
When I look at the security situation in Europe today, I do not see peace in the traditional sense. I see a conflict already underway that does not look like a conventional war. There are no large troop movements across borders, no declared battles, no formal front lines. But there are fires, explosions, disrupted communications, damaged infrastructure, and a steady stream of incidents that, taken together, form a clear pattern.
This is Russia’s unconventional war on Europe. It is a campaign of sabotage, subversion, and hybrid aggression designed to weaken Western resilience, fracture political unity, and undermine support for Ukraine without triggering a full-scale military response from NATO or the European Union.
The numbers tell an important part of the story. According to research from the International Institute for Strategic Studies (IISS), the number of Russian sabotage operations in Europe almost quadrupled from 2023 to 2024. Confirmed sabotage against European critical infrastructure increased by 246 percent over the same period. In 2024 alone, more than 30 incidents were recorded, targeting transportation networks, government facilities, energy systems, communications infrastructure, and defense-related industry.
This is not a random collection of criminal acts. It is a deliberate strategy rooted in Russian military doctrine and executed by state intelligence services, primarily the GRU. The objective is not to win a single battle but to erode the foundations of European security over time.
The doctrine behind the sabotage
To understand why Russia uses sabotage so extensively, you have to understand how Russian strategists think about conflict. In Moscow’s view, war does not begin with the first shot. It begins long before, through political pressure, economic coercion, disinformation, cyber operations, espionage, and targeted acts of violence that can be difficult to attribute.
Russian military doctrine explicitly integrates sabotage of critical national infrastructure into its concept of hybrid warfare, known in Russian as gibridnaya voyna. The doctrine allocates a 4:1 ratio of non-military to military tools, meaning the majority of the struggle is intended to take place in the shadows rather than on the battlefield.
This approach is designed to exploit the legal and political constraints of democratic societies. European governments must operate within the rule of law, respect civil liberties, and maintain public support. Russia does not face the same constraints. It can use covert action, criminal networks, and proxy actors to disrupt while maintaining plausible deniability.
The result is a form of aggression that is intentionally ambiguous. An explosion at a railway depot could be an accident. A fire at a warehouse could be electrical failure. A ship’s anchor could cause a damaged undersea cable. This ambiguity is not a bug in the system. It is the feature.
Russian doctrine intentionally blurs the lines between war and peace, making it challenging for European governments to detect, attribute, and respond to such aggression. The goal is to remain just below the threshold that would trigger Article 5 of the NATO treaty or a unified EU response.
The targets: critical infrastructure at the center
The IISS report makes clear that Russia’s sabotage campaign focuses heavily on European critical infrastructure (ECI). This includes energy grids, pipelines, ports, railways, airports, undersea fiber-optic cables, water systems, and industrial facilities.
The logic is straightforward. Modern societies depend on interconnected systems. Disrupt one node, and the effects ripple outward. A damaged rail line delays military shipments. A severed undersea cable interrupts communications. A fire at a defense contractor’s facility slows production. A power outage affects hospitals, businesses, and public confidence.
According to the CSIS database of Russian sabotage activity, roughly 21 percent of attacks targeted critical infrastructure such as pipelines, undersea cables, and the electricity grid. Another 27 percent targeted transportation, 27 percent targeted government and military sites, and 21 percent targeted industry, including defense companies.
Germany has been the most affected country, with 58 incidents recorded, followed by Belgium, Denmark, and the Netherlands. But the campaign is not limited to Western Europe. Incidents have been reported across NATO and EU member states, from the Baltic region to Southern Europe.
The timing is also significant. The sharp rise in sabotage operations coincided with Russia’s full-scale invasion of Ukraine in February 2022 and spiked in 2023 and 2024. This suggests that sabotage is not a side effect of the war in Ukraine. It is an integral part of Russia’s broader strategy to weaken Western support for Kyiv and test European resolve.
The methods: how the sabotage is carried out
Russian sabotage operations use a variety of methods, often chosen for their simplicity and deniability. The CSIS database identifies explosives, blunt or edged instruments (such as anchors), arson, electronic attack, and physical vandalism as the main weapons and tactics.
Some incidents involve sophisticated planning. Others appear opportunistic. What they share is a focus on creating disruption rather than mass casualties. This is important because it reduces the likelihood of a strong retaliatory response.
Consider a few examples:
- Railway sabotage: Fires and explosions at rail depots and along freight lines have disrupted logistics networks used for military and civilian shipments. In some cases, tracks have been damaged or signaling systems tampered with.
- Undersea cable damage: Multiple incidents of damaged or severed undersea communications and energy cables have raised concerns about the vulnerability of critical seabed infrastructure. While some damage may be accidental, the pattern suggests deliberate targeting.
- Warehouse and industrial fires: Fires at logistics centers, defense-related facilities, and industrial sites have caused significant economic damage and operational delays.
- Airport disruptions: Explosive devices or suspicious packages have led to flight cancellations, evacuations, and heightened security alerts at civilian airports.
- Energy infrastructure: Attacks on pipelines, substations, and energy facilities threaten to disrupt power supplies and increase economic costs.
These methods are not new. What is new is the scale, coordination, and frequency. The IISS data shows that the number of significant, verified hybrid attacks against Europe in the first half of 2025 was approximately one-third of the total recorded for 2024, a year that saw a peak in such incidents. This could indicate a slowdown, or it could mean that many assaults have not yet been confirmed.
