The “Russian hybrid war” narrative: a new NATO strategy of tension?
Does the evidence support the narrative? Or does it rather point to a “hybrid war” — a campaign of psychological warfare — being waged by the EU-NATO establishment itself, against its own population?
Lately, not a day goes by in Europe without some drone scare, fire or blackout being blamed on Russia. We are told that these incidents are all part of a relentless “hybrid war” that Russia is waging against Europe — one that involves drone incursions, airspace violations, sabotage, arson, cyberattacks and more. We are told this “includes plots to place incendiary devices aboard DHL cargo planes, blow up railroad tracks in Poland, and burn down warehouses and shopping centers all over Europe”, as well as “acts of sabotage against defense companies and the defense industry in Europe”, and “attacks on European critical infrastructure” — but also, apparently, sending secret agents to defecate in the lavatories of Finnish MPs. We are also told that “[s]uch attacks began occurring shortly after Russia launched its full-scale invasion of Ukraine in 2022”, and have escalated in recent months and weeks. According to Kaja Kallas, “Europe faces a fast-proliferation of sabotage attacks and airspace violations”.
Tensions escalated dramatically last month after Germany formally attributed an attempted explosive-drone attack at Leipzig/Halle Airport to Russia, with subsequent investigations reportedly tracing the operation back to Russian military intelligence. This raised the stakes considerably: it was one of the most serious incidents on German soil ever officially pinned on Moscow by Berlin — albeit a “failed” one. German foreign minister Johann Wadephul said the attack “fits into a broader pattern of Russian hybrid operations in Europe”.
Within hours, EU-NATO leaders across multiple capitals had not only accepted the attribution but agreed on what the incident meant: a piece of a coordinated campaign, with a known motive, requiring a predetermined response, i.e., sanctions and more Ukraine support. “The evidence is clear”, said NATO Secretary General Mark Rutte, on the same day as the German government’s announcement — though at that point the Germans hadn’t yet shared any evidence, either with the public or, it would appear, with other EU-NATO governments. French President Emmanuel Macron also said that the attack was clear evidence that “the Russian hybrid threat against Europeans... has intensified”. Polish Foreign Minister Radosław Sikorski warned that Russia’s confrontation with Europe was becoming increasingly “kinetic”, adding that “Russia is at war with Europe”. “This is the new normal”, said European Commission President Ursula von der Leyen. Seemingly confirming this, just a few weeks later, on September 29, the Estonian government officially accused Russian special services of commissioning an arson attack on the building of the Estonian defence company Milrem — another serious step up from the previous pattern of alleged but unofficial attributions to Russia.
Warnings of worse to come
Meanwhile, we are also constantly told that Russia intends to escalate even further — i.e., that we should brace for much more serious attacks against Europe, possibly just around the corner. Within the space of a few days, it was reported that “European intelligence officials have raised the possibility of an imminent Russian test of NATO, with one saying a potential attack could come in a matter of ‘months, not years’”; that, according to the FBI, “Russia is plotting targeted assassinations across the US and in European countries”; and that there exists a CIA report warning Italy, France and Spain about a potential Russian operation involving drone attacks launched from merchant ships in the Mediterranean Sea, or so the journalist who published the “scoop” in El Mundo claimed to have been told by an anonymous source close to the Lithuanian Ministry of Defense.
The article received massive global coverage — yet, in less than 24 hours, both Italian Defense Minister Guido Crosetto and Macron firmly denied receiving any such warning and dismissed the claims as groundless, suggesting that the story was concocted either by the “anonymous source” or by the journalist himself. The episode also shows that such claims, especially when presented with no supporting evidence whatsoever, need to be treated with extreme caution — particularly when they rest on shaky logic to begin with. In this case, for example, one may reasonably wonder what interest Russia would have in attacking Spain and Italy, two of the least enthusiastic supporters of the forever war Ukraine.

Authoritative chart showing Russian hybrid attacks on the EU—all FAKE. Note they even include the notorious Skripal case, a high-handed false flag carried out by MI6/CIA resulting in the possible death of the Skripals, about whom nothing is known to date, after they disappeared in the hands of British intelligence. Images like this, though, increase the credibility of the West's unrelenting lies, a very old campaign of disinformation against Russia.
But there have been even more bizarre claims. In recent weeks, there has been coordinated messaging across NATO that Russia could be preparing a “false flag attack... in the next few months” — i.e., a drone or missile strike that Russia would then claim was an “accident” or even try to blame on Ukraine. But how would Russia benefit from either of these scenarios? They have both occurred already — there have been several instances of stray Russian and Ukrainian drones entering NATO airspace near the border with Ukraine (see below) — and the only effect has been to harden NATO’s stance. Moreover, if Russia were aiming for plausible deniability, why did it allegedly leave its fingerprints all over the attempted drone attack in Leipzig/Halle? And how do these claims square with the opposite claim that Russia may launch an open attack against a NATO country “within months”, as Danish intelligence recently said? Which one is it? But we are not expected to ask questions or point out inconsistencies in the story; we are simply expected to believe what our media and governments tell us.
Is Russia about to attack? Even NATO isn’t sure
Of course, none of us has any way of knowing what Russia is planning to do, especially given that this is a dynamic situation in which Russia’s actions are influenced by NATO’s actions and vice versa. Russian President Vladimir Putin, for his part, denies all allegations, and has repeatedly stated — most recently on September 19 — that Russia has “no aggressive intentions towards Europe or European countries” and is ready to restore relations and cooperate with its European neighbours — while at the same time accusing European leaders of using the alleged Russian threat to justify their own policies and seek an escalation with Moscow. Of course, one may argue that if Russia were poised to attack, it wouldn’t tell Europeans in advance, and so its words shouldn’t be taken at face value.

The appointment of notorious Russophobes, like Kaja Kallas, an Estonian political operative, to Vice President of the EU European Commission, guarantees that the tensions with Moscow will not abate. These are all calculated moves by the Western ruling class dominated by the US.
