Russia's Shadow Fleet, the Tankers Spying on NATO From the Sea
According to a report from the International Institute for Strategic Studies, the IISS, based in London, drones have overflown sensitive installations across
- According to a report from the International Institute for Strategic Studies, the IISS, based in London, drones have overflown sensitive installations across
- Introduction: when a civilian tanker becomes a military platform
- A report documenting 144 suspicious overflights
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
Introduction: when a civilian tanker becomes a military platform
A report documenting 144 suspicious overflights
According to a report from the International Institute for Strategic Studies, the IISS, based in London, drones have overflown sensitive installations across 13 NATO countries at least 144 times between August 2024 and February 2026. Some of these overflights are reportedly linked to vessels belonging to Russia's shadow oil fleet, aging tankers that skirt Western sanctions on Russian oil by frequently changing flag and ownership.
The American military outlet Stars and Stripes documented, on July 2, 2026, several specific cases in which suspicious vessels allegedly served as launch platforms for drones observed near sensitive bases, including some housing NATO nuclear weapons in Europe. This finding deliberately blurs the line between maritime commerce and disguised military operation.
What this profile sets out to draw
This piece profiles this shadow fleet, which several Western analysts now describe as a tool of hybrid warfare serving the Kremlin, drawing on available reports and the vessels specifically named by Western investigations.
What stands out in this file is the apparent ordinariness of these merchant vessels, which masks a far more troubling military function than their declared oil-shipping activity.
What Russia's shadow fleet actually is
A fleet born to dodge oil sanctions
Russia's shadow fleet refers to several hundred tankers, often old and poorly maintained, bought or leased through shell companies to keep exporting Russian oil despite Western sanctions imposed since the 2022 invasion of Ukraine. These vessels frequently change flag, disable their maritime tracking systems, and often operate without insurance that meets international standards.
This fleet allows Moscow to keep oil revenues flowing that are essential to funding its war effort, while formally sidestepping the price-cap mechanisms put in place by the G7 and the European Union.
A military use layered on top of the commercial function
What the IISSreport reveals is that some of these vessels no longer merely transport oil: they reportedly also serve as discreet platforms for launching or logistically supporting observation drones, exploiting their legal presence in international waters to approach sensitive installations without raising the suspicion normally reserved for declared military vessels.
This dual function, commercial and military, illustrates a central feature of Russian hybrid warfare: using civilian infrastructure for strategic ends, making any Western response legally and diplomatically more complex.
The vessels specifically named by Western investigations
Arctica, Boracay and Zhigulevsk under surveillance
Several Western reports, including the one relayed by Stars and Stripes, specifically name vessels such as the Arctica, the Boracay and the Zhigulevsk among the ships suspected of taking part in surveillance operations near NATOinstallations. These vessels, registered under flags of convenience, match the typical profile of the shadow fleet documented for years by researchers specializing in maritime sanctions.
The fact that these vessels are named individually, rather than mentioned generically, strengthens the report's credibility and allows Westernintelligence services to track their movements more precisely in the months ahead.
Trajectories that coincide with drone overflights
Western investigators have established temporal correlations between the presence of these vessels in certain maritime zones and the observation of unidentified drones near sensitive bases on land, without, however, being able to establish absolute causal certainty for each incident taken individually.
This methodological limit does not invalidate the overall finding: the repetition of these coincidences, over several months and several countries, far exceeds what chance could credibly explain.
The targeted bases, from the United Kingdom to France
RAF Lakenheath, Volkel and Île Longue in the crosshairs
Among the sites mentioned in Western reports are the British base at RAF Lakenheath, the Dutch base at Volkel, and the French naval installation at Île Longue, which houses part of France's nuclear deterrence force. These three sites share one thing in common: their top-tier strategic sensitivity for Western defense.
The choice of these targets, should the links to the shadow fleet be further confirmed, would suggest a deliberate intent to map the defenses and operational routines of the most critical installations of Western deterrence, rather than random interest in arbitrary military sites.
Psychological pressure as much as technical
Beyond gathering technical intelligence, these repeated overflights also serve a psychological purpose: demonstrating to NATO that its most sensitive installations are never entirely shielded from outside observation, even outside any context of open conflict with Russia.
