Event Brief
Denmark's Defence Intelligence Service (DDIS) released an updated threat assessment on September 24, 2026 warning that Russia is likely to intensify its hybrid war against the West in the coming months, carrying out more frequent attacks against NATO with, in the agency's words, "greater consequences for the countries targeted than in the past." DDIS director Thomas Ahrenkiel told a press conference that there is "a low but growing risk that Russia will launch a limited military attack against one or several Nato countries bordering Russia," while stressing the agency still considers a full invasion of a NATO member "highly unlikely." Denmark's Security and Intelligence Service (PET) separately told AFP that Russian intelligence services are "actively preparing acts of sabotage targeting the defence industry in Denmark."
The assessment outlines specific scenario types rather than a single threat vector. Ahrenkiel described the possibility of Russia deploying a small number of unmarked military personnel into a neighboring NATO country's territory "under the pretext of protecting local Russian minorities," alongside the option of long-range drone or missile strikes on infrastructure supporting Ukraine, including possible false-flag operations using Ukrainian-made drones. DDIS said a force build-up sufficient for such action would take several months to prepare and would be difficult to conceal, and separately noted hybrid attacks could now extend to "destructive cyber attacks that cripple critical societal functions," a shift from earlier campaigns that mainly aimed at spreading fear and weakening public support for aid to Ukraine toward direct sabotage against defense companies and military rail transports.
The warning lands amid a cluster of related intelligence disclosures across Europe within the same 48-hour window. Germany has blamed Russia for an attempted drone attack at Leipzig/Halle Airport, prompting EU members to call for new sanctions. Separately, a CIA-originated warning reported by Spanish outlet El Mundo, citing Lithuanian defense-ministry sources, alleges Russia may be planning to launch Gerbera-type explosive drones from commercial vessels in the Mediterranean to strike Spain, France, or Italy — a report Defense News notes has not been independently corroborated. NATO's Deputy Supreme Allied Commander Europe told reporters around the same period that Russian President Vladimir Putin is becoming "increasingly cavalier, dangerous and risk accepting," even as a British defense official maintained the UK's assessment that Putin is not seeking direct confrontation with NATO.
Danish Defense Minister Jeppe Bruse framed the assessment in terms of Russian frustration: Moscow is under greater pressure than at any point since the invasion began but is not achieving its battlefield goals, and is therefore turning to attacks on Ukraine's supporters instead. DDIS separately assessed the Kremlin will not achieve a significant breakthrough on the Ukrainian front line within the next six months. The assessment does not describe imminent action — Ahrenkiel was explicit that "we do not expect a conventional Russian military attack against Denmark" — but it marks an official intelligence-service escalation in tone from prior assessments, moving from framing hybrid activity as pressure and disruption toward the possibility that future incidents will cause materially greater harm than sabotage and disinformation campaigns to date.
Intersection Groups (7)
Proximity: DirectNear-TermFLOW C
NATO
NATO's political and military leadership must now reconcile a member state's intelligence assessment describing rising sabotage and possible limited attacks with the alliance's collective-defense threshold, which hybrid activity is explicitly designed to stay below. NATO must decide whether to adjust its Baltic Sea and eastern-flank posture, expand attribution and response mechanisms for below-threshold attacks, and coordinate a unified messaging position after a Deputy Supreme Allied Commander already called Putin 'increasingly cavalier' while UK officials maintain Russia is not seeking direct confrontation.
Strategic Options
01Convene a North Atlantic Council session to align member-state threat assessments and issue a unified hybrid-threat doctrine statement, similar to NATO's 2024 hybrid CoE coordination model.
02Expand the NATO Baltic Sentry maritime patrol mission to cover Mediterranean shadow-fleet vessel monitoring given the reported Gerbera drone threat to Spain, France, and Italy.
03Direct the NATO Hybrid CoE in Helsinki to issue rapid attribution guidance so member states can respond to sabotage incidents without waiting for full Article 5 consultations.
↳ Denmark's warning that consequences will be 'greater than in the past' signals that NATO's existing below-threshold response playbook, built around attribution and diplomatic protest, may already be insufficient for the next wave of incidents.
FLOW Rationale: NATO's complexity is driven by needing to reconcile divergent member-state intelligence reads (Danish escalation warning vs. UK's de-escalatory assessment) into one alliance posture without an established consensus mechanism for below-threshold Russian activity.