This is true, of course. At the same time, insofar as most states are rational actors that tend to think and act strategically — and Russia certainly fits the description — one may ask what rational or strategic interest Russia would have in launching an attack on Europe that could easily lead to an all-out NATO-Russia war, especially since Russia’s refusal so far to retaliate in kind to NATO-enabled Ukrainian attacks on its territory, including against civilians, has likely been motivated precisely by a desire to avoid such an outcome. Interestingly enough, such scepticism is shared even by some voices within the NATO establishment.
Estonia’s foreign intelligence service, for example, wrote in its 2026 Annual Report, published in February: “There is... no cause for panic. In the Estonian Foreign Intelligence Service’s assessment, Russia has no intention of militarily attacking Estonia or any other NATO member state in the coming year. We are likely to reach a similar assessment next year”. Even Finnish President Alexander Stubb, otherwise very hawkish on Russia, has pushed back against warnings from fellow European leaders that Russia could attack NATO in the near future, saying Helsinki’s intelligence sees no evidence of an imminent military threat. “We don’t see the evidence of that”, Stubb said. “In our intelligence we see that there is activity but no imminent military threat right now”. Indeed, as reported by Politico, even NATO’s official assessment remains that there is no imminent threat: “At this time, we see no imminent threat of attack”, said a NATO official speaking on behalf of the organisation. On September 29, at a joint NATO press conference, Lithuanian PM Mindaugas Sinkevičius stated that he asked Mark Rutte for real intelligence evidence of Russia preparing an imminent attack, receiving confirmation that none exists. “I asked [Rutte] is there proof, real proof, that Russia is planning something? But there is actually nothing”, he said.
This shows that even NATO’s own assessments are highly contradictory. In terms of public sentiment, however, it makes little difference, since the imminent-attack claims far outweigh the more cautious assessments, which generally receive hardly any coverage. In any case, in the absence of evidence pointing in one direction or the other, speculations about future scenarios ultimately remain just that: speculations — especially considering that we have to assume that Russia’s posture isn’t fixed but is inevitably influenced by NATO’s actions. What we can assess with some certainty is what Russia has been engaged in so far — which in turn provides us with the best possible insight as to what it might do next. The question that needs to be asked is thus: does the evidence support Western claims that Russia is engaged in a “hybrid war” against Europe?
The “hybrid war” reports — and its inconsistencies
There are several databases and reports that purport to quantify Russian hybrid warfare, which are often cited as proof of a coordinated, escalating Russian campaign. These include datasets and reports by the European Repository of Cyber Incidents, which is strictly focused on cyber attacks, Leiden University, the Soufan Center, Associated Press, the US-based think tank Center for Strategic and International Studies (CSIS), the UK-based International Institute for Strategic Studies (IISS) and the Bratislava-based think tank GLOBSEC. Taken individually and at face value, each of these reports paints an apparently damning picture comprising dozens — and in some cases hundreds — of alleged sabotages, attacks and influence operations spanning several European countries over many years. Worrying indeed. Read side by side and in detail, however, they tell a very different story: the numbers diverge wildly; the central concept is undefined; attribution often rests on nothing more than press reports of official suspicion; and the reports’ own caveats — buried in footnotes, appendices and methodology sections — often undercut the claims made in their executive summaries.
For starters, the numbers don’t add up. Depending on which report you read, Russia carried out somewhere between 52 and 255 hybrid attacks in Europe after February 2022 — a fivefold spread for what is supposedly the same campaign. The Soufan Center, covering just six countries — two of them, Moldova and Georgia, outside the EU — records more incidents for 2025 alone than CSIS does for three years across the whole continent. The numbers diverge because there is no agreed answer to the most basic question: what is a hybrid attack? The IISS paper itself concedes that hybrid warfare is “an amorphous term” with wide variation in definitions. Some reports limit themselves to physical attacks and plots, and even then these range from arson to placing pro-Kremlin stickers, vandalism and spraying graffiti; others include “influence operations” such as monthly peace demonstrations in Amsterdam; and others even include Russian naval passages through the English Channel. Ultimately the term can be used to include almost anything. The biggest difference in numbers is determined by the treatment of (alleged) drone sightings attributed to Russia — numbering in the hundreds but in most cases eventually debunked (see below) — and hence excluded by most reports, despite receiving huge media coverage and being one of the largest contributors to the “hybrid war” hysteria.
Moreover, in most cases, the evidence linking Russia is very weak — or non-existent. Across these reports, the evidence that Russia was behind a given incident usually consists of a news article reporting that officials suspect it. There is no independent verification: if a government says “Russia did it”, it goes on the list — even in the absence of any evidence. Moreover, the Leiden dataset includes incidents that were linked to Russia by officials or politicians, or uncovered by journalistic investigations — but also those that merely “appeared to fit in a pattern” of similar events. The reports also lean on each other. IISS’s dataset is built on the Leiden dataset; GLOBSEC cites the Leiden figures, IISS and an AP count; CSIS cites the Leiden research; the Soufan Center interviewed the author of the Leiden dataset. Ultimately, most roads lead back to the same pool of media reports of official claims — in most cases of “possible” or “likely” Russian involvement. And those official claims are not neutral. The IISS paper, remarkably, says so itself: decisions about attribution are “rarely made in a political vacuum”, and public statements “reflect broader strategic calculations as much as their confidence in the evidence”.
Nor can many of the organisations behind these reports be considered neutral. The IISS, CSIS and GLOBSEC all have funding ties to American and European arms manufacturers (GLOBSEC counts among its donors the defence company Helsing, which the Ukraine war has turned into Europe’s most valuable startup), as well as to the transatlantic establishment, and are known for their hawkish approach to the Ukraine war and to Russia. The language of the reports themselves betrays their ideological commitment. The CSIS brief argues that NATO should abandon its “mindset of self-deterrence” and launch a “calibrated offensive campaign” against Russia. The IISS urges a “more assertive and proactive stance”, with its chair, Lord Mark Sedwill, saying that Britain was at war with Russia. The GLOBSEC report speaks of “state terrorism”.
