NATO is tightening intelligence-sharing across the alliance after Denmark’s military intelligence service warned that Russia is likely to intensify hybrid operations against the West in the coming months, a shift that is pushing European governments to treat sabotage, cyberattacks, covert influence and ambiguous military incidents as part of a single security problem rather than a series of isolated episodes. The warning does not amount to a prediction of a Russian invasion of NATO territory. Denmark’s assessment instead describes a low but rising risk of a limited military attack designed to test, divide or intimidate the alliance while staying below the threshold of a full conventional war. NATO’s top commander, U.S. Air Force General Alexus Grynkewich, said the alliance is responding by increasing intelligence exchange and strengthening readiness while stressing that a limited attack remains unlikely and that NATO retains the means to defend its territory.

A Danish warning changes the tone of Europe’s security debate
The new Danish assessment, published on September 24 by the Danish Defence Intelligence Service, is notable not because it predicts imminent war but because it explicitly places hybrid pressure and limited military action on the same escalation ladder. The service said it expects Russia to increase the frequency and consequences of hybrid attacks against NATO and the West. It also judged that the risk of a limited military strike against one or more NATO countries bordering Russia is low but growing. At the same time, the service said a full-scale Russian invasion of a NATO state remains unlikely, though it can no longer be excluded entirely. That distinction is central. Intelligence assessments often become distorted when a conditional risk is reduced to a headline prediction. Denmark is not saying that Moscow has decided to launch a conventional attack on NATO. It is describing a security environment in which Russian leaders may be more willing to take calibrated risks if they believe the political consequences can be contained. A limited strike, in that framework, would be intended to create uncertainty inside the alliance rather than seize and hold substantial territory. Thomas Ahrenkiel, the head of Denmark’s defence intelligence service, said possible scenarios could include isolated drone or missile attacks on infrastructure connected to support for Ukraine, false-flag operations using Ukrainian-made drones, or a small incursion into a NATO border area under a political pretext. Those examples are scenarios in an intelligence assessment, not confirmed Russian plans. Their significance lies in the logic they illustrate: an action could be militarily limited yet strategically disruptive if it generates argument over attribution, proportionality and whether NATO’s collective-defence mechanisms should be activated.
Hybrid warfare thrives in the space between peace and open conflict
The phrase “hybrid warfare” is used broadly, sometimes too broadly, to describe activities that combine military, intelligence, economic, technological and informational pressure. In the current European context, officials use it to encompass sabotage, destructive or disruptive cyber operations, attacks on logistics, covert influence, disinformation, GPS interference, suspicious drone activity and pressure on critical infrastructure. The common feature is ambiguity. The activity may be harmful enough to impose costs, but deniable enough to delay a unified response. That ambiguity is strategically useful because NATO’s greatest strength is also one of the conditions an adversary may try to exploit: decisions are political as well as military. An obvious armed attack on allied territory would create a much clearer case for collective action. A fire at a warehouse, a severed cable, a cyber intrusion, an unexplained drone over an airport or a dangerous encounter at sea can generate uncertainty about who is responsible and what level of response is justified. The time required to investigate may itself be part of the effect. European governments increasingly describe these events as a campaign rather than a sequence of unrelated security incidents. Russia rejects that characterization and has repeatedly denied responsibility for sabotage and hybrid attacks in NATO countries. Those denials matter because the public record contains incidents with very different levels of evidence. Some have been formally attributed by governments following criminal and intelligence investigations. Others remain suspicious but unresolved. Treating all of them as equally proven would be analytically unsound and politically dangerous. The emerging NATO response therefore depends heavily on intelligence fusion: combining military surveillance, police investigations, cyber forensics, border data, financial intelligence and national security reporting to identify patterns that no single country can see on its own. That is one reason Grynkewich’s emphasis on faster intelligence-sharing is more than bureaucratic language. In a hybrid confrontation, the ability to establish a pattern quickly can be as important as the ability to intercept a missile.
