CRITICAL INFRASTRUCTURE

Russia's Hybrid War on Europe

Water, Energy and Drones Now Share One Playbook. Recorded Future's Insikt Group ties attacks on water systems in Norway and Poland, Polish energy infrastructure and drone incursions near NATO territory to a single Russian hybrid warfare doctrine.

Matt Lucas  |  September 27, 2026  |  5 min
Editorial hero illustration
2 years
Window for a coordinated campaign
18 kg
Gerbera drone weight
160 km/h
Gerbera drone speed
4
Countries named in incidents
TL;DR
  • What: Recorded Future's Insikt Group documents Russia running cyber sabotage, drone incursions and AI-generated disinformation against European states that back Ukraine.
  • Impact: Water and wastewater systems in Norway and Poland and Polish energy infrastructure have already been hit, and drones have been flown near Estonia and Romania's Neptun Deep offshore gas facility.
  • Fix / mitigation: Enforce phishing-resistant MFA and harden internet-facing firewalls, VPNs, email and web portals, the initial access points Russian operators favor.
  • Who's at risk: Critical infrastructure operators, plus logistics, dual-use and specialized equipment makers whose work supports Ukraine, face the highest targeting risk.

Russia is running a cyber and physical pressure campaign against Europe, and the targets are the systems people depend on every day. Recorded Future's Insikt Group links attacks on water and wastewater infrastructure in Norway and Poland, attacks on Polish energy infrastructure attributed to Russia-aligned actors, and drone incursions near Estonia and Romania to one doctrine. The pieces are not yet coordinated. Insikt assesses that Russia could turn them into a coordinated campaign over the next two years.

For defenders, the headline is not a new exploit. It is a shift in who gets targeted and why. Insikt's answer: proximity to Ukraine's war effort.

What Insikt Group documented

The report groups Russian activity in Europe into three categories that now run in parallel.

The Gerbera drone referenced in the reporting is roughly 2 meters long, weighs about 18 kilograms and flies at around 160 km/h. It is cheap, expendable and built to test air defenses and response times, not to win a battle. Recon, not assault.

The doctrine behind it

Russian officials described this approach in 2013 as "New Generation Warfare." The goal is to test an adversary's defenses, degrade its infrastructure and create fear inside its government and population without a kinetic invasion. A tampered water system, a disrupted power asset and a drone over a gas platform each look minor alone. Taken together they measure how fast European states detect, attribute and respond, and whether the public loses confidence while that happens.

The escalation window

Insikt describes current activity as disconnected elements. Its assessment is that Russia could escalate into a coordinated campaign within two years. Organizations that treat each incident as isolated will be planning for the wrong threat.

Who is actually at risk

Chelsea Cederbaum, senior threat intelligence analyst at Recorded Future, put the key risk metric plainly: a company's "proximity to providing material support to Ukraine's war effort." That widens the target set well beyond utilities.

If your company ships, builds or maintains anything that reaches Ukraine, directly or through a supplier, assume you are on the list. Mid-size suppliers are attractive precisely because they have less security staff than the utilities and defense primes they serve.

How the cyber side gets in

The initial access pattern is well known and still works. Russian operations prioritize internet-facing firewalls, VPN concentrators, email systems and web portals. Those edge devices are where credentials are phished, where unpatched appliances get exploited and where a single stolen session opens a path into IT and then into OT. Water and small energy operators often expose remote access for vendors and on-call staff, and that remote access is the bridge.

Recorded Future's top recommendation is phishing-resistant multifactor authentication. SMS codes and push approvals can be relayed or fatigued. FIDO2 security keys and platform passkeys bind the login to the real site and defeat the adversary-in-the-middle kits used against VPN and email portals.

What the report does not give

The public reporting names no CVE, no malware family and no patched version. The defensive guidance is control-level: hardened edge devices, phishing-resistant MFA and segmentation. The checks below are built around those controls, not a single vendor fix.

What to do this quarter

Bottom line

Russia is probing Europe's water, energy and logistics layers with low-cost tools and deniable actors. The campaign is not yet coordinated, and the defenses that matter are not exotic: locked-down edge devices, MFA that cannot be phished and OT networks that cannot be reached from the internet. Organizations that close those gaps now will be harder targets if the two-year escalation Insikt describes arrives.

Questions about your exposure?

RedEye Security provides assessments for organizations that need to understand their real risk.

Talk to us