform incident, additional detail on Russian-linked information operations, corroboration from German counterintelligence, and more explicit warnings from Donald Tusk and Lithuania about attacks on energy and transport infrastructure. The near-term forecast of a hazardous NATO-territory or airspace incident remains likely but medium confidence because Finnish and Russian statements continue to argue against imminent full-scale escalation. A separate information-operations judgement has been added, while the previous election-focused judgement is not carried as a lead judgement in this update because the current reporting bears more directly on operational hybrid activity.
Key judgments
- Russia is very likely sustaining a broad hybrid campaign against European states supporting Ukraine. Reported evidence includes at least 151 Russian grey-zone incidents recorded by the US Congressional Research Service between February 2022 and March 2026, 144 suspicious drone sightings across 13 European states, a fourfold increase in sabotage operations in 2024, the German attribution of the Leipzig/Halle Airport drone plot to Russia, German investigators' assessment that professionals working for the Russian state carried out the attack, and the Bundeswehr Military Counterintelligence Service assessment that a significant share of suspected sabotage cases in Germany are linked to Russia. The evidence also includes a Kremlin-linked cyber claim against Norwegian state platforms and proxy arson against European defence plants and logistics hubs. Attribution remains unresolved for the explosive uncrewed maritime vehicle near Romania's Neptun Deep platform and the uncrewed system intercepted in Lithuanian airspace, so the campaign judgement is stronger than attribution of every individual incident. (Confidence: high · ASSESSED)
- I&W: German, Polish, Baltic or other European authorities publicly attribute a new sabotage, arson, cyber or drone incident to Russian state organs, the GRU, the FSB or Russia-linked proxies. (0-14 days)
- I&W: The Leipzig, Romanian offshore-platform and Lithuanian airspace investigations close without Russian links and no new Russian-linked case is reported across Europe. (1-3 months)
- A further hazardous Russian-linked incident affecting NATO territory or airspace is likely within 1 to 3 months, while open Russia-NATO kinetic conflict is very unlikely in the same period. Donald Tusk cited intelligence assessments warning of Russian drone or missile strikes on countries supporting Ukraine, including Poland, and NATO's military committee chair said Russia has been testing the alliance through aerospace violations and drone incidents. Recent exposure includes the 15 September drone shot down over Lithuanian airspace, a Russian-attributed Kh-101 missile crash roughly 100 kilometres inside Poland, a Russian cruise missile striking Polish farmland in late July, and a drone entering Romanian airspace on 8 September. Countervailing evidence lowers confidence in escalation severity and timing: Finnish President Alexander Stubb reported activity but no immediate military threat, assessed that Russia lacked the interest and capacity for full-scale escalation, and Sergei Lavrov denied intent to strike allied states. (Confidence: medium · ASSESSED)
- I&W: A drone or missile again enters Poland, Lithuania, Latvia, Estonia or Romania, and NATO or national authorities confirm a Russian origin or state linkage. (0-3 months)
- I&W: Thirty to ninety days pass without a new airspace or missile incident in NATO territory while Finland and other exposed states maintain assessments of no immediate military threat. (1-3 months)
- Russian actors are likely to sustain information operations designed to shape perceptions of the war, weaken support for Ukraine and amplify uncertainty around security incidents. Reported activity includes bots and fake websites, forged branding for 28 British organisations, AI-generated videos depicting Ukrainian military losses and alleged atrocities, Russian-language Kremlin narratives dominating Ukrainian-news searches on TikTok, and false stories targeting Ukrainians on Polish-language TikTok. Confidence is medium because several claims rely on political statements or single-source monitoring, the individual operators behind some TikTok content remain unidentified, and Russian direction of every item is not established. (Confidence: medium · ASSESSED)
- I&W: Independent monitoring identifies a new coordinated cluster of AI-generated videos, bots or fake websites carrying Kremlin narratives about Ukrainian casualties, alleged Ukrainian atrocities or planned attacks on Poland. (0-14 days)
- I&W: European monitoring bodies and major platforms report no new coordinated Russian-language campaign, while the current anti-Ukrainian stories on Polish-language TikTok stop recirculating. (1-3 months)
- European governments are likely to expand protective measures against Russian-linked hybrid activity, while the EU response is likely to remain politically uneven. France has announced new measures to protect critical infrastructure and defence sites, and the Carpathian 8 states established a framework for intelligence sharing, critical-infrastructure protection and civil defence. At the same time, EU ambassadors agreed to remove Alisher Usmanov and Mikhail Fridman from the sanctions list while extending sanctions on about 3,000 other individuals and entities; France and Luxembourg supported the removals, Latvia announced national sanctions, and Ukrainian officials called the decision unacceptable. Confidence is medium because several protective measures remain announcements and the sanctions reporting contains unresolved differences over the policy's legal and political status. (Confidence: medium · ASSESSED)
- I&W: France assigns the announced infrastructure protections, Carpathian 8 members activate their intelligence-sharing and civil-defence framework, and additional EU states announce national sanctions after the delistings. (1-3 months)
- I&W: No operational follow-through appears on the French or Carpathian 8 measures, while additional EU governments publicly contest or dilute the sanctions extension. (1-3 months)
Outlook & scenarios
Managed hybrid pressure without open NATO conflict (50%)
Russia sustains cyber operations, sabotage, proxy arson, disinformation and drone probes against European states supporting Ukraine. Germany, France, Poland, the Baltic states and other exposed governments strengthen protection of airports, defence sites, energy infrastructure and transport links. No incident produces a sustained NATO military response.
