Recent developments in Russia’s hybrid warfare campaign can be characterized by a widening range of tactics, spanning maritime sanctions evasion, coercive signaling at sea, drone pressure around NATO’s borders, disinformation, and covert action in Europe. Where earlier iterations of Russian hybrid activity relied heavily on covert influence operations and deniable proxy actions, the current campaign is marked by a willingness to operate closer to the surface. Shadow fleet vessels have been identified in Baltic shipping lanes, Russia-linked drones have penetrated NATO airspaces, and Russian influence networks have continued targeting foreign political systems while European governments expose covert plots linked to Russian services.
Taken together, these activities represent a strategy of calibrated escalation designed to impose costs on NATO members, erode public confidence in Western institutions, and exploit the space below the threshold of a formal military response. The breadth and simultaneity of activity across so many domains suggests deliberate strategic coordination rather than opportunistic escalation, indicating that Russia has meaningfully adapted its hybrid toolkit in response to Western support for Ukraine.
Shadow Fleets and Maritime Sanctions Evasion
Russia has maintained its use of shadow fleet vessels as a method of aggression. In March, a Russia-linked fuel tanker drifted near Italian islands, causing security concerns due to its fuel load, while explosions aboard a separate shadow fleet tanker off the Italian coast raised sabotage suspicions. The shadow fleet’s role in potential undersea infrastructure sabotage has also continued. In May 2026, Russian-flagged tanker Saga was detected loitering above a subsea cable network near Crete, raising suspicions, though no damage has been confirmed. Enforcement has simultaneously tightened. Sweden reported that its coast guard has intercepted five ships this year that were either directly or indirectly linked to servicing Russian trade, including four foreign flagged vessels that were suspected of operating in Russia’s external commerce. In June 2026, the UK seized a sanctioned vessel accused of directly or indirectly supplying prohibited Russian oil. Switzerland also widened sanctions, including against foreign companies involved in maritime transport from countries such as Turkey, Azerbaijan, and the United Arab Emirates, underscoring the degree to which third-country shipping networks are now part of the enforcement picture.
Russia has escalated its rhetoric in response. Russian President Vladimir Putin has threatened mirror retaliation against countries seizing Russian ships or cargo, framed such actions piracy and robbery, and indicated any response would not be geographically limited to the waters where seizures occur. This serves a dual purpose, namely by recasting sanctions enforcement as unlawful coercion, while signaling to commercial operators, insurers, and port authorities that the risk now includes retaliation at sea as well as financial penalties. Even if Russia does not act on these threats, the generated uncertainty may overshadow enforcement decisions, which would represent a cost-free gain for Russia.
Drone Incursions Along NATO’s Eastern Flank
Russian-linked drone activity has continued to expose vulnerabilities on NATO’s eastern edge and has become one of the most active hybrid warfare instruments of 2026. In May, a Russian drone crossed the Romanian border and crashed near the city of Galați, while an August 2026 incursion marked the fourth unmanned aircraft to be destroyed over the country this year, reviving concerns about the security of the alliance’s frontier with the war zone. In a separate August 2026 incident, NATO aircraft shot down a diverted Ukrainian drone after it entered Latvian airspace near the Russian border, with air force personnel suspecting Russian interference diverted it into the region’s skies, triggering a multinational response including temporary precautions in Finland. Drone sightings have similarly been reported in Bulgaria and Germany, raising alarm about Russian escalation deeper into NATO territory. In August 2026, a drone bomb attack was investigated in Germany, which involved the placement of a quadcopter carrying plastic explosives next to a Ukrainian cargo plane at the major shipping and military hub of Leipzig airport. United States intelligence sources suspect Russia to be behind the incident, with DNA traces linking the incident to a 2024 Leipzig airport firebomb plot also orchestrated by suspected Russian-employed individuals. A second drone incursion was identified within Leipzig airspace on the same day as the drone bomb, causing an aircraft collision, while a third device was identified a day later flying over a Germany-based army installation carrying Patriot air-defense systems components. The continued drone incursions over Germany and other NATO countries caused Germany’s military chief, General Carsten Breuer, to issue a public warning that Russian drone activity is deliberately undermining and testing NATO defenses, citing that member nations are facing hybrid attacks daily. However, incidents have also been reported outside of NATO territory, with Moldova experiencing similar incidents in January and March 2026, indicating how war spillover is a threat to European nations regardless of membership status, and how such activity could double as a deliberate act to undermine Ukrainian support.
Russia is simultaneously scaling its strike infrastructure. Ten drone launch bases near the Ukrainian and Belarusian borders have been identified, comprising 59 launch rails and capacity for over 1,000 drones at a single site, suggesting deliberate capability building rather than improvised battlefield adaptation. Shadow fleet vessels are also strongly suspected of doubling as drone launch platforms, with incursions over NATO territory assessed as likely originating from ships operating in the Baltic and North Sea. This integration of maritime and aerial operations is one of the most significant tactical evolutions of 2026, allowing Russia to project drone capability closer to NATO territory without relying on fixed, targetable infrastructure.
