top of page
Search

Russia's Hybrid War Is Escalating, and Britain Has Been Pulled In

Sep 10
7 min read

By Lady Olga Maitland


A warning worth heeding


Lord Robertson has repeatedly warned that the UK's national security is "in peril": that we are under attack and not safe. He is right, and we are not immune from what is unfolding in Europe. Moscow's rhetoric towards Britain has hardened in step. Russia's defence ministry has threatened three UK sites producing drones and military hardware for Ukraine (in London, Leicester and Suffolk), warning of "unpredictable consequences." Dmitry Medvedev, deputy chairman of Russia's Security Council, said the threat should be taken "literally," signalling Moscow's readiness to widen the conflict. Andrei Fedorov, a former Russian foreign minister, has alleged that plans for a hybrid attack on the UK are being drawn up at the highest levels of the Russian government.


Leipzig: a watershed moment

Events in Germany last week should be taken seriously. Leipzig airport is no ordinary site. It is a major European freight and logistics hub, home to Ukraine's Antonov Airlines and to DHL Express cargo flights, and it carries real significance for NATO and German military transport. That made it a clear target, and a troubling demonstration that a major airport can be penetrated.


Berlin has now formally attributed to Russia the incident of 4-5 August, when a quadcopter drone carrying a fist-sized package of military-grade explosives (identified as 800 grams of Semtex) was found hovering near the ground between two Ukrainian Antonov An-124 heavy freighters. It failed to explode; a robot disarmed it. CCTV reportedly showed the drone deliberately flying into the wing of one Antonov before hovering nearby. That same night, a diverted DHL cargo plane collided mid-air with a separate drone, striking the tail near the fuel tank. The damage was minor, but confirmed not to have been caused by a bird. The strike came just 20 minutes after the first drone was found.


Berlin says Russian intelligence supplied the expertise and equipment to two low-level local agents: a Belarusian travelling on a Russian passport who entered Germany on a tourist visa, and a Latvian holding both Latvian and Russian passports. Both left the country before the drones were discovered.


Ten days later, on 14 August, investigators found a third drone in a field at Kabelsketal, west of the airport, carrying around 50 grams of hexogen (RDX), along with a control unit, electronics, an antenna, and signs of a possible burn or explosion site. They are now considering whether it was part of the same operation rather than an abandoned device.


Other unexplained incidents have followed. Within 24 hours of each other, an improvised explosive device struck the Preilack substation in Brandenburg and a power plant near Cologne was knocked offline for 24 hours. Police are treating Preilack as a potential terrorist attack and the Cologne incident (Bergheim) as suspected sabotage. There is no evidence yet that Russia carried out either attack, but the timing and pattern are pushing German authorