> ## Content Index
> Fetch the complete content index at: https://www.adriadefense.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# European Intelligence Warns Russian Hybrid Threat Is Rising
- URL: https://www.adriadefense.com/european-intelligence-warns-russian-hybrid-threat-is-rising/
- Published: 2026-09-23T07:00:53.000Z
- Updated: 2026-09-23T07:00:52.000Z
- Description: Czech, Latvian and Swedish intelligence assessments point to rising Russian sabotage, cyber and influence activity across Europe, while differing on escalation risks.
- Author: AdriaDefense Desk
- Tags: Russia, Czech Republic, Latvia, CEE, Intelligence, Sabotage

European intelligence services are warning that Russian hybrid activity against NATO countries could intensify as Moscow shows a greater willingness to use sabotage, cyber operations, influence campaigns and recruited proxies across Europe. Recent assessments from Czech, Latvian and Swedish security officials point to an increasingly aggressive pattern, although Baltic intelligence services continue to assess the probability of an open conventional Russia-NATO conflict as low. 

The assessments place Central and Eastern Europe at the center of a security problem that increasingly falls between traditional espionage and conventional military defense. Czech counterintelligence has documented Russian recruitment of agents for potential sabotage, while Latvia reported on September 18 that the number and scale of Russian unconventional attacks had increased in recent months. 

## Czech intelligence tracks Russian recruitment for sabotage

Michal Koudelka, director of the Czech Security Information Service, or BIS, was among the European intelligence chiefs interviewed by The Guardian about Moscow's evolving activities. The officials described concern that Russia could pursue more consequential actions against European states as part of an effort to test NATO cohesion. 

BIS's own 2025 annual assessment provides a more detailed picture of the methods Czech counterintelligence has identified. Koudelka said Russian hybrid activity ranged from disinformation and propaganda to cyberattacks, traditional intelligence operations and the recruitment of what the Czech service calls Telegram agents who could conduct sabotage in the Czech Republic and elsewhere in Europe. 

The use of locally recruited operatives reduces Moscow's dependence on intelligence officers operating under diplomatic cover. It can also complicate attribution because recruits may have limited or no formal connection with Russian state institutions.

Sweden's Security Service, Säkerhetspolisen, has identified a similar model. Its 2025-2026 threat assessment says Russia increasingly uses disposable agents recruited online for individual assignments, with money often serving as the principal motivation. 

The Swedish assessment says this model provides Russia with greater plausible deniability while allowing operations to continue despite European restrictions on Russian intelligence personnel.

## Latvia sees more unconventional Russian attacks

Latvia's Constitution Protection Bureau, or SAB, published an updated security assessment on September 18, only days before the latest intelligence warnings became public.

SAB said the number and scale of Russian unconventional attacks had increased in recent months. The Latvian service expects Moscow to continue using hybrid methods against NATO members, including information and influence operations and cyberattacks. 

However, Latvia's assessment introduces an important distinction between hybrid escalation and conventional war.

SAB continues to assess the probability of an open conventional military confrontation between Russia and NATO as low in the short and medium term. It expects the Kremlin to maintain a confrontational relationship with NATO and Western countries while using threats of escalation, hybrid operations and other measures below the threshold of conventional conflict. 

Estonia has reached a comparable conclusion on the immediate military threat. The Estonian Foreign Intelligence Service's 2026 assessment says Russia does not currently intend to attack Estonia or another NATO member militarily during the coming year, while warning that Russia's military reforms will strengthen its capabilities over the longer term. 

The distinction matters for interpreting warnings that Russia could test NATO. European intelligence assessments do not establish that Moscow has decided to launch a conventional attack against the alliance. They point instead to growing concern about activities that can impose costs, create uncertainty or test political responses while remaining below the threshold of open war.

## Sabotage and proxies complicate NATO's response

Hybrid operations present a different deterrence problem from a conventional military attack because attribution can take time and responsibility can remain deliberately obscured.

