COLUMN: Russian Hybrid Warfare — 50,000 Digital Signals and a Europe That Won't Strike Back
On June 17, 2026, the AsymIntel European strategic autonomy monitor published an analysis that deserves to be read as an alarm. The European External Action Service (EEAS) documented a sustained and escalating pattern of Russian hybrid activities against European Union member states. These activities include: cyberattacks, sabotage, disruption of critical infrastructure, and in
- On June 17, 2026, the AsymIntel European strategic autonomy monitor published an analysis that deserves to be read as an alarm. The European External Action Service (EEAS) documented a sustained and escalating pattern of Russian hybrid activities against European Union member states. These activities include: cyberattacks, sabotage, disruption of critical infrastructure, and in
- COLUMN: Russian Hybrid Warfare — 50,000 Digital Signals and a Europe That Won't Strike Back
- Introduction: The EEAS documents, the ECFR quantifies, Europe watches
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
COLUMN: Russian Hybrid Warfare — 50,000 Digital Signals and a Europe That Won't Strike Back
Introduction: The EEAS documents, the ECFR quantifies, Europe watches
A sustained and escalating pattern
On June 17, 2026, the AsymIntel European strategic autonomy monitor published an analysis that deserves to be read as an alarm. The European External Action Service (EEAS) documented a sustained and escalating pattern of Russian hybrid activities against European Union member states. These activities include: cyberattacks, sabotage, disruption of critical infrastructure, and information manipulation. Not an isolated crisis. Not a one-off incident. A sustained pattern — that is the word used, and it matters.
In parallel, the European Council on Foreign Relations (ECFR) documented a pattern of physical-digital hybrid attacks with concrete examples: drone incursions into Polish and Danish airspace, disruptions at Munich airport, and coordinated online activity designed to confuse the public and erode trust in authorities. The ECFR processed close to 50,000 digital signals across major and niche digital platforms to document this campaign. Fifty thousand signals. This is not artisanal work — it is an industrial operation.
What the numbers reveal
The AsymIntel report assigns Europe's dependence on Russian hybrid operations a high risk rating. The physical-digital attack surface gap: high. The persistence of Russian hybrid operations: high. And the operationalized European offensive response: none. That contrast is what I want to dig into in this column. Not the threat — it is documented, analyzed, quantified. But the absence of a proportional response.
The European Council extended its restrictive measures against Russian hybrid threats until October 9, 2026, covering 47 individuals and 15 entities. This is an institutional signal of recognition of a persistent threat. But targeted sanctions against 47 individuals against an information and sabotage machine generating 50,000 digital signals per analysis period — that disproportion says everything.
Information warfare — its specific mode of operation
Confuse to paralyze, not to convince
The goal of Russian information warfare is not to convince Europeans that Putin is right. That would be too ambitious and too difficult to measure. The goal is more modest and more perverse: confuse the public and erode trust in authorities. No need to convince. Just create doubt. Doubt about NATO's intentions. Doubt about the truthfulness of war reporting. Doubt about the motivations of governments supporting Ukraine. This diffuse doubt is the fertile ground in which disinformation does its most effective work.
The ECFR documents that this campaign operates on two simultaneous levels: physical (drones, sabotage, infrastructure disruptions) and digital (coordinated disinformation, narrative amplification, algorithmic manipulation). The synchronization between these two levels is the key to its effectiveness: a physical disruption creates the event, coordinated digital activity amplifies the informational chaos around that event. Together, they produce a destabilization effect that exceeds the sum of its parts.
Digital platforms as a battlefield
AsymIntel notes that AI-driven manipulation of the informational environment has been documented at scale across the 50,000 digital signals analyzed. AI enables disinformation content to be produced at unprecedented volume and speed, narratives to be tailored to specific audiences in each country, and platform moderation mechanisms to be circumvented. This is an industrialization of propaganda that traditional counter-disinformation tools are not yet equipped to counter effectively.
The EU's response in this domain — the Digital Services Act (DSA), moderation transparency obligations, systemic risk reporting requirements — creates a legal framework but not yet an active counter-capability. Europe can identify priorities and fund them. It cannot yet compel member states to transform their informational defenses, align their counter-disinformation policies, or close specific capability gaps. That is the central enforcement gap.
Physical sabotage — drones in sovereign airspace
Incursions that test the limits
The drone incursions into Polish and Danish airspace documented by the ECFR are not navigation accidents. They are deliberate tests of NATO and member state responses to sovereign airspace violations conducted by state actors using instruments that provide plausible deniability. The militarily attributable but officially unattributed drone — it is the perfect vector for a policy of gradual escalation without triggering Article 5.
The disruptions at Munich airport follow the same logic: strike civilian connectivity nodes, create economic and logistical costs, test resilience and response capability. These are not military attacks. They are aggression operations below the threshold of military response — precisely where international law and NATO doctrine are most ambiguous.
