Skip to content
The ColumnProfile· No. 1663

PROFILE: Putin, master of grey zones — Russia's hybrid strategy against the Baltic states and Poland

On June 26, 2026, Latvia's State Security Service published an intelligence warning that received less international attention than it deserved: Russia's hybrid operations targeting the Baltic states and Poland had reached a new level of intensity and sophistication. The warning documented a pattern of activities — drone incursions, GPS jamming, sabotage networks, cyberattacks,

Premium reading
MadMax
Key takeaways
  1. On June 26, 2026, Latvia's State Security Service published an intelligence warning that received less international attention than it deserved: Russia's hybrid operations targeting the Baltic states and Poland had reached a new level of intensity and sophistication. The warning documented a pattern of activities — drone incursions, GPS jamming, sabotage networks, cyberattacks,
  2. PROFILE: Putin, master of grey zones — Russia's hybrid strategy against the Baltic states and Poland
  3. Introduction: The warning from Riga
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

PROFILE: Putin, master of grey zones — Russia's hybrid strategy against the Baltic states and Poland

Introduction: The warning from Riga

June 26, 2026 — Latvian intelligence speaks

On June 26, 2026, Latvia's State Security Service published an intelligence warning that received less international attention than it deserved: Russia's hybrid operations targeting the Baltic states and Poland had reached a new level of intensity and sophistication. The warning documented a pattern of activities — drone incursions, GPS jamming, sabotage networks, cyberattacks, and targeted information operations — that constituted, in the assessment of Latvian intelligence, a deliberate campaign of grey zone aggression designed to test Alliance resolve without triggering Article 5.

Grey zone aggression is aggression calibrated to stay below the threshold that would legally and politically require a military response. It is the strategy of the tactically clever and the morally unscrupulous. Vladimir Putin has elevated it to an art form — pursuing the objectives of territorial pressure and political destabilization through instruments that Western democracies struggle to attribute, deter, and respond to within their existing legal and institutional frameworks. The June 26 Latvian intelligence report is a roadmap to how this art form is currently being practiced against NATO's eastern flank.

The pattern: four documented incidents

Latvian intelligence's warning contextualized the current hybrid campaign within a documented pattern of incidents spanning the past 18 months. The Estonian Auvere power plant drone incident of March 2026 — a Russian-linked drone that breached Estonian airspace and passed within kilometers of a critical energy facility — demonstrated Russia's willingness to test NATO's air defense and airspace sovereignty responses. The 19 unexplained drone incidents over Poland in September 2025, attributed by Polish intelligence to Russian or Russian-linked actors, demonstrated the same testing logic applied to a larger and more strategically significant NATO member.

Kaliningrad-originating GPS jamming, which has disrupted civilian aviation over the Baltic region with increasing frequency, and the GRU-linked sabotage network — physical sabotage operations against rail, energy, and logistics infrastructure in Baltic and Polish territory — complete the picture of a multi-domain grey zone campaign that is simultaneously escalating and deniable. Putin is telling NATO that he can reach inside Alliance territory without crossing the threshold that would require a formal military response. The message is deliberate. The restraint in sending it is strategic, not principled.

The Estonian Auvere incident: a precision test

What happened and what it demonstrated

The Auvere power plant drone incident of March 2026 was more than a navigation accident or a stray commercial drone. The Auvere oil shale power plant is one of Estonia's most critical energy facilities — its disruption would affect Estonian power generation at a level relevant to military and civilian operations alike. A drone capable of reaching Auvere from Russian or Belarusian territory, equipped with an explosive payload or a reconnaissance payload, would provide both an intelligence collection opportunity and a potential sabotage capability.

Estonian and NATO authorities attributed the drone's presence to Russian-linked actors — a judgment based on the drone's origin trajectory, its capabilities, and the intelligence context of known Russian hybrid operation patterns. The incident did not produce casualties or physical damage. It was almost certainly designed not to — the value of the operation lies in the demonstration rather than the destruction: Russia showing Estonia that it can reach its critical infrastructure, that NATO's air defense cannot intercept every penetration, and that the cost of deterring this kind of operation falls on Alliance members to bear.

The Alliance response and its limitations

NATO's formal response to the Auvere incident was measured — an expression of concern, a reference to Alliance solidarity, and consultations within the North Atlantic Council about improving airspace surveillance and response capabilities in the Baltic region. This measured response reflects the real limitations of applying the Alliance's collective defense framework to incidents that have not caused casualties and whose attribution, while assessed as Russian-linked, cannot be publicly documented to the standard that formal Alliance action would require.