The strategic purpose: weakening resilience and unity
Russia’s sabotage campaign is not intended to conquer territory in Europe. It is intended to create a different kind of victory: a Europe that is too divided, too exhausted, and too uncertain to maintain strong support for Ukraine or to present a unified front against Russian aggression.
This strategy targets three key areas:
1. Public confidence
Every fire, explosion, or disruption feeds a narrative that European governments cannot protect their own citizens. Over time, this erodes trust in political leadership and security institutions. It also creates space for disinformation campaigns that blame NATO, the EU, or Ukraine for the instability.
2. Political unity
European governments have struggled to forge a unified response to Russian sabotage. Some member states perceive the threat differently. Some prioritize economic ties with Russia. Others worry about escalation. This divergence makes it difficult to coordinate actions, establish effective deterrents, or impose adequate penalties on Moscow.
The IISS paper notes that EU member states lack a shared threat perception, the EU lacks a responsible political entrepreneur with sufficient impetus, and a diversity of procedures complicates decision-making across policy areas relevant to security and defense.
3. Economic and military capacity
Sabotage imposes real costs. Repairing damaged infrastructure, increasing security measures, and investigating incidents all require resources. Defense companies face delays. Energy supplies become less reliable. Transportation networks operate below capacity. These effects may seem small individually, but they accumulate.
Russia does not need to cripple Europe’s economy. It only needs to make the cost of supporting Ukraine appear too high.
The policy challenge for European governments
The central challenge for European governments is that Russian sabotage operates in the “gray zone” between peace and war. Traditional tools of deterrence and defense are not well suited to this environment.
Military forces are designed to respond to clear acts of aggression, not to a series of ambiguous incidents that can be explained as accidents or criminal acts. Law enforcement agencies can investigate and prosecute individuals, but they cannot easily attribute actions to a state actor without intelligence that may be classified. Diplomatic responses, such as expelling diplomats or imposing sanctions, often come too late and lack sufficient impact.
The IISS report notes that European capitals have encountered difficulties in responding effectively to Russian sabotage activities. They have struggled to coordinate actions, establish effective deterrents, and impose adequate penalties on Moscow.
This is compounded by the fact that Russia’s campaign is decentralized and hard to attribute. Operations may be carried out by GRU officers, contracted criminals, recruited locals, or unwitting accomplices. The chain of command is obscured. Evidence is often destroyed or never collected.
What a European response could look like
A meaningful response requires more than reactive measures. It requires a shift in how European governments think about security, deterrence, and resilience.
1. Improved detection and attribution
European governments need better intelligence-sharing, forensic capabilities, and analytical resources to detect sabotage early and attribute it accurately. This includes investing in physical security monitoring, cyber-physical systems protection, and cross-border cooperation between law enforcement and intelligence agencies.
Public attribution is also important. When governments can confidently identify Russian involvement, they should say so clearly. Silence creates space for denial and disinformation.
2. Hardening critical infrastructure
Critical infrastructure must be treated as a strategic asset, not just an economic one. This means:
- Increasing physical security at key sites.
- Improving redundancy in energy, communications, and transportation networks.
- Conducting regular vulnerability assessments.
- Developing rapid response protocols for sabotage incidents.
- Protecting undersea cables and seabed infrastructure through surveillance and international cooperation.
3. Legal and regulatory tools
European governments can strengthen legal frameworks to prosecute sabotage, espionage, and foreign interference more effectively. This includes:
- Expanding the definition of sabotage to cover hybrid tactics.
- Enhancing penalties for state-sponsored criminal activity.
- Improving screening of foreign investments in critical sectors.
- Strengthening export controls on dual-use technologies.
4. Deterrence and costs
Deterrence in the gray zone requires imposing costs that matter to Moscow. This could include:
- Coordinated sanctions targeting individuals and entities involved in sabotage.
- Expelling intelligence officers operating under diplomatic cover.
- Disrupting Russian financial networks used to fund operations.
- Supporting Ukrainian defense efforts to raise the cost of aggression.
5. Public communication
Governments must communicate clearly with their citizens about the nature of the threat without causing unnecessary panic. Transparency about incidents, when possible, helps counter disinformation and builds public support for necessary security measures.
The broader strategic picture
Russia’s sabotage campaign is part of a larger strategy that includes cyber operations, disinformation, political interference, economic coercion, and military posturing. The goal is not to win a single conflict but to reshape the European security environment in Moscow’s favor.
This strategy assumes that Western democracies are slow to respond, divided in their priorities, and reluctant to take risks. It also assumes that European publics will eventually tire of the costs associated with supporting Ukraine and confronting Russia.
These assumptions are not guaranteed to be correct. European governments have begun to recognize the severity of the threat. NATO has increased its focus on hybrid warfare. The EU has proposed new measures to protect critical infrastructure. Member states are investing more in defense and security.
But progress is uneven. Some governments still treat sabotage as a law enforcement issue rather than a national security threat. Others lack the resources or political will to act decisively.
Europe’s Next Line of Defense
I believe the next phase of this conflict will be defined by how well Europe adapts to the reality of hybrid warfare. The tools of the past are not sufficient. The institutions are not fully aligned. The mindset is still catching up.
Russia’s sabotage operations are likely to continue as long as they appear effective and low-risk. The campaign may fluctuate in intensity, but the underlying strategy is unlikely to change unless Moscow concludes that the costs outweigh the benefits.
For European governments, the choice is clear. They can continue to respond reactively, treating each incident as an isolated event. Or they can develop a comprehensive strategy that treats sabotage as what it is: an act of war by other means. The quiet war is already underway. The question is whether Europe will remain quiet in the face of it.




