In May 2025, the UK’s National Cyber Security Centre and international partners disclosed a Russian military intelligence campaign against Western logistics and technology organisations. Attackers targeted email accounts and internet-connected cameras to gather information about assistance moving to Ukraine. A compromised mailbox could reveal a delivery schedule; a camera could help track the shipment. NCSC campaign disclosure.

This is a useful starting point for understanding Russian hybrid operations: a digital intrusion can serve an objective far beyond the computer it compromises.

For Europe, the challenge extends across three connected targets — information, essential services, and public trust. Understanding that relationship makes the threat easier to assess and the defence easier to organise.

Based on sources reviewed through 1 October 2026. Official assessments and investigative allegations are attributed below; defensive recommendations are the article’s analysis.

What Russia is trying to achieve

Hybrid operations combine different forms of pressure to influence an opponent’s decisions. The Council of the EU includes cyberattacks, information manipulation, economic coercion, covert political activity, and military pressure in its description. Such campaigns can make responsibility difficult to establish and complicate a response below the perceived threshold of war. Council overview.

The EU identifies Russia’s persistent activities as including sabotage, infrastructure disruption, cyberattacks, and interference with democratic processes. Council assessment of Russia’s hybrid activities.

For a defender, the practical question is what those actions could achieve: expose a sensitive negotiation, delay support to Ukraine, intimidate a supplier, or undermine confidence in a public institution. The target may be Europe’s ability to make and carry out decisions together, rather than a particular server.

These methods do not replace conventional warfare. In Ukraine, they operate alongside Russia’s invasion. Elsewhere in Europe, organisations need to consider their role in the wider system: a transport company, research institute, or maintenance provider may hold information or access valuable to an adversary.

Three ways the pressure works

1. Steal information that supports a wider operation

In the campaign disclosed in May 2025, NCSC and partners attributed the activity to GRU Unit 26165, also known as APT28. Reported methods included credential guessing, spear-phishing, abuse of Exchange mailbox permissions, and access to cameras near relevant locations. NCSC campaign disclosure.

The significance is what the attacker can learn. Email can reveal routes, timing, contacts, and handover instructions without disrupting the service. An organisation measuring security only through uptime can miss a consequential intrusion.

Sensitive information also travels through people. NCSC’s Star Blizzard advisory describes impersonated contacts, rapport-building, and phishing aimed prominently at personal email accounts. It documents session-cookie theft and malicious forwarding rules. A protected corporate system therefore does not cover every account used by a researcher, journalist, or policy adviser. Star Blizzard advisory.

The defensive lesson: identify who can read operational information and through which accounts. Remove unnecessary access, protect high-risk users, and investigate changes to forwarding and mailbox permissions.

2. Disrupt a service or a critical dependency

The EU attributed the attack on Viasat’s KA-SAT satellite network to Russia. Its declaration states that the attack occurred one hour before the invasion on 24 February 2022 and affected users beyond Ukraine, including EU member states. EU attribution declaration.

The case shows how an organisation can suffer from an operation without being its intended target. Communications, power, transport, and suppliers connect European services across borders.

Physical sabotage belongs in the same continuity assessment. The UK government’s GRU profile links Unit 29155 to the 2014 Vrbětice ammunition warehouse explosions in Czechia. Its profile also describes Sandworm, associated with Unit 74455, as specialising in destructive cyber operations against strategically important targets. Different capabilities can create a similar business consequence: an essential service becomes unavailable. UK GRU profile.

Economic pressure can exploit dependencies too. In October 2022, the European Council explicitly described Russia’s weaponisation of energy. For organisations, the corresponding planning question is what happens when a critical supply can be withheld and an alternative takes months to arrange. European Council energy conclusions.

The defensive lesson: map what the essential service depends on. Two providers may still share a cable route, power source, or upstream system. Test whether the fallback works when the primary service and its administration channel are unavailable.

3. Shape how people interpret events

An information operation can attack credibility without compromising the institution it impersonates.

On 4 September 2024, the US Department of Justice announced the ongoing seizure of 32 domains used in the Doppelganger influence campaign. Its affidavit alleged Russian government direction of operators using lookalike news domains, fake personas, advertising, and other distribution methods. Stated objectives included reducing support for Ukraine and influencing foreign audiences, including in Germany. These are investigative allegations, not convictions. DOJ disclosure.

The mechanism is easy to understand: a familiar publisher’s appearance makes fabricated content look credible. A screenshot can hide the domain and publication history that would expose the impersonation.

A real incident can also provide material for misleading claims. Stolen documents may be released selectively, and authentic material can be mixed with fabricated content. Analysts must investigate both the intrusion and the authenticity of what circulates publicly.

The defensive lesson: protect official publication channels and establish how people can verify a statement independently. When investigating suspected manipulation, preserve original pages, addresses, and publication times. A popular claim or shared political opinion alone does not establish a coordinated foreign operation.

Why this matters in Finland and the Baltic region

The same three targets — information, services, and trust — provide a useful lens for Northern Europe.

On 28 September 2026, Yle reported Supo counterintelligence chief Teemu Liikkanen’s assessment that the Russian sabotage threat in Europe had increased over the summer. He identified defence industry and activities supporting Ukraine as particularly exposed in Finland, while saying there was no indication of immediate danger. This is a reported intelligence assessment, not attribution of a specific Finnish incident. Yle interview report.

Regional infrastructure also requires preparation for disruptions whose cause may initially be unknown. A damaged undersea cable calls for continuity action while investigators determine whether the cause was accidental, negligent, criminal, or state-directed. Commercial links to Russia or a suspicious vessel route do not, by themselves, prove a Kremlin order.

