(GREY ZONE FILE) Russia shifts from disruption to sabotage and pressure below the threshold of war

Sep 25, 2026 | ANALYSIS, GEOPOLITICS, HYBRID THREATS, NEWSLETTER, SECURITY & DEFENSE

By CIVIL | Hybrid Threats Monitoring

IN BRIEF — Russia’s hybrid campaign is becoming more selective and more closely tied to infrastructure that supports Ukraine. | Ambiguity is part of the strategy: uncertain attribution delays responses, fuels political disputes and raises the cost of defending critical infrastructure. | The broader objective appears to be coercive rather than conventional, to make support for Ukraine seem increasingly dangerous and politically costly for European societies. | The risk of a direct Russian attack on NATO remains low in the near term, but sabotage, cyber operations, information warfare and limited tests of alliance cohesion are becoming more significant. | For North Macedonia and the Western Balkans, the political and information risk is substantial, especially where external influence operations can be amplified by domestic political and media actors.

Russia’s pressure campaign against Ukraine and its European supporters appears to be entering a more dangerous phase. The pattern is shifting from broad disruption and relatively low-risk sabotage toward more selective operations against infrastructure directly connected to military logistics, communications, defence production and the economic networks sustaining Ukraine.

The emerging objective is not necessarily to provoke a conventional conflict with NATO. A more plausible purpose is coercive: to create enough physical danger, economic cost and political uncertainty that European governments begin limiting their own support for Ukraine.

Recent developments in Germany, Poland and Ukraine, combined with increasingly explicit warnings from European intelligence services, suggest that what happens inside Ukraine and what happens across Europe should no longer be viewed as entirely separate security theatres.

From sabotage to strategically selected targets

The attempted attack at Leipzig/Halle Airport is the clearest recent example.

On 1 September, the German government formally attributed the 4 August incident to Russia, saying police investigations, intelligence findings, the target, technical expertise and operational pattern supported the attribution. German authorities had discovered a drone carrying explosives at the airport, one of Europe’s largest cargo hubs and a strategically important site for military transport. Criminal proceedings remain ongoing, meaning the political attribution and the judicial process should still be distinguished.

The choice of location matters. Leipzig/Halle hosts Ukrainian Antonov heavy-lift aircraft and supports NATO’s Strategic Airlift International Solution programme. Reporting after the incident indicated that the explosive drone had been discovered close to Ukrainian cargo aircraft and that the airport plays a significant role in military logistics.

The incident therefore represents more than another unexplained drone sighting. An operation capable of causing casualties or disabling a major logistics hub would narrow the distance between “hybrid activity” and physical attack without necessarily crossing the threshold of an overt Russian military strike on NATO territory.

A second case emerged in Poland on 23 September, when fire broke out at a Starlink ground station in Wola Krobowska, south of Warsaw. Polish Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski said the fire appeared deliberate and described the method as consistent with Russian hybrid activity. But responsibility has not yet been conclusively established, and Polish investigators are still examining the cause. The facility carries internet traffic through Poland, including communications serving Ukraine.

That distinction is important. A broader Russian sabotage campaign can be real without every fire, malfunction or security incident being Russian-directed. Over-attribution would itself produce some of the effects such a campaign seeks: fear, confusion, declining institutional credibility and pressure for increasingly restrictive security measures.

Ukraine and Europe are becoming part of the same operational system

At the same time, Russia has intensified its campaign against Ukraine’s economic infrastructure.

Railways, ports, warehouses, steel plants, fuel infrastructure and commercial logistics have increasingly come under attack. The pattern suggests an effort not simply to damage military targets but to degrade the wider economic system that allows Ukraine to continue functioning during a prolonged war.

Ukraine’s railway network has been hit repeatedly, while port and border infrastructure in the Odesa region has suffered sustained attacks. Ukrainian officials reported around 1,500 attacks on railway infrastructure during 2026 by mid-September, alongside extensive strikes on ports, vessels and transport corridors.

Russia has also rapidly expanded the use of jet-powered attack drones. Reuters reported that during the first three weeks of September Moscow launched about 2,100 jet-powered drones and 136 missiles against Ukraine. Ukrainian Air Force spokesperson Yurii Ihnat said Ukraine was intercepting only about 60 percent of the faster jet-powered models, compared with more than 90 percent of earlier propeller-driven variants. The newer drones can fly substantially faster and at altitudes beyond the effective reach of many mobile air-defence teams.

This creates an important economic asymmetry. Relatively inexpensive attack drones can force defenders either to accept greater penetration rates or to use scarce and much more expensive air-defence systems against them. The problem is therefore not simply technological. It becomes a contest over ammunition stocks, industrial capacity and the cost of sustaining protection over time.

The attacks inside Ukraine and the security incidents in Europe point toward a wider contest over the infrastructure that enables Ukrainian resistance. Inside Ukraine, Russia can target production, transport and economic activity directly. Outside Ukraine, the threshold is different, but communications nodes, airports, defence factories and logistics networks can still be disrupted through sabotage, cyber operations or deniable intermediaries.

Ambiguity as a weapon

European intelligence officials increasingly describe a similar evolution. On 24 September, Denmark’s Defence Intelligence Service assessed that Russia is likely to escalate its hybrid campaign against NATO and the West in the coming months. It described the risk of limited Russian military attacks against a NATO country as low but rising, while judging a full-scale invasion unlikely.

Other European intelligence chiefs differ over how imminent a limited military test might be. Czech intelligence chief Michal Koudelka has publicly raised the possibility of a limited incursion, drone or missile attack, while Latvian security chief Normunds Mežviets has said there are no indications of an imminent attack and warned that exaggerated public fear could itself assist Russian psychological operations.

Where there is considerably more agreement is on sabotage. Swedish, Latvian and Czech intelligence officials have described a move away from relatively random arson and disruption toward railways, defence companies and infrastructure linked to assistance for Ukraine.

This is where ambiguity itself becomes a weapon, creating an operational advantage.

Open military aggression creates relatively clear political consequences. Sabotage creates arguments: Was the incident deliberate? Who ordered it? Is the evidence sufficient for public attribution? Does it justify sanctions, countermeasures, NATO consultations or something stronger?

Russia does not need to organize every suspicious fire or infrastructure failure for that environment to impose costs. Once a credible sabotage campaign exists, intelligence and law-enforcement services must investigate subsequent incidents as potential national-security threats. Resources are consumed even when an event eventually proves accidental.

The attribution gap therefore becomes part of the vulnerability. A covert operation can take minutes; establishing responsibility to a standard that governments are prepared to defend publicly can take weeks or months.

Coercion through self-deterrence

The political objective may be even more important than the physical damage.

The message produced by such operations is not necessarily that Russia is preparing to invade Europe. It is that supporting Ukraine increasingly carries consequences at home: disrupted transport, damaged infrastructure, cyber incidents, higher security costs and potentially casualties.

The strategic effect is achieved if Europeans begin asking whether assistance to Ukraine is worth those risks.

This is a form of coercion through attempted self-deterrence. Rather than forcing NATO to change policy through conventional military superiority, Moscow can benefit if European governments restrict themselves because they fear escalation.

European intelligence officials have explicitly connected the intensification of sabotage with an effort to weaken public backing for Ukraine and divide NATO. The European Union similarly described the Leipzig attack as part of a wider Russian campaign aimed at undermining European security, resilience and support for Ukraine.

Physical and information operations can reinforce one another. Sabotage produces insecurity; propaganda provides an explanation for it. Kremlin-aligned narratives can then argue that NATO governments themselves created the danger by supplying Ukraine and that reducing support is the only path to “de-escalation”.

For democratic governments, this presents an unusually difficult communications problem. Denying genuine threats creates vulnerability. Exaggerating them can produce panic, political polarisation and precisely the self-deterrence an adversary may be seeking.

The distinction between a confirmed incident, an official attribution, an intelligence assessment and a plausible but unverified connection is therefore not semantic. It is part of national resilience.

Russia is also operating under constraints

None of this means Moscow possesses unlimited capacity. Russia continues to commit enormous military and financial resources to the war in Ukraine while also having to protect its own infrastructure from Ukrainian long-range strikes. European intelligence officials who warn of escalation also point to these constraints when explaining why a conventional attack on NATO remains unlikely in the near term. At the same time, the Russian economy is under growing pressure from the costs of sustaining the war, deepening financial imbalances and the increasing burden placed on banks and regional budgets, as former Ukrainian ambassador Oleksandr Levchenko argues in his analysis for CIVIL Today.