The absence of an offensive response and its consequences
AsymIntel is explicit: there is "no operationalized European offensive response" to Russian hybrid operations. This void is not only a capability problem — it is a signal to Moscow. A signal that hybrid operations can continue without triggering an asymmetric European response in the same domains. This de facto impunity encourages escalation rather than deterring it.
Several response approaches are available: counter-disinformation operations, targeted cyberoffensives against Russian propaganda infrastructure, disruption of identified influence networks, or simply a clear public attribution policy that names Russian operations and those responsible. These tools exist. Some member states use them bilaterally. But a coordinated, systematic European response is still absent — and that gap is one the expected European Security Strategy summit must close.
The European Security Strategy — an existential test
The institutional moment of truth
The European Security Strategy (ESS) expected in 2026 is identified by AsymIntel as "the definitive institutional test" of whether the EU can consolidate its fragmented defensive architecture into a coherent strategic posture. The EU's composite strategic autonomy score in the report is 0.42 out of 1 — below average. The trajectory: deteriorating.
The weakest pillars are sovereignty coverage, dependency reduction, and capability building. Europe scores relatively better on alliance coherence and institutional capabilities. In plain language: it is good at meetings and declarations, less good at decisions that actually transform its military and informational capabilities. That is a brutal but accurate diagnosis.
What official documents alone cannot accomplish
The EU Strategic Compass, the European Defence White Paper 2030, the EU Cybersecurity Strategy — these documents exist and establish real priorities. But AsymIntel highlights that the proliferation of strategic documents without consolidation is high. The EU can identify and fund priorities, but it cannot compel member states to transform their defense industries, align procurement decisions, or close specific capability gaps. The execution gap is the central challenge.
To be fair: this is the same constraint as any supranational organization functioning by unanimous consent. NATO reform took decades. Building an autonomous European defense and hybrid counter-interference capability will also take time. But the Russian threat does not take a break while Europe builds its institutions.
The American context — when the protector gradually withdraws
The US National Defense Strategy 2026
The AsymIntel report notes that the US National Defense Strategy 2026 confirms that American support to Europe will remain critical but become more limited. It describes this shift as a "confirmed structural withdrawal rather than a temporary negotiating posture." In other words: this is not Trump improvising. This is American policy structurally evolving toward an Indo-Pacific reorientation.
This reality transforms the European security equation. Europe was protected for decades by an American umbrella so comprehensive it never had to develop credible autonomous defense capability. That umbrella is shrinking. Dependence on American support is rated as "high and shifting." This is not a reason to panic — it is a reason to accelerate investment in Europe's own capabilities.
Technological dependency — AI and informational sovereignty
AsymIntel highlights the absence of a European sovereign technological response to AI-driven manipulation of the informational environment. Europe depends on American digital platforms — whose moderation policies and algorithmic architectures are decided in San Francisco, not in Brussels. Against a Russian hybrid campaign that operates precisely through these platforms, this technological dependency is a strategic vulnerability.
Addressing this vulnerability requires not only stronger platform regulation (the DSA is a start), but also the development of European capabilities in AI analysis and countermeasures in the informational domain. This is a long-term, costly investment whose results will not be visible within an electoral cycle. All the more reason to start now.
What Ukraine brings to this equation — resilience as a model
Kyiv as a laboratory for hybrid resilience
Ukraine has been the global laboratory for Russian hybrid warfare since 2014. Disinformation, cyberattacks, opinion manipulation, clandestine operations — Ukraine has endured every technique that Russia is now deploying more broadly across Europe. Ukrainians have developed remarkable informational resilience: an active civil society, robust independent media, fact-checking centers, and a culture of constructive skepticism toward unverified sources.
Europe has everything to learn from the Ukrainian experience. Ukrainian counter-disinformation services, the practices of Ukrainian journalists managing information during crises, the protocols of Ukrainian authorities to prevent algorithmic panic — all of this represents a body of practical knowledge that European institutions should systematically integrate into their own resilience frameworks.
On the same topic
OPINION: ChatGPT Takes Your Pulse — Public Health Entrusted…
OpenAI states, on the page announcing the launch of "Health in…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
OPINION: Merz Under Fire as the CDU Learns the…
On July 29, 2026 , Le Monde describes an " unprecedented…
The NATO Hybrid Centre and coordination with Kyiv
The NATO Strategic Communications Centre of Excellence and the NATO Hybrid Centre are already working with Ukrainian partners on these questions. But the depth of coordination remains insufficient relative to the threat. Ukraine's experience is not only useful for understanding the current war — it is the best available warning for preparing the hybrid wars of tomorrow.
Ukraine's future membership in the EU would bring with it this unique experience. A Ukrainian member state would perhaps be the most competent actor in the Union in the domain of hybrid resilience — turning its national tragedy into a collective strategic resource. That is one more argument for accelerating integration, not slowing it down.
Council restrictive measures and their limited reach
47 individuals, 15 entities — a symbolic response to an industrial machine
The European Council extended its restrictive measures against Russian hybrid threats until October 9, 2026. These measures target 47 individuals and 15 entities. They include travel bans and asset freezes. They signal institutional recognition of a persistent threat — that is their primary value. Their operational value is far more limited. The individuals planning cyberattacks or disinformation operations against Europe mostly have neither travel to Europe planned nor assets there to freeze.