NATO’s top commander says the alliance is stepping up intelligence exchange
Grynkewich, NATO’s Supreme Allied Commander Europe and commander of U.S. European Command, told Reuters that the alliance is increasing intelligence-sharing in response to a series of incidents apparently linked to Russia. He described the developments as concerning but argued that NATO should remain calm and confident. His message was deliberately dual-track: acknowledge a more complicated threat environment without amplifying the uncertainty that hybrid operations are designed to create. The practical value of broader intelligence-sharing is speed. An airport drone incident in Germany may initially appear to be a domestic law-enforcement case. A maritime encounter off Denmark may sit with naval authorities. A cyber intrusion into a logistics provider may be handled by a national cyber agency. If similar technical indicators, operational methods, procurement chains or intelligence signatures appear across cases, national compartmentalization can conceal the larger picture. Sharing allows investigators to compare those fragments before months of separate work produce the same conclusion. It also supports deterrence. Public attribution is only credible if governments can demonstrate internally that the evidence is strong enough to withstand allied scrutiny. If a state intends to accuse another government of sabotage or covert attack, its partners need confidence in the assessment before they impose sanctions, adjust force posture or publicly support the accusation. Weak attribution can fracture an alliance; strong attribution can narrow the space for plausible deniability. Grynkewich said a limited Russian attack on NATO territory is unlikely but cannot be ruled out. He also said the alliance has the authorities and capabilities needed to respond if threats emerge. That wording is important because it separates readiness from prediction. Military planning assumes contingencies that intelligence may still judge improbable. The existence of response options is not evidence that a specific attack is expected. It is evidence that NATO wants Moscow to understand that ambiguity will not automatically produce paralysis.
Germany’s Leipzig case has become a reference point
One of the incidents repeatedly cited by European officials is the attempted drone attack at Leipzig/Halle Airport in Germany in August. German authorities said an explosive-laden drone was found near a Ukrainian cargo aircraft and later attributed the operation to Russian state actors following police and intelligence work. Berlin summoned the Russian ambassador and announced diplomatic measures in response. Moscow rejected the accusation and said the evidence had been fabricated. The case is significant because Leipzig/Halle is not simply a civilian airport. It is a major cargo hub, and logistics infrastructure has strategic value during a war in which European countries are supplying Ukraine with weapons, equipment and humanitarian support. An attack on transport infrastructure can therefore serve several purposes simultaneously: disrupt operations, raise insurance and security costs, create fear among workers and test how quickly authorities can identify responsibility. From a NATO perspective, the difficulty is that even a serious act of sabotage may not resemble the conventional military scenarios for which collective defence was originally designed. A drone launched covertly from inside Europe is different from a missile visibly fired from Russian territory. The physical damage may be smaller, but the political challenge can be greater because the alliance must determine whether the incident is criminal, intelligence-related, military or some combination of the three. Germany’s attribution has become part of a broader European argument that hybrid attacks need faster, more coordinated consequences. The deterrence problem is straightforward: if an actor believes covert action can produce disruption while avoiding meaningful retaliation, the incentive to repeat it grows. But retaliation without reliable attribution creates its own risk. The balance between speed and evidentiary confidence is therefore one of the central problems NATO is trying to solve through deeper intelligence cooperation.
The Baltic and Danish straits sit at the center of the pressure zone
Denmark’s threat assessment comes after a series of tense incidents in the Baltic region, an area where civilian shipping, energy infrastructure, NATO military activity and Russian naval movements overlap in a confined maritime space. The Danish straits are the primary route connecting the Baltic Sea with the North Sea and the wider Atlantic. They are strategically important for NATO but also for Russian commercial and military traffic, including oil shipments and naval deployments. Earlier in September, Denmark said a Russian frigate fired two flares toward a Danish military helicopter that had been sent to photograph the ship in international waters. Danish officials said one flare passed close to the aircraft and that no warning or radio contact preceded the action. Denmark summoned the Russian ambassador. Moscow disputed Copenhagen’s account of responsibility, accused Danish helicopters of unsafe maneuvers near Russian warships and said the incident required investigation. The encounter did not trigger NATO collective-defence consultations, and Danish officials did not describe it as an armed attack on Danish territory. Its importance lies instead in the risk of miscalculation. Military aircraft and warships routinely observe one another in international waters. When those encounters become more aggressive, the margin for error narrows. A flare is not a missile, but an action that places an aircraft at risk can escalate rapidly if crews interpret intent differently or respond defensively. The Baltic environment also includes undersea cables, pipelines, offshore energy assets, ports and dense commercial traffic. Damage to any of those systems can have economic consequences disproportionate to the physical scale of an incident. That makes the region an ideal environment for grey-zone pressure: strategically important, technically complex and difficult to monitor continuously. Denmark’s warning reflects not only concern about deliberate attack, but about a pattern of behavior that could make accidents and escalation more likely.
