Europe Is Facing a Different Kind of War
Europe has spent more than four years watching the war in Ukraine from outside its own borders.
Missiles have struck Ukraine.
Russian and Ukrainian forces have fought across the battlefield.
European governments have supplied weapons, intelligence and financial assistance.
But NATO territory has largely remained outside the direct battlefield.
That separation is becoming increasingly difficult to maintain.
Across Europe, authorities are investigating suspected sabotage, cyberattacks, drone incursions, arson and other incidents that security officials increasingly view as part of a broader hybrid threat.
One case has become particularly disturbing.
At Leipzig/Halle Airport in Germany, an explosives-laden drone was discovered near a Ukrainian Antonov cargo aircraft earlier this month. Investigators later found a third drone near the airport containing suspected military-grade explosives. Germany has not officially attributed the operation to Russia, although Russian involvement is being investigated and Western security officials have increasingly pointed toward Moscow. Russia denies responsibility.
The question is therefore not whether Russia has formally attacked NATO.
It has not.
The much more complicated question is whether Europe is experiencing a campaign designed to remain below the threshold that would trigger a conventional NATO response.
The Leipzig Airport Incident
Leipzig/Halle is not an ordinary civilian airport.
It is one of Germany’s major cargo hubs and has also been used for military logistics involving Ukraine.
That makes the August incident particularly sensitive.
German investigators discovered an explosive-equipped drone near a Ukrainian Antonov cargo aircraft.
Another drone was reportedly involved in an incident involving a cargo aircraft after the airport was closed.
Then investigators discovered a third drone in the surrounding area days later, along with suspected military explosives.
German Chancellor Friedrich Merz has said the government intends to reveal who is responsible, but Berlin has so far stopped short of officially accusing Russia.
That distinction is critical.
There is substantial suspicion.
There is evidence being investigated.
There are intelligence assessments pointing toward Russia.
But suspicion is not the same as publicly established attribution.
A responsible analysis therefore has to leave that question open.
Why Russia Is Being Investigated
The suspicion surrounding Russia does not exist in isolation.
European governments have reported a broader increase in suspected hybrid operations since Russia’s full-scale invasion of Ukraine.
These have included cyberattacks, sabotage, arson, GPS interference, espionage and drone-related incidents.
The Washington Post reported that European officials believe the Leipzig incident fits a wider pattern of suspected Russian aggression against European countries supporting Ukraine. It also reported suspected or investigated incidents involving weapons facilities in several European countries.
A former senior German intelligence official described the Leipzig incident as consistent with what he characterised as a major increase in hybrid aggression across Europe.
But again, individual incidents require individual evidence.
That matters because several explosions and fires that have been linked to possible Russian activity remain under investigation, and authorities in countries including Italy and Bulgaria have not publicly established Russian responsibility for those incidents.
What Is Hybrid Warfare?
Hybrid warfare occupies the uncomfortable space between peace and conventional war.
It can involve:
Cyberattacks.
Disinformation.
Sabotage.
Espionage.
Arson.
GPS disruption.
Proxy operations.
Political interference.
Drone incursions.
Attacks against infrastructure.
The purpose is often not to destroy an enemy’s military in the traditional sense.
The purpose can instead be to create uncertainty.
Make governments spend money on security.
Create fear.
Disrupt supply chains.
Damage political confidence.
Discourage support for an opponent.
And test how a country responds.
That makes hybrid warfare particularly attractive to a state that wants to pressure an adversary while maintaining plausible deniability.
The Most Dangerous Part Is the Ambiguity
A conventional missile attack is relatively easy to understand.
A missile crosses a border.
It explodes.
The attacker can often be identified.
Hybrid warfare is different.
A fire starts in a warehouse.
A drone appears near an airport.
A computer network suddenly stops working.
GPS signals disappear.
A suspicious individual is arrested.
A critical piece of infrastructure is damaged.
Who did it?
Was it a government?
A criminal group?
A lone actor?
A proxy?
An intelligence service?
Or an accident?
That uncertainty creates strategic paralysis.
Governments must decide whether to retaliate without always possessing enough evidence to publicly prove who was responsible.
That is precisely where hybrid warfare becomes powerful.
Is Russia Testing NATO?
This is the most controversial question surrounding the current situation.
Several European officials and security experts believe Russia may be testing NATO’s response.
The theory is relatively straightforward.
Moscow could conduct operations that remain below the threshold of conventional armed conflict.
Then it can observe what happens.
Does NATO respond?
Does Germany retaliate?
Does Poland increase military deployments?
Does Europe impose new sanctions?
Does Washington become involved?
Does the alliance remain united?
Or does everyone simply issue statements?
The Washington Post reported that European officials and security experts believe Russia may be attempting to determine how far it can push NATO without provoking a major response.