Potential operations can include cyberattacks, arson, sabotage of infrastructure, influence campaigns, espionage, drone activity and operations conducted through recruited intermediaries. Different incidents also carry very different levels of evidence linking them to a foreign state.

Swedish security authorities have cautioned against automatically attributing suspicious infrastructure incidents to Moscow. Säkerhetspolisen has investigated suspected sabotage involving telecommunications infrastructure, water facilities and other targets and concluded in multiple cases that a foreign state was not responsible. 

At the same time, Sweden considers the Russian sabotage threat real and says targets affecting Western support for Ukraine receive particular attention. The Swedish service assesses that Russian hybrid activity in Europe has become increasingly offensive. 

The distinction between confirmed Russian operations and unexplained incidents is particularly important as drone sightings, infrastructure failures and cyber incidents generate growing security concern across Europe.

## Russian intelligence operations extend beyond sabotage

The hybrid campaign is not limited to physical disruption.

On August 10, Sweden disclosed that Säkerhetspolisen had disrupted an intelligence operation directed by Russia's Foreign Intelligence Service, or SVR. Swedish authorities said the operation sought information about decision-making that could support influence activity and undermine Sweden, NATO and the European Union. 

The case involved an agent connected to a foreign diplomatic mission in Sweden and demonstrated that Moscow continues to combine traditional human intelligence methods with influence operations.

Czech intelligence has similarly described Russian activity as a combination of conventional espionage, cyber operations, disinformation and recruitment of individuals capable of conducting actions on the ground. 

These methods allow Russian services to adjust the scale and visibility of individual operations. A cyber intrusion, influence campaign or proxy sabotage operation can generate political and economic effects without requiring conventional Russian military forces to cross NATO borders.

## CEE becomes a frontline for counterintelligence

Central and Eastern European states face particular exposure because of their geography, military support for Ukraine and role in moving personnel and equipment toward NATO's eastern flank.

The intelligence challenge increasingly overlaps with defense planning. Protecting transport networks, military installations, defense manufacturers, energy infrastructure and communications systems requires coordination between armed forces, intelligence services, police, cyber agencies and private operators.

For NATO governments, the central issue is therefore not only whether Russia could eventually mount a conventional military challenge. European intelligence reporting increasingly points to a parallel contest already taking place through espionage, sabotage, cyber operations, influence activity and deniable proxies. 

The Czech, Latvian, Swedish and Estonian assessments differ on how quickly the threat could escalate and on the probability of direct military confrontation. They converge more clearly on another point: Russian intelligence and security services continue to conduct hostile activity against European states, and hybrid methods are likely to remain a central part of that effort. 

## Russian hybrid operations in Europe: key questions

### What are European intelligence agencies warning about?

European security services are reporting Russian espionage, cyberattacks, influence operations, sabotage activity and recruitment of proxy operatives. Czech BIS has specifically identified recruitment through Telegram for potential sabotage operations, while Swedish intelligence describes increasing Russian use of disposable agents. 

### Do intelligence agencies expect Russia to attack NATO?

The public assessments are more nuanced. Latvia's SAB assesses the probability of an open conventional Russia-NATO confrontation as low in the short and medium term, while Estonia's Foreign Intelligence Service says Russia does not currently intend to militarily attack a NATO member during the coming year. Other European officials have warned that Moscow could attempt more limited provocations or hybrid actions intended to test NATO's response. 

### How does Russia recruit operatives for sabotage?

Czech and Swedish security services say Russia increasingly recruits individuals online for individual operations. Sweden describes some of them as disposable agents who may be motivated primarily by money and have no long-term role in Russian intelligence structures. 

### Why is Central and Eastern Europe particularly exposed?

CEE countries host NATO forces and infrastructure, provide substantial support to Ukraine and sit along key military and logistics routes on the alliance's eastern flank. Their intelligence and security services are consequently monitoring Russian espionage, cyber, influence and sabotage activity alongside conventional military threats.