Cyber risk is moving closer to physical security
Denmark’s Resilience Agency separately raised its assessment of the threat from destructive cyberattacks, saying Russia is likely to attempt such operations against Denmark. Cybersecurity has long been treated as a parallel domain to conventional defence, but the distinction is increasingly artificial. Railways, ports, electricity networks, telecommunications, hospitals, airports and military logistics all depend on digital systems. An intrusion can create physical disruption without an explosive device ever crossing a border. The strategic effect of cyber operations depends on timing and target selection. A temporary website outage is a nuisance. A coordinated attack on transport, power or communications during a military crisis can complicate mobilization and decision-making. A cyber operation against a company supplying Ukraine can disrupt production while preserving deniability. An intrusion that steals information rather than destroys systems can reveal vulnerabilities for future use. For NATO governments, this creates a problem of thresholds similar to sabotage. Cyberattacks vary enormously in severity. Some are espionage, an activity conducted by almost every major power. Others are criminal ransomware. Others may be state-directed destructive operations. Determining when a cyber incident becomes a national-security attack requires both technical evidence and political judgment. Intelligence-sharing helps connect malware signatures, infrastructure, operator behavior and intelligence reporting across borders. The challenge is especially acute because much European critical infrastructure is privately owned. Governments may possess intelligence about a threat but depend on telecommunications companies, grid operators, cloud providers, transport firms and industrial suppliers to implement defensive measures. A modern deterrence strategy therefore requires a network that extends beyond military headquarters. The front line of hybrid security may be a data center, a railway control room or a maintenance contractor long before it is a NATO base.
The real target may be alliance cohesion rather than territory
Ahrenkiel said the purpose of a hypothetical limited attack would not necessarily be territorial conquest but division inside NATO. That assessment reflects a broader concern among European officials: the alliance can be tested politically without being challenged militarily on a scale that would guarantee a unified response. If an incident is ambiguous, allies may disagree over whether it was deliberate, who carried it out and how strongly to respond. That creates a spectrum of possible coercion. At one end are influence operations and cyber espionage. Further along are sabotage and covert attacks against infrastructure. Beyond that are dangerous military encounters, airspace violations or deliberately ambiguous strikes. At the far end is overt armed attack. The problem is not that every incident naturally escalates along this spectrum. It is that an adversary may try to move up and down it while constantly measuring political reaction. Collective defence is most credible when the threshold is unmistakable. Hybrid pressure tries to blur it. A member state hit by a suspicious drone may demand solidarity while others ask for more evidence. Governments may agree on attribution but differ on sanctions or military response. Domestic political movements may exploit uncertainty. Information operations can amplify disagreement before technical investigations are complete. The Danish assessment therefore focuses as much on political psychology as on weapons. A limited strike that causes modest physical damage could still succeed strategically if it persuades some allies that supporting Ukraine has become too risky or that defending a particular member could drag Europe into a larger war. Conversely, a coordinated and proportionate response can deny that objective even if the original act cannot be prevented. Cohesion is part of deterrence.
The EU is using sanctions against the information side of the campaign
On the same day Denmark released its threat assessment, the Council of the European Union imposed restrictive measures on Xenia Fedorova, a Russian media figure and former senior executive of RT France, over what the Council described as foreign information manipulation and interference. The EU said the designation brought the sanctions framework for Russian destabilizing activities to 81 individuals and 20 entities. The EU’s action illustrates how European institutions define hybrid pressure more broadly than physical sabotage. Information operations are treated as part of the same security ecosystem because they can shape the political environment in which governments respond to military or covert incidents. Narratives that deny attribution, exaggerate alliance divisions, question support for Ukraine or portray defensive measures as aggressive can influence public perception even when they do not directly damage infrastructure. The Russian government and Russian-linked media figures have consistently rejected Western allegations that Moscow is conducting an organized campaign to destabilize Europe, and they accuse EU governments of censorship and political repression. Those competing claims should not be collapsed into equivalence: sanctions are formal political decisions based on European assessments, while legal and evidentiary standards vary across jurisdictions. But the existence of competing narratives is itself part of the environment NATO and the EU are trying to manage. Information warfare complicates crisis response because speed favors the first persuasive story, while evidence often arrives slowly. A manipulated video, false claim of responsibility or fabricated document can circulate widely before investigators determine what happened. Intelligence-sharing therefore increasingly includes not only secret information but coordinated public communication. If governments disagree publicly while still investigating, that gap can become a vulnerability.