But, in fact, as noted above, the reports themselves contain very little evidence, if any, to support the “Russia is at war with Europe” narrative.
Aside from the handful of sabotages that have resulted in convictions — discussed below — and even then with only tenuous links being drawn to the Russian state, virtually all the incidents logged in these reports are based purely on unsubstantiated claims made by Western officials, security services or media outlets, often without presenting evidence (as we shall see, this also applies to formally attributed actions like the Leipzig/Halle drone incident). As the Associated Press admits, “[i]t is often difficult to prove Russia’s involvement, and the Kremlin denied carrying out a sabotage campaign against the West. But more and more governments are publicly attributing attacks to Russia”. This constant talk of “possible” or “potential” Russian attacks ultimately generates a public perception of a relentless campaign being waged against Europe, even in the absence of evidence. As Ivo Capaul of ETH Zürich noted, the effect of the media coverage and political climate (a wholly intended one, I would add) is to create “cognitive biases in the form of a clustering illusion” — seeing patterns between data points that are not necessarily connected, or that in some cases don’t exist at all.
The claims don’t stand up to scrutiny
Indeed, what is astonishing is how many widely reported claims of Russian sabotage ended up collapsing upon basic scrutiny. One of the most infamous cases occurred in September of last year, when it was widely reported (initially by the Financial Times) that Russia had “recklessly” jammed the GPS of von der Leyen’s airplane over Bulgaria, forcing pilots to land using “paper maps” after “circling the airport for an hour”. NATO Secretary General Mark Rutte was quick to suggest that the incident was part of a wider pattern of “hybrid warfare” that included “cyber attacks and severing subsea cables”. Public outcry ensued. However, the story collapsed within hours: a flight tracking service demonstrated that the signal was never lost and the plane was actually only 9 minutes late. Bulgarian Prime Minister Rosen Zhelyazkov stated there was nothing to investigate. This was a significant case of claims promoted by sources close to the top of the European Commission being prominently exposed as false, yet the claims made were never retracted or clarified. Nor did they give rise to wider scrutiny of the “Russian hybrid warfare” narrative.
But this was not an isolated case: there have been countless claims of Russian sabotage or hybrid activity that were massively amplified by the media, only to be subsequently debunked or proven false — the latter going largely unreported. In November 2024, a series of incidents causing damage to cables in the Baltic Sea was widely reported in the media. Coverage was fuelled by European decision-makers openly attributing the incidents to Russia even before the investigations had been concluded. The lack of clear information sparked public speculationabout who was responsible for the incidents and how exactly they had come about. Finnish authorities detained a ship, suspected of being part of Russia’s “shadow fleet” used to avoid sanctions, after that cable and others were damaged. It eventually turned out that the damaged undersea cables in the Baltic Sea had been caused by Hong Kong- and China-flagged ships — not by Russian vessels. The Finnish intelligence service SUPO observed that “statistically, the number of cases of cable damage in recent years is quite typical for the Baltic Sea”. Yet again, no apology was issued by European authorities for the false claim.
That same month, a DHL plane crashed in Lithuania. Several European officials implied that the crash might have been the result of Russian sabotage, with these claims being widely amplifiedin the Western media. On the very day of the crash, before any investigation had been carried out, Annalena Baerbock, Germany’s then foreign minister, raised the possibility that it could be a “hybrid incident”, referencing the recent severing of the Baltic Sea cables. General Carsten Breuer, the Bundeswehr’s chief of defence, went even further, suggesting it may have been a “test” by Russia to probe weaknesses, saying “We encountered a similar situation earlier this year, and now something has occurred that fits this pattern” and that the Kremlin might be “checking vulnerabilities”. A few days after the crash, Sir Richard Moore, the then head of MI6, alleged that Russia had launched a “staggeringly reckless campaign of sabotage” in Europe. In March 2025, exhaustive investigations by the Lithuanians revealed that the crash was caused by pilot error, a finding that was not reported with anything like the prominence of the original allegations that the plane was brought down by Russian action. Once again, notable accusations were demonstrated to be provably false in a way that should raise questions around the wider narrative being pushed — but that didn’t occur.
A similar situation played out when Heathrow airport near London shut down on March 21, 2025, after an electricity substation caught fire. Claims that the fire was part of a hybrid warfare campaign were widely publicised. Philip Ingram, a former colonel in British military intelligence, was quoted as saying that the attacks looked like something “straight out of the Russian military intelligence playbook”. A few months later, the real cause of the accident was revealed, and it proved to be far more mundane: a privatised electricity company had failed to properly maintain and upgrade the installation. The same pattern of accusations running ahead of the facts could be seen in other cases, from explosives found near a NATO pipeline to a hole in the fence of a German water treatment facility.
The drone panic — much ado about nothing?
A similar pattern can also be observed in the “Russian drone” hysteria that has come to dominate the “hybrid war” narrative over the past year. In particular, the autumn of 2025 saw a veritable media frenzy around the issue. Numerous reports were published of drone sightings all over Europe — in Germany, Poland, France, Norway, Lithuania, Denmark and other countries — often resulting in airport closures. European leaders, such as Germany’s Chancellor Friedrich Merz, openly blamed Russia for the drones. “Our suspicion is that Russia is behind most of these drone flights”, Merz said after incidents at Munich airport, without providing any evidence. Danish Prime Minister Mette Frederiksen and von der Leyen called it a “hybrid war”. The Danish Justice Minister went as far as comparing the situation to 9/11. The crisis came at a time when European leaders were locked in intense debate over Europe’s common defence policy, after US President Donald Trump had put a (temporary) stop to military shipments to Ukraine. Indeed, several of these sightings occurred just ahead of an October 2025 summit of European leaders in Copenhagen, where funding for a “drone wall” and other defence measures was high on the agenda.
