The Last Millimeter Before the War

September 1, 2026

On August 4, a worker at Leipzig airport found a drone beside a Ukrainian Antonov used for transporting military equipment; it carried explosives and a detonator. Ten days later another device appeared along with about fifty grams of military-use hexogen. The German investigation remains open and Berlin has not formally attributed the operation to Russia yet, although it is expected to do so imminently. However, this is what happened. Now we will focus on what could have happened. If the device had not failed, Europe could have woken up to a destroyed aircraft, a closed terminal and perhaps dead people.

That margin is the explanation of how Russia’s hybrid warfare has evolved in these years. The label “hybrid” was used to group together cyberattacks, influence campaigns, sabotage, electronic interference, espionage and operations through intermediaries years ago. However, in 2026, the term retains descriptive usefulness, but begins to create a political problem. One thing is to combine different instruments and another thing entirely is to use the word as if it also described the intensity. When a drone carries explosives alongside a military aircraft, a fire reaches a defense company or an intelligence service recruits third parties to attack people, its surname remains “hybrid” regardless of the type and the consequences. Camille Grand, former deputy secretary general of NATO, summarized it this summer by saying that Europe is in a hybrid war that increasingly has less of a hybrid character.

“One thing is to combine different instruments and another thing entirely is to use the ‘hybrid warfare’ as if it also described the intensity”

The difference with 2025 is clearer where there are comparable series. The Finnish regulator Traficom received 1,704 GPS interference reports in aviation during the whole of last year. By the end of July 2026 it had already accumulated 1,755. Seven months have outpaced twelve. On the other hand, Lithuania has observed a transformation in the infrastructure that makes that pressure possible. According to its regulator, Russia would have moved from 3 spoofing antennas (a kind of identity-spoofing cyberattack) in Kaliningrad at the start of 2025 to 36 in May 2026, with the capability to falsify signals up to about 450 kilometers. Electronic warfare is beginning to operate as a permanent territorial capability, capable of degrading air navigation, maritime traffic, mobile networks and civilian services across a large part of the Baltic region.

The spike in 2026 also appears in the targets. In August a facility used by Milrem Robotics in Estonia—maker of unmanned ground vehicles deployed in Ukraine—caught fire. Tallinn is investigating a possible Russian involvement. In Slovakia, police thwarted an assault on a drone factory and detained three foreigners with incendiary material. In the Black Sea, Romania destroyed a naval drone loaded with explosives just a few hundred meters from Neptun Deep, the gas project that aims to make the country the EU’s leading gas producer. Days earlier, a Spanish F-18 deployed with NATO’s air policing shot down over Romania another drone which, according to allied preliminary assessment, appeared to be Russian. Although degrees of attribution vary, there is a convergence in their logic. The pressure is moving closer to the military industry, Kiev’s support logistics, energy and allied forces on the eastern flank.

Moscow has also found a way to cheapen that proximity. The think tank International Institute for Strategic Studies (IISS) calls it the gig economy of intelligence operatives. In June, two men were convicted in the United Kingdom of arsons against properties linked to former prime minister Keir Starmer. They had been recruited via Telegram by a person connected to the Russian government. The expulsions of hundreds of Russian officials from European embassies complicated operating with professional personnel. In this way, the response has been to replace part of that infrastructure with vulnerable teenagers, criminals, supporters and remotely recruited third parties, paid for a specific task and disposable afterward.

The model changes the economics of sabotage. While an intelligence officer requires training, cover, secure communications and years of investment, a proxy only needs a phone, some instructions and money. A small commercial drone can force the closure of an airport whose protection demands radars, electro-optical sensors, electronic warfare, jammers and interceptors. After Leipzig, Germany accelerated the deployment of mobile anti-drone means at its eight major airports. In this sense, the attacker buys cheap scale and the defender buys expensive security. And it is precisely that cost relationship that allows multiple attempts to be made even if some fail.

“After Leipzig, Germany accelerated the deployment of mobile anti-drone means at its eight major airports. The attacker buys cheap scale and the defender buys expensive security”

Furthermore, technology widens the advantage. Some devices can operate via 4G or 5G mobile networks, reducing the usefulness of classical jamming. Proxies add more uncertainty, as they can target the wrong objective, exceed instructions or cause unforeseen casualties. The method that cheapens and distances the sponsor also raises the risk of accidental escalation. The easier it is to launch an operation, the harder it is to control the outcome. Sabotage-for-hire resembles the kamikaze drone: once launched, it is lost and replaced.

Europe responds to these intrusions at its own pace. While a fire takes minutes, investigating who bought the material, who opened a Telegram account, who paid and which Russian service was behind it can take months. The attacker moves at river speed and the democratic state at glacier speed, creating a temporal gap that must be understood as a strategic capability. In the interim, the incident is discussed as crime, vandalism, terrorism, espionage, sabotage, etc., and each label triggers different authorities, laws and responses. Within these administrative seams, Russian ambiguity runs wild.