Scale (Moderate): The DDIS assessment concerns hybrid attacks and a 'low but growing' risk of a bordering-state incident, not an Article 5-triggering event, but it materially affects NATO's threat posture and internal cohesion messaging.
Complexity (High): NATO must interpret conflicting internal assessments (Danish escalation warning versus UK assessment that Russia isn't seeking confrontation) while designing a below-threshold response doctrine that doesn't yet exist in codified form.
Key Question
Can NATO develop a unified attribution and response framework for below-Article-5 hybrid attacks before the 'coming months' escalation window described by Denmark's Defence Intelligence Service closes?
Watch Signals:- [Possible] A North Atlantic Council statement or joint hybrid-threat communique issued in response to the Danish assessment — no confirmed schedule exists yet for such a session.
- [Likely] Expansion of NATO's Baltic Sentry or a new Mediterranean maritime monitoring initiative, given the reported Gerbera drone threat already prompted France's Defense Council meeting on September 16, 2026.
- [Possible] Further NATO commander statements characterizing Putin's risk tolerance, following the Deputy Supreme Allied Commander Europe's September 22 remarks.
Proximity: DirectMonitorFLOW C
Russia
The Kremlin faces a named intelligence assessment describing its own campaign strategy — sabotage against defense firms, disinformation, and infrastructure strikes — as a deliberate effort to divide NATO while battlefield gains stall. Russian military leadership must calibrate hybrid operations to remain below the threshold that would trigger a unified NATO response, a balance made harder as Denmark's Defense Minister frames Moscow as under mounting pressure from a lack of frontline progress.
Strategic Options
01Continue current denial posture — Moscow has repeatedly denied any involvement in hybrid warfare or sabotage operations in NATO countries.
02Escalate cyber and infrastructure sabotage against Ukraine-supporting defense firms while maintaining plausible deniability through shadow-fleet vessels and Ukrainian-made drone false-flag tactics, as DDIS suggested.
03De-escalate visible hybrid activity temporarily to undercut the credibility of Western intelligence warnings and complicate NATO's unified-response efforts.
↳ DDIS's characterization of a potential limited attack as 'a desperate move' reframes Russian hybrid escalation as a symptom of battlefield weakness rather than confidence, which cuts against the narrative of an emboldened, expansionist Kremlin.
FLOW Rationale: Russia's calibration challenge is structural: sustaining below-threshold pressure across multiple NATO states simultaneously while its own military resources remain committed to the stalled Ukraine front, per Denmark's own assessment that no breakthrough is expected within six months.
Scale (Moderate): The assessment describes intensified but still 'limited' and 'desperate' Russian actions rather than a shift in Russia's core war strategy in Ukraine, per DDIS's own characterization of a potential attack as 'a desperate move.'
Complexity (High): Russia must sustain hybrid pressure calibrated precisely to avoid NATO's Article 5 threshold while simultaneously managing battlefield stagnation, a Danish minister's framing that it is 'not achieving its goals,' and now more overt Western intelligence exposure of its tactics.
Key Question
Can Russia sustain simultaneous hybrid pressure against multiple NATO states without triggering the unified alliance response that a limited kinetic attack risks provoking?
Watch Signals:- [Likely] Continued Russian embassy denials of hybrid warfare involvement following each new incident, consistent with the pattern already shown after the Leipzig/Halle Airport accusation.
- [Possible] Further shadow-fleet vessel-linked drone incidents in the Baltic or Mediterranean, given the precedent of the February 2026 Öresund Strait incident near the Charles de Gaulle carrier.
- [Possible] A Kremlin statement responding directly to the DDIS assessment, following the pattern of prior Putin remarks dismissing NATO's drone-related accusations as 'nonsense.'
Proximity: DirectImmediateFLOW C
Denmark
Denmark's own defense-industrial base is named by PET as an active sabotage target, requiring the government to harden physical and cyber security at defense manufacturers while managing public messaging that avoids alarm even as officials describe growing risk. Copenhagen must also balance its role as an outspoken voice on Russian threats with its Defense Minister's own framing that Denmark does not expect a conventional military attack.
Strategic Options
01Direct PET and DDIS to issue joint sector-specific security guidance to Danish defense manufacturers named as sabotage targets, mirroring measures taken after 2025's drone incursions over Danish airports and military sites.
