본문으로 건너뛰기
2026년 9월 29일 (Tue)

LUXDIGEST

밀리터리뉴스-en

Denmark Intelligence Assessment Warns of Rising Russian Hybrid Attacks

NATO와 러시아의 하이브리드 위협을 상징하는 발트해 안보 회의 모습

Danish Intelligence Warns Russia Could Escalate Hybrid Attacks

Russia is likely to intensify its hybrid warfare against NATO and the West over the coming months, Denmark’s Defence Intelligence Service (FE) said in a threat assessment published on September 24, 2026. The agency said not only the frequency of attacks but also their potential impact and wider effects on society could increase.

At the same time, the FE assessed that the risk of Russia launching a limited military attack against one or more NATO members remains low but is rising. A full-scale invasion of a NATO country, however, remains highly unlikely, the agency said, adding that there are currently no signs Russia is preparing for one.

Key Findings of the FE Threat Assessment

The English-language threat assessment released by the FE runs to three pages. It says Russia is seeking to weaken Western support for Ukraine through sabotage, disruptive cyberattacks and drone operations in Europe.

According to the FE, Russia’s hybrid attacks have so far focused on creating fear in European societies and swaying public opinion against support for Ukraine. More recently, there have also been signs that Russia is directly targeting support networks, including defence contractors and railways used to transport military supplies to Ukraine.

The Danish intelligence service said Russia could carry out more frequent and serious attacks against the West and NATO in the coming months. These could include cyberattacks capable of disrupting critical societal functions, as well as sabotage posing a significant risk of casualties.

Hybrid Warfare: A Combination of Cyberattacks and Sabotage

Unlike conventional warfare, which relies primarily on military force, hybrid warfare combines cyberattacks, sabotage, disinformation, political and economic pressure, and military provocations. Such operations are often designed to obscure who is behind them, making it difficult to respond and establish responsibility.

The FE said Russia is seeking to test the West’s willingness to respond while remaining below the threshold of armed conflict, and to encourage divisions within NATO. It may deliberately stage attacks so they appear to be isolated incidents, making it harder for allies to agree on a joint response.

European countries, including Denmark, are already exposed to threats ranging from cyber intrusions targeting defence facilities and critical infrastructure to distributed denial-of-service attacks that take websites offline and sabotage aimed at communications and transport networks.

Risk of Limited Military Attack Remains Low but Is Rising

The FE assessed that the risk of Russia launching a limited military attack against one or more NATO countries bordering Russia is low but increasing. Such an attack could take place even as the war in Ukraine continues.

Possible scenarios include long-range strikes against infrastructure critical to supporting Ukraine, so-called false-flag operations intended to conceal Russian involvement, and the deployment of small units without national insignia.

The FE said Russia could choose a limited attack to test the alliance’s response threshold even if it did not want a full-scale war with NATO. A full-scale invasion, however, would require the large-scale mobilisation of troops and equipment and could take at least six months to prepare, making it difficult to carry out covertly in the short term.

NATO’s Challenge: Coordinated Response and Infrastructure Protection

The assessment underscores the need for NATO to develop a coordinated response not only to military threats but also to attacks in cyberspace and against civilian infrastructure. As incidents involving unclear perpetrators and motives continue, information-sharing and rapid joint decision-making will become increasingly important.

If Russia follows the pattern identified by the FE and directly targets support networks for Ukraine, strengthening the security of defence contractors, railways, ports, communications networks and energy facilities will be a central priority. Threat intelligence-sharing between governments and private companies will also need to expand.

The report is less a warning that a full-scale Russian invasion of NATO is imminent than an indication that pressure and provocations below the threshold of armed conflict could become more frequent. NATO members will need to review both their deterrence and crisis-response capabilities, including the possibility that limited military and hybrid attacks could be combined.

Frequently Asked Questions (FAQ)

Does the Danish intelligence service believe a Russian attack on NATO is imminent?

No. The FE assessed that the risk of a limited military attack is low but rising, while the possibility of a full-scale invasion of a NATO country remains very low.

What would Russia’s hybrid attacks include?

They could include cyberattacks, sabotage, disinformation and influence operations, military provocations, and disruption of critical infrastructure. A defining feature is the use of multiple tools at once to create social unrest and political divisions.

What form could a limited military attack take?

Possible scenarios include long-range attacks on infrastructure critical to supporting Ukraine, false-flag operations, and the deployment of small units without national insignia.

Does the assessment say Denmark itself faces a heightened risk of attack?

The limited military attacks discussed in the report would primarily target NATO countries that share a border with Russia. For Denmark, the focus is on remaining alert to hybrid threats such as cyberattacks and sabotage rather than to a direct military attack.

What should NATO prepare to do?

Members should strengthen information-sharing and improve the security of critical infrastructure, including defence facilities as well as energy, communications and transport networks. It is also important to establish procedures for rapidly deciding whether a joint response is warranted when an attack occurs.

김지훈 기자
Facebook X (Twitter) 링크복사