top of page

When Hybrid Attacks Stay Below Article 5: Europe’s Strategic Communications Problem

4 days ago
6 min read


Finally, Europe is not debating whether hybrid attacks are a real security threat. The question now is how to respond when the hostile activity is serious enough to threaten national security and actually falls below the threshold of a conventional hard power projection and armed attack.

 

The past few weeks have brought the problem into sharper focus. Germany formally attributed the August drone incident at Leipzig/Halle Airport to Russia (DW, 2026). Days later, a NATO fighter shot down a suspected Russian military drone carrying explosives after it entered Lithuanian airspace from Belarus. In the Baltic Sea, a Russian frigate fired flares near a Danish military helicopter. European officials have linked these incidents to a wider pattern of sabotage, cyber operations, airspace violations and other hostile activity. The EU has described the campaign as becoming “more frequent and more brazen.” (EU, 2026). 

 

At the same time, European ministers have stressed that they do not see an imminent Russian military attack on NATO. Reporting from this week's European discussions captures the tension: governments are warning about intensifying sabotage, cyberattacks and drone incursions while also arguing that Moscow is using these activities to create fear and test Western resolve (Reuters, 2026).

 

None of these incidents automatically triggers Article 5, and that is precisely the problem.

For Europe, the challenge is not only detecting hybrid activity. It is establishing a credible and understandable relationship between an attack, attribution, response and further communication. If that relationship remains unclear, Russia can continue testing European reactions without necessarily crossing the threshold of conventional military confrontation.

 

The space below Article 5 is getting crowded

 

NATO's position is deliberately flexible. Article 5 applies in the case of an “armed attack”, but NATO explicitly states that this assessment is made case by case and is not limited to conventional military strikes. Significant cyberattacks and other hybrid attacks may qualify depending on their circumstances. (NATO, 2026). One can argue that flexibility is necessary. Potentially, a cyberattack on critical infrastructure, sabotage of a railway, a drone incursion or an attack on an airport cannot automatically be treated in the same way as a missile strike or military invasion.

 

But the ambiguity creates another problem: what happens in the space between Article 4 consultation and Article 5 collective defense?

 

Recent events show that this space is becoming strategically important and narrowed.

On September 14, an Italian fighter operating under NATO's Baltic Air Policing mission shot down a suspected Russian Geran-2 drone that entered Lithuanian airspace. Lithuanian authorities said the drone was carrying explosives. (Reuters, September 14 2026). The incident was different from earlier accidental drone crashes. It involved an armed drone, NATO airspace and an actual interception.

 

Yet it did not become an Article 5 case.

 

The same week, EU foreign policy chief Kaja Kallas pointed to the combination of incidents across Europe: a Russian warship firing flares at a Danish helicopter, the drone shot down over Lithuania, and the Leipzig airport incident. Her argument was that Europe was facing a “pattern” rather than isolated events. (EEAS, September 15 2026).

 

In a way that distinction matters. Hybrid warfare is often designed around cumulative pressure. Each incident can remain below the conventional threshold while the overall pattern becomes strategically significant.

 

The threshold is becoming part of the message

 

Hybrid warfare works partly by exploiting uncertainty. A drone crossing an airspace boundary can be described as an accident. A damaged cable can be blamed on an equipment failure. A cyberattack can be attributed to criminals. A suspected act of sabotage can remain under investigation for months.

 

Individually, these incidents may be ambiguous, collectively, they can form a pattern. That is precisely what European officials are now describing (EEAS, 2026). NATO identifies Russian sabotage, cyber activity, disinformation, political influence and provocations at Allied borders as part of a broader campaign against its members. NATO's Military Committee has also warned that Russia's investment in “cognitive warfare” is intended to undermine trust and weaken Allied unity (Brussels Morning, 2026).

 

The communications challenge is obvious: if every incident is treated separately, the adversary benefits from fragmentation. If every incident is immediately presented as an act of war, governments risk losing credibility and unnecessarily escalating the situation.

 

Strategic communications therefore have to connect individual incidents to a broader threat picture without overstating what is known.

 

Attribution is itself a strategic action

 

The Leipzig case is important because Germany eventually moved from investigation to public attribution. Berlin said Russia was responsible for the August drone attack, while Moscow denied involvement. The EU subsequently described the incident as an attempted Russian hybrid act of sabotage and linked it to a broader pattern of hostile activity. Consequently, public attribution changes the strategic environment. But attribution only strengthens deterrence if it is connected to consequences. Otherwise, public naming risks becoming a norm: Russia is blamed, a statement is issued, sanctions are discussed, and the cycle continues. And the problem is not to disclose intelligence or announce every response publicly. The idea is to communicate the logic of the response.

 

Strategic ambiguity is useful, while strategic uncertainty is not.

 

NATO has deliberately maintained some ambiguity around its response options. An adversary should not have a complete map of how NATO would respond to every type of attack. But ambiguity should not mean that Russia is unable to understand whether an attack will produce consequences. This distinction is central to credible deterrence.

 

A useful strategic message would be: you may not know exactly what response an attack will trigger, an adversary should know that it will trigger a response.

 

In September, Ursula von der Leyen proposed a European counter-hybrid playbook and an Emergency Security Protocol for incidents that fall below armed aggression but clearly threaten national security (Euronews, 2026). The stated purpose is to coordinate a European response, deter further escalation and mitigate the impact.

 

The institutional proposal matters. But the communications component matters just as much. A response mechanism that exists only inside government documents will have limited deterrent value.

 

Europe needs a clearer communications architecture

 

A European approach to hybrid threats should therefore include four communications principles.

 

First, communicate attribution with calibrated confidence.

 

Governments should distinguish between an incident under investigation, an incident assessed as foreign-directed, and an incident formally attributed to a state. NATO's approach to information threats emphasizes the importance of identifying, analyzing and assessing hostile activity so that responses can be timely and calibrated. It also explicitly connects information threats with physical activities such as sabotage (NATO, 2026). Second, communicate consequences without necessarily communicating capabilities.

 

Governments do not need to reveal intelligence operations, cyber capabilities or military plans. But they should make clear when an incident has triggered diplomatic, economic, intelligence or security measures. Operational secrecy can coexist with strategic clarity.

 

Second, communicate the pattern, not just the incident.

 

A cyberattack, a drone incursion and infrastructure sabotage may involve different agencies and different responses. Strategic communications should explain when governments assess that these incidents form part of a broader campaign. This is particularly important because Russia benefits from keeping each action in a separate category.

 

Third, communicate resilience as part of deterrence.

 

This is an underused element of European messaging. Lithuania is now designing critical energy infrastructure with the possibility of drone attacks explicitly in mind (Reuters, 2026). NATO has also strengthened requirements for civilian resilience across energy, communications, transport, food, water and healthcare (NATO, 2026).

 

An attack that fails to produce strategic disruption is a failed coercive operation. And it is not only the infrastructure policy. It is strategic communication. Most importantly, the audience is not only Moscow.

 

Hybrid operations are designed to create political effects inside the target state. Russia does not need every European citizen to believe a particular false narrative. It can benefit from uncertainty, fatigue and the perception that governments are unable to protect critical infrastructure or agree on a response.

 

NATO explicitly defines hostile information activities as efforts to weaken and divide the Alliance, and its approach stresses proactive communication as a tool for resilience. This means European governments have two audiences during a hybrid incident: the first is the adversary and the second is their own population.

 

The message to the first should be: hostile activity generates costs.

 

The message to the second should be: the state understands what happened, is acting proportionately, and remains capable of protecting society.

 

Below Article 5 cannot mean below the communications threshold

 

Europe does not need to make every hybrid incident an Article 5 crisis. Nor should it try to remove all ambiguity from its response.

 

It needs something more practical: a predictable communications logic for the grey zone.

 

When a serious incident occurs, governments should be able to communicate based on the five “whats”:

 

What happened.What we know.What we assess.What we are doing.What happens if it happens again.

 

However, deterrence will not come from having more institutions or issuing stronger statements. It will come from making Europe's response understandable. Russia does not need to know exactly where every European red line is. But it should understand that operating below Article 5 does not mean operating without consequences. And at the same time, European publics should understand the same thing.

 

The strategic communications test is therefore not to promise that every hybrid attack will trigger escalation. It is to make clear that every serious attack will trigger a deliberate response, and that repeated attacks will change the further and final calculation.


Photo: Scott Peterson / Getty Images, via The Kyiv Independent


____________________

By Mariam Gamdlishvili, Executive Director, SSI

 
 
bottom of page