02Reinforce physical security and surveillance of Danish defense-industrial sites and rail transports carrying military equipment, given DDIS's specific citation of these as new sabotage targets.
03Coordinate directly with allied intelligence services on shared threat indicators, building on the multinational troop and technical support Denmark received during 2025's drone-incursion response.
↳ Denmark is simultaneously the source of the alliance's most alarming public threat assessment and a named, current target of the sabotage activity it describes, giving its warning unusual first-hand credibility compared to secondhand intelligence-sharing reports.
FLOW Rationale: PET's statement that Russian intelligence services are 'actively preparing' sabotage against Denmark's defense industry names a current, in-progress threat rather than a future contingency, demanding immediate protective action for the named sector.
Scale (Moderate): PET's warning names Denmark's defense industry specifically as an active target of Russian sabotage preparation, a direct and current threat to national infrastructure rather than a general regional risk.
Complexity (High): Denmark must execute concrete protective measures against an active, ongoing sabotage-preparation threat to its defense industry while simultaneously managing the domestic and alliance-level messaging implications of being the country that issued the most alarming assessment.
Key Question
What specific protective measures has Denmark's government directed toward the defense-industry sites that PET says Russian intelligence services are actively targeting for sabotage?
Watch Signals:- [Possible] A disclosed sabotage incident or arrest linked to Denmark's defense industry, following the pattern of the January 2026 Lithuanian prosecution of individuals accused of coordinating attacks with Russian intelligence.
- [Possible] Additional drone incursions over Danish military or industrial sites, echoing the pattern of the 2025 airport and base incursions that prompted NATO troop deployments to Copenhagen.
- [Likely] Danish government announcement of enhanced security funding or measures for defense manufacturers following PET's public warning.
Proximity: DirectNear-TermFLOW C
European defense-industrial manufacturers
Manufacturers producing or transporting military equipment for Ukraine face heightened sabotage risk, per DDIS's specific citation of attacks shifting from general disruption toward stopping military support from reaching Ukraine through sabotage against defense companies and rail transports. These firms must now weigh increased security investment, insurance costs, and supply-chain resilience against sabotage that intelligence services say has already begun.
Strategic Options
01Increase physical security and surveillance at production facilities and along rail routes carrying military equipment to Ukraine, in direct response to DDIS's identification of this as an active sabotage target category.
02Coordinate with national intelligence services (following Denmark's PET model) to receive sector-specific threat briefings and indicators.
03Diversify transport routes and methods for military equipment shipments to reduce single-point sabotage vulnerability along fixed rail corridors.
↳ The shift DDIS describes — from fear-based disinformation toward direct sabotage of defense companies and military rail transports — represents a change in Russian tactics from influencing public opinion to physically degrading Ukraine's supply chain at the source.
FLOW Rationale: The named shift toward sabotaging defense companies and rail transports directly threatens the physical operations and delivery timelines of firms supplying Ukraine, a concrete operational risk rather than a reputational or political one.
Scale (Moderate): DDIS specifically named sabotage against defense companies and railway transports carrying military equipment as a new category of Russian hybrid activity, directly affecting this sector's operations and logistics.
Complexity (High): Firms must secure geographically dispersed production and transport infrastructure against an adversary using shadow-fleet vessels and unmarked operatives, a threat model that conventional corporate security frameworks are not designed to counter.
Key Question
Which specific defense manufacturers and rail transport routes supplying Ukraine has Denmark's PET identified as active Russian sabotage targets, and what physical security measures are currently in place at those sites?
Watch Signals:- [Possible] A confirmed sabotage incident at a European defense manufacturing site or along a rail corridor carrying military equipment to Ukraine.
- [Possible] Announcements of increased security funding or personnel at named defense-industrial sites following the DDIS assessment.
- [Likely] Continued attribution disputes, given Moscow's consistent pattern of denying involvement in sabotage operations against NATO countries.
Proximity: CloseNear-TermFLOW C
European Union
Following Germany's attribution of the Leipzig/Halle Airport drone attack to Russia, EU members have already called for new sanctions; the Danish assessment adds pressure for the bloc to formalize a collective hybrid-threat response mechanism covering cyber resilience, critical infrastructure protection, and sanctions coordination across member states with differing risk exposure and political appetite for confrontation.