Virtually all “Russian drone” sightings, however, soon turned out to be unfounded. The drone incident that led to the shutdown of Frankfurt Airport was caused by a 41-year-old “amateur drone pilot”. The closure of Lithuania’s largest airport, it turned out, was not due to Russian drones, but to hot air balloons used by cigarette smugglers. In one striking case, it was reportedthat, according to Polish Prime Minister Donald Tusk, Polish state security had neutralised a drone over the presidential palace and that Poland’s president had asked for NATO support. But the prime minister’s account was incorrect and was later corrected; one of those arrested was a young Ukrainian man, the other person his 17-year-old Belarusian girlfriend. Jacek Dobrzynski, spokesman for the Minister for the Coordination of Special Services, denied shortly afterwards to Euronews any rumors that this was an espionage operation: “We reject rumors that this is a large-scale espionage operation. These are young people, maybe it was carelessness, maybe ignorance, maybe they wanted to make a film”.
In fact, an investigation by the Dutch newspaper Trouw found that in nearly 60 other incidents there was “much panic and hardly any evidence of Russian involvement”. Evidence in 41 of the drone sightings remained inconclusive. Furthermore, there were 14 cases of other flying objects (civilian aircraft, birds) being mistaken for drones and three turned out to be civilian “hobby” drones operated by private individuals. For example, people in Belgium mistook (small) planes and helicopters for drones, while the flying objects in South Limburg and Billund, Denmark, were stars. Investigations in Denmark, Belgium and Norway came to similar conclusions: in most cases, drone sightings were inaccurate and unverified and turned out to be aircraft, helicopters or satellites; no evidence was found that these were in any way connected to Russia.
There have been similar cases more recently. In mid-September, a NATO fighter jet was scrambled after a possible drone sighting in Lithuanian airspace — but it turned out to be a flock of birds. Just a few days earlier, Norwegian Prime Minister Jonas Gahr Støre had claimed that Zelensky’s plane was “almost hit by a drone” while taking off from Moldova en route to Oslo. However, official reports from Moldovan authorities and Ukrainian presidential sources later clarified what actually happened: the drone in question never came close to the airport; it crashed about 160 kilometres away, near the Moldovan-Ukrainian border. And so the story quietly vanished from the front pages, without corrections or apologies — but the mainstream press, now permanently on a Third World War footing, had already achieved its aim: to point the finger at Moscow and stoke a fresh wave of alarm.
Spillover from the war next door
Moldovan authorities and security experts later said that the drone was indeed of Russian origin. Even though, as always, no independent verification was possible, this is not improbable. It fits a pattern. There have been a handful of incidents — in Romania, Moldova and Poland — where it was confirmed that Russian drones had indeed entered these countries’ airspace. But in virtually all cases these airspace violations occurred near these countries’ border with Ukraine, during Russian attacks on nearby Ukrainian targets, and thus were most likely stray drones — i.e., drones that veered off course, possibly due to Ukrainian anti-drone jamming. In other words, they look much more like spillover from the war next door than a campaign of deliberate incursions.
This also applies to the Russian cruise missile that crashed in a field in Poland in July, likely because it either malfunctioned or was thrown off course by interference. Even Polish Prime Minister Tusk later stressed that “there are no reasons to think Poland was the intended target for this missile”. Meanwhile, news of Russian fighter jets occasionally entering Estonian airspace, sometimes just for a few seconds, also tends to attract a lot of media attention these days. In fact, these incidents tend to occur close to a narrow strip of international airspace over the Gulf of Finland where it is very easy to stray into Estonia’s airspace by accident, and have been occurring for years.
The most recent incident to date occurred in Lithuania, on September 15, when a drone entered the country’s airspace from Belarus and was shot down in central Lithuania. The Lithuanian president himself said the incident was most likely not a deliberate attack against Lithuania. “Most likely, it was a Russian drone intended for Ukraine that was diverted from its course by Ukrainian electronic warfare measures and entered our territory, where it was shot down”, he said. Indeed, strays aren’t only Russian. In March and May, several Ukrainian drones crashed in Finland, Latvia and the other Baltic states during Ukraine’s long-range attacks on Russian oil infrastructure, possibly because of Russian electronic warfare. Russia, for its part, denied the accusations — and accused the Baltics/NATO of actively allowing Ukrainian drones to use their airspace for strikes on Russia, framing it as NATO aggression. In one instance, the drones struck oil infrastructure in Latvia, triggering the resignations of both the Latvian prime minister and defence minister, though the story barely made the headlines.
There are, however, two incidents (allegedly) involving Russian drones far from the Ukrainian border: the September 2025 event in Poland and, of course, the “failed drone attack” at Leipzig/Halle airport in August, which is discussed further down. On the night of September 9-10, 2025, Poland claimed to have shot down several Russian drones that had crossed into its airspace, in some cases nearly 300 kilometres into the country, with NATO air defences involved in the response. This occurred amidst the ongoing Polish, Lithuanian, and NATO drills involving 30,000 Polish troops and just ahead of the upcoming Russian-Belarusian Zapad 2025 drills. Some therefore suspect that this was either a deliberate provocation by Russia or a botched recon mission, but it might also have been due to NATO jamming. Moreover, a Polish house was badly damaged. Images of the heavily damaged home were broadcast around the world as evidence of Russia’s brazen assault in the first-ever direct engagement between NATO and Moscow. However, it was later revealed that the house had been hit by a missile fired from a Polish F-16, not by a Russian drone, as the Warsaw government had initially claimed. In any case, even Western intelligence officials “privately” admitted to CNN that the Russian incursion was probably not intentional, and that the flight paths suggested the drones had lost their bearings because of electronic warfare countermeasures.
