Listen to the article
Key Takeaways
🌐 Translate Article
📖 Read Along
💬 AI Assistant
A new Ukrainian dataset maps Russia’s sabotage, drone and cyber campaign against Europe since 2022. The numbers are rising, the attacks are getting more dangerous, and the pattern points to preparation for a next phase of military aggression.
By André Pienaar
Russia is at war in Europe and with NATO, although much of the European public does not know it. That is the finding of the most comprehensive open-source record yet compiled of Russia’s campaign against the continent, by the Kyiv-based Sahaidachnyi Security Center.
The Center’s tracker, “The Everywhere War”, has now logged 522 incidents since 24 February 2022 that were either attributed to Moscow by NATO governments in Europe or fit the established pattern of Russian clandestine operations: drones over airports and air bases, explosives on railway lines, severed undersea cables, arson at warehouses and shopping centres, jammed aircraft navigation, assassination plots and cyber sabotage.
The trend line is one of escalation. Between January and August this year, 100 incidents were officially attributed to Russia, against 60 in the same period of 2025. A senior NATO official told National Security News the true figure was likely above 200 in 2026, excluding cyber operations. The NATO official summarised the situation in one line: “Numbers are up, severity is up, [Russia’s] risk appetite is up.”
From probing to shaping future military operations
The centre’s companion study, “The War That ‘Does Not Exist’: Russian Sub-Threshold Aggression Against Europe and Scenarios for Its Escalation”, makes an argument many governments have been slow to accept. Currently, we tend to file hybrid activity as a separate and lesser category of hostility, somewhere between espionage and vandalism, to be handled by police and counter-intelligence services. When the GRU hired two young men to attack Prime Minister Starmer’s home, the Crown Prosecution Service charged them with “conspiracy to damage a building with fire” rather than with terrorism.
Russian military doctrine does not see it that way. In the Kremlin’s conception, sub-threshold operations are an opening phase of a war. It is the stage at which conditions are shaped for the operations that may follow.
The fact that the Kremlin views these attacks as an extension of its war of aggression in Ukraine is reflected in the fact that the lead agency in these clandestine operations is the Russian GRU, or the Main Directorate of the General Staff of the Armed Forces of the Russian Federation, rather than the two civilian intelligence agencies, the SVR (the foreign intelligence agency) and the FSB (the internal security service).
The Centre’s director, Lesia Ogryzko, describes a qualitative shift in the Russian campaign, and the evidence supports her analysis.
The record shows three distinct phases. In the first two years of the full-scale invasion of Ukraine, activity was dispersed, deniable and concentrated on the dual-use infrastructure of the Baltic and Nordic regions: the Balticconnector gas pipeline, damaged in October 2023, and the Estlink-2 power cable, severed by a shadow-fleet tanker in December 2024.
The first surge came in spring 2024, once Moscow had concluded that the war in Ukraine would be long and turned to raising the price paid by Ukraine’s backers. Arsonists hit a Ukrainian-linked warehouse in east London; fire destroyed Warsaw’s Marywilska shopping centre; incendiary parcels ignited inside the DHL network. The second surge, in autumn 2025, took the campaign into the air and onto the railways: a mass drone incursion into Polish airspace, three MiG-31s over Estonian territory, drones closing Copenhagen airport, and an explosive device on the Warsaw–Lublin line that Prime Minister Donald Tusk ranked among the gravest threats to Polish security since the invasion began. Attacks have only escalated in pace and severity since.
2026 has brought something new: physical harm and attacks aimed directly at civilians. In May, a Russian drone struck an apartment building in Galați, Romania, injuring two people. German authorities have linked a suspected Russian operative to an attempted drone attack on Leipzig airport, which the European Union said bore the hallmarks of state-sponsored terrorism. In August, Polish authorities detained a Russian citizen accused of plotting, on behalf of Russian intelligence, to kill a dual US-Ukrainian national; Tusk called it the first Russian attack on an American citizen on NATO territory. The Dutch military intelligence service has reported the first Russian cyber sabotage of a Dutch public service designed to seize control of the system. The White House reportedly sent CIA Director John Ratcliffe to Moscow to warn against any attack on NATO members, with the Baltic states singled out.
The locations of the attacks show Russia’s military priorities. The incidents cluster along the arteries that carry Western support to Ukraine, namely the Polish rail corridor, German logistics hubs, the airports and ports of the North and Baltic Seas, and along NATO’s frontier from Estonia to Romania. Over the whole Baltic basin sits a near-permanent blanket of GPS jamming and spoofing. This is not random harassment. It is a clandestine military targeting pattern, and much of it reads like reconnaissance and probing of response times, political thresholds, which infrastructure fails and how quickly it recovers.
The Kremlin’s objectives
Elena Davlikanova describes the tactical objectives: to coerce allies into cutting support for Ukraine and to wear down public backing by imposing social and economic costs on NATO countries in Europe. The strategic objective is to test, and to hollow out, the credibility of NATO’s collective defence without ever triggering a military response. Each incident is calibrated to stay below the point at which Article 5 becomes a live question. Every incident that goes unanswered erodes Article 5. The Kremlin dismisses the entire catalogue; its spokesman, Dmitry Peskov, called such claims “scare stories” in August.
Imposing a cost
NATO countries’ response so far has been slow, cautious, defensive and uncoordinated. President Macron has ordered critical sites protected, the UK charged the men who tried to burn down the Prime Minister’s home with “conspiracy to damage a property with fire”, Poland has strengthened its air defences, Germany is preparing its hospitals, and NATO launched Eastern Sentry along the eastern flank last September. None of these necessary steps changes Moscow’s calculation. A campaign built on clandestine deniability and low cost is only defeated by removing both. Six steps could do that.
- Educate citizens to understand that we are at war. Leaders need to educate their citizens about the clear and present danger that Russia and the axis of aggressors’ operations pose to their safety and the reality that we are in the opening phase of a war.
- Attribute collectively and quickly. Joint EU–NATO attribution within days rather than weeks, months and years, backed by published evidence, strips away the deniability that makes the campaign cheap.
- Make the shadow fleet pay. The uninsured tankers of the Baltic, the North Sea and, increasingly, the Cape of Good Hope route are a source of war finance and supply, but also now an instrument of sabotage. RUSI has reported that the shadow fleet now serves as a platform for drones that are being sent onshore into NATO airspace for surveillance, probing of defences and sabotage attacks. Inspection, detention and interdiction should be a priority for combined NATO naval operations as a matter of urgency.
- Close the recruitment market. Much of the Russian campaign runs on disposable agents recruited online for cash. Prosecute this publicly as terrorism and cut the payment channels.
- Harden the corridors. Counter-drone coverage at airports, bases and rail junctions, and resilient logistics, should be funded as defence. Public-private partnerships should be established for the drone defence of critical infrastructure.
- Establish reciprocity and a red line. Expel intelligence officers from Russia and its allies – Iran, the People’s Republic of China and North Korea – publicly identify and sanction the GRU units responsible, and make clear that a fatality on NATO soil caused by a Russian operation will be treated as a military attack with reciprocity. Target Russian bases and operations abroad to make the point.
The Sahaidachnyi Centre calls this the war that “does not exist”. This is a reference to how uninformed our public is about the objectives and scale of Russia’s aggressive clandestine operations. The clandestine war exists and it is escalating fast towards the next phase of operations. The question is whether NATO chooses to recognise it before the Kremlin begins the next phase of its military operations.