This psychological dimension fits within the broader hybrid warfaredoctrine the Kremlin has applied across Europe for years, seeking to maintain a climate of permanent uncertainty without ever crossing the threshold of an openly acknowledged act of war.
Thirteen NATO countries affected by these incursions
A geography spanning the Alliance's entire northern and western flank
The 144 incidents documented by the IISS span thirteen NATO member states, a geographic spread suggesting a coordinated operation rather than a series of isolated, unrelated incidents. This wide distribution also complicates the coordination of a unified Western response, with each affected country initially handling the incident according to its own national procedures.
This fragmentation of the initial response illustrates a structural vulnerability of NATO against this type of diffuse hybrid threat: unlike a conventional military attack, these drone incursions do not automatically trigger a collective defense mechanism under Article 5.
The challenge of a collective response still being built
Several European defense officials have called for better coordination of information-sharing between member states regarding these drone incidents, in order to build a fuller, faster picture of the threat, rather than treating each incursion as an isolated event unconnected to the others.
This coordination remains, to this day, largely a work in progress, leaving Russia tactical room to maneuver until NATO harmonizes its detection and response doctrine against unidentified drones.
On the same topic
COMMENTARY: A Supermarket in Chernihiv — the Normalization of…
On the night of July 27 to 28, 2026 , the…
REPORT: Kaduna, Benue, Rural Nigeria Left Alone Against Its…
At least 30 people were killed when gunmen attacked a village…
BILLET: Altman and Huang Head to the Senate as…
According to Boursorama , Sam Altman of OpenAI and Jensen Huang…
What Moscow's relative silence reveals
No claim, but no clear denial either
Russia has neither claimed nor formally denied using its oil fleet for military observation purposes near NATO installations. This calculated silence lets Moscow preserve a valuable strategic ambiguity: no confirmation that would justify a firm Alliance response, and no denial that would publicly commit it on ground it prefers to keep vague.
This deliberate ambiguity is a central feature of modern hybrid warfare operations, where the ability to plausibly deny remains as valuable as the operation itself.
A well-honed strategy of plausible deniability
The Kremlin has, in the past, applied this same logic of plausible deniability to other sensitive files, from cyberattacks attributed to officially non-governmental groups to sabotage operations in Europe attributed to Russian military intelligence units.
This methodological continuity reinforces the credibility of Western suspicions, even absent a direct admission from Russian authorities regarding the military use of these civilian tankers.
The technical limits of certain attribution
What Western reports cannot yet prove
It must be acknowledged honestly: attributing every drone overflight with absolute certainty to a specific shadow-fleet vessel remains, to this day, technically difficult. Maritime tracking systems, often disabled by these vessels precisely to evade surveillance, complicate formal, incontestable attribution for each incident taken in isolation.
This technical limitation does not, however, erase the value of the overall finding established by the IISS: the statistical correlation between the presence of these vessels and drone observations, repeated over more than eighteen months and thirteen countries, far exceeds what a purely coincidental explanation could justify.
Why methodological caution remains necessary
This piece chooses to present these elements as converging indicators rather than definitive, individual proof for each incident, in order to preserve factual rigor on a file where the temptation of excessive certainty would be counterproductive to the credibility of the overall finding.
This rigor in no way diminishes the gravity of what these reports reveal about Russia's likely intentions toward NATO's critical infrastructure.
The still-timid Western response to this threat
Scattered national measures
Several European countries have independently strengthened their drone detection capabilities near sensitive sites, without a common NATOdoctrine yet formally adopted for this specific type of maritime hybrid threat. This scattered response reflects the Alliance's structural difficulty in organizing quickly against threats that don't fit the mold of classic, immediately identifiable military aggression.
Some countries have also tightened port controls on vessels suspected of belonging to the shadow fleet, hoping to limit their access to the most sensitive territorial waters, without, however, being able to fully prevent them from sailing in adjacent international waters.
