Hybrid attacks are coordinated hostile actions, conducted by state or non-state actors, designed to remain below the threshold of open armed conflict: sabotage, arson, cyber attacks, drones on airports, jamming of satellite signals, disinformation campaigns. They are not a declared war and this is precisely why they work: they exploit the ambiguity and the difficulty of attributing responsibility with certainty, which is precisely what makes the response complicated. The term has returned to the center of the European debate after the explosive drone found at Leipzig airport and the new sanctions being prepared against Russia.
The definition: below the threshold of war
The European Union’s formulation describes hybrid threats as a combination of diplomatic, military, economic and technological measures used in a coordinated manner by state or non-state actors to exploit an adversary’s vulnerabilities, with actions designed to stay below the threshold that could constitute, or be perceived as, an act of war. The Italian Ministry of Defense document «Countering hybrid warfare: an active strategy» uses a similar definition: coordinated actions in multiple domains, «below the threshold of armed conflict and often unattributable», aimed at damaging, destabilizing or weakening the target state.
The decisive characteristic with respect to conventional war is therefore not the type of instruments – which can also be very violent – but the way in which they are combined: actions across multiple domains, coordinated with each other, kept below threshold and built to remain deniable. The attacker is counting on the affected country to take weeks or months to formally establish who did it, if it succeeds at all.
How they manifest themselves
The repertoire is large and expanding. It includes sabotage of critical infrastructure, from undersea cables to railway lines; arson at warehouses and factories; cyber attacks on hospitals, ports and administrations; The jamming and it spoofing of satellite signals, i.e. the disturbance or falsification of GPS coordinates which causes air and maritime navigation to fail; unauthorized drone overflights over airports and military bases; airspace violations; disinformation campaigns and electoral interference. A separate category is recruiting, often through Telegramof local perpetrators charged with carrying out sabotage or delivering bombs for a fee: in September 2025 the Lithuanian General Prosecutor’s Office announced that fifteen people were suspects in the investigation into four terrorist acts with hybrid purposes, three of whom are still wanted internationally.
A rapidly growing phenomenon
The Munich Security Report 2026 mapped, based on data from the Acled project, episodes of suspected Russian hybrid activity in European Union and NATO countries between January 2022 and December 2025, recording strong growth in the phenomenon, particularly evident in the autumn of 2025. The report notes that many of these episodes are constructed to remain deniable or ambiguous, allowing pressure to be exerted without offering any basis for attribution.
The most acute moment was September 2025: around twenty Russian drones penetrated Polish airspace and three MiG-31 fighters violated Estonian airspace for twelve minutes. Both governments have requested NATO consultations under Article 4, the procedure that allies activate when they believe their security is threatened. Another indicator comes from Germany: reports of drones in the fifteen main German airports went from 101 in the first half of 2025 to 166 in the same period of 2026, according to data from Deutsche Flugsicherung, the body that controls air traffic.
The Leipzig case and the problem of attribution
The episode that brought the topic back to the top of the European agenda was that of Leipzig/Halle airport: on the night between 4 and 5 August a drone equipped with explosives was found in the cargo area, near Ukrainian aircraft, in what the German government later defined as an attempted attack. The trigger was removed by the bomb squad. On September 1, almost a month later, Berlin formally attributed the attack to Russia and announced the closure of the Russian consulate general in Bonn as of September 18. Moscow has denied all charges.
Those four weeks are the exact measure of the problem: collecting the elements is one thing, tracing the instigator and taking on the political responsibility of saying it publicly is another entirely. This is why EU High Representative Kaja Kallas, at the meeting of Foreign Ministers in Wicklow, linked the multiplication of these episodes to the acceleration of the sanctions package against Russia.
Because the issue concerns Sicily
One of the most sensitive fronts for Italy is the underwater one. Over twenty submarine fiber optic cables land in Sicily – in the stations of Palermo, Catania, Mazara del Vallo, Pozzallo and Trapani – and make the island a strategic hub for digital traffic between Europe, Africa, the Middle East and Asia. Globally, more than 95 percent of international internet traffic travels over undersea cables. According to the I-Com research institute, Italy is home to 34 submarine cable systems, distributed across Sicily, Puglia and Liguria, and is the world’s fourth largest producer of complete systems for these infrastructures.
On 23 June 2026, the European Commission financed the establishment of the first two regional hubs for the protection of submarine infrastructures with 5.8 million euros: one in the Baltic, coordinated by Finland, and one in the Mediterranean, coordinated by Italy together with Greece, Cyprus and Malta, to which 3.3 million go. On April 17, the president of the Chamber’s Defense Commission, Nino Minardo, announced that the Italian headquarters will be in Sicily. In the Mediterranean, unlike the Baltic covered by the operation Baltic Sentry, There is currently no equivalent permanent NATO operation specifically dedicated to the protection of submarine infrastructures; However, the maritime security operation is active in the basin Sea Guardianwhich can also be responsible for the protection of critical infrastructure at sea.
Because it’s difficult to answer
The answer remains the open question. For a hybrid threat to trigger mutual aid mechanisms it must reach a high threshold: that of an ‘armed attack’ under Article 5 of the Atlantic Treaty, or an ‘armed aggression’ under Article 42(7) of the Treaty on European Union, which is the mutual assistance clause. NATO specifies that the assessment is made on a case-by-case basis and that particularly serious cyber or hybrid attacks may also be included. In the meantime, the Union is working on ordinary tools. On 16 March 2026, the Council approved conclusions on strengthening the capacity to counter hybrid threats, focusing onHybrid Toolbox; on 11 February the Commission presented an action plan on drones and counter-drones, which paves the way for the European Drone Defense Initiative.