Skip to content
The ColumnAnalysis· No. 3053

Russia strikes NATO infrastructure, and the West hits back

On June 29, 2026, a detailed report confirmed what several Western intelligence services had feared for months: cybercriminal groups tied to Russia

Premium reading
MadMax
Key takeaways
  1. On June 29, 2026, a detailed report confirmed what several Western intelligence services had feared for months: cybercriminal groups tied to Russia
  2. Introduction: when digital sabotage replaces Russian tanks
  3. A quiet but very real escalation
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

Introduction: when digital sabotage replaces Russian tanks

A quiet but very real escalation

On June 29, 2026, a detailed report confirmed what several Western intelligence services had feared for months: cybercriminal groups tied to Russia are now running coordinated, destructive attacks against critical infrastructure sitting inside the borders of NATO member states. This is no longer classic espionage. It is a deliberate escalation toward physical sabotage carried out through digital means.

According to analysis reported by b2b-cyber-security.de, groups affiliated with the FSB, Russia's domestic security service, simultaneously targeted roughly thirty renewable-energy sites, wind and solar, a manufacturing company, and a heating plant supplying nearly 500,000 residents in Poland. The attack on the heating plant was stopped before it could cause a mass outage, but the destructive intent was never in doubt.

Poland, the testing ground for Russian hybrid warfare

Poland has found itself on the front line of this hybrid war for several years now. Poland's CERT called the preceding December 29 incident one of the most severe ever recorded against its power grid, comparing it to a digital act of "arson" designed to permanently wipe data rather than simply spy.

The choice of target is no accident. Hitting renewable energy and district heating in the dead of winter is a way to fracture the social cohesion of an allied country without firing a single shot.

Let's be clear from the start: this is not an isolated incident, it is a pattern repeated for years, and the persistent refusal of some Western leaders to call it what it is has only delayed a collective response that was already overdue.
Call it what it is: this is an attack on a NATO member state, carried out by actors affiliated with the Russian state. The fact that it travels through cables instead of armored columns does not make it any less serious, and the West needs to stop treating these incidents as mere tech-page curiosities.

Berserk Bear, a signature the Kremlin can't hide

An actor the FBI has tracked for years

Western investigators link part of this campaign to the group known as Berserk Bear, also called Dragonfly, tied to Center 16 of the FSB. An FBI report published in August 2025 had already documented this group's methods, active for more than a decade against Western energy networks.

This is not some improvised actor. It is a patient state apparatus that maps critical infrastructure long before striking, potentially planting backdoors for months or even years before activating them at the moment judged most politically useful.

An influence war redeploying toward the West

According to an analysis from The Register also published on June 29, 2026, four years after the invasion of Ukraine began, Russia is redirecting part of its influence and digital sabotage operations straight at the United States and Europe, a sign that Moscow now treats the Western information front as a strategic priority in its own right.

This strategic repositioning confirms something too many Western leaders took too long to admit: the war against Ukraine was never an isolated regional conflict. It is a systemic confrontation against the Western order itself, and it is also being fought inside our power plants.

Poland's pushback and the Alliance's vigilance

Warsaw raises its tone against Moscow

On July 1, 2026, Reuters reported that Warsaw is now explicitly warning about Russia's intent to exploit tensions tied to the war in Ukraine to carry out additional sabotage operations on Polish soil. Polish authorities no longer hide their concern, a bluntness that breaks from the usual diplomatic caution.

That bluntness has its uses: it forces European partners to take the threat seriously instead of filing it away as an isolated incident. According to United24Media, Polish intelligence services have even raised the possibility that Moscow could use unmarked troops against the Baltic states, a scenario that would have sounded like geopolitical science fiction just five years ago.

NATO builds up collective cyberdefense

Facing this sustained pressure, several members of the Atlantic Alliance have accelerated their investment in collective cyberdefense, part of the broader push toward Western rearmament observed since Russia's aggression against Ukraine began in 2022.

This is exactly the kind of coordinated response that needs to become the norm. An attack on a NATO member, even a digital one, must be treated as an attack on all of them, and Warsaw deserves the full backing of its Western allies in this silent confrontation.

What this strategy reveals about Russian intentions

Moscow's denial, a well-worn routine

As with every incident of this kind, the Kremlin denied any involvement in these cyberattacks. This systematic denial, repeated for years against increasingly solid technical evidence, no longer fools many Western cybersecurity experts, who methodically document the digital infrastructure used by these groups.

The real question is no longer whether Russia is involved, but how far it is willing to go before triggering a conventional military response from NATO.

A strategy of constantly testing red lines

Every attack of this kind also functions as a test of Western detection and response capabilities. By patiently probing the defenses of Polish, Romanian, or Baltic energy networks, Moscow sharpens its understanding of the Alliance's structural vulnerabilities, with an eye toward a potentially larger conflict.

I'll say it plainly: this strategy of constant testing is exactly why Western vigilance is non-negotiable. Letting our guard down against these repeated provocations would hand Moscow a free map of our weak points.

The real-world impact on civilian populations

District heating, a strategic target in winter

Striking a heating plant that supplies nearly 500,000 people is anything but accidental. It is a calculated choice meant to maximize psychological impact on a civilian population, without a single Russian soldier crossing a border. The attempt was foiled, but the mere fact that it was pushed this far shows the determination of the operators involved.