The limitation is structural, not political: Article 5 requires an "armed attack," and a drone that passes near a power plant without causing damage does not straightforwardly qualify. The Alliance is therefore left responding to grey zone incidents with measures short of collective defense — enhanced surveillance, bilateral reassurance, diplomatic statements — that are less deterrent than formal military response but more defensible within the Alliance's legal framework.

The 19 Polish drone incidents: testing a larger target

September 2025: a month that should have produced more alarm

The 19 drone incidents over Polish territory in September 2025 — attributed by Polish intelligence to Russian or Russian-linked actors — represent the largest documented grey zone aerial penetration of NATO airspace in the current period. Poland is not Estonia — it is a country of 38 million, a major NATO contributor, the primary logistics corridor for Western military support to Ukraine, and a country that has been investing more of its GDP in defense than any other NATO member. Russian grey zone operations targeting Poland carry different strategic implications than operations targeting smaller Baltic states.

The September 2025 incidents occurred in a period of particular sensitivity: during an active Ukrainian operational phase, while Polish logistics infrastructure was processing significant volumes of military equipment for Ukraine. The timing suggests that the drone operations were intended not only to test Polish airspace responses but to generate intelligence about the logistics infrastructure whose disruption would directly impact Ukrainian military resupply. Grey zone operations against Poland are, in part, operations against Ukraine.

Poland's response: investment and public acknowledgment

Poland's response to the September 2025 incidents was more public and more specific than most Alliance responses to grey zone provocations. Prime Minister Donald Tusk made explicit public statements acknowledging the drone operations and their attribution to Russian actors, refusing the diplomatic ambiguity that might have allowed the incidents to be officially characterized as accidents or navigation errors. This public acknowledgment served multiple purposes: it contributed to deterrence by making the attribution public, it built domestic political support for continued defense spending, and it sent a direct message to Moscow that Warsaw was tracking its operations and naming them.

Poland's defense investment — at 4% of GDP, the highest in NATO — includes specific funding for air defense systems, counter-drone capabilities, and airspace surveillance designed to address exactly the kind of grey zone aerial penetration that the September 2025 incidents demonstrated. Poland is building the defensive infrastructure that grey zone deterrence requires. It is doing so faster than any other European NATO member, and under more direct operational pressure.

Kaliningrad GPS jamming: the invisible weapon

Disrupting civilian infrastructure without violence

Kaliningrad — Russia's Baltic exclave between Poland and Lithuania — has been the source of systematic GPS jamming affecting civilian aviation, maritime navigation, and logistics operations across the Baltic region with increasing frequency. GPS jamming is a grey zone tool par excellence: it causes real disruption and real cost (diverted flights, compromised navigation, degraded logistics efficiency) without causing the physical casualties that would trigger formal military or legal responses.

The civilian aviation disruption has been the most publicly visible effect. Multiple airlines operating in the Baltic region have reported GPS interference severe enough to require alternative navigation procedures and in some cases flight route changes that add cost and time to regional aviation. The International Civil Aviation Organization (ICAO) has documented the jamming pattern and raised it through diplomatic channels with Russia — which has, predictably, denied responsibility while continuing the operations.

The military dimension of GPS warfare

The military dimension of Kaliningrad GPS jamming is more significant than the civilian disruption it causes. GPS-dependent weapons systems, drone navigation, and military logistics all rely on GNSS signals that can be degraded by jamming at sufficient power levels. By normalizing GPS jamming in the region — establishing it as a persistent background condition rather than a specific operational event — Russia reduces the calibration accuracy of GPS-dependent systems that NATO members in the region would use in an actual conflict.

NATO has responded by increasing attention to GPS-independent navigation alternativesinertial navigation systems, encrypted military GPS (which is harder to jam than civilian signals), and tactical communication systems that are less GNSS-dependent. These adaptations are underway but incomplete. Kaliningrad's GPS jamming is a long-term capability degradation operation that compounds over time the longer it continues without a decisive response.

GRU sabotage networks: the physical dimension

Operations against infrastructure and logistics

Latvian intelligence's June 2026 warning identified an active GRU-linked sabotage network operating across Baltic and Polish territory — a network responsible for physical interference with rail infrastructure, energy facilities, logistics hubs, and communication systems. The documented operations include suspicious fires at freight facilities, interference with rail signaling systems, and the disruption of logistics operations that support Western military supply chains for Ukraine.