Ukraine remains the strategic center of gravity
Although the latest warnings concern NATO territory, the war in Ukraine remains the central driver of the confrontation. European officials argue that many hybrid operations are intended to raise the cost of supporting Kyiv, disrupt supply networks and weaken political willingness to continue military and financial assistance. Russia denies carrying out sabotage in Europe and says NATO countries are escalating the conflict by arming Ukraine. The logistics network behind Ukrainian defence stretches far beyond the Ukrainian border. Weapons, ammunition, spare parts, air-defence systems, fuel, medical supplies and humanitarian aid move through European ports, railways, roads, depots and airfields. Industrial plants across Europe are producing or repairing equipment. Training facilities host Ukrainian personnel. Cyber networks coordinate procurement and transport. That distributed architecture makes the support system resilient, but it also creates many potential pressure points. A conventional Russian strike on a NATO logistics hub would carry an obvious risk of escalation. A covert action, cyber intrusion or deniable sabotage attempt may appear to offer a different risk-reward calculation. That is the logic European security services are trying to counter: reduce the attacker’s confidence that covert activity will remain unattributed, and increase the likelihood that multiple governments will respond collectively rather than treat each case as a domestic anomaly. The timing is especially sensitive because Russia and Ukraine continue to exchange long-range strikes while diplomacy over energy infrastructure and Black Sea shipping remains uncertain. Europe is preparing for another winter in which Ukrainian power systems, logistics and air defence will be under pressure. Hybrid activity against European support networks could magnify the effects of battlefield operations without requiring direct confrontation between Russian and NATO forces.
A limited attack is not the same as an invasion scenario
The most alarming part of Denmark’s assessment is the statement that a limited Russian military attack on a NATO country is now a low but growing risk. That judgment requires careful interpretation. The Danish service simultaneously said a full-scale invasion remains unlikely. The two scenarios involve different objectives, force requirements and escalation dynamics. A conventional invasion designed to seize large territory would require substantial forces, logistics and preparation. Russia remains heavily committed in Ukraine, and any major attack on NATO would risk war with an alliance possessing far greater aggregate economic and military resources. A limited attack, by contrast, could involve a small number of weapons, troops or covertly supported actors and might be designed to test political reaction rather than achieve lasting territorial control. That does not make a limited attack safe or easily containable. The opposite may be true. A small incident can create intense pressure for immediate response while leaving uncertainty over intent. Governments must decide whether the attack is a deliberate strategic move, a local unauthorized action, a false flag, a technical error or the opening phase of something larger. Those decisions may need to be made before complete intelligence is available. The purpose of public threat assessments is partly to reduce that uncertainty in advance. By discussing possible scenarios openly, Denmark is signaling that seemingly isolated incidents will be evaluated within a broader strategic context. It is also signaling to Russia that attempts to exploit ambiguity are being anticipated. Public warning can therefore function as deterrence: a tactic is less attractive if the intended surprise has already been described and allies are preparing a coordinated response.
Moscow denies the accusations and says Europe is escalating
Russia’s position is an essential part of the story because the central dispute is one of attribution and intent. Moscow has repeatedly denied conducting sabotage or hybrid warfare against NATO states and says Western governments use such accusations to justify military spending, sanctions and deeper involvement in Ukraine. The Russian embassy in Denmark rejected the new Danish assessment as unsupported by credible evidence and accused Western governments of increasing tensions. Russian officials have also disputed specific incidents. In the Danish helicopter case, Moscow accused the Danish side of dangerous flying near its warship. In the Leipzig case, Russian authorities rejected Germany’s attribution. Those denials do not invalidate Western findings, but they reinforce the reason independent evidence and allied intelligence review matter. The political consequences of attribution are too serious for assumption to substitute for investigation. There is also a broader strategic disagreement. Russia portrays NATO expansion, Western military assistance to Ukraine and alliance activity near its borders as threats to Russian security. NATO states describe their measures as defensive responses to Russia’s invasion of Ukraine and to hostile activity affecting allied territory. Each side therefore interprets military readiness by the other through a different narrative of cause and effect. That mutual suspicion raises the risk that even routine military activity can be interpreted as deliberate escalation. The more frequently ships, aircraft, drones and intelligence platforms operate in close proximity, the greater the chance that an incident begins without a central political decision to escalate. Crisis-management channels and professional military procedures remain important precisely because deterrence does not eliminate accidents.