If that assessment is correct, the objective may not be destruction.
It may be reconnaissance.
NATO Has a Problem
NATO was built primarily around deterrence against conventional military attack.
Article 5 is designed around the principle that an armed attack against one member can be treated as an attack against the alliance.
But what happens when the attack is ambiguous?
What happens when nobody can immediately prove who conducted it?
What happens when a drone carrying explosives is found near an aircraft but fails to detonate?
What happens when a cyberattack temporarily disrupts government services but causes no physical casualties?
What happens when a factory catches fire and investigators cannot establish whether it was sabotage?
These situations are strategically uncomfortable.
Invoking Article 5 over an ambiguous incident could trigger enormous escalation.
Doing nothing could encourage further operations.
That is the dilemma.
The Baltic States Are Especially Worried
For Estonia, Latvia and Lithuania, this is not an abstract debate.
The Baltic states share borders with Russia or Belarus and have spent years warning about Russian military and hybrid threats.
Their geographical position makes them particularly vulnerable.
Any Russian operation against a Baltic NATO member would immediately create a major alliance crisis.
That is why Baltic governments have generally taken a harder line than some larger Western European countries when identifying potential Russian activity.
The concern is not simply that Russia might launch a conventional invasion.
It is that Moscow could attempt to exploit political divisions, infrastructure vulnerabilities and information warfare before any conventional conflict begins.
Poland Is Another Critical Pressure Point
Poland has become one of the most important military and logistical hubs supporting Ukraine.
It is also geographically exposed to Russia and Belarus.
Recent incidents involving airspace violations and Russian military activity have therefore been taken extremely seriously in Warsaw.
The strategic problem is obvious.
If Russia wants to disrupt Western military assistance to Ukraine, Poland is an important part of the logistical chain.
But an attack on Polish territory would carry enormous consequences because Poland is a NATO member.
That makes Poland both a critical target for potential disruption and a critical test of NATO deterrence.
The Cyber Front Is Expanding
The hybrid conflict is not limited to physical incidents.
Today, European governments are also dealing with cyber operations.
Norway reported this week that a pro-Russian hacker group claimed responsibility for a major distributed denial-of-service attack against Norwegian public digital services. Norwegian authorities have not publicly confirmed the group’s claim, but the incident disrupted digital services for several days.
This illustrates another feature of modern conflict.
A country does not necessarily need to destroy a power plant or military base to cause disruption.
A digital attack can create economic costs, inconvenience citizens and test government resilience.
And because cyberattacks can be conducted remotely, attribution becomes extremely difficult.
GPS Has Become a Battlefield
Another overlooked element is satellite navigation.
GPS and other satellite-navigation systems are essential to modern aviation, shipping, logistics and military operations.
European countries have reported increasing interference with navigation signals, particularly in regions near Russia and Belarus.
Such interference can have civilian consequences.
Aircraft and ships depend heavily on accurate navigation.
Military forces depend on it even more.
The use of electronic warfare to interfere with navigation systems therefore creates another layer of confrontation without conventional combat.
Why Europe Is Vulnerable
Europe’s vulnerability comes partly from the nature of modern infrastructure.
Power systems are interconnected.
Airports are interconnected.
Financial networks are interconnected.
Undersea cables connect countries.
Railways cross borders.
Digital government systems connect millions of citizens.
A relatively small disruption can therefore create effects far beyond the original target.
This is exactly why European governments are now investing more heavily in infrastructure protection, counter-drone technology and intelligence cooperation.
France, for example, has increased its assessment of threats to critical infrastructure following the Leipzig incident. French intelligence chief Celine Berthon warned that defence, technology, energy and communications sectors are particularly exposed.
Why Would Russia Do This?
There are several possible strategic explanations.
The first is deterrence.
Russia could seek to discourage European governments from continuing military assistance to Ukraine.
The second is disruption.
Attacking logistics or defence infrastructure could make weapons production and transportation more difficult.
The third is psychological.
If European populations begin believing that supporting Ukraine makes them less safe, political pressure on governments could increase.
The fourth is intelligence gathering.
Hybrid operations can reveal how quickly European governments detect, attribute and respond to threats.
The fifth is political division.
If European countries disagree about who is responsible for attacks, the response becomes weaker.
None of these explanations proves Russian responsibility for any particular incident.
But they explain why European intelligence services are treating the broader pattern seriously.
Russia Denies Responsibility
Moscow has rejected accusations of involvement in sabotage operations.
That is an important part of the story.
Russia has repeatedly denied responsibility for various incidents that Western governments have attributed or suspected to be linked to Russian intelligence services.
This creates a recurring problem.
Western governments say the pattern points toward Russian activity.
Russia denies it.
Investigations continue.
And the public often receives incomplete information.
The result is a geopolitical environment where attribution itself becomes part of the conflict.