Hazardous NATO spillover incident (30%)
A Russian-linked drone or missile again enters or strikes territory in Poland, Lithuania, Latvia, Estonia or Romania. NATO intercepts the system or attributes the incident to Russia, prompting an alliance political crisis and additional military protection measures without an immediate wider war.
Limited diplomatic pause alongside continued hybrid activity (15%)
US, Ukrainian and Russian diplomatic contacts produce a limited halt to attacks on energy infrastructure. Ukraine remains ready for an energy ceasefire, but Russia continues lower-level cyber, information and sabotage activity while negotiations proceed.
Wider multi-domain escalation, low-probability wildcard (8%)
Russia-linked sabotage, cyberattacks, disinformation and an airspace incident occur in close succession, with an attack causing casualties at a European transport or defence site. NATO governments respond with direct military measures, creating the sharpest risk of an open Russia-NATO confrontation.
Recommendations
- Maintain a single 14-day incident matrix covering Leipzig/Halle Airport, Lithuanian airspace, Polish territory and rail infrastructure, Romanian offshore energy facilities, Baltic energy and transport sites, and Norwegian government networks.
- Separate confirmed incident reporting from attribution. Treat the precise Leipzig date, the origin of the Polish missile, and the identities behind the Romanian and Lithuanian uncrewed systems as unresolved until primary or independently corroborated reporting is available.
- Prioritise collection on links between physical incidents and digital activity. Compare timing, targets, infrastructure sectors, Russian state messaging, proxy recruitment and recurring technical signatures across sabotage, cyber, drone and maritime cases.
- Track information operations around every new security incident. Preserve examples of AI-generated videos, fake websites, bot amplification and Polish-language TikTok narratives before platforms remove or alter the content.
- Monitor implementation rather than announcements of European protective measures. Record which French, Carpathian 8, Polish, Baltic and other national measures receive funding, assigned personnel, exercises or new detection equipment.
- Assess alliance cohesion through sanctions and response decisions. Track EU follow-through on the delisting of Alisher Usmanov and Mikhail Fridman, national sanctions announced by member states, and any joint NATO response to a new airspace incident.
- Use the absence of a new NATO-territory incident over the next 30 to 90 days as a confidence check on the near-term spillover forecast, while retaining the lower-probability warning case of a coordinated multi-domain attack.
Confidence & uncertainty
Overall confidence is high for the campaign-level assessment because the pattern is supported by multiple independent sources, including the US Congressional Research Service, the International Institute for Strategic Studies, German authorities and military counterintelligence, NATO officials, European governments, major media and wire reporting. Confidence is lower for the timing of a future NATO-territory incident, attribution of individual uncrewed systems, the exact date of the Leipzig incident, and the scale of any Russian response to diplomatic or sanctions pressure.