The gap between the threat — 50,000 digital signals, drone incursions, airport disruptions, sabotage operations — and the response — 47 names on a blacklist — is a measure of the distance between recognition and action. That gap must be closed with active response capabilities, not only sanctions lists.
The coordinated response mechanisms that are missing
What is missing in Europe is a coordinated response mechanism to Russian hybrid operations that simultaneously engages multiple dimensions: cyber, informational, physical, and diplomatic. Member states act individually. EU agencies — ENISA, Europol, EUvsDisinfo — partially coordinate. But there is no single body with the mandate, resources, and authority to orchestrate a coherent operational response to a hybrid attack in real time.
The NATO Hybrid Centre partially fills this role for Alliance members. But coordination between this center and EU structures remains underdeveloped. And Ukraine — which has the deepest experience of any nation in the Northern Hemisphere facing Russian hybrid warfare — is still not integrated as a full partner in these structures.
The necessary investments — figures and priorities
Funding informational resilience at European scale
Countering Russian disinformation and hybrid operations requires investments that are not yet at the scale of the threat. The budget of EUvsDisinfo — the EU's main tool for tracking and countering Russian disinformation — is minuscule compared to the resources Russia invests in its influence operations. Digital literacy initiatives in European educational systems are fragmented. Research on algorithmic manipulation techniques is underfunded.
The EU Strategic Compass mentions these priorities. The Defence White Paper 2030 repeats them. What is needed now is a concrete investment plan with amounts, timelines, and evaluation mechanisms. Not another document. A budget. A schedule. Measurable results. That is what European publics can support and understand — and what the threat demands.
Training journalists and protecting democratic actors
European journalists who cover Russian disinformation, informational security researchers, social media monitoring experts — all are essential actors in hybrid defense. They need training, resources, legal protection, and access to platform data. DSA regulations open some access — but implementation delays and platform resistance continue to slow this work.
Press freedom, source protection, media independence — these are not merely abstract democratic values. They are components of informational resilience against hybrid warfare. A fragmented, underfunded, or politically captured media landscape is a strategic vulnerability that Russia exploits with precision.
Conclusion: The urgency of a European hybrid response doctrine
What is missing — a counter-interference architecture
The diagnosis is clear, the gaps identified, the risks quantified. What is missing is a European hybrid response architecture that is as offensive as it is defensive, coordinated across member states, resourced adequately, and decoupled from electoral cycles to endure over time. This architecture does not yet exist. It is referenced in strategic documents. It is not yet operationalized.
Discover
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
BILLET: Altman and Huang Head to the Senate as…
According to Boursorama , Sam Altman of OpenAI and Jensen Huang…
The 2026 European Security Strategy is the opportunity to change that. If it includes binding execution mechanisms, coordinated offensive response capabilities, and an informational sovereignty architecture funded at the level of actual needs — it will be a turning point. If it is yet another document that identifies priorities without enforcing them, it will be yet another disappointment.
Time works against passivity
Every additional month without a European offensive response is another month in which Russia consolidates its techniques, refines its methods, and ensures that the cost of its hybrid operations remains zero. This is not a war that pauses during institutional deliberations. It is a war that intensifies precisely because the adversary perceives deliberation itself as an exploitable weakness.
Ukraine did not have the luxury of deliberating indefinitely. It responded, adapted, resisted. Europe still has time to make that choice before being forced to make it under more advanced crisis conditions. This June 17, 2026 brief is a warning. The question is how many additional warnings will be needed before the response matches the threat.
By Maxime Marquette, columnist
Columnist's transparency note
Sources and method
This column draws primarily on the June 17, 2026 weekly brief from the AsymIntel European Strategic Autonomy Monitor, which compiles data from the EEAS, the ECFR, and several other institutional sources. All figures and indicators cited — the score of 0.42, the 50,000 digital signals, the 47 sanctioned individuals, the high risk ratings — come from that document unless otherwise noted. I did not have access to the raw data underlying the ECFR analysis.
My analysis of the implications for European policy and the comparison with the Ukrainian experience reflects my stated editorial positions.
Stated biases
I support a more offensive European response to Russian hybrid operations. I consider the current EU passivity in this domain a strategic weakness. I am pro-Ukraine and convinced that Ukrainian experience is a resource for European security. These positions are clearly identified as editorial judgments.
What I do not know with certainty: the precise content of the 2026 European Security Strategy (not yet published at the time of writing), and the true extent of hybrid response capabilities that some member states have developed bilaterally but not publicly.
Sources
Primary sources
Secondary sources
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). COLUMN: Russian Hybrid Warfare — 50,000 Digital Signals and a Europe That Won't Strike Back. MadMax. https://mad-max.co/en/article/chronique-la-guerre-hybride-russe-50-000-signaux-numeriques-et-une-europe-qui-ne
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.