The wind and solar farms targeted at the same time fit the same logic: destabilizing Europe's energy transition at the precise moment when Europe is trying to cut its dependence on Russian hydrocarbons.

A psychological war as much as a technical one

Beyond any potential physical damage, these operations also aim to sow doubt about the reliability of Western infrastructure in the eyes of its own citizens. A population that fears power or heating outages becomes more receptive to arguments against continued support for Ukraine.

That's the cynicism at the heart of this strategy: dumping the psychological weight of the war onto Polish, Romanian, or Baltic civilians, far from the Ukrainian front, to patiently erode Western political will to keep backing Kyiv.

Article 5's persistent blind spot on cyber

Whether a destructive cyberattack against a member state could ever trigger Article 5 of the North Atlantic Treaty remains largely unresolved within the Alliance. This legal ambiguity objectively benefits Moscow, which can test the limits without automatically triggering a collective response.

Several Western diplomats are now pushing to clarify this threshold, arguing that the current ambiguity encourages rather than deters this kind of hybrid aggression.

Sanctions still seen as insufficient by Warsaw

Despite several rounds of sanctions imposed on Russia since 2022, Polish authorities believe the Western response remains insufficiently deterrent against such targeted operations against critical civilian infrastructure.

On this point, I share Poland's frustration. Economic sanctions, however significant, are no substitute for a clear doctrine of cyber retaliation, and the West is still slow to build a coherent framework for responding to this kind of aggression.

Lessons for other member states

The Baltic states on heightened alert

The Polish warning relayed by United24Media about possible unmarked Russian troops targeting the Baltic states fits into a pattern of heightened vigilance shared by Estonia, Latvia, and Lithuania, all three of which have already faced similar incidents in recent years.

These countries are investing heavily in the resilience of their own energy networks, aware they could be the next targets of a campaign comparable to the one waged against Poland.

The critical role of intelligence sharing among allies

The speed with which the attack on the Polish heating plant was detected and neutralized owes much to intelligence cooperation among Western allies. That coordination remains one of NATO's biggest assets against a threat that, by definition, ignores national borders.

This is exactly why Atlantic solidarity matters: no single country, however technologically advanced, can protect itself alone against a state-backed cyber threat as well-funded as the one the Kremlin has built.

What Kyiv can teach the West on this front

Ukraine's experience, an unwilling laboratory

Since 2022, Ukraine has endured Russian cyberattacks of an intensity unmatched anywhere in Europe, targeting its power grid, its banks, and its public administrations. Painful as it has been, this experience has made Ukrainian cybersecurity teams among the most battle-tested in the world against the methods of the FSB and the GRU.

Several NATO countries, including Poland, have now strengthened direct technical cooperation with Kyiv to draw on this hard-won expertise, an intelligence exchange that benefits the entire Alliance.

A partnership that strengthens collective Western defense

This technical cooperation shows just how inseparable Ukraine's fate has become from Western security. Supporting Kyiv militarily and financially also means gaining, in return, unique cyber expertise forged through direct contact with Russia's most aggressive methods.

Here's another argument, rarely highlighted, for continued support to Ukraine: this country isn't just defending itself, it is indirectly shielding NATO's entire eastern flank by absorbing and dissecting Moscow's blows.

Conclusion: cyberdefense, the new front of Atlantic solidarity

A clear signal for Western capitals

This wave of attacks against critical infrastructure in Poland confirms that the confrontation with Russia is no longer confined to Ukrainian trenches. It is also being fought in data centers, power grids, and industrial control systems across NATO member states.

Firmness remains the best answer

Facing this sustained pressure, the Western response needs to stay firm, coordinated, and transparent. Publicly documenting these attacks, as Polish authorities and the researchers cited by b2b-cyber-security.de and The Register have done, strips Moscow of one of its favorite tools: plausible deniability.

By Maxime Marquette, columnist

Columnist's transparency note

Who I am and my acknowledged biases

I am a columnist, not a technical cybersecurity expert. My analysis rests on public reports and journalistic investigations already published, not on direct access to classified data. I am openly pro-Western and pro-NATO on this file, and I consider Poland's defensive posture legitimate and necessary.

What I don't know

I cannot confirm with absolute certainty the exact technical attribution of every attack to the Berserk Bear group, a task that falls to specialized agencies. I rely on the consensus of the cited reports, assuming it may evolve as new evidence emerges.

Sources

Primary sources

B2B Cyber Security — Russia-linked groups attack critical infrastructure in NATO states, June 29, 2026

The Register — Four years into Ukraine invasion, Russia turns influence ops back to US and Europe, June 29, 2026

Secondary sources

Reuters — Poland warns Russia seeks to exploit Ukraine tensions with sabotage operations, July 1, 2026

United24 Media — Polish intel warns Russia could use unmarked troops against Baltic states

Reuters — Polish officials blame Russian domestic spy agency for Dec. 29 cyberattacks, January 30, 2026

The Kyiv Independent — ongoing coverage of Russia's hybrid war against Ukraine and the West

Get the geopolitics analyses

Conflicts, powers, alliances: the MadMax thread without the noise.

Cite this article

Maxime Marquette (2026). Russia strikes NATO infrastructure, and the West hits back. MadMax. https://mad-max.co/en/article/la-russie-attaque-les-infrastructures-de-l-otan-l-occident-riposte

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Analysis1903 words10 min read