Intelligence gaps
- [EEI 1.1 · PARTIAL] Reports, operator notifications, CCTV or satellite imagery showing unexplained physical damage or operational outages at critical infrastructure sites (power substations, gas pipelines/compressor stations, water treatment plants, railway signaling centers, major telecom exchanges). Recommended collection: satellite/imagery
- [EEI 1.2 · PARTIAL] Observed reconnaissance activity around critical sites indicative of attack planning (unauthorised drone flights, repeated surveillance visits, loitering vehicles, mapping/photography of assets). Recommended collection: open-source/media
- [EEI 1.3 · UNCOVERED] Law-enforcement or customs seizures, arrests or interdictions of persons or shipments carrying explosives, sabotage tools, specialty cutting/electrical equipment, or covert comms gear destined for/near critical infrastructure. Recommended collection: law enforcement
- [EEI 2.1 · UNCOVERED] Emergence or amplification of coordinated social-media networks (sets of accounts, pages, channels) pushing identical narratives or hashtags across multiple platforms, including bot-like activity metrics and origin IP/common management indicators. Recommended collection: social-media/OSINT
- [EEI 2.2 · UNCOVERED] Publication or internal guidance from state-run media, proxy outlets, or identified influence platforms distributing talking points, pre-scripted messaging, or translated content targeted at specific EU countries/communities. Recommended collection: open-source/media
- [EEI 2.3 · UNCOVERED] Distribution of manipulated multimedia (deepfakes), targeted phishing/whaling campaigns, or localized false narratives timed to political events (elections, protests, court rulings) with tracked reach and engagement metrics. Recommended collection: cyber/forensic
- [EEI 3.1 · UNCOVERED] Unusual financial transactions: wire transfers, crypto conversions, or payments to shell companies, NGOs or individuals exceeding typical baselines that link to known proxies or front organisations. Recommended collection: financial
- [EEI 3.2 · UNCOVERED] Travel and movement indicators for suspected operatives: repeated border crossings, chartered/irregular flights, booking patterns or mobile/location data placing identified individuals in staging areas shortly before incidents. Recommended collection: border/immigration
- [EEI 3.3 · UNCOVERED] Cargo, freight or maritime movements with discrepancies (concealed/dual-use equipment, false manifests, unusual routing) detected at ports, rail hubs or via AIS that correspond to deliveries of material used in sabotage or influence operations. Recommended collection: customs/ports
- [EEI 3.4 · UNCOVERED] Intercepted or otherwise-obtained communications showing tasking, coordination, or payment instructions between Russian agencies/handlers and proxy groups, including identified command-and-control servers or encrypted group identifiers. Recommended collection: signals-intel/SIGINT
Cited sources
[1] European External Action Service (EEAS) · Statement by High Representative/Vice-President Kaja Kallas to the European Parliament for the Joint Debate on Russia’s hybrid attacks against Member States: strengthening the EU’s coordinated response and protecting European security and democracy (A) · sha256:25dc96ab926e [2] Atalayar · Dark Times Ahead for Europe (D) · Tue Sep 22 2026 07:30:00 GMT+0000 (Coordinated Universal Time) · sha256:339c2ae90c92 [3] Citizen Digital · Europe braces for Russian escalation beyond Ukraine (B) · Wed Sep 23 2026 00:12:00 GMT+0000 (Coordinated Universal Time) · sha256:cb2a1d371f96 [4] LIGA.net · The President of Finland warned Europe against an "overreaction" to Russian threats and acts of sabotage (B) · Tue Sep 22 2026 08:44:32 GMT+0000 (Coordinated Universal Time) · sha256:d864aa98f1ca [5] Atlantic Council · Russia is trying to bully Europe into abandoning Ukraine (C) · Thu Sep 03 2026 20:27:49 GMT+0000 (Coordinated Universal Time) · sha256:626bd515295e [6] zn.ua (Дзеркало тижня / Mirror Weekly) · СМИ: в Германии разбился истребитель F-16 ВВС США недалеко от авиабазы Шпангдалем (B) · sha256:62e985660ab8 [7] EUobserver · What JK Rowling’s Voldemort can teach us about Ukraine war (B) · Tue Sep 22 2026 09:39:41 GMT+0000 (Coordinated Universal Time) · sha256:797e16ea9771 [8] The Canadian Press (republished by Barrie 360) · Ottawa taking cautious approach to possible Russian hybrid threats (A) · Tue Sep 22 2026 22:45:27 GMT+0000 (Coordinated Universal Time) · sha256:faad6ed15ba8 [9] Fox News Digital · Battle-tested Zelenskyy sounds chilling alarm on where Putin’s war could head next (B) · Tue Sep 22 2026 22:11:03 GMT+0000 (Coordinated Universal Time) · sha256:f8b7358d8e2a [10] BBC · UK to fight Russian disinformation and push new global AI standards, Burnham says (A) · Wed Sep 23 2026 01:08:40 GMT+0000 (Coordinated Universal Time) · sha256:cf24b8bc2951 [11] The Ukrainian Week · TikTok’s AI disinformation machine: new front in the information war - The Ukrainian Week (B) · sha256:bf1a7540a619 [12] UK Government (gov.uk) · PM meeting with President of the European Commission Ursula von der Leyen: 22 September 2026 (A) · Wed Sep 23 2026 00:35:41 GMT+0000 (Coordinated Universal Time) · sha256:2f157bf59c60 [13] United24 Media · Ukraine's New “Carpathian 8” Links Eight Nations, 126 Million People, and €40 Billion in Projects (B) · Tue Sep 22 2026 11:23:21 GMT+0000 (Coordinated Universal Time) · sha256:588150cbcf5a [14] BBC · Ukraine anger as EU removes Russian oligarchs from sanctions list (A) · Tue Sep 22 2026 19:06:06 GMT+0000 (Coordinated Universal Time) · sha256:6ab5d854b62d [15] n-tv.de · +++ 05:33 Angriff auf Region Cherson: Vier Mönche verletzt, einer tot +++ (B) · Tue Sep 22 2026 22:01:00 GMT+0000 (Coordinated Universal Time) · sha256:d5062be483cd
Source content hashes were computed at collection time; the cited text is preserved unmodified for the life of this product.
TLP:CLEAR