Several individuals linked to this network have been arrested in Baltic states and Poland over the past 18 months — arrests that have provided intelligence about the network's structure, recruitment methods, and operational objectives. The arrested individuals have been a mix of Russian intelligence officers operating under commercial cover and locally recruited agents from the Russian-speaking diaspora and from individuals with financial or personal vulnerabilities that made them susceptible to GRU recruitment.

Recruitment targeting and counter-intelligence

The GRU's recruitment methodology for Baltic and Polish sabotage networks reflects a systematic targeting of specific vulnerability categories. Individuals with financial difficulties, criminal records, ideological alignment with Russian political positions, family connections to Russia or Belarus, and professional access to critical infrastructure are the primary recruitment targets. The GRU's patience in cultivating these individuals — sometimes over years before activating them for specific operations — reflects the long-term operational investment that grey zone warfare requires.

Baltic and Polish counter-intelligence services have invested significantly in detecting and disrupting these recruitment operations — with notable success in the arrest record, but with the honest acknowledgment that every arrest represents an operation that was detected, and that the number of undetected operations is unknown by definition. Grey zone warfare's most uncomfortable feature is that success is invisible and failure is what gets counted.

Medvedev's rhetoric: the political overlay

Threatening language as a grey zone tool

Dmitry Medvedev — the former Russian President now serving as Deputy Chairman of the Security Council — has become the primary voice of Russian nuclear and escalatory rhetoric directed at NATO's eastern flank. His statements targeting the Baltic states and Poland with specific territorial threats, nuclear references, and historical revisionism serve a specific grey zone function: they create an ambient atmosphere of threat that conditions Baltic and Polish public discourse, generates domestic political pressure in those countries, and tests Alliance members' willingness to respond to rhetorical aggression with diplomatic cost imposition on Russia.

Medvedev's rhetoric is calibrated to be deniable as official Russian policy — he speaks in a personal capacity, using informal channels, with language that can be characterized as the opinion of a private individual rather than a state position. This deniability is the grey zone quality that makes it simultaneously effective as intimidation and difficult to formally attribute and respond to as a state action. The intimidation works because it is credible given Russia's behavior. The deniability serves Russia by preventing the response that credible threats should logically generate.

The deterrence calculus of rhetorical threats

Whether Medvedev's rhetoric actually deters Baltic and Polish policy — whether it causes those governments to moderate their support for Ukraine, their defense investments, or their advocacy within NATO — is the key question for assessing its effectiveness. The available evidence suggests it does not: Baltic defense spending has continued to increase, Polish support for Ukraine has remained unconditional, and NATO's eastern flank has moved toward greater military presence rather than the restraint that Russian deterrence rhetoric aims to produce.

The failure of Medvedev's rhetoric to deter Baltic and Polish behavior is itself strategically important evidence — it demonstrates that the countries most directly targeted by Russian grey zone aggression are the least susceptible to the deterrence logic those operations are designed to create. Fear, for these countries, produces resolution rather than restraint. Russia consistently underestimates this dynamic, and consistently suffers the strategic consequences of its underestimation.

Tusk: "prepare as the most exposed group"

The frank acknowledgment of exposure

Donald Tusk's statement — calling on Poland and its Baltic allies to "prepare as the most exposed group" within NATO — reflects the frank strategic assessment of a leader who has absorbed the intelligence picture without the diplomatic softening that multilateral forums tend to produce. Poland and the Baltic states are the most exposed: they share land borders with Russia or Belarus (or both), they are the primary logistics corridor for Western support to Ukraine, and they are the primary targets of the grey zone campaign documented in the June 26 Latvian intelligence warning.

Tusk's "most exposed group" framing is a call to action directed both internally — at Polish society and institutions — and externally, at NATO partners who may underestimate the threat's specific geographic concentration. It is also a statement about solidarity responsibility: the countries most exposed have the strongest legitimate claim to extraordinary Alliance support, and Tusk is making that claim explicitly rather than relying on the general language of collective defense that may not produce the specific resources the eastern flank requires.

The German general's assessment: 2029 attack possible

The June 2026 intelligence environment includes an assessment from a senior German general — reported in German defense reporting — that a Russian conventional military attack against NATO territory was possible by 2029. This assessment does not represent official NATO policy or a consensus intelligence judgment; it represents one senior officer's reading of Russian military rebuilding capacity, strategic intention signals, and the logical trajectory of Russia's current military posture if the Ukraine conflict ends without strategic defeat for Moscow.