For this reason, NATO has begun to close those gaps. In 2026 it has maintained Baltic Sentry and Eastern Sentry, created its ninth advanced land forces group in Finland, and eight Baltic allies have taken Task Force X-Baltic to a second phase to integrate unmanned maritime systems and persistent sensors. By the end of August, regional countries agreed to prepare a joint force for drone defense. The architecture improves mainly denial—i.e., detect, protect, intercept and recover. Nevertheless, punishment remains less automatic: the EU sanctioned in July nine Russian citizens and four entities of the cyber ecosystem and publicly named the 16th FSB Center for operations against several member states. Attribution and response to each specific attack remain slow and negotiated.

“While a fire takes minutes, investigating who bought the material, who opened a Telegram account, who paid and which Russian service was behind it can take months”

That is why it is essential to highlight the value of NATO Article 4. It is usually understood as the diplomatic prelude to Article 5, though its utility is more precise. It allows turning a threat still under discussion into a collective problem before there is agreement on whether an armed attack has occurred. The Alliance itself concedes that a hybrid operation or a cyberattack of sufficient gravity can trigger collective defense and that assessment will be made on a case-by-case basis. Moscow knows that formula, but the operational problem is figuring out exactly what “sufficient gravity” means.

Each incident yields information. A drone leaves traces such as its radar cover, while the cyber intrusion shows how long a government takes to isolate a network. Likewise, sabotage reveals when the matter leaves police jurisdiction and enters intelligence. Pekka Toveri, a Finnish MEP, said: “Putin decides alone, while the North Atlantic Council always needs time.” The hybrid problem thus begins to be also a problem of decision latency.

Europe detects more and intercepts earlier, but punishment remains less predictable. A lost consumer drone costs little and a detained proxy can be replaced, just as when a Telegram account disappears another appears. When the consequence arrives months later through sanctions or public attribution, the investigation can be impeccable and its deterrent capacity quite lower. The EU is trying to shorten that gap. France, traditionally prudent with attribution, has also hardened its language. Its services acknowledged this summer that illegal drone overflights of military installations and defense companies had doubled compared with late 2025.

“A lost consumer drone costs little and a detained proxy can be replaced, just as when a Telegram account disappears another appears”

We can see that the attacker works at tactical speed and the democratic state at evidentiary speed. The river against the glacier and its consequent strategic advantage. While Europe debates whether a fire was vandalism, espionage or sabotage, Moscow may already have obtained the information it sought. That is why attention should be paid to the August warnings about a possible false-flag operation. U.S. and European sources have pointed to scenarios in which Russia could use a Ukrainian drone or one presented as such to provoke an incident on allied territory. On August 10, Reuters reported that Poland, Estonia, Latvia and Lithuania were physically strengthening dams, power plants, gas facilities and other critical infrastructure. In this way, the hypothesis has moved from the realm of prospective analyses to conditioning real domestic security deployments.

Spain in the hybrid coordinates

Spain enters that map more naturally than its geography would suggest. On August 16, a Spanish F-18 deployed in Romania shot down a drone that had penetrated Romanian airspace, the fourth incursion recorded there in 2026. Meanwhile, the National Security Annual Report places submarine cables among infrastructures exposed to hybrid threats, and the Navy regularly monitors ships linked to the Russian dark fleet. Physical distance protects less and less when Spanish defense is deployed in the East and communications, energy and logistics depend on networks that traverse the whole continent.

Russia does not hold the monopoly on these tools either. Iran uses criminal networks and proxies, China relies on intermediaries for technological espionage, influence and transnational repression. The Russian singularity lies in its integration with an open conventional war. The burning of a European factory, interference with a navigation signal and the destruction of a Ukrainian storage facility belong to distinct legal categories, but they can respond to a single operational logic.

Perhaps that is the fundamental change of 2026. Europe has spent years trying to determine where peace ends and war begins. Conversely, Russia seems more interested in measuring how far the space between the two can be distorted. Jean Monnet wrote that “Europe will be forged in crises and will be the sum of the solutions adopted to those crises.” The Russian campaign adds another layer to this question. Europe may also end up becoming the sum of the responses it did not dare to give because a red line that the adversary can measure, probe and move attack after attack ends up looking less like a border and more like an invitation.

Natalie Foster

I’m a political writer focused on making complex issues clear, accessible, and worth engaging with. From local dynamics to national debates, I aim to connect facts with context so readers can form their own informed views. I believe strong journalism should challenge, question, and open space for thoughtful discussion rather than amplify noise.