Navigation interference presents another operational problem. EASA reports increased Global Navigation Satellite System interference since February 2022 in regions including the Baltic Sea and the Arctic. Jamming disrupts reception; spoofing can produce misleading positioning or timing information. EASA’s regional assessment does not attribute every event to Russia. EASA GNSS guidance.

The response follows the dependency: communications teams need viable alternate routes; transport operators need approved navigation contingencies; system owners need to understand reliance on satellite-derived timing. Responsible specialists should own these decisions, particularly where safety is involved.

Connect the evidence without inventing a connection

Hybrid operations require teams to share context. A security operations centre may see mailbox access, facilities may see an unexplained camera change, and communications staff may see a forged announcement. Each team holds only part of the picture.

Consider a hypothetical logistics incident: a dispatch mailbox has an unapproved forwarding rule, a camera configuration changes, and a lookalike news page claims that deliveries have stopped. Operations confirms that dispatch is still functioning.

The immediate tasks are to contain the mailbox access, investigate the camera change, preserve the original fake page, and communicate the verified service status. The events belong on one timeline, but the scenario does not establish that they share an operator.

Keep three questions separate:

  1. What happened? Establish the access, damage, or service impact from reliable records.
  2. Are the events connected? Look for corroboration such as linked identities, shared infrastructure, or non-public details.
  3. Who is responsible? State the evidence and confidence behind attribution, distinguishing organisational findings from official assessments.

An organisation can protect its systems before it establishes state sponsorship. Equally, naming Russia does not explain which access path to close or which service to restore.

A focused defence plan

Organise preparation around the same three targets. The following recommendations translate the cases into control objectives; they should be implemented through supported administration methods and normal change control.

Protect the information

The identity and messaging teams should prioritise accounts that hold sensitive operational or policy information. Require phishing-resistant authentication where supported, review recovery and fallback methods, remove unnecessary mailbox delegation, and restrict unapproved external forwarding.

Verify the result: use a designated test account to confirm that prohibited authentication methods and forwarding destinations fail. Review effective permissions rather than relying only on a written policy. NCSC recommends strong-factor MFA and timely updates in its logistics guidance, and addresses forwarding in the Star Blizzard advisory. Logistics guidance, Star Blizzard guidance.

Phishing-resistant authentication reduces credential-phishing exposure; stolen sessions and compromised devices remain separate risks. During an incident, assess sessions and persistence as well as passwords.

Keep essential services working

IT, facilities, and operations should jointly identify the components that can stop the service. Remove unnecessary public management access, apply supported security updates, restrict camera and contractor permissions, and protect critical physical access points. Give each exposure an owner.

The recovery owner should separate backup privileges from production administration and arrange a trusted restoration path. The service owner should confirm alternative connectivity, supplier capacity, and realistic replacement times.

Verify the result: test that untrusted networks cannot reach restricted management interfaces and expired contractor access fails. Restore a selected service with its dependencies, and confirm that production credentials cannot delete protected recovery copies. Exercise the loss of a critical provider or component through a safe simulation.

These controls serve different purposes. Access restrictions reduce opportunity; backups support recovery; neither prevents all physical disruption. Patching also does not establish that an already compromised environment is clean. Industrial testing and isolation must preserve safety and follow operator-approved procedures.

Preserve public trust

Communications and IT should protect publication accounts and domain administration, establish a known alternate channel, and agree how technical findings reach the spokesperson. Staff should know where to verify announcements when ordinary email fails.

Verify the result: during an exercise, issue and authenticate an update without the primary email service. Confirm that communications staff can establish the actual service impact with operations.

A useful update states what people need to know: “Our booking service is unavailable. Dispatch is operating through the published contingency number. We are investigating the cause and will update at 14:00 UTC.” It provides an action and a deadline while the investigation continues.

When an incident happens

Appoint one coordinating lead and bring in technical response, operations, facilities, communications, and legal counsel according to the impact. The initial response has four priorities:

  • Safety and continuity: protect people and stabilise essential operations. Avoid changes that create additional industrial or operational hazards.
  • Evidence and containment: preserve expiring logs, original messages, public pages, and relevant access records; close demonstrated malicious access paths. Retain original timestamps and document clock differences.
  • Accurate communication: publish verified impact, available alternatives, and the next update time. Separate facts from hypotheses and correct material false claims without unnecessarily repeating them.
  • Escalation and recovery: use established national CSIRT, police, sector-authority, and provider contacts. Legal counsel should determine applicable notification duties. Validate restored services and trusted administration before declaring recovery complete.

A short joint exercise can test all four. Use the logistics scenario above, then remove normal email and the primary administrator account. The useful measure is whether the team can coordinate, preserve evidence, authenticate an update, and restore the service.

Russia’s documented activities warrant preparation. Effective defence protects information, keeps services functioning, and communicates accurately under pressure. It also preserves the standards of evidence and open debate that hostile influence seeks to weaken: an outage, political disagreement, or Russian-speaking community is not proof of an operation.

Sources

  1. Council of the EU: Hybrid threats.
  2. Council of the EU: Russia’s hybrid activities.
  3. NCSC: Western logistics and technology targeting — 21 May 2025.
  4. NCSC: Star Blizzard spear-phishing — 7 December 2023.
  5. Council of the EU: KA-SAT attribution — 10 May 2022.
  6. UK government: GRU cyber and hybrid operations — updated 13 July 2026.
  7. European Council: Energy conclusions — conclusions of 20 October 2022.
  8. US Department of Justice: Doppelganger disruption — 4 September 2024.
  9. Yle: Supo official on the sabotage threat — 28 September 2026.
  10. EASA: GNSS outages and alterations.