Since Russia’s full-scale invasion of Ukraine in February 2022, Russia has escalated its use of hybrid, asymmetric warfare across Europe, far beyond the former Soviet Union, where Russia historically focused its aggression. These tactics fall under a Russian military strategy known as New Generation Warfare (NGW). Insikt Group assesses that Russia is likely to escalate NGW tactics over the next two years, potentially culminating in a full-scale NGW campaign. Europe-based private and public sector entities are very likely at risk of physical and cyber sabotage as Russia deploys NGW tactics. Critical infrastructure entities in Europe are at high risk of being targeted, potentially resulting in data loss, physical damage to facilities, or injury or death of personnel.
Russian hybrid and sabotage activity is nothing new; asymmetric responses to perceived provocations by Russia’s adversaries date back to at least the Soviet Union, when such tactics were called “active measures.” These tactics differ from conventional, kinetic warfare. They do not involve troops moving across a country’s border or a state’s military dropping bombs on an adversary’s capital city. Instead, they are a complex kit of psychological, cyber, and physical tactics meant to achieve several key aims:
- Test the enemy’s defensive capabilities, as Russia evaluates whether to escalate aggression into a formal, kinetic conflict
- Degrade the enemy’s critical infrastructure
- Sow an environment of fear in the enemy’s government and population to degrade the enemy’s ability to respond
These tactics fall broadly under a strategy Russian military officials in 2013 termed “New Generation Warfare” (NGW). Insikt Group assesses that Russia started using NGW tactics in Ukraine during and after it annexed Crimea in February 2014; however, since Russia’s full-scale invasion of Ukraine in February 2022, Russia has escalated its use of these tactics across Europe, far beyond the former Soviet Union, where Russia historically focused its aggression.
The very rules of war have changed. The role of nonmilitary means of achieving political and strategic goals has grown and, in many cases, they have exceeded the power of force of weapons in their effectiveness.
Valeriy Gerasimov, Chief of the General Staff of the Russian Armed Forces
Quoted from the 2013 article in Military-Industrial Kurier, where Gerasimov laid out the New Generation Warfare strategy

Russia Using Varied Tactics, from Arson to Airspace Violations
Russia has used various tactics while employing NGW tactics across Europe, from influence operations to airspace incursions to physical sabotage operations.
Influence Operations: Russia has consistently launched influence operations to manipulate public opinion across Europe, and particularly in states Moscow likely views as Kyiv’s core European supporters: the UK, France, Germany, and Poland. These operations include Doppelgänger, Operation Overload, Operation Undercut, and CopyCop. They have often involved impersonating national and pan-European media outlets to disseminate Kremlin propaganda.
CopyCop Campaign Expansion (Late August 2026): The CopyCop disinformation network expanded further, continuing to impersonate localized news and fact-checking outlets across Europe — especially in France and Norway — using AI-generated text and voice clones.
Airspace Incursions: Starting in September 2025, suspected violations of NATO airspace by what are likely Russian drones or jets reached unprecedented levels. Insikt Group tracked 30 such violations between September 2025 and January 2026, compared to 23 suspected or confirmed violations between March 2022 and August 2025. The most commonly targeted countries have been Poland and Romania; however, violations have occurred outside of Russia’s historic sphere of influence, including in Germany, the UK, Denmark, and Norway.
Estonian Border Incursion (September 1, 2026): Estonian defense forces tracked multiple Russian drones near the Estonian border, including one that breached southeastern Estonian airspace. Ground air defenses went on high alert, and NATO F-16 jets stationed at Estonia’s Ämari Air Base were scrambled.
Territorial Waters Violations and Undersea Cable Targeting: Russia has increasingly used violations of NATO territorial waters and targeting of undersea cables to test NATO’s resilience, collect intelligence, and keep NATO in a reactive, defensive posture.
Neptun Deep Gas Field Drone Interception (August 20, 2026): Romanian authorities intercepted and destroyed an explosive-laden Russian surface maritime drone detected near the Neptun Deep offshore gas project in the Black Sea. Authorities determined the incident was meant to threaten offshore energy infrastructure and test NATO maritime response protocols.

Physical Sabotage Operations: Russia-nexus individuals and entities have increasingly used physical sabotage operations to degrade critical infrastructure in NATO territory, propagate a narrative that Western states cannot protect their populations from threats, and harm NATO’s ability to collectively respond to Russian aggression. These attacks often target civilian or dual-use critical infrastructure that directly or indirectly supports either European collective defense or Europe’s material support for Ukraine.
Leipzig/Halle Airport Drone Incident (August 2026): On September 1, 2026, the German government publicly blamed Russia for the alleged sabotage plot at Leipzig/Halle Airport, describing it as part of a broader pattern of hybrid activity in Europe. German police recovered drones carrying military-grade hexogen explosives designed to cause damage to cargo infrastructure. The Halle Airport is a key military and logistics hub for German military support for Ukraine.
Offensive Cyber Operations: Russian cyber activity directed at European targets has typically emphasized access-oriented operations, including attacks on internet-facing firewalls, virtual private networks (VPNs), email services, and web portals. These operations are likely intended to enable intelligence collection, operational reach, and long-term access rather than immediate disruption. Russian cyber activity has been broad in scope, targeting multiple regions and sectors.
Distributed Denial-of-Service (DDoS) and Access Operations in Norway (August 30, 2026): Russia-nexus cyber threat actors launched coordinated cyberattacks against Norwegian public sector infrastructure, forcing key government portals offline. Norwegian authorities termed the campaign a targeted effort to degrade Norway’s infrastructure in retaliation for Norway’s military support for Ukraine.
Select Metrics Related to Russian Hybrid Warfare in Europe
Airspace Incursions:
- 30 suspected violations between September 2025 and January 2026
- 23 suspected violations between March 2022 and August 2025
Physical sabotage operations:
- Four-fold increase between 2023 and 2024; 2025 is consistent with 2024
- Most commonly targeted states between January 2018 and June 2025: Germany, Estonia, Latvia, Lithuania, Poland
Russia Likely to Escalate Aggression in Near-Term, Potentially into Full-Scale NGW Campaign
Insikt Group assesses that Russian hybrid warfare in Europe has thus far been largely opportunistic, despite employing increasingly aggressive tactics. Over the next two years, Russian President Vladimir Putin is likely to escalate aggression across Europe, potentially coalescing the above-described tactics into a full-scale NGW campaign.
Putin likely sees fractured European unity and inconsistent US assistance to European collective defense efforts as offering him a finite window of opportunity prior to the 2028 US Presidential election, which could result in a US President more willing to commit US military and political resources to bolstering Europe’s defensive capabilities.
In contrast to Russia’s current hybrid warfare campaign — which we assess is largely opportunistic — a full-scale NGW campaign is likely to involve more frequent incursions and violations, multiple tactics used concurrently to strain NATO resources, and escalated aggression as detailed in the chart below. Russia would still be unlikely to seek permanent damage to European critical infrastructure or mass civilian harm, as Russia likely does not want to risk invoking NATO’s Article 5 common defense clause.
Indicators of Full-Scale NGW Campaign in Europe, Implications, and Recommendations
Indicators of NGW Campaign
Implications for Public & Private Entities
Recommendations
Convergence of narratives across propaganda outlets
Public Sector: Increased political polarization; reduced public trust in government
Private Sector: Brand damage if firms are named in influence operations
Ensure information environment monitoring is attuned to Russia-nexus narratives
Lower altitude incursions, perhaps with transponders turned off
Private Sector: Disruptions in business operations
Ensure joint civil-military air incident protocols are in place, including aviation alerts
Territorial Waters Violations & Targeting of Undersea Cables
Non-compliance with escorts or hails
Private Sector: Operational losses for telecommunications, finance, and other key sectors, should undersea cables be cut
Ensure port-state coordination and physical hardening of cable landing sites
Targeting of civilian sites, such as shopping malls or residential neighborhoods
Concurrent sabotage operations and airspace violations to maximize disruption
Private Sector: Facility loss or damage; threat to worker safety; supply chain interruption
Ensure physical security measures are in place, including perimeter detection, anti-drone measures, and so on.
Enhance public-private partnerships and rapid liaison channels with law enforcement and intelligence services
Offensive Cyber Operations
Intrusions and DDoS activity spikes during politically significant events
Private Sector: Elevated risk of disruption for key logistics, transport, rail, and aviation systems
Coordinate with the national Computer Emergency Response Team (CERT) and National Counterintelligence and Security Center (NCSC)

In February 2026, Insikt Group published an in-depth assessment of how Russia employs New Generation Warfare tactics across Europe and what escalated aggression might look like. This report includes indicators of escalated aggression and recommendations for European public and private entities.
Preparing for Russia’s New Generation Warfare in Europe
About Insikt Group®
Recorded Future’s Insikt Group, the company’s threat research division, comprises analysts and security researchers with deep government, law enforcement, military, and intelligence agency experience. Its mission is to produce intelligence that reduces risk for customers, enables tangible outcomes, and prevents business disruption.

