Russia-Europe Tensions: Hybrid Threats and Ukraine War
Russia-Europe Tensions: Hybrid Threats and the Ukraine War. Europe is not officially at war with Russia. Yet the boundary between war and peace is becoming increasingly difficult to define.

Across Europe, governments are investigating drone incursions, sabotage attempts, cyberattacks, arson, airspace violations and suspected foreign-agent networks. Some incidents have been officially attributed to Russia. Others remain under investigation. And the latest case near Britain’s RAF Fairford has introduced another possibility: Iran.
The danger is not simply that one of these incidents could cause casualties or damage critical infrastructure. The greater danger may be cumulative. Repeated incidents can create fear, disrupt public life, consume intelligence resources, test political resolve and deepen divisions among countries supporting Ukraine.
But there is another danger: premature attribution.
In a hybrid conflict, an unexplained incident can become a geopolitical story long before investigators establish who actually planned it. That is why the central question is not simply who is being accused.
It is: What has actually been proved, what has been officially attributed, what remains under investigation, and who could benefit from the resulting uncertainty?
https://mrpo.pk/the-transatlantic-tug-of-war/
Europe needs a new strategy for Russian grey zone aggression

When European Commission President Ursula von der Leyen called for a new “counter-hybrid playbook” in her recent State of the Union address, she conceded a grim reality: Europe’s institutions have failed to keep pace with Moscow’s escalating campaign of grey zone aggression. However, the response in Brussels remains focused on reacting to Russian actions rather than establishing credible deterrence. Admitting Europe’s vulnerability is a necessary first step. But managing the aftermath of Russian attacks is neither strategy nor “strategic independence.”
The approach envisioned by von der Leyen appears to suffer from a number of flaws including the same unanimity requirements that have repeatedly stalled EU sanctions. A single captured government can block collective action against Russia, as has repeatedly happened since 2022.
There are now plans to create a European Security Council bringing together EU leaders with partners including Ukraine, the United Kingdom, Norway, and Canada. However, it is not clear whether this new body will help streamline collective responses, especially if all participants have veto powers.
Despite these concerns, most European policymakers would agree that new approaches are necessary to reflect the deteriorating security environment. Genuine deterrence will no longer come from strategic restraint. Instead, Europe should adopt a more active defensive strategy, because Russia will continue to expand the current campaign of hostile actions until it finds the continent’s real red lines. At that point, miscalculation on either side becomes a major risk.
What Is Hybrid Warfare?
Hybrid warfare describes the use of different forms of pressure below the level of conventional war.
These can include:
- Cyberattacks
- Sabotage
- Arson
- Drone operations
- Espionage
- Disinformation
- Election interference
- GPS jamming and signal disruption
- Attacks on transport or energy infrastructure
- Recruitment of local individuals to conduct covert operations
- Economic pressure
- Psychological operations
The attraction is obvious. A conventional military attack is relatively easy to identify. A cyberattack, suspicious fire, drone incursion or act of sabotage may be much harder to attribute.
That creates what security experts call a grey zone.
NATO Secretary General Mark Rutte recently described these activities as grey-zone tactics, including drones, sabotage and cyberattacks. NATO officials have also said that Russia’s activity is creating a changed security environment across Europe. (NATO)
The strategic advantage of such operations is ambiguity. If responsibility cannot be established immediately, governments face a difficult choice. Respond too aggressively and they risk escalation. Respond too weakly and they may encourage further activity. That dilemma is at the heart of Europe’s current security problem.
Europe Is Seeing a Growing Number of Incidents
European governments have reported an increase in incidents involving drones, cyber operations, sabotage and airspace violations.
Poland has reported repeated security incidents involving Russian military activity and drones. Romania has reported more than 100 incursions by drones or drone fragments connected to the wider fighting around Ukraine. Lithuania has also experienced drone-related incidents.
European officials increasingly argue that these incidents cannot all be treated simply as accidental spillover from the Ukraine war.
Polish Foreign Minister Radoslaw Sikorski has described some of the activity as actual attacks rather than merely threats. Romanian officials, however, have made an important distinction: they say there is no evidence that Romania itself is being deliberately targeted, while arguing that Russia remains responsible for the risks created by attacks near Romanian territory. (Reuters)
That distinction matters.
