A series of incidents since early August 2026 indicates an increasingly active hybrid threat environment across Europe. Whilst the likelihood of conventional military action against NATO members remains low, recent reporting highlights a growing risk of disruption through sabotage, cyber activity, drone incursions, surveillance, insider-enabled access, proxy actors and other deniable means.
Organisations connected to defence, energy infrastructure, logistics, critical national infrastructure or NATO supply chains should consider the threat environment elevated and review their security posture accordingly. For affected organisations, this can translate into operational downtime, damaged infrastructure, reputational exposure, and (where personnel or access are involved) a compromised ability to trust your own security architecture from the inside out.
Between 4 and 5 August, a drone carrying suspected explosives was discovered within the secure area of Leipzig/Halle Airport. German authorities subsequently confirmed an investigation into the incident at what is recognised as critical national infrastructure. How the device came to be within a controlled-access area has not been publicly explained, and incidents of this kind often raise broader questions around access control, vetting and potential insider involvement.
The airport is strategically significant due to its freight operations and links to military and Ukraine-related logistics. German media later reported that the drone had been located near Ukrainian Antonov aircraft and contained explosive material. A further drone-related incident was reported later in August.
On 1 September, the German Government attributed responsibility for the drone incidents to Russia.
Subsequent incidents included:
The clustering of these incidents within a single month signals a shift from isolated opportunism to sustained, coordinated pressure on German infrastructure, the kind of tempo that outpaces reactive, incident-by-incident security responses.
Collectively, these incidents illustrate the continuing vulnerability of strategically significant infrastructure to low-level disruptive activity, and, in several cases, point to personnel and insider risk vulnerabilities as the more likely enabling factor, ahead of failures in perimeter or cyber security alone.
On 25 August, CIA director Ratcliffe has flown to Moscow for, reportedly, meetings with Russian intelligence officials. No official explanation of significance has been offered by either the U.S or Russian Governments. Yet, commentators have proposed various theories, including renewed prisoner swap negotiations or the commencement of fresh Ukraine-based peace talks. Our analysis does not support these hypotheses, pointing instead towards Director Ratcliffe sharing with his Russian counterpart intelligence citing Russian intentions to test NATO resolve by increasing hybrid attacks, specifically within NATO countries. The purpose of Director Ratcliffe's visit was to deter Russian intentions by confirming a strong NATO response as a consequence. If accurate, this suggests Russia's hybrid campaign is a deliberate, sanctioned strategy rather than deniable freelancing, meaning organisations should expect continuation and escalation, not a one-off spike.
On 23 August, it emerged that Russia had withdrawn its ambassador to the United Kingdom, Andrey Kelin. No successor has yet been announced. The development follows a period of deteriorating diplomatic relations, including repeated Russian criticism of UK military support to Ukraine. On 25 August, former Russian Deputy Foreign Minister Andrei Fedorov stated that UK facilities producing drones for Ukraine could face action from "unknown sources", including cyber activity and other non-conventional measures.
Following announcements by UK and French officials regarding deeper military support and technology cooperation with Ukraine, Russian officials issued further warnings directed towards both countries.
Dmitry Medvedev publicly referenced British defence facilities and multinational defence manufacturers as potential targets. The Russian Ministry of Defence also published a list of more than twenty European manufacturing sites allegedly involved in producing technologies supporting Ukrainian drone programmes. Medvedev subsequently amplified the list, describing the locations as legitimate targets. Publicly naming specific facilities in this way also raises the likelihood that staff and contractors at these sites could be targeted for approach, recruitment or coercion, adding an insider dimension to the wider threat picture.
While these statements do not necessarily indicate an intent to conduct direct attacks within NATO territory, they are significant because they publicly identify defence-related organisations and infrastructure as areas of interest.
On 20 August, Romanian authorities destroyed a maritime drone carrying an explosive charge in the vicinity of the Neptun Deep offshore gas project in the Black Sea. The drone was located only a few hundred metres from infrastructure associated with the project. Romanian authorities described the incident as part of an intensification of irresponsible activity by Russia. The incident is particularly significant because Neptun Deep represents strategically important European energy infrastructure and is located within NATO territory. An attack of this kind against energy infrastructure inside NATO territory would represent a marked escalation, testing the practical (not just rhetorical) boundaries of Alliance red lines, with second-order effects for energy security and pricing across the region.
Recent Russian messaging has focused increasingly on European defence manufacturers and associated supply chains.
Particularly relevant is the identification of European sites linked to advanced aerospace, defence and drone technologies, including facilities in the Netherlands.
Although Destinus was specifically referenced, many identified locations sit within broader defence and technology ecosystems that include major industry participants such as Thales.
This is notable because Thales and its subsidiaries provide a range of air defence, counter-drone and military support capabilities used across Europe and in support of Ukraine. Such organisations, and those operating within their supply chains, may face elevated risks from cyber activity, hostile intelligence collection, insider recruitment, surveillance or other forms of hybrid interference.
The principal threat is not assessed to be direct military attack, but rather intelligence gathering, disruption, reconnaissance and attempts to identify vulnerabilities across strategically important defence networks, with personnel in privileged or trusted positions representing one of the most likely means of achieving this.
For organisations connected to Ukraine, NATO, defence production, energy, logistics or other critical supply chains, the more credible concern is the potential for low-level, deniable or disruptive activity designed to create operational, financial or psychological effects without crossing the threshold of open conflict.
Across the incidents outlined above, personnel and insider risk factors feature as a primary (rather than incidental) enabling vector. Four key areas warrant particular attention:
We will continue to monitor developments and assess their implications for European organisations.
Against this backdrop, a growing number of our clients are turning to structured insider risk assessments, not as a precautionary afterthought, but because insider risk is increasingly one of the most efficient routes available to a hostile actor. These assessments identify where an organisation is genuinely vulnerable and benchmark its current level of maturity against good practice.
Organisations wishing to review their exposure, test existing insider risk measures or assess the resilience of critical operations can contact Signpost Six for an independent threat-informed insider risk assessment and expertise support. See also our Defence Market Analysis 2026 for a deeper look at sector-specific insider risk vectors.
This brief reflects Signpost Six’s observations based on the information available to us at the time of writing. The situation remains fluid, and our assessment may be revised as further information becomes available.