Strategic Options
01Advance the new sanctions package EU members have called for following the Leipzig/Halle Airport attack attribution to Russia.
02Fund a bloc-wide critical infrastructure hardening initiative targeting the destructive cyberattack capability DDIS specifically flagged.
03Establish a rapid-attribution mechanism for hybrid incidents so member states are not forced to build individual national cases before requesting EU-level support, as Denmark, Germany, and Lithuania have each done separately.
↳ The EU's sanctions push originated from a single attributed incident in Germany, but the Danish assessment reframes that incident as part of a systematic, intensifying campaign rather than an isolated event, strengthening the political case for bloc-wide rather than country-by-country responses.
FLOW Rationale: Coordinating a new sanctions package and infrastructure-protection response across member states with unevenly distributed exposure — Nordic and Baltic border states versus the separately reported southern European drone threat — requires consensus among 27 governments with differing threat perceptions.
Scale (Moderate): EU members have already moved to call for new sanctions against Russia following the Leipzig/Halle incident, showing the assessment is translating into concrete policy deliberation at the bloc level.
Complexity (High): The EU must coordinate a unified sanctions and infrastructure-protection response across 27 member states with varying direct exposure — from Baltic and Nordic states facing named threats to southern states like Spain named in a separate, uncorroborated drone-threat report — requiring consensus-based decision-making that is inherently slow.
Key Question
Will EU member states agree on a unified sanctions package and hybrid-threat response mechanism before the 'coming months' escalation window described in Denmark's intelligence assessment closes?
Watch Signals:- [Likely] Formal EU Council discussion or announcement of a new Russia sanctions package, given member states have already called for one following the Leipzig/Halle attribution.
- [Possible] EU-level critical infrastructure protection funding announcements specifically citing destructive cyberattack risk, following DDIS's explicit warning about this threat category.
- [Possible] Diplomatic friction between member states over the uncorroborated CIA-sourced Mediterranean drone-threat report, given Defense News notes it has not been independently confirmed.
Proximity: CloseNear-TermFLOW D
Baltic and Nordic border states (Lithuania, Latvia, Estonia, Poland, Finland)
As the states DDIS specifically identified as potential targets of a 'limited military attack against one or several Nato countries bordering Russia,' these governments face the most direct scenario described in the assessment — including the possibility of unmarked Russian personnel entering their territory under a minority-protection pretext. National defense ministries must accelerate border surveillance and rapid-response protocols even though DDIS says any Russian force build-up would take months and be hard to conceal.
Strategic Options
01Increase border surveillance and intelligence-sharing specifically focused on detecting the several-months-long force build-up DDIS says would precede any limited attack.
02Request NATO reinforcement of the enhanced Forward Presence battlegroups already stationed in the Baltic states as a deterrence signal.
03Develop specific response protocols for the 'unmarked personnel under minority-protection pretext' scenario DDIS described, drawing on lessons from the 2014 Crimea precedent referenced implicitly in that scenario description.
↳ DDIS's specific scenario of unmarked troops entering under a minority-protection pretext directly echoes tactics used in Crimea in 2014, suggesting Danish intelligence sees a recognizable historical playbook rather than a genuinely novel threat vector for these states.
FLOW Rationale: Border states face the specific 'limited military attack' scenario DDIS named, involving unmarked troops or long-range strikes, a large-scale threat to territorial integrity even though the agency assessed the probability as low.
Scale (Large): These are the specific countries DDIS named as potential targets of a limited military attack, the most severe scenario in the assessment, directly implicating their territorial security and national defense posture.
Complexity (High): Border states must distinguish genuine force build-up indicators from routine Russian military activity along a shared frontier, coordinate detection with NATO allies, and prepare response options for a scenario explicitly designed to divide the alliance rather than trigger conventional war.
Key Question
What detection thresholds have NATO's Baltic and Nordic border states established to distinguish routine Russian military activity from the several-months-long force build-up that Denmark's intelligence service says would precede a limited attack?
Watch Signals:- [Possible] Reports of unusual Russian troop movements or unmarked personnel activity near NATO's eastern border, which DDIS says would take months to conceal.
- [Likely] Continued airspace violations or drone incursions in Baltic states, following the established pattern including the 2026 Ukrainian drone incursions into Latvia, Lithuania, and Estonia.