Intelligence-sharing is only useful if governments can act on it
NATO’s decision to intensify intelligence exchange addresses one part of the problem, but information alone does not create resilience. Intelligence must move quickly enough to reach the authorities responsible for protecting airports, energy systems, ports, railways and telecommunications. It must also be specific enough to support action without exposing sensitive sources and methods unnecessarily. That is harder than it sounds. Intelligence agencies classify information according to national rules, and some data cannot be widely distributed. Police investigations operate under evidentiary standards different from military intelligence. Private companies may need actionable warnings but cannot be given the underlying secret reporting. Cyber indicators can be shared at machine speed, while human-source intelligence may require strict compartmentalization. The architecture of cooperation matters as much as the volume of information. The most effective model is likely to combine strategic sharing at NATO headquarters with operational networks among national agencies. A suspicious drone component recovered in one country can be compared with parts found elsewhere. A malware signature can be distributed across allied cyber centers. A financial transaction linked to procurement can be matched against sanctions data. Maritime tracking can reveal repeated patterns involving vessels of interest. None of these pieces alone proves a campaign, but together they can change confidence levels. The political benefit is equally important. If allied governments see the same evidence at roughly the same time, they are less vulnerable to information gaps that produce contradictory public statements. A coordinated assessment does not guarantee agreement on policy, but it improves the odds that disagreement is about response rather than basic facts. In a hybrid confrontation, establishing a shared reality is itself a strategic advantage.
Deterrence requires proportionate consequences without uncontrolled escalation
The hardest policy question is how to impose costs on hybrid aggression without turning every ambiguous incident into a military crisis. If NATO responds too weakly, covert pressure may become normalized. If it responds too aggressively before attribution is solid, it risks escalation based on incomplete information. The alliance therefore needs a menu of responses rather than a single threshold-based reaction. Sanctions are one tool, as the EU’s hybrid-threat listings demonstrate. Diplomatic expulsions can disrupt intelligence networks. Criminal prosecutions can expose operatives and intermediaries. Cyber measures can degrade infrastructure used for hostile operations. Military deployments can reassure vulnerable allies without attacking anyone. Public attribution can deny secrecy and impose reputational costs. Economic restrictions can target companies that facilitate procurement or logistics. The concept of proportionality is strategic as well as legal. A response should be strong enough to alter the adversary’s calculation but controlled enough to preserve political support among allies. Hybrid deterrence is therefore cumulative. One sabotage incident may lead to sanctions; repeated incidents may produce broader restrictions, force deployments and changes in rules of engagement. The goal is to make each additional operation more expensive than the last. This is where allied unity becomes the decisive variable. Russia’s presumed objective, according to Danish intelligence, is to divide NATO. A measured but collective response can frustrate that objective even when it does not eliminate the underlying threat. Conversely, dramatic rhetoric followed by fragmented action can reinforce the perception that the alliance is politically vulnerable. Deterrence depends not only on military capability but on the credibility of political follow-through.
Europe is entering a security phase where ambiguity itself is a weapon
The significance of Denmark’s warning and NATO’s response is that they redefine what preparation for conflict now means. Europe is not only planning for tanks crossing borders or missiles striking cities. It is preparing for pressure that may arrive through compromised networks, covert operatives, anonymous drones, manipulated information, disrupted transport or aggressive encounters that stop just short of open war. That does not mean a wider European war is inevitable. The Danish intelligence service explicitly judges a full invasion of NATO territory unlikely, and Grynkewich said a limited attack is also unlikely. Those judgments matter. Responsible security policy should not transform low-probability scenarios into certainty. But low probability is not the same as irrelevance when the consequences could be severe and when intelligence services see the risk moving upward. The alliance’s answer is increasingly based on reducing the strategic value of ambiguity. Faster intelligence-sharing can shorten attribution timelines. Stronger infrastructure can limit disruption. Coordinated sanctions and law-enforcement action can raise costs. Visible military readiness can make limited attacks less attractive. Clear public communication can reduce the political effect of disinformation. None of those tools alone is decisive, but together they can narrow the grey zone in which coercion works best. For Europe, the broader lesson is that the war in Ukraine has transformed the continent’s security environment even outside the battlefield. The line between external conflict and internal resilience has become thinner. Ports, data centers, airports, energy networks, media systems and commercial supply chains now sit inside strategic calculations once associated mainly with armed forces. NATO’s intelligence response is therefore not simply about collecting more secrets. It is about giving governments enough shared understanding to prevent uncertainty from becoming a weapon against the alliance itself.