A drone crossing a border does not automatically prove that the country on the other side was its intended target.
A weapon launched toward Ukraine can malfunction, lose navigation or be diverted by electronic warfare.
But an accident can still become a NATO crisis if it kills people or damages infrastructure.
The Leipzig/Halle Airport Case
One of the most serious recent cases occurred at Germany’s Leipzig/Halle Airport on 4 August 2026.
An explosive-laden drone was found after an incident involving a Ukrainian cargo aircraft. The airport is strategically important because it is also connected to wider European military logistics.
German authorities subsequently concluded that Russia was responsible for what Berlin described as a hybrid attack.
The German government formally stated in September that it had concluded Russia was responsible for the attempted attack. (Bundesregierung)
This case is therefore different from an incident where responsibility remains unknown.
There has been an official German attribution. But even here, the wording matters.
Russian responsibility is the German government’s conclusion. It should not automatically be transformed into a claim that every individual involved has been publicly proven in court to have acted under Russian orders.
That distinction becomes particularly important when intelligence services identify suspected links to Russian military intelligence.

So, What Is the GRU?
The GRU, the name commonly used in Western countries, is Russia’s military intelligence service, formally known today as the Main Directorate of the General Staff of the Russian Armed Forces.
It is responsible for military intelligence and has been associated by Western governments with espionage, cyber operations and covert activities abroad.
The GRU should not be confused with Russia’s domestic security service, the FSB, or its foreign intelligence service, the SVR.
Recent European investigations have produced allegations of links between suspected sabotage networks and Russian military intelligence.
Britain, for example, has prosecuted an individual accused of assisting a person believed to be connected with the GRU Volunteer Corps in preparation for sabotage. The case remains subject to the normal judicial process, and the defendant is presumed innocent unless proven guilty. (Crown Prosecution Service)
A suspected GRU connection is evidence of a particular intelligence lead or investigation. It is not automatically proof that the Russian state ordered every suspicious incident attributed to Russia.
Lithuania: A Warning About Attribution
Lithuania provides another useful example.
A drone was shot down after entering Lithuanian airspace. Authorities said the drone was of a type used by Russia and was likely connected to the war in Ukraine.
That does not necessarily mean Russia deliberately attacked Lithuania.
The drone may have been intended for Ukraine and ended up somewhere else.
This illustrates one of the most dangerous features of the present environment.
Intent and consequence are not always the same thing.
A weapon can have one intended destination and produce a completely different geopolitical crisis.
Poland and the Ukrainian Border
Poland faces an especially sensitive situation because it is both a NATO member and Ukraine’s major logistical gateway to the West.
Warsaw has warned that Russia could attempt to disrupt transport routes and border crossings used to support Ukraine.
Polish authorities have also reported incidents involving drones and other Russian military activity.
But here again, precision matters.
A threat against a Polish border crossing is not the same thing as a confirmed Russian attack on that crossing.
The distinction may sound academic.
It is not.
Once NATO territory is deliberately attacked, the political and military consequences become much more serious.
Is Russia Testing NATO?
Some European officials believe Russia is testing the limits of Western tolerance. The theory is straightforward.
If an operation remains below the threshold of conventional war, Moscow may be able to impose costs without triggering a major military response.
That could include:
- Disrupting logistics
- Damaging infrastructure
- Creating public anxiety
- Increasing insurance and security costs
- Diverting intelligence resources
- Slowing military assistance to Ukraine
- Creating political disagreements
- Encouraging European governments to question the risks of continued support for Kyiv
European officials have publicly described Russian hybrid activity in similar terms, including attempts to create fear and division among Ukraine’s supporters. (Reuters)
But there is an important counterpoint.
European governments are not unanimous in believing that Russia is preparing an imminent conventional attack on NATO.
Estonian and Lithuanian officials have recently emphasized that they do not see evidence of an imminent large-scale Russian assault on NATO, even while warning about growing hybrid activity. (Reuters)
That distinction should remain in any serious analysis.
Hybrid escalation is not the same thing as preparation for a full-scale NATO-Russia war.
Then Iran Enters the Picture
The European security story has become more complicated because Iran has now entered the discussion. Iran is already connected to the wider European security environment through its military relationship with Russia.