The 2029 horizon is sobering not because it is certain — it is not — but because it defines the planning requirement: NATO's eastern flank states have approximately three years to reach a defense posture that deters a conventional military attack of the kind the German general's assessment contemplates. Three years, for military capability development and Alliance infrastructure investment, is a very short window. The grey zone campaign underway now is preparation — the testing of Alliance responses and the degradation of infrastructure — for a potential conventional military option that Russia wants to preserve even if it never exercises it.

What deterrence requires: from grey zone to full spectrum

The legal and institutional gaps that must be closed

Effective deterrence of Russia's grey zone campaign requires closing the legal and institutional gaps that the campaign exploits. This means: establishing attribution standards for grey zone operations that allow timely Alliance responses without requiring the evidentiary thresholds designed for conventional warfare; developing Article 5 equivalents for hybrid attack thresholds that Russia has calibrated its operations to stay below; expanding the range of collective Alliance responses to include cyber countermeasures, economic measures, and intelligence declassification that impose costs on grey zone operations without triggering the escalation Russia uses to threaten; and resourcing Baltic and Polish intelligence and counter-intelligence operations at the scale the threat environment requires.

Each of these requirements is technically achievable within existing Alliance frameworks. None has been fully implemented. The gap between what deterrence requires and what the Alliance has built is the space in which Russia's grey zone campaign currently operates with limited cost.

The eastern flank as the learning laboratory

The Baltic states and Poland are, in effect, NATO's grey zone learning laboratory — the territory where Russia's hybrid aggression is being conducted at highest intensity and where the Alliance's responses are being developed in real time. The doctrines, legal frameworks, counter-intelligence methods, and deterrence tools that the Alliance develops in response to the June 2026 intelligence picture will determine its capacity to deter and respond to grey zone campaigns that, if Russia achieves sufficient confidence in their effectiveness, will expand to other Alliance territory.

Getting the response right on NATO's eastern flank is not only about protecting Estonia, Latvia, Lithuania, and Poland. It is about developing the institutional capacity that will protect every Alliance member against a form of aggression that Russia has perfected against Ukraine and is now deploying against NATO itself. The stakes of the laboratory are continental.

Conclusion: the profile of a grey zone strategy

Putin's grey zone mastery: the complete picture

Vladimir Putin's grey zone strategy against the Baltic states and Poland is not improvised. It is a deliberate, multi-domain campaign — aerial testing through drone incursions, navigation warfare through GPS jamming, physical disruption through sabotage networks, psychological pressure through Medvedev's rhetoric, and the long-term preparation that all of these activities represent for a conventional military option Russia wants to preserve. The June 26 Latvian intelligence warning provides the most current documented map of this campaign. The map is detailed, specific, and alarming.

The response that the moment requires

The response this profile demands is not panic but urgency — the urgency of Alliance members who understand the pattern, who have the resources and the institutional capacity to close the gaps that grey zone aggression exploits, and who choose to act before the 2029 planning horizon transforms from a warning into a reality. Tusk knows this. The Baltic leaders know this. The German general knows this. The question is whether the rest of NATO knows it with equal clarity and equal urgency. The June 26 intelligence warning should help answer that question. The answer matters more than most of what is discussed in the Alliance's formal councils.

By Maxime Marquette, columnist

Columnist's transparency note

Editorial position

This profile analyzes Russia's grey zone strategy against NATO's eastern flank based on the June 26, 2026 Latvian intelligence warning and documented incidents. The columnist supports robust Alliance deterrence of Russian hybrid aggression and considers the eastern flank states' warnings credible and urgent. All incidents cited are drawn from publicly available intelligence reports and credible news sources cited below.

Scope and limitations

Intelligence assessments cited in this article are based on publicly released materials from Baltic and Polish security services; classified assessments are not accessible to the columnist. The German general's 2029 attack assessment is based on German defense reporting and represents one officer's analysis, not official NATO policy. Attribution of specific drone incidents and sabotage operations to Russian actors reflects the assessments of the relevant national intelligence services.

Sources

Primary sources

Secondary sources

Get the geopolitics analyses

Conflicts, powers, alliances: the MadMax thread without the noise.

Cite this article

Maxime Marquette (2026). PROFILE: Putin, master of grey zones — Russia's hybrid strategy against the Baltic states and Poland. MadMax. https://mad-max.co/en/article/portrait-poutine-maitre-des-zones-grises-la-strategie-hybride-russe-contre-les-e

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Profile2 reads3220 words5 min read