Disinformation Campaigns and AI Generated Narratives
Russian influence operations have continued to expand in scale and sophistication. A sanctioned Russian government-backed influence unit was observed leaking fake documents that attempted to discredit Ukrainian President Volodymyr Zelenskyy, while a separate investigation found that Russia leveraged Ukrainian contract saboteurs to manufacture the appearance of an underground pro-Russia resistance, converting physical acts of sabotage into propaganda content. In March 2026, Latvia’s Defense Ministry detailed a coordinated Russia-backed disinformation campaign designed to discredit Latvia, Lithuania, and Estonia by falsely claiming the Baltic nations allow their territories to be used for Ukrainian attacks against Russia. The narratives were disseminated by Russian media outlets and Telegram channels citing the countries opened their airspace for Ukrainian drones, a claim that has been strongly denied. Other operations are reportedly using over 1,000 artificial intelligence (AI)-generated videos as part of a mass disinformation weapon, dubbed a ‘narrative kill chain,’ that tailors attacks per the target audience. Content directed against military personnel focus on discrediting military leadership and undermining Ukrainian advances on the battlefield, while civilian-targeted content attempts to push emotional fatigue, undermine trust in institutions, and encourage acceptance of Russian conditions. The shift to AI-generated content at industrial scale represents a qualitative change in Russia’s disinformation capacity, as it removes the need for human content production, and allows operations to be run at volumes that overwhelm the fact-checking and platform moderation infrastructure that Western governments have developed in response to earlier campaigns.
Election Interference in Europe and the US
Russia’s interference in European elections has been particularly active as election cycles continue across the region. Disinformation pushing pro-Russia narratives flooded information during elections in Bulgaria, Armenia, and Germany, with campaigns typically leveraging social media platforms to distribute coordinated narratives aimed at influencing voting outcomes. In August 2026, the Matryoshka operation was identified targeting the September Saxony-Anhalt regional elections in Germany, impersonating established media brands to spread fabricated allegations. The campaign is believed to be a continuation of activity attempting to interfere in the 2025 German federal election, in which Storm-1516 reportedly targeted leading candidates Robert Habeck and Friedrich Merz with fake videos alleging ballot manipulation. Both Matryoshka and Storm-1516 have also been identified running influence campaigns against former French prime ministers Edouard Philippe and Gabriel Attal, who are prominent candidates for France’s 2027 presidential election. The continuation of such operations and their convergence in running parallel campaigns across geographically and politically distinct targets not only points to centralized tasking but also provides example of persistent infrastructure that can be rapidly redirected toward new electoral environments as they emerge. Activity has also spread beyond European borders, with a US federal review of Russian election interference declaring an elevated threat of potential campaigns ahead of the November 2026 midterms, underlining that Russia continues to view electoral disruption in Western democracies as a strategic instrument rather than a purely regional concern.
Physical Sabotage of European Defense Supply Chains
Russia-linked covert activity in Europe has grown into an organized pattern of networked operations. The region has faced multiple deliberate attacks, including arson attempts and explosions across the Czech Republic, France, Bulgaria, Italy, Latvia, and others through 2026, impacting companies involved in the manufacturing of weapons, ammunition, drones, and other equipment designed for Ukraine. Western intelligence sources view the incidents as part of a Russia-backed campaign intended to disrupt military supply chains and test the depth in which Russia can operate within NATO territory without provoking a collective response. More recently on August 24th, 2026, Russian government advisor, Andrei Fedorov, claimed that ‘unknown sources’ may begin to target UK drone factories as part of a ‘semi-military’ response to UK Prime Minister Andy Burnham sharing blueprints for British cruise missile components with Ukraine. Such activities show a recurring pattern of the Russian Intelligence Service’s engagement of local criminals to provide Russia deniability, with individual incidents potentially resembling industrial accidents or being claimed by environmental, antimilitary, or activist movements.
A June 2026 European Parliament briefing separately highlighted Russian government ‘blacklists’ and intimidation tactics directed towards journalists, politicians, and activists across Europe who support Ukraine, framing the activity as a wider foreign interference architecture rather than isolated harassment incidents. Treating any single case in isolation risks misreading the cumulative strategic intent, which appears to be the steady erosion of European political will through covert pressure and the threat of violence on European soil. The broadening counterintelligence posture now required of pro-Ukrainian governments represents a sustained resource demand that may itself be part of Russia’s strategic calculus, with governments likely hesitant on directly attributing targeted incidents to the Russian government for fears of instigating escalation.
Closing Thoughts
Russia’s hybrid warfare campaign in 2026 reflects a deliberate and adaptive strategy that is growing more capable, more coordinated, and more difficult to counter. Across the examined domains, a consistent logic is visible. Russia seeks to impose costs on Western support for Ukraine, test and erode NATO cohesion, and undermine the domestic political conditions in European states that sustain that support, all while retaining sufficient deniability to avoid triggering a unified alliance response. What has changed in the current period is the degree of integration between these domains. The suspected use of shadow fleet vessels as drone launch platforms, the conversion of sabotage operations into disinformation content, and the synchronization of influence campaigns with electoral calendars all point to a more sophisticated operational architecture.
European governments and NATO members face a compounding challenge. Each individual incident may fall below the threshold of a decisive response, yet the cumulative effect is a sustained erosion of security, institutional trust, and political resolve. Addressing this will require not only tactical countermeasures in each domain, but a shared analytical framework that treats these activities as components of a single coherent campaign rather than a series of unrelated provocations.
To learn more about how Silobreaker can help monitor geopolitical landscapes and track state-backed operations, request a demo here.