Leipzig/Halle: an assessment but little evidence
There is one major drone incident — arguably the most important so far in terms of its political repercussions — that remains to be discussed: the Leipzig/Halle incident. On August 5, Germany’s interior ministry announced that the evening prior staff at Leipzig/Halle Airport — a major cargo hub that since 2022 has also become a key logistics centre for NATO and for shipments to Ukraine, and Germany’s main hub for flights to the country — had noticed a small drone resting on the tarmac near a parked Ukrainian Antonov freighter, allegedly carrying an explosive charge and a detonator. The charge did not go off, and investigators said the explosive device was defused. Around the same time, a DHL cargo aircraft approaching the airport reportedly collided mid-air with a second drone, though no wreckage was found, possibly because it was destroyed in the engines. About three weeks after the attack, investigators found another drone in a field in Kabelsketal, an area adjacent to the airport in Saxony-Anhalt, possibly carrying military explosives.
On September 1, the German government officially blamed Russia for the incident, saying that intelligence points to “people being involved who acted on behalf of Russian state entities”. The following day German media reported that the Federal Prosecutor’s Office was investigating two suspects — a Belarusian and a Russian, at least one of whom was said to be tied to a(n unnamed) Russian intelligence service — though this wasn’t officially confirmed. So far, nobody has been arrested or even charged. The same day, Germany also announced the closure of the Russian consulate in Bonn, Moscow’s last remaining consulate in the country, and of the “Russian House” in Berlin — a further downgrading of already minimal diplomatic ties.
Russia denied involvement in the Leipzig incident; Kremlin spokesman Dmitry Peskov had previously called the claims of a Russian sabotage campaign in Europe “empty and ephemeral”. Yet, within hours of the German government’s announcement — before any suspect had been publicly identified or any evidence made public — NATO, EU and national leaders all rallied behind Germany, in a choreographed show of support that suggested careful advance coordination. They all issued near-identical statements, expressing “full solidarity” with Germany and accusing Russia of carrying out a “hybrid attack” and even of engaging in “state-sponsored terrorism”, as Kaja Kallas called it. “The evidence is clear”, said NATO Secretary General Mark Rutte.
In fact, at that point, German authorities hadn’t provided any actual evidence to the public — or, it would appear, to other EU governments. Rather, Interior Minister Alexander Dobrindt had simply stated “taken together, police investigations, patterns of the offences and intelligence findings establish Russian responsibility for the attempted attack at Leipzig Airport”, adding that “the means used to carry out the act” of sabotage in Leipzig — and he listed the drone’s configuration, various components used and explosives — “are known to us from other hybrid operations conducted by Russia and its war against Ukraine”. But this is not evidence; it’s a description of an assessment — one that the public was expected to take at face value.
Even establishment-aligned voices and outlets have expressed doubts. “The German government now maintains that the modus operandi, as well as police and intelligence findings, point to Russia as the perpetrator”, Johannes Varwick, professor for international relations and European politics at Halle-Wittenberg University, told EUobserver. “That may be plausible, but there is evidently no proof — at least none that has been made public, not even in qualified or indirect terms”, Varwick said. Subsequent media reports offered some details — the type of explosive, a supposed DNA trace — but these were not confirmed by authorities, leaving the public with a set of partially overlapping anonymous leaks, each attributed to security circles. Given the EU and NATO’s track record on “Russian hybrid warfare”, and its pattern of making evidenceless claims against Russia, several of which were later quietly disproved and many more never substantiated, a degree of scepticism seems warranted. Indeed, both the AfD and the left-populist BSW have questioned the lack of evidence presented when the Berlin government made its allegation.
Given the potential consequences of openly accusing Russia of attempting to carry out a terrorist attack in Germany, the least German authorities can do is provide some hard evidence to the public; otherwise people might be tempted to agree with Maria Zakharova, spokeswoman for Russia’s Ministry of Foreign Affairs, who said that evidence of Russian responsibility “simply does not exist and cannot exist”. Until then, the Leipzig/Halle incident should be treated as yet another unsubstantiated claim made by Western governments and echoed by the media, which the public is simply asked to accept at face value.
The German government’s treatment of the incident closely resembled the Polish authorities’ response to the November 2025 rail sabotage, when two explosive devices damaged sections of the Warsaw-Lublin line. Polish Foreign Minister Radoslaw Sikorski immediately described the act as Russian “state terrorism”, while Prime Minister Tusk called the incident “probably the worst attack on state security since the outbreak of war in Ukraine”, emphasising that “a line has been crossed”. Within only 70 hours, Polish security forces had identified two suspects said to be responsible for both attacks who had already fled to Belarus — both Ukrainian “with long histories of collaborating with Russian intelligence”, according to Tusk. A third Ukrainian was then arrested, but the case has yet to come to court. The “worst attack” in years on Poland’s security appears to have been quickly forgotten.
The “Russian disinformation” narrative
Another point that deserves brief mention is the alleged informational dimension of Russia’s supposed hybrid war. We are told that Russia has been engaged for years in a massive influence and disinformation campaign aimed at manipulating helpless European voters; indeed, it has now become commonplace across Europe to blame virtually every unwelcome electoral outcome — including the recent Icelandic EU referendum — on Russian interference. Yet this is probably the dimension where the evidence is scantest — and where the consequences have been most dramatic. It has provided the basis for the introduction of censorship tools, such as the Digital Services Act (DSA), and for increasingly pervasive “electoral integrity” tools, such as the Democracy Shield, which in practice allow the EU to interfere ever more in national elections, under the guise of fighting Russian interference.
Romania represents the most glaring case. In November 2024, the independent eurosceptic and NATO-critical candidate Călin Georgescu emerged as the surprise winner of the first round of the presidential election. Before the runoff, which polls suggested he would win comfortably, could take place, the constitutional court annulled the result in an unprecedented move, citing alleged Russian interference — specifically a social media campaign on TikTok supporting Georgescu. No evidence was ever provided. Indeed, internal documents later obtained by the US House Judiciary Committee showed that TikTok had explicitly informed the Commission that it had found “no evidence” of a coordinated inauthentic network. Nonetheless, the electoral bureau subsequently barred Georgescu from participating in the re-run altogether.