Russian forces have used Iranian-designed or Iranian-produced drones in the war against Ukraine, and European governments have sanctioned Iranian entities linked to military drone development and supply. But that does not establish that Iran is behind the European sabotage cases currently being attributed to Russia. The latest RAF Fairford incident demonstrates why.
RAF Fairford: Iran, Russia, or Something Else?
On 27 September, British police arrested five British men near RAF Fairford after suspicious vehicles were reported moving toward the military airfield. RAF Fairford is particularly sensitive because it has been used by U.S. aircraft involved in operations against Iran.
The men were arrested on suspicion of explosives offences and preparation of a terrorist act. Police subsequently released them on bail while emphasizing that the investigation was continuing.
Petrol was reportedly recovered from the vehicles, but no explosives were found.
British counterterrorism authorities have said they are investigating whether individuals may have been acting for a foreign state.
Iran is one possibility being examined.
Russia’s and Islamist extremists’ involvement has also been considered.
Iran has denied involvement. British investigators have not publicly established that the Iranian government ordered, financed, or directed the alleged operation. (Reuters)
That makes Fairford fundamentally different from the Leipzig case.
At Leipzig, the German government has formally attributed responsibility to Russia.
At Fairford, the investigation is still open.

Why Iran Looks Plausible
There is a reason investigators and analysts are examining an Iranian connection.
The United States has used RAF Fairford for military operations against Iran.
Iranian officials have previously threatened American military interests in response to attacks on Iranian territory, and Iran’s Revolutionary Guards have described bases used for attacks against Iran as legitimate targets.
That provides a possible motive.
But motive is not proof.
A government can have a motive for an attack without carrying it out.
This is one of the oldest mistakes in intelligence analysis: confusing who might benefit with who actually did it.
Could Someone Be Trying to Kill Two Birds With One Stone?
This question deserves examination, but not a premature conclusion.
Suppose an incident near a U.S.-linked British airbase eventually proves to have an Iranian connection.
That would fit the immediate context of the war involving Iran.
But suppose investigators eventually establish a Russian connection.
That would raise a different possibility: that Russia was exploiting the Iran-West confrontation to create another security crisis inside Europe.
And there is a third possibility.
The perpetrators could be independent actors, proxies, or individuals influenced by several competing information networks without receiving direct orders from a government.
British counterterrorism police themselves have said they are examining whether individuals could have been acting knowingly or unknowingly on behalf of a foreign state. (Reuters)
This is exactly why the Fairford case should not yet be presented as “Iran attacked Britain.”
That statement would go beyond the publicly established evidence.
Nor should it automatically be presented as another Russian operation.
The honest position is simpler:
Investigators are examining several possibilities, including Iranian and Russian links, but public evidence has not yet established state responsibility.
Could Iran and Russia Both Benefit?
This is where hybrid warfare becomes particularly complicated.
Russia and Iran have cooperated in several areas, particularly around the Ukraine war. But cooperation does not mean that every action by one country is coordinated with the other.
At the same time, both countries have strategic reasons to challenge aspects of the Western security order.
An incident involving Iran could therefore create consequences useful to Russia, even if Russia had nothing to do with it.
Likewise, an incident blamed prematurely on Iran could create political pressure on Tehran even if the evidence eventually points elsewhere.
This produces a disturbing possibility:
Sometimes the information surrounding an incident can become strategically important regardless of who actually committed it.
That is why attribution itself has become part of the battlefield.
The Information-Warfare Problem
A suspicious event occurs.
Social media immediately supplies a culprit.
Politicians demand answers.
News organizations publish competing explanations.
Governments release fragments of intelligence.
The public forms an opinion.
And only later do investigators establish what actually happened.
Hybrid warfare can exploit precisely this sequence.
Russia is accused by European governments of using disinformation and covert influence to weaken Western support for Ukraine.
Iran has also been accused by Western governments of using proxies and information operations.
But accusations must still be tested against evidence.
Otherwise, Europe risks fighting an information war against itself.
Cyber Warfare: The Invisible Battlefield
Physical sabotage receives headlines because people can see a burning building or a crashed drone.
Cyberattacks are different.
A hostile cyber operation can target:
- Electricity networks
- Banks
- Hospitals
- Railways
- Airports
- Government systems
- Telecommunications
- Military logistics
- Satellites and navigation systems
A successful cyberattack may never produce a dramatic photograph.
Yet its economic impact can be enormous.
