In a new report the Heligan Group argues that hybrid warfare is no longer peripheral but central to Moscow’s military doctrine, as sabotage, infrastructure attacks and election interference escalate across Europe.
As much of the strategic debate in recent years has focused on the long term challenge posed by China, Russia now represents the most immediate and proximal threat to UK and European security, according to the Primer briefing document.
The report argues that Moscow’s systematic use of hybrid warfare, described in Russian doctrine as new generation warfare, is already reshaping the European security environment, frequently below the threshold of conventional armed conflict.
Heligan states that Russia’s approach to ‘grey zone’ operations is neither opportunistic nor ad hoc, but explicitly embedded within its military doctrine. Activities including sabotage, cyber operations, disinformation, political interference and economic pressure are treated as a core extension of warfighting capability rather than a supplement to conventional force.
“Russia does not see grey zone activity as something short of war,” explains Will Ashford Brown, Director of Strategic Insights at Heligan Group. “It is integral to how Moscow pursues strategic objectives, weakens adversaries and reshapes the operating environment without triggering a direct military response.”
Scale and Intent
Recent incidents across the UK and Europe illustrate what Heligan describes as the scale and intent of Russia’s campaign.
In October 2025, two British men were jailed for carrying out an arson attack on a London warehouse supplying aid to Ukraine, causing £1.3 million in damage. The individuals were reportedly recruited via the encrypted messaging platform Telegram by the Wagner Group, a mercenary organisation operating under the umbrella of the Russian armed forces.
“This case highlights a recurring pattern,” Ashford Brown notes. “Russian linked actors are increasingly recruiting individuals through online platforms to conduct deniable acts of sabotage, often motivated by money rather than ideology.”
Similar tactics have been observed elsewhere in Europe. In Poland, a series of sabotage incidents targeted the national rail network, including an explosion on a key line connecting Poland and Ukraine. In a separate coordinated operation, explosive devices concealed in parcels caused fires at mail depots in Germany, Poland and the UK. Investigators believe the operation was orchestrated by Russia’s military intelligence agency, the GRU, with recruitment again facilitated via Telegram.
Heligan argues that the combination of deniability, remote recruitment and low cost tactics complicates attribution and weakens traditional deterrence frameworks.
Maritime Infrastructure Under Pressure
Beyond land-based sabotage, Heligan highlights the extension of Russia’s grey zone campaign into the maritime domain, particularly in the Baltic Sea.
The report points to the growing role of Russia’s so called shadow fleet, a network of vessels used to evade sanctions, in incidents involving damage to critical undersea infrastructure.
In late 2024, fibre optic cables linking Germany to Finland and Sweden to Lithuania were severed, with vessel tracking data placing Russian linked ships directly over the damage sites. A month later, the oil tanker Eagle S, linked to the shadow fleet, was suspected of cutting the Estlink 2 power cable between Finland and Estonia, alongside several data cables. Finnish authorities subsequently boarded and seized the vessel.
“These incidents demonstrate how low-tech methods, such as dragging anchors along the seabed, can have high impact consequences,” Ashford Brown explains. “Undersea cables are critical to internet connectivity, financial transactions and energy flows. Disruptions carry serious economic and national security risks, while plausible deniability complicates deterrence.”
Airspace Incursions and Alliance Resolve
Heligan also highlights intensified activity in the air domain, with a marked increase in Russian aircraft and drones violating European sovereign airspace.
Such incursions have forced the temporary closure of civilian and military airports and prompted repeated NATO interceptions. What began as limited probes has, according to the report, evolved into deeper penetrations near sensitive military installations.
“The objective is to normalise these violations,” Ashford Brown argues. “By gradually shifting the boundaries of acceptable behaviour, Russia seeks to weaken NATO’s collective resolve and reduce the likelihood of a forceful response.”
Targeting Democratic Processes
At a strategic level, Heligan warns that Moscow continues to target democratic processes across Europe.
The report cites Moldova’s recent national election as an example of sustained Russian interference, involving disinformation campaigns, bots and paid online activists. The significance of the outcome was underscored when Polish Prime Minister Donald Tusk described the eventual pro-European victory as having saved democracy.
Heligan concludes that the cumulative effect of these activities is a persistent erosion of security, trust and resilience across the UK and its allies. Western reluctance to categorise hybrid warfare as genuine warfare risks enabling Russia to continue these operations largely unchallenged.
While welcoming elements of the UK’s Strategic Defence Review, particularly its emphasis on cyber capability, insider threat mitigation and the protection of critical national infrastructure, the group warns that countering grey zone threats will require closer collaboration between government and industry, alongside a broader recognition that conflict has entered a new phase.
“It is entirely plausible that the next major conflict has already begun,” Ashford Brown concludes. “We simply struggle to recognise it as war because its character is fundamentally different from the conflicts of the past.”
Pic: Will Ashford Brown