What actually remains
As we have seen so far, the picture that emerges on closer inspection is very different from the one painted by Europe’s leaders and media. Many of the most widely publicised cases of supposed Russian “hybrid warfare” — von der Leyen’s jammed plane, the Baltic cable cuts, the DHL crash in Vilnius, the Heathrow fire, the wave of drone sightings that swept Europe in the autumn of 2025, the Romanian TikTok campaign — turned out to be media-amplified speculation that collapsed under basic scrutiny, with the retractions, if any, receiving a fraction of the coverage of the original allegations. Many others were simply never substantiated. Where Russian drones did demonstrably enter NATO airspace, they almost always did so near the Ukrainian border during strikes on nearby Ukrainian targets, and most likely by accident — a by-product of the war next door rather than a deliberate campaign against Europe. And even in the case of Leipzig/Halle, the most politically consequential incident to date, the German government has yet to make public any actual evidence of Russian responsibility.
Ultimately, once all the speculative, unproven or outright non-existent “incidents” are cast aside, what remains is a handful of cases of demonstrable sabotage. Of the hundreds of incidents attributed to Russia, only a small number have led to convictions — and even in these, the link to the Russian state has rarely been demonstrated. The courts have convicted low-level, usually paid recruits; evidence of who gave the orders was either never tested in open court, rested on guilty pleas or went no further than contact with anonymous handlers on Telegram. In no case has a Russian official been identified, let alone tried.
Poland has secured the most convictions, including 14 members of a network that planned to derail aid trains to Ukraine in 2023 and three Ukrainians convicted in 2025 of belonging to a sabotage group. Yet charges over the most notorious fire attributed to that group, at Warsaw’s Marywilska shopping centre, were only filed in April 2026, and prosecutors admit that the arsonist, as well as the alleged mastermind ordering the attack from within Russia, haven’t been identified.
The case most often cited as proof of a Russian parcel-bomb campaign is murkier still: in July 2026, a court sentenced Igor Rogov, a former Navalny campaign worker granted asylum in Poland, to seven years for spying on Russian exiles for the FSB, Russia’s main security agency, and for involvement in an explosives parcel intercepted in 2024. The trial was held behind closed doors — and according to some reports, Rogov might actually have been part of a Ukrainian intelligence operation smuggling explosive components into Russia.
Elsewhere, the pattern repeats. In Lithuania, a Ukrainian teenager pleaded guilty to the IKEA arson in Vilnius, while the investigation into who commissioned it continues. In Estonia, the conviction of an activist for organising an attack on the interior minister’s car on behalf of the GRU, Russia’s military intelligence agency, came without a public hearing. In London, the men who burned a warehouse storing Starlink equipment for Ukraine were convicted of acting for the Wagner Group, but the evidence pointed to a handler contacted on Telegram, not an identifiable state body. A Colombian who set fire to Prague buses for a promised $3,000 was sentenced on a plea deal that never established who was behind his Telegram contact.
Germany’s one completed trial is telling. In August, the Stuttgart court found that a Russian state body was behind GPS-tracker parcels sent toward Ukraine, allegedly to scout targets and transport routes for sabotage. The federal prosecutor had alleged that parcels carrying incendiary devices were to follow, but the supposed arson plot couldn’t be proven. Of the three Ukrainian defendants, one courier was convicted and given a sentence he had already served; the other two were acquitted. The same pattern applies to the case most frequently cited in Western capitals as proof of Russia’s “hybrid war”: the incendiary parcels that caught fire at courier hubs in Birmingham, Leipzig and near Warsaw in July 2024. Investigators believe the parcels — sent from Lithuania and containing sex toys, cosmetics and massage pillows fitted with homemade magnesium-based devices — were a GRU-directed “dry run” for attacks on cargo flights to North America. Arrests followed in Poland and Lithuania, and several suspects have been charged with acting on behalf of Russian intelligence. Formal terrorism trials began in early 2026 in both Warsaw and Vilnius, where prosecutors aim to prove that the operation was orchestrated by Russian military intelligence.
Taken together, these cases show that some genuine acts of sabotage have taken place, but while intelligence agencies across Western capitals tend to attribute these hybrid activities to Russia, the actual evidence tested in European courts often reveals a much lower-level operational reality: paid proxies, anonymous digital handlers and ambiguous operations that rarely result in establishing proven ties to the Russian state. But even if Russia were behind every one of these cases, we would still be talking about a few dozen incidents a year at most — none of them fatal, and with damage that, while sometimes serious, has been confined to individual sites. A genuine counter-intelligence problem, perhaps, if real; but hardly the existential threat or sustained all-out hybrid war that European leaders routinely invoke — and not even remotely comparable to the sustained campaign of drone strikes that NATO countries have been enabling deep inside Russia, including against civilian targets, by supplying Ukraine with intelligence and satellite support, and increasingly the drones themselves, as well as long-range missiles (more on this further below).
The attacks nobody talks about
But perhaps the most gaping hole in the story is the fact that there indeed has been one very serious attack on Europe’s infrastructure in recent years — however, this wasn’t carried out by Russia, but, according to German prosecutors themselves, by Ukraine. I am referring, of course, to the 2022 Nord Stream bombing. Whether one believes that the bombing was effectively carried out by a Ukrainian group acting alone, or that Ukraine is being used to deflect attention from the role of the US and NATO in the sabotage, is beside the point (personally, I’m partial to the latter explanation). Nor is an in-depth analysis of the sabotage itself within the scope of this article. What matters for the sake of the present discussion is that, even if we take the official story to be true — that this was an entirely Ukrainian operation — the reaction of the German and other EU governments remains nonetheless shocking: the country officially accused of carrying out the worst case of industrial terrorism in Europe’s history, in a plot that according to media reports was conceived at the highest levels within the Ukrainian state, wasn’t subjected to sanctions or political confrontation; on the contrary, it was promised open-ended financial and military support, and showered with hundreds of billions of euros. Meanwhile, the attack itself was quickly swept under the carpet — but not before the Western media tried, absurdly, to pinthe attack on Russia.
