NATO reports significant increase in hybrid Russian attacks on alliance states
Quick Look
- NATO has seen a significant increase in Russian hybrid attacks on member states, with over 200 recorded incidents last year, excluding everyday cyberattacks.
- A senior official in Brussels warned of increasing severity and riskiness of the attacks and announced measures such as a new critical energy infrastructure network to increase deterrence and protect support for Ukraine.
AI-generated summary
Why It Matters
NATO classifies covert hostile actions below the threshold of an overt military attack as a hybrid attack, including sabotage, cyberattacks and disinformation campaigns. The aim is often to weaken a state, create uncertainty and achieve political or military goals without triggering a classic war.
According to information from the military alliance, the number of hybrid attacks by Russia on NATO states is increasing significantly. Last year alone, more than 200 were recorded. This does not include everyday cyber attacks, explained a senior NATO official in Brussels. There are thousands of these every month against NATO headquarters alone.
Regarding the case of the explosive drone at Leipzig/Halle Airport, the NATO representative said that, in his opinion, the explosives found indicated that a Russian secret service was directly involved. “Semtex isn’t something you hand out to some kid you recruited while playing video games,” he said.
Preparing for further escalation?
Like the German government, NATO classifies the incident as a hybrid attack, despite the fact that there was ultimately no explosion. This usually refers to covert hostile actions below the threshold of an open military attack, such as sabotage, cyber attacks or disinformation campaigns. The aim is often to weaken a state, create uncertainty and achieve political or military goals without triggering a classic war.
According to NATO's assessment, Russia's goal is, among other things, to undermine political and practical support for Ukraine and to prepare for possible further escalation. This includes, for example, scouting out critical infrastructure and logistics chains as well as pre-positioning malware in important industrial control systems.
NATO is particularly concerned about a change in the quality of attacks. “The number is increasing, the severity is increasing and the willingness to take risks is increasing,” the official said. This also increases the risk of victims among citizens of the alliance states. For NATO, it is currently a matter of remaining calm and increasing deterrence. This involves military measures, but also about reducing the incentive for attacks through effective protection of the infrastructure.
Energy networks should receive better protection
Specifically, according to the information, a new network for critical energy infrastructure (Critical Energy Infrastructure Network) is to be set up. This is intended to exchange safety-relevant information with operators. Joint emergency exercises and support, for example in drone defense and cyber defense, are also planned. The already created network for underwater infrastructure should serve as a model. According to the official, this has led to a significant decrease in security-related incidents.
According to the NATO representative, the defense alliance can react in various ways in the event of particularly serious hybrid attacks. For example, the commander in chief of the NATO armed forces even has the opportunity to ask alliance states to use offensive cyber capabilities.
What to Watch
AI outlook — possibilities, not facts
NATO will set up the Critical Energy Infrastructure Network in the coming months and conduct the first joint emergency exercises.
Likely · Within months
Russia will continue to increase its hybrid attacks against NATO countries in terms of frequency, severity and risk tolerance.
Likely · Within months
Open Questions
- What concrete evidence points to the direct involvement of a Russian secret service in the Leipzig/Halle incident?
- How exactly does NATO plan to exchange security-related information in the new Critical Energy Infrastructure Network?
- What specific offensive cyber capabilities could NATO countries deploy in the event of a serious hybrid attack?