What a common doctrine should include
Several maritime security experts advocate for a common NATO doctrine that would include systematic, rapid sharing of drone detection data between member states, along with a maritime sanctions mechanism specifically targeting vessels identified as belonging to the Russian shadow fleet.
Without this stronger coordination, each country will continue handling these incidents in isolation, which structurally benefits a Russia that clearly coordinates these operations on a far larger scale.
The link to the economic war against Russia
The shadow fleet, a pillar of financing the war in Ukraine
It must never be forgotten that this fleet's primary function is to skirt Western oil sanctions so Russia can keep funding its war effort against Ukraine. Every barrel carried by one of these tankers represents revenue that escapes, at least partially, the price cap imposed by the G7.
This economic dimension makes the dual military function of these vessels even more concerning: the same ships financing Russia's war machine in Ukraine would also be spying on Western defenses, creating a dangerous convergence between economic warfare and hybrid warfare.
Why sanctioning these vessels remains a legal challenge
Effectively sanctioning these vessels remains legally complex, since they frequently change flag, registered owner and insurance company, quickly rendering any sanction measure obsolete against the speed of this fleet's administrative reshuffling.
This constant race between Western measures and Russian adaptation illustrates the structural limits of classic maritime sanctions against an adversary with sufficient resources to continually renew its legal front structures.
Discover
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
BILLET: Altman and Huang Head to the Senate as…
According to Boursorama , Sam Altman of OpenAI and Jensen Huang…
What Kyiv is watching from its own theater of war
A threat that echoes Russia's own tactics in the Black Sea
For Ukrainian observers, this use of civilian vessels for military ends is nothing new: the Ukrainian navy has documented for years similar tactics used by the Russian fleet in the Black Sea, where civilian or paramilitary vessels have regularly served as observation platforms or logistical support for Russian military operations.
This tactical continuity, from the Black Sea to European waters near NATO, confirms that Russia's doctrine of hiding military activity behind civilian cover is not confined to the Ukrainian theater, but constitutes a widespread method of Kremlin action.
Western vigilance that should draw on Ukraine's experience
Ukraine's accumulated experience since 2022 in identifying these dual-use vessels could usefully feed Western detection capabilities, on a file where intelligence cooperation between Kyiv and its Western allies benefits both sides.
This cooperation, already underway on other maritime security files, would be worth strengthening specifically on the question of the shadow fleet and its suspected military use near NATO installations.
Scenarios for the coming months
Between silent escalation and coordinated response
Several trajectories are possible for this file going forward. Russia could continue, or even intensify, this type of operation as long as the political and material cost remains low for it. Conversely, a more coordinated Western response, including targeted maritime sanctions and a common detection doctrine, could gradually reduce this shadow fleet's room to maneuver.
The most likely scenario, according to several European security analysts, remains a prolonged intermediate phase: neither immediate dramatic escalation nor a quick resolution of the problem, but gradual diplomatic pressure accompanied by scattered national measures, pending a possible common NATO doctrine.
What should be watched most closely
The publication of new reports by the IISS or other security research institutes, along with any sanction decisions specifically targeting individually named vessels, will be the most reliable indicators of how this file evolves in the months ahead.
The absence of such concrete measures, conversely, would confirm that NATO remains, for now, better at documenting this threat than at effectively countering it on the ground.
Why this file goes beyond a purely maritime question
A test of Western cohesion against hybrid warfare
This file on the shadow fleet and drone overflights implicitly tests NATO's ability to respond collectively to threats that don't fit the mold of classic military aggression. If the Alliance fails to build a coordinated response on this relatively contained file, it raises questions about its ability to handle even more sophisticated forms of hybrid warfare in the future.
This test goes well beyond the question of Russian tankers alone: it concerns the entire Western collective security doctrine, at a moment when forms of conflict are evolving faster than the legal and institutional frameworks meant to contain them.
A lesson for the entire authoritarian axis
How NATO handles this file will be watched not only by Moscow, but also by Beijing, Tehran and Pyongyang, who are closely observing Western capacity to respond to hybrid warfare tactics without triggering open military escalation.
A Western failure on this file would send a signal of weakness to that entire authoritarian axis, while a firm, coordinated response would strengthen the credibility of Western deterrence doctrine far beyond the sole question of Russian tankers.