Besides the Nord Stream sabotage, there is the case of the bomb that exploded at the entrance of an apartment building in Monaco in June, seriously injuring a Ukrainian tycoon with links to Russia and members of his family. The suspected bomber, a Ukrainian woman, fled back to Ukraine, where she was found shot dead a few days later. Though the Ukrainian state has not been formally implicated, a serving officer of Ukraine’s military intelligence agency initially confessed to her murder (though he later retracted his confession). Yet this attack, too, quickly faded from the headlines. It isn’t hard to imagine how Europe’s leaders and media would have reacted had the officer in question belonged to Russia’s GRU.
The real hybrid war
Ultimately, serious scrutiny of the “Russian hybrid warfare” narrative can only lead to one disquieting conclusion. A “hybrid war” is indeed being waged against Europe — but it is being waged by the EU-NATO establishment itself, against its own population. Europeans are being subjected to a sustained campaign of cognitive or psychological warfare aimed at conditioning them to believe that Europe is under attack from Russia, and that these hybrid attacks are a prelude to conventional hostilities — a claim for which, by and large, there is little or no proof. What the record points to, in fact, is a deliberate campaign of threat inflation in which governments, media outlets and defence-funded “think tanks” have colluded to instil a permanent sense of fear in the population, through relentless coverage of “incidents”, “attacks”, “sabotages” and “campaigns” that, in most cases, simply do not exist. As Mihail Evans, a research fellow at the Institute for Advanced Studies, New Europe College in Bucharest, wrote:
When an officially promoted narrative remains unquestioned by the bulk of the media and is, indeed, actively bolstered, we are in a fairly unusual situation. Something similar happened during the pandemic and one might suspect that the media management techniques finessed then have now been repurposed. In both cases there is an attempt to mold public perceptions and behavior primarily through fear. [...] After scrutinizing the weak basis for claims of “hybrid war”, we might begin to suspect that there is indeed a “playbook” at work, but one that is being run by NATO and the EU.
Indeed, this psychological conditioning extends well beyond the news pages. Consider, for example, the almost simultaneous release of two feature-length films, in the UK and France, both revolving around a NATO-Russia conflict. In the Sky Original docudrama miniseries The Wargame, released last month, real-life political figures, such as Michael Gove and Nicola Sturgeon, must react in real-time to a simulated Russian attack on UK soil; meanwhile, in the French geopolitical thriller Jupiter, to be released in cinemas in November, a newly elected French president must decide whether to launch a unilateral nuclear attack on Russia in response to Russia issuing a nuclear ultimatum against Ukraine. Two films do not make a conspiracy, but they show how thoroughly the idea of war with Russia has migrated from the security establishment into mainstream entertainment.
Cui bono?
There are several reasons why the EU-NATO establishment might have an interest in wildly inflating the Russian threat. For starters, there is significant and growing opposition in many European countries to the forever war in Ukraine — to the vast sums still being poured into the country and to the economic costs of the war — and to the broader EU-NATO rearmament drive, which, by European leaders’ own admission, will require painful cuts to the welfare state. When Europeans watch Russian forces struggling, more than four years on, to advance beyond eastern Ukraine, they may well ask why such sums should be spent defending the continent against a country that has shown neither the capability nor any evident intention to attack it. “This is where the idea of a ‘hybrid war’ comes in”, Evans argues. “It allows defense spending boosters to claim that Russia is offensively striking European nations in nonconventional ways and to imply that such covert aggression might at any moment move to open hostilities”.
A number of respected international relations scholars have suggested that this is indeed what is happening. A February 2025 report for the Latvian Institute for International Affairs by Galvin Wade — a former Director for Russia, Baltic, and Caucasus Affairs at the US National Security Council — contends that the employment of the “nebulous tagline” of hybrid war is “driven as much by the need to goose flagging defense budgets and waning NATO cohesion as to analyze Moscow’s behavior”. Indeed, in late 2025 EU Commissioner for Defence Andrius Kubilius used the (subsequently debunked) “Russian drone” scare to argue for increased counter-drone abilities. “All of Europe is under threat”, he said, adding: “Russian drones can strike Belgium, Netherlands, France and more. From ships drones can target all coasts of Europe. All Member States need capabilities to detect drones”.
It worked. Sabotage allegations have driven increases in defence budget allocations, including a €250 million European Commission package for “drone and counter-drone capabilities”. In the summer of 2026, NATO countries pledged $40 billion (around €35 billion) for the same. This means that the military-industrial sector also has a vested interest in inflating the Russia threat. As already noted, many of the think tanks pushing the “hybrid war” narrative, such as the IISS, the CSIS and GLOBSEC, all have funding ties to American and European arms manufacturers that are directly profiting from the war in Ukraine — and from an inflated perception of the threat posed to Europe by Russia. Since the start of the war in Ukraine, American defence companies have enjoyed steady growth, while Europe’s rearmament drive has sharply boostedthe revenues of European arms makers. The European counter-drone market alone is expected to quadruple by 2030. More recently, following the El Mundo report about Russia’s plan to launch drones from ships against Mediterranean countries (also swiftly debunked), Robert Brovdi, commander of Ukraine’s drone unit, told the Italian daily la Repubblica that “Italy, too, must set up its own brigade of unmanned systems; this will be crucial for defending against attacks from the sea”.
Europe’s security and intelligence establishment also stands to benefit from the “Russian hybrid war” narrative. It’s no coincidence that many of these claims originate with the security services themselves — agencies that stand to gain larger budgets or broader powers from the perception of a sabotage threat, raising obvious questions of conflict of interest. Germany’s foreign intelligence service, the BND, for example, has invoked the danger of Russian sabotage to shedrestrictions on its activities dating back to the post-war era, and may now be permitted to conduct sabotage operations of its own, along with offensive cyber attacks and more aggressive espionage. In the Netherlands, Prime Minister Rob Jetten pointed to the sabotage threat when unveiling a new national security law granting intelligence agencies expanded powers.