That is precisely why hybrid operations remain attractive. They offer Moscow a comparatively low-cost way of imposing disproportionate costs on European states while complicating attribution, political decision-making and escalation management within NATO.

Russia’s election and imported legitimacy

Russia’s September parliamentary election demonstrated another element of its influence architecture: the use of selected foreign “observers” to project international legitimacy around a tightly controlled electoral process. Independent monitoring was heavily restricted, while Russia also extended voting into occupied Ukrainian territories.

Among the foreign participants was Goran Dimov of North Macedonia, whom Russian state broadcaster Vesti Perm presented simply as an “international observer from North Macedonia” and quoted praising compliance with the law and the atmosphere at polling stations. Earlier Russian state and Russian-linked publications had presented Dimov as a “senior adviser” or member of the foreign-policy sector of the North Macedonian party Levica. Levica later told CIVIL Media that he held no function in the party, had not been sent to the event and did not represent its positions, but did not directly answer CIVIL’s separate question about whether he was a party member, as documented in a dossier published on 27 April 2026.

There is no evidence establishing why that political identification disappeared from the September coverage. The information effect, however, is evident: the more neutral label of an “international observer from North Macedonia” allows favourable individual statements to function as external validation. The broader mechanism is to restrict credible independent scrutiny while amplifying selected foreign voices that reinforce the image of international legitimacy.

What this means for North Macedonia and the Western Balkans

The immediate physical exposure of North Macedonia is lower than that of Poland, Germany or the Baltic states. The political and information dimension, however, is directly relevant.

North Macedonia joined the EU statement condemning the Leipzig/Halle incident and identifying it as part of Russia’s broader hybrid campaign.

That should place practical questions on the security agenda: whether airports, energy installations and military transport routes have been reassessed; whether institutions are prepared for destructive cyber incidents; whether security services are monitoring attempts to recruit local intermediaries; and how authorities would communicate an ambiguous incident without either concealing legitimate concerns or creating unnecessary alarm.

For the Western Balkans, the larger vulnerability lies in the interaction between external influence operations and domestic political actors. Russian messaging does not need to persuade entire societies. It can be effective if influential political, media or online actors translate an external security incident into arguments against NATO, the European Union or continued assistance to Ukraine.

This makes information resilience inseparable from physical security.

The next test may remain deliberately below the threshold of war

During the coming months, the most probable continuation of the current pattern is further pressure on defence production, railways, airports, communications systems and Ukraine-related logistics, combined with cyber operations and sustained attacks on Ukraine’s energy and economic infrastructure.

A more serious but still lower-probability scenario is a deliberately limited drone, missile or quasi-military incident on NATO territory designed not to start a conventional war, but to test political cohesion: how quickly allies agree on attribution, whether consultations produce concrete action and how much ambiguity is sufficient to delay a response.

The most important warning signs would therefore not consist of a single dramatic event. They would be clustering: repeated incidents affecting several Ukraine-support nodes; surveillance or unusual drone activity around strategic facilities; coordinated Russian narratives describing specific NATO infrastructure as legitimate targets; a shift from disposable criminal proxies toward more technically capable operators; and, above all, evidence of corresponding Russian military preparations near NATO territory.

The absence of large-scale force concentration, logistics buildup and other conventional military preparations would continue to weigh against an imminent Russian invasion. But it would not eliminate the danger of a smaller, deniable test.

That distinction is important. Russia does not need to defeat NATO militarily to achieve a strategic gain. It can benefit if Ukraine is progressively exhausted while European governments become more cautious, divided and politically constrained.

The most successful hybrid operation may therefore be one that causes comparatively little physical damage but produces a much larger political result: persuading Europeans to impose limits on themselves.

 


The CIVIL Hybrid Threats Monitoring (CHTM) team brings together members of CIVIL’s editorial and journalistic staff, working in cooperation with university professors specialising in security and defence, as well as independent analysts. Its work is entirely independent, carried out on a voluntary basis and supported by modest contributions from citizens across the Western Balkans, Europe and beyond.


YOUR SUPPORT TO CIVIL MATTERS.

Support independent journalism, democratic resilience, and the defense of freedom of expression. Help CIVIL counter disinformation, hybrid threats, and authoritarian influence.

Contribute NOW

Truth Matters. Democracy Depends on It