The Information War Is Part of the Battlefield
There is another layer to all of this.
Every suspected attack produces competing narratives.
One side says Russia is responsible.
Another says the evidence is insufficient.
Russian social media networks may celebrate incidents involving Western defence infrastructure.
Western governments warn of Russian hybrid warfare.
Critics accuse governments of exaggeration.
Others accuse governments of being too cautious.
The information environment therefore becomes another battlefield.
That is why factual discipline is particularly important.
Calling every unexplained explosion “Russian sabotage” can weaken legitimate investigations.
But dismissing a growing pattern simply because attribution is difficult can be equally dangerous.
Europe Is Beginning to Change Its Security Strategy
The response is already visible.
Germany has opened new structures dedicated to drone security.
France is reassessing threats to critical infrastructure.
Eastern European countries are increasing surveillance.
NATO is strengthening monitoring of airspace and military activity.
European governments are increasingly treating hybrid warfare as a permanent security challenge rather than an occasional problem.
This could eventually produce a major transformation in European defence policy.
For decades, defence planning focused heavily on tanks, aircraft, missiles and soldiers.
Now governments also have to defend:
Data centres.
Ports.
Airports.
Factories.
Railways.
Undersea cables.
Satellites.
Telecommunications networks.
And civilian drones.
The battlefield is expanding.
The Risk of Escalation
The greatest danger is that an operation intended to remain below the threshold of war accidentally crosses it.
Imagine a drone attack causes casualties.
A European government publicly attributes it to Russia.
NATO responds with military measures.
Russia retaliates.
Another NATO country becomes involved.
Suddenly, an operation that began as a covert action becomes a conventional confrontation.
This is why hybrid warfare can be more dangerous than it initially appears.
It creates repeated opportunities for miscalculation.
Is Europe Already at War With Russia?
Technically, no.
NATO is not at war with Russia.
European NATO members are not conducting a declared conventional war against Moscow.
But the boundary between peace and conflict is becoming increasingly difficult to define.
Cyberattacks can be acts of aggression.
Sabotage can cause physical damage.
Drone incursions can violate sovereign airspace.
Disinformation can interfere with democratic processes.
Espionage can undermine national security.
The traditional definition of war was built around armies fighting armies.
Modern conflict does not always work that way.
The Real Test May Be NATO’s Response
The central question now is not simply whether Russia is conducting hybrid operations.
It is whether NATO can respond effectively without triggering a much larger conflict.
If NATO responds too weakly, Russia could conclude that further escalation is relatively safe.
If NATO responds too aggressively, the confrontation could become military.
The alliance therefore has to find a narrow middle ground.
Deterrence without uncontrolled escalation.
That may be one of the hardest strategic problems facing Europe.
What Happens Next?
The immediate focus will be Germany’s investigation into the Leipzig/Halle Airport incidents.
Berlin has indicated that it expects to identify those responsible.
If German authorities publicly attribute the operation to a Russian state actor, the political consequences could be significant.
It could trigger stronger sanctions, increased security measures and further NATO coordination.
If investigators cannot establish responsibility, the broader debate will continue.
Either way, European governments are unlikely to treat the incident as an isolated curiosity.
The security environment has already changed.
Conclusion
Europe is entering a new phase of geopolitical confrontation.
The most dangerous part is that it does not necessarily look like a war.
There may be no declaration.
No invasion.
No mass mobilisation.
Instead, there are drones near airports, cyberattacks against government systems, suspected sabotage at defence facilities, GPS interference and increasingly aggressive intelligence operations.
The Leipzig/Halle incident is particularly serious because investigators found an explosives-laden drone near a Ukrainian military-linked cargo aircraft and later discovered another drone containing suspected military-grade explosives. Germany has not yet officially blamed Russia, and Moscow denies involvement.
That uncertainty should not be mistaken for insignificance.
The evidence surrounding individual incidents still needs to be established.
But the broader European security environment is undeniably becoming more dangerous.
The question confronting NATO is no longer simply whether Russia could attack Europe someday.
It is whether Europe can recognise, deter and respond to attacks that deliberately stop short of looking like war.
Because if the strategy is to test NATO one step at a time, the most important question may be:
How many steps can the alliance tolerate before someone crosses a line that cannot be uncrossed?
Frequently Asked Questions?
No. Russia and NATO are not officially at war. However, NATO members increasingly describe cyberattacks, sabotage, espionage and other activities as serious hybrid-security threats.
Â
That has not been officially established by Germany. Russian involvement is being investigated and has been suggested by security sources and officials, but Moscow denies responsibility and the investigation remains ongoing.
Â
Potentially, but Article 5 does not automatically apply to every cyberattack, sabotage incident or drone violation. NATO members would assess the circumstances collectively and determine whether an incident constitutes an armed attack requiring an alliance response.