The human factor behind the technical reports
Base security crews on permanent alert
Behind the overflight statistics and expert reports are security teams at the affected military bases, forced to treat every unidentified drone overflight as a potential threat, with all the vigilance and operational stress that implies over time.
This daily pressure, rarely mentioned in media coverage of this file, represents a real human cost for the personnel responsible for securing these sensitive installations, confronted with a threat that is difficult to anticipate and effectively counter with the means currently available.
Vigilance that carries a human and material price
Strengthening detection capabilities, if eventually adopted at the NATO level, will also represent a considerable material and human investment, at a time when European defense budgets are already heavily stretched by support for Ukraine and the Alliance's broader rearmament goals.
This cost, real as it is, remains far lower than that of a serious incident arising from failing to take this hybrid threat seriously enough in time.
The role of Western insurers in this file
Insurance coverage growing harder to obtain
Several Western maritime insurers have tightened their acceptance criteria for vessels resembling the shadow fleet profile, particularly those that have disabled their tracking system or frequently changed flag in recent years. This insurance pressure represents one of the few genuinely effective economic levers against this fleet, since a vessel without compliant insurance becomes far more vulnerable in the event of a major maritime incident.
This insurance strategy, driven notably by markets such as London's, complements classic government sanctions by directly targeting the economic viability of these vessels rather than only their formal legality.
An effectiveness still limited by Russian alternatives
Russia, however, has developed its own parallel insurance mechanisms to sidestep this Western pressure, partially reducing the long-term effectiveness of this insurance approach. This constant adaptation illustrates, once again, the Kremlin's ability to find economic workarounds for every new Western measure.
This perpetual race between sanctions and circumvention reinforces the idea that only a coordinated action, combining sanctions, insurance pressure and a military detection doctrine, can truly reduce this dual-use fleet's room to maneuver.
Conclusion: a gray-zone threat demanding a clear response
A file that illustrates the new forms of warfare
Russia's shadow fleet and its suspected use for drone surveillance operations near NATO installations perfectly illustrate the new forms of conflict the West must now face: diffuse threats, hard to attribute with absolute certainty, but whose accumulation of converging evidence leaves little doubt about the strategic intentions behind them.
One hundred forty-four documented incidents, thirteen countries affected, individually named vessels: this file can no longer be treated as a series of isolated anecdotes. It demands a response equal to its systemic scale.
What to watch in the coming months
The true measure of Western seriousness on this file will be seen in the adoption, or lack thereof, of a common detection and maritime sanctions doctrine specifically aimed at vessels identified as belonging to this shadow fleet.
Until that common doctrine emerges, Russia will retain a comfortable operating space between the threshold of an isolated incident and that of an openly acknowledged act of war, a space precisely designed to exploit the Atlantic Alliance's structural hesitations.
By Maxime Marquette, columnist
Columnist's transparency note
My acknowledged biases
I sign this profile as an engaged observer of the Western camp, not as a neutral journalist. I support the sovereignty of Ukraine and I consider Vladimir Putin'sRussia, alongside China, Iran and North Korea, a structural threat to Western security.
What I do not claim to know
I cannot confirm with absolute certainty the attribution of every drone overflight to a specific shadow-fleet vessel. This profile relies on IISS reports and available, verifiable journalistic investigations, explicitly flagging the methodological limits of individual attribution where they exist.
Sources
Primary sources
Ministry of Defense of Ukraine — maritime security context, July 2026
IISS — report on drone incursions near NATO installations
Stars and Stripes — Russian drones near NATO nuclear bases, July 2, 2026
Secondary sources
The New York Times — drone incursions in Europe attributed to Russia, July 2, 2026
Foreign Policy — analysis of Russian hybrid warfare in Europe
Newsmax — Russian drones and European defense, July 2, 2026
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). Russia's Shadow Fleet, the Tankers Spying on NATO From the Sea. MadMax. https://mad-max.co/en/article/la-flotte-fantome-russe-ces-petroliers-qui-espionnent-l-otan-depuis-la-mer
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.