European governments increasingly treat cyberattacks and physical sabotage as part of the same broader security challenge.
Critical Infrastructure Is Becoming a Battlefield
Europe’s vulnerability extends beyond military bases.
Energy infrastructure, ports, airports, railways, telecommunications networks, undersea cables and satellite systems are all potential targets for disruption.
The Baltic region is particularly sensitive because of its proximity to Russia and Belarus and the concentration of important energy and communications infrastructure.
The problem is not necessarily that every damaged cable or malfunctioning system represents sabotage.
That would be another form of sensationalism.
The real challenge is determining when an apparently ordinary technical failure is simply an accident and when it is part of a coordinated campaign.
The Accidental-War Problem
Perhaps the most dangerous scenario is not a carefully planned Russian or Iranian attack.
It is a miscalculation.
Imagine a drone intended for a target in Ukraine crosses into Poland.
A NATO aircraft intercepts it.
The drone crashes into a civilian area and kills several people.
Moscow says it was an accident.
Warsaw says the violation was deliberate.
Social media claims it was an attack.
NATO begins military preparations.
Russia responds.
Within hours, an incident that nobody originally intended to become a war could create a rapidly escalating confrontation.
The same danger exists in the Baltic Sea, the Black Sea and around military aircraft operating close to national borders.
What About Article 5?
This question naturally arises whenever Russian activity touches NATO territory.
NATO’s Article 5 states that an armed attack against one member is considered an attack against all.
But Article 5 is not an automatic button that launches a predetermined military response.
NATO members would assess the circumstances and determine what collective action is required.
This matters because not every airspace violation, cyberattack, or sabotage incident automatically becomes an Article 5 event. The political and legal context matters. So does the evidence establishing who was responsible.
Is Europe Already at War With Russia?
No. Europe is not officially at war with Russia.
NATO and Russia remain adversaries, and European countries are providing extensive military and financial support to Ukraine. Russia, meanwhile, continues its war against Ukraine.
But Europe is experiencing a much more dangerous grey-zone security confrontation.
That confrontation can involve actions that are hostile without crossing the threshold of conventional war. This distinction is important because exaggerated claims of an ongoing Russia-NATO war can create unnecessary fear while understating the genuine security problems that European governments are facing. Both errors are dangerous.
What About Iran?
Iran should therefore be treated as a separate but increasingly relevant dimension of Europe’s security problem.
There are established facts connecting Iran to Russia’s military use of drones and to the wider confrontation between Iran and Western states.
There are also current investigations examining whether individuals connected to Iran may have been involved in the Fairford incident.
But there is currently no sufficient public evidence to merge these facts into one sweeping conclusion that Iran is behind Russia-linked sabotage throughout Europe.
That would be an analytical shortcut.
The same principle applies in the opposite direction.
The existence of documented Russian sabotage activity does not mean Russia is responsible for every unexplained incident.
A serious investigation must ask four separate questions:
Who carried out the operation?
Who directed or financed it?
What evidence connects the perpetrators to a state?
Who benefits from the resulting political and psychological effects?
Those questions are more useful than simply asking which country makes the most convenient headline.
What Is Europe Really Facing?
Europe’s emerging security problem is therefore larger than the possibility of a Russian attack.
It is a mixture of:
Russian hybrid activity
Iran-related security risks
Cyber warfare
Sabotage
Drone incursions
Espionage
Foreign-agent recruitment
Disinformation
Critical-infrastructure vulnerability
Accidental escalation
And perhaps most importantly:
Uncertainty about attribution.
The challenge for European governments is to respond strongly enough to deter hostile activity while avoiding escalation based on incomplete evidence.
That requires better intelligence sharing, stronger infrastructure protection, improved air and drone defenses, cybersecurity, counterintelligence and rapid investigation.
It also requires something less glamorous but equally important:
Discipline in public communication.
A government should be able to say:
“We believe Russia was responsible.”
It should also be able to say:
“We are investigating whether Iran was involved.”
And when the evidence is incomplete, it should be willing to say:
“We do not know yet.”
That last sentence may be the most important weapon against sensationalism.
The Larger Strategic Question
The war in Ukraine has already transformed European security.
Russia’s military confrontation with Ukraine has expanded into a broader contest involving sanctions, energy, cyber operations, intelligence, industrial capacity, military logistics and information.
Iran’s confrontation with the United States and its wider relationship with Russia add another layer.
The danger is that these separate conflicts could begin interacting with each other.
An incident in Britain could be interpreted through the lens of Iran.
A drone incident in Poland could be interpreted through the lens of Russia.
A cyberattack could be blamed on a state before investigators have established its origin.
A false accusation could itself produce political consequences.
And an accidental military encounter could become more dangerous because governments are already operating in an atmosphere of suspicion.
That is the real grey zone.
It is not simply the space between war and peace.
It is the space between fact and attribution, intention and consequence, deterrence and escalation.
What Should Europe Do?
The most practical response is neither panic nor complacency.
Europe needs:
- Stronger intelligence sharing
- Better protection of airports, ports, railways and energy systems
- Improved counter-drone capabilities
- Stronger cyber defenses
- Greater protection against foreign-agent recruitment
- Faster investigation of suspicious incidents
- Clear communication about what is known and unknown
- Coordinated responses among NATO and EU members
- Stronger protection of critical infrastructure
- Mechanisms to prevent accidental escalation
And perhaps above all, European governments need to preserve the credibility of their evidence.
If every unexplained incident immediately becomes a Russian or Iranian attack, eventually the public will stop believing official warnings. That would benefit precisely the actors Europe is trying to deter.
The Bottom Line
Europe is not at war with Russia, and the available evidence does not justify saying that Iran is secretly responsible for every new security incident. What is happening is more complicated.
There is substantial evidence of growing Russian hybrid activity across Europe, and Germany has formally attributed the Leipzig/Halle airport attack to Russia. European officials are also reporting increasing drone incursions, sabotage attempts and cyber threats. (Bundesregierung)
At the same time, the RAF Fairford case demonstrates why attribution must remain evidence-based. British investigators are examining possible foreign-state involvement, including possible Iranian and Russian connections, but the investigation has not publicly established that either government ordered the alleged operation. (Reuters)
The most important lesson may therefore be simple:
In an age of hybrid warfare, the first story is not necessarily the final truth.
Europe needs to be vigilant enough to detect hostile operations, strong enough to deter them and disciplined enough not to confuse suspicion with proof. Because when every mystery becomes an accusation, and every accusation becomes a geopolitical fact, the grey zone becomes even more dangerous.
Frequently Asked Questions
1. Is Europe at war with Russia?
No. European NATO and EU countries are supporting Ukraine, while Russia is at war with Ukraine. Europe is, however, facing an increasingly serious security confrontation involving alleged Russian hybrid operations, cyberattacks, sabotage and airspace incidents.
2. What is the GRU?
The GRU is the name commonly used in Western countries for Russia’s military intelligence service, formally known as the Main Directorate of the General Staff of the Russian Armed Forces. It is associated with military intelligence, espionage and covert activities.
3. Is Iran behind the sabotage incidents in Europe?
There is no public evidence establishing that Iran is responsible for the Russian-linked sabotage incidents discussed in this article. Iran is relevant to the wider security picture, and British investigators are examining possible Iranian involvement in the RAF Fairford case, but that investigation has not established Iranian state responsibility.
4. What happened at RAF Fairford?
British police arrested five men near RAF Fairford on 27 September 2026 after suspicious vehicles were reported near the military base. The men were arrested on suspicion of explosives offences and preparation of a terrorist act and were later released on bail while the investigation continued. Police are examining multiple possible explanations, including potential foreign-state involvement.
5. Could Russia and Iran both be involved in European hybrid warfare?
Both Russia and Iran have been associated by Western governments with different forms of covert or hybrid activity, but that does not establish that they are jointly conducting the European incidents discussed here. Each incident requires its own evidence and attribution.
6. What is the biggest danger from hybrid warfare?
One major danger is escalation through miscalculation. A drone, a cyberattack, or an act of sabotage may cause casualties or damage without immediately revealing who is responsible. If governments respond based on incorrect attribution, an incident below the threshold of war could escalate into a much larger confrontation.
A few factual points in this integrated version are particularly important: Moldova is not NATO or EU territory, the Leipzig/Halle attribution is an official German government conclusion, while Fairford remains an open British investigation. The latest reporting says British police are examining possible foreign-state involvement and Iran denies involvement. (Reuters)