But it is not merely the military-industrial complex and defence-security establishment that stands to benefit from the ever-present spectre of a looming “Russian threat”. This also provides the EU establishment with a broader authoritarian dividend, insofar as it is routinely invoked as a justification for the ongoing assaults on democratic norms and increasingly authoritarian governance — from online censorship to the repression of dissent and interference in national elections. It supplies the external enemy without which this authoritarian consolidation would be far harder to justify — a permanent state of emergency, after all, requires a permanent threat. This is among the reasons why the EU establishment has proved so resistant to any de-escalation with Russia.
Escalation dressed up as defence
One final point deserves mention: the way in which the “hybrid war” narrative allows Western governments to present their own escalation against Russia as a mere “response” to Russian aggression. Indeed, Admiral Giuseppe Cavo Dragone, the outgoing chair of NATO’s Military Committee, openly stated that NATO was considering a far more “aggressive” posture towards Russia’s covert activities — up to and including pre-emptive strikes, which he suggested could be regarded as a form of “defensive action”. In late September, just days after the latest wave of “hybrid war” alarm, Ukraine launched more than 1,000 drones at Russia, including what was described as its largest-ever attack on Moscow. This was only the latest in a sustained campaign of strikes against Russia’s principal cities, its strategic infrastructure and, by extension, its leadership — supported by Western intelligence, executed with Western weapons and now backed by an explicit G7 commitment to “accelerate” the delivery of long-range capabilities. But the Western logic is self-reinforcing: if Russia were to retaliate, its response would be held up as proof that the warnings had been right all along. The logic is so brazen that one cannot help but wonder whether Western elites are actively trying to provoke a Russian response.
Whatever the case may be, the inflated “hybrid war” narrative clearly serves the interests of European governments and NATO far better than an actual hybrid war would serve Russia’s — let alone a conventional attack on NATO. According to European officials, Russian sabotage is meant to weaken European support for Ukraine. Yet it seems far more likely to have the opposite effect. Commenting on the Leipzig/Halle incident, for example, political scientist Johannes Varwick asked what interest Russia would have in an attack likely to produce “a deepening of the perception of threat in Germany, a stronger commitment to supporting Ukraine”. “Surely, even any Russian ‘planners’ would have recognised that a materially inconsequential provocation ultimately harms Russia and benefits Ukraine”, he added. “The question, therefore, is: cui bono?”.
From Gladio to today
Exactly: cui bono? Who benefits? This leads to a disquieting question: given how much European governments and NATO have invested in — and come to depend on — the “hybrid war” narrative, and the broader idea of Russia as an existential threat to Europe, will they continue to limit themselves to inflating a threat that has little basis in reality? Or might they at some point feel compelled to go further? There is, after all, a historical precedent involving NATO. In October 1990, Prime Minister Giulio Andreotti confirmed to the Italian parliament the existence of “Gladio”: a secret paramilitary network, established in the early post-war years in various NATO countries under NATO auspices with CIA involvement, equipped with hidden arms caches and maintained for four decades outside any parliamentary oversight. The European Parliament’s resolution of November 1990 described an organisation that had “eluded all democratic control” and had been implicated in certain member states, “as evidenced by various judicial inquiries”, in serious cases of terrorism.
Parliamentary inquiries followed in Italy, Belgium, Switzerland, and Germany. In Italy, those inquiries reached the sharpest conclusions. A decade later, a report by members of the parliamentary commission on massacres concluded that a “strategy of tension” — bombings of civilians in public places, blamed on the left to frighten the electorate towards the anti-communist right — had been “organised or promoted or supported by men inside Italian state institutions and, as has been discovered more recently, by men linked to the structures of United States intelligence”. This is what is commonly known today as a false flag: a covert operation designed to conceal who is really responsible and pin the blame on someone else. It is curious, then, that European and NATO officials have themselves accused Russia of planning false flag attacks. Could this be preparing the public for a scenario in which an attack bears no trace of Russia — and is nonetheless blamed on Moscow precisely for that reason, as a “Russian false flag”?
A self-fulfilling prophecy
Whatever the answer, one danger is already clear: that of a self-fulfilling prophecy. A narrative that casts every fire, drone sighting or damaged cable as an act of war does not merely misdescribe reality; it begins to reshape it. Governments that have spent years telling their citizens they are already at war with Russia leave themselves little room for restraint when the next incident comes — and incidents will keep coming, whether caused by drones knocked off course by electronic warfare, by birds, by pilot error or by genuine sabotage. Poland is changing its rules of engagement so that pilots can open fire on the basis of radar data alone; NATO’s top military officials openly discuss pre-emptive strikes; Ukraine’s strikes deep inside Russia, enabled by Western intelligence and weapons, keep intensifying. Each step is presented as a response to Russian aggression. Seen from Moscow, each looks like confirmation that NATO is preparing for war — and Moscow’s countermeasures, in turn, will be read in European capitals as proof that the warnings were right all along.
This is the classic security dilemma, and in such a climate it would take very little — a misidentified drone, a misread radar track, an incident attributed to Russia before the facts are in — for a “hybrid war” that exists largely on paper to turn into a real one between nuclear-armed powers. That is the ultimate danger of today’s strategy of tension: not merely that it exaggerates a threat, but that, by exaggerating it for long enough, it may end up creating it. Avoiding that outcome requires precisely what European governments have so far refused to offer: evidence before accusations, corrections as prominent as the claims they retract and a willingness to talk to Moscow rather than merely about it.
Thanks for reading. Putting out high-quality journalism requires constant research, most of which goes unpaid, so if you appreciate my writing please consider upgrading to a paid subscription if you haven’t already. Aside from a fuzzy feeling inside of you, you’ll get access to exclusive articles and commentary.
Thomas Fazi
Website: thomasfazi.net
Twitter: @battleforeurope
Latest book: The Brussels Empire: The EU’s Silent Coup Against Democracy (German version only for now: Die Brüsseler Tyrannei: oder Der diskrete Staatsstreich)