- [Possible] NATO announcement of reinforced Forward Presence battlegroups or additional troop rotations in Baltic states in response to the DDIS assessment.
Proximity: AffectedMonitorFLOW C
European air travel and airport operators
Airports across Europe face recurring operational disruption risk from drone incursions, following the pattern of the Leipzig/Halle Airport attack Germany attributed to Russia and prior 2025 closures of Copenhagen and Oslo airports linked to suspected Russian drone activity. Airport operators must weigh counter-drone technology investment against the low-cost, high-disruption nature of the Gerbera-type drones cited in intelligence reporting.
Strategic Options
01Invest in counter-drone detection systems specifically calibrated for small, low-radar-signature drones like the Gerbera type cited in CIA-sourced reporting.
02Coordinate with national aviation authorities on standardized drone-incursion response protocols, building on the precedent set by the 2025 Copenhagen and Oslo airport closures.
03Establish rapid communication channels with national intelligence services for real-time threat updates during high-profile events or periods of heightened tension.
↳ The Gerbera drone's small explosive payload is explicitly designed for symbolic disruption rather than destruction, meaning airport operators face a threat optimized to maximize operational shutdown time and public anxiety rather than casualties.
FLOW Rationale: Airport operators must build detection capability against drones specifically engineered to be small, concealable, and disruptive rather than lethal, a distinct technical challenge from conventional aviation security threats.
Scale (Moderate): The threat has already produced concrete operational disruption, including prior closures of Copenhagen and Oslo airports and the attempted Leipzig/Halle attack, directly affecting flight operations and passenger safety protocols.
Complexity (High): Detecting and countering small, low-cost drones like the Gerbera — described as capable of 600-kilometer range and designed for concealment rather than mass destruction — requires new technical capabilities that most civilian airport security frameworks were not built to address.
Key Question
Have European airports named in intelligence warnings, including those in Spain, France, and Italy, deployed counter-drone detection systems capable of identifying small, low-signature drones like the Gerbera before an incursion forces a shutdown?
Watch Signals:- [Possible] Additional unexplained drone sightings forcing temporary airport closures in Western or Southern Europe, following the pattern already seen at Leipzig/Halle, Copenhagen, and Oslo.
- [Possible] Announcements of new counter-drone technology procurement by major European airport operators.
- [Unlikely] Confirmed attribution of a drone incident to Russian shadow-fleet vessels within the reporting period, given Moscow's consistent denial pattern and the currently uncorroborated nature of the Mediterranean drone-threat report.
The claims behind this analysis, each with its verification status — including what is contested, unverified, or could not be established.
What each grade meansDenmark's Defence Intelligence Service (DDIS) said on September 24, 2026 that Russia will intensify hybrid warfare against NATO and the West with "greater consequences for the countries targeted than in the past."
Establishes the core claim of the event and its qualitative escalation from prior warnings.
DDIS director Thomas Ahrenkiel said there is "a low but growing risk that Russia will launch a limited military attack against one or several Nato countries bordering Russia," while calling full invasion of a NATO country "highly unlikely."
Distinguishes the low-probability kinetic scenario from the higher-probability hybrid escalation, shaping how seriously border states versus non-border allies should weight the warning.
Danish Security and Intelligence Service (PET) told AFP that Russian intelligence services are actively preparing sabotage acts targeting Denmark's defence industry.
Names Denmark's own defense-industrial base as a live, current target rather than a hypothetical future one.
Germany has blamed Russia for an attempted drone attack at Leipzig/Halle Airport, prompting EU members to call for new sanctions against Russia.
Provides the immediate precedent event that has driven renewed EU-level policy attention to hybrid warfare just before the Danish assessment.
A CIA-originated warning reported via Spanish outlet El Mundo, citing Lithuanian defense-ministry sources, alleges Russia may launch Gerbera-type explosive drones from commercial vessels to strike Spain, France, or Italy; Defense News notes this report has not been independently corroborated.
Shows the hybrid-threat warning extending beyond Russia's immediate NATO border states to southern Europe, though this specific claim carries lower sourcing confidence than the DDIS assessment.
DDIS said a Russian force build-up sufficient for a limited attack on a NATO country would require several months of preparation and would be difficult to conceal.
Gives NATO and border states an observable early-warning window rather than a scenario of sudden, undetectable attack.