Updated: September 28, 2026

On the night of August 4–5, a drone carrying explosives was discovered at Leipzig/Halle Airport. A month later, the German government publicly attributed the attempted attack to Russia.

One explosive-laden drone at a German airport does not, by itself, redefine European security. The problem is that it did not happen in isolation.

In recent months, European authorities have reported a growing number of acts of sabotage, cyberattacks, attempted attacks on infrastructure, information operations, drone incursions and violations of national airspace. In some cases, governments say they have established a connection to Russia. In others, that connection remains a suspicion. And in still others, the origin of the incident is unclear.

What has changed is that Europe is increasingly reluctant to treat every episode as an isolated event.

After the Leipzig incident, the German government explicitly described it as a Russian hybrid attack. On September 14, Germany's National Security Council said the country remained a target of Russian hybrid operations and approved additional measures against espionage and sabotage and to protect critical infrastructure.

That change in language matters.

For years, European governments largely debated the risk that Russia's war against Ukraine might one day spill beyond Ukraine's borders. Today, official statements by NATO and European governments increasingly describe a different reality.

There is no full-scale war between Russia and NATO.

But the old definition of peace is becoming harder to apply.

A war that is difficult to see

In military and security policy, the term hybrid warfare describes the use of military and non-military, overt and covert methods in combination: sabotage, cyberattacks, disinformation, economic pressure, operations conducted through intermediaries and other tools that can damage an adversary without immediately crossing the threshold into conventional war.

Its defining feature is ambiguity. It deliberately blurs the line between war and peace.

A conventional attack is at least relatively easy to identify. There is a missile. There is a launch site. There is a target. There is a state that fired it.

In the gray zone, almost nothing is that simple.

A warehouse catches fire.

A cable is damaged.

A drone crosses into another country's territory.

A government computer network stops working.

Who did it?

Was it a state operation, a paid intermediary, a criminal group, a technical failure or simply an accident?

By the time investigators find an answer, the consequences are already real.

The targeted country has to strengthen security at airports and power plants, spend more on air defense, cybersecurity and counterintelligence, inspect thousands of miles of infrastructure and decide how far it can go in responding without triggering a larger confrontation.

In that sense, uncertainty is not a weakness of a hybrid operation. It is one of its most useful features.

One drone is not a war

September brought a series of incidents that intensified the debate over Russian activity beyond Ukraine.

German Defense Minister Boris Pistorius pointed to several of them, including a drone carrying explosives over Lithuania that was destroyed by NATO aircraft, Russian military activity near NATO's eastern border and the attempted attack in Leipzig. His broader point was that the threat was becoming more tangible and harder for European governments to dismiss as theoretical.

But this is also where an important distinction has to be maintained.

Not every drone found over Europe was deliberately sent by Russia against a NATO country.

Not every fire is sabotage.

Not every damaged cable is an operation by Russian intelligence.

And even when a government publicly attributes an incident to Russia, that remains an attribution made by a particular state on the basis of its investigation and intelligence assessments.

Moscow rejects accusations that it is waging a hybrid war against NATO or preparing for a confrontation with the alliance. Russian officials repeatedly say that Russia has no intention of attacking NATO member states.

The danger, therefore, is not that Europe has already entered a conventional war with Russia.

It is that an enormous space has opened between unmistakable peace and unmistakable war — a space in which hostile operations can continue for years.

Why the old question no longer works

Since February 2022, the question has usually been framed in a familiar way: Will Russia attack a NATO country?

That question assumes a recognizable scenario — Russian troops crossing the border into Estonia, Latvia, Lithuania or Poland, followed by a debate over Article 5 of the North Atlantic Treaty.

But a modern confrontation does not necessarily begin with a tank column.

NATO itself has made clear that an armed attack need not take only a conventional military form. The alliance has said that serious cyber or hybrid operations could, depending on their scale and circumstances, lead allies to consider invoking Article 5. Any such decision would be made case by case.

That is where the central problem begins.

What counts as an attack?

If a group acting on instructions from a foreign intelligence service sets fire to a factory, is that a criminal offense or a military operation?

If a drone carrying explosives reaches an international airport, is that sabotage or an armed attack?

If a cyberattack disables a country's power grid for several days, how different is the result from a missile strike on the same infrastructure?

There is no universal answer.

And that creates a paradox.

An actor seeking to avoid a direct NATO military response has a strong incentive to remain just below the threshold at which allies would collectively define what happened as an armed attack.

The threshold

Imagine two extremes.

At one end is a spy caught trying to obtain classified documents. States have engaged in espionage for centuries. Countries do not go to war every time an intelligence officer is exposed.

At the other is a Russian missile deliberately fired at a European city. In that case, there would be very little ambiguity about the nature of the event.

Between those two points, however, lies a wide spectrum.

Arson.

A cyberattack.

A damaged railway line.

An operation against a defense plant.

A drone incursion.

GPS jamming.

A damaged undersea cable.

An information operation.

The use of intermediaries who can be paid to carry out an operation while the state behind them denies any connection.

Any one of these incidents may be too limited to justify a major response. Viewed together, however, they can produce a very different picture.

That is why the argument over terminology is more than semantics.

If every incident is treated as ordinary crime, a broader campaign can be missed.

If every accident is immediately labeled a Russian attack, a campaign can be imagined where none has been proven.

The responsibility of the state is to establish attribution.

The responsibility of journalism is not to turn suspicion into evidence.

But once a connection has been established, a political question remains: how should a country respond to actions that may be insufficient, individually, to constitute war but that collectively form part of a sustained campaign against it?

The most convenient kind of war

Hybrid warfare has another advantage for the state conducting it: it forces the target to argue over whether a war exists at all.

A conventional invasion tends to unite a society.

Ambiguity divides it.

One person says Russia is already at war with Europe.

Another replies that there is no war because Russian troops have not crossed a NATO border.

In the strict military sense, the second statement is correct. Russia and NATO are not currently engaged in a direct armed conflict.

Yet it is also becoming increasingly difficult to dismiss everything that is happening as a collection of unrelated accidents. Germany has formally attributed the Leipzig incident to Russia and says it remains a target of Russian hybrid operations. NATO has for years treated cyber and hybrid threats as part of the alliance's collective security problem.

The result is a peculiar situation.

European governments are building defenses against activities they describe as hybrid warfare while simultaneously trying to prevent those activities from escalating into conventional war.

That may explain why both Russia and NATO remain so careful around the final threshold.

Russia denies that it intends to attack the alliance. NATO stresses that it will defend allied territory but does not define every hostile incident as an armed attack.

Both sides understand the cost of a mistake.

Has the war already crossed Ukraine's borders?

If war means Russian tank columns moving through Poland or missiles deliberately striking Berlin, the answer is straightforward: no.

There is no such war in Europe outside Ukraine today.

But if the question concerns a confrontation involving sabotage, cyber operations, information warfare and other covert instruments, the answer becomes more complicated.

European governments say that confrontation is already under way.

And perhaps the most important change in the autumn of 2026 is not the number of drones, cyberattacks or acts of sabotage.

It is the question Europe now has to ask.

Until recently, that question was: What happens if the war in Ukraine eventually spreads beyond Ukraine?

Now it is becoming something else:

How many acts normally associated with war can take place on the territory of a country at peace before it becomes impossible to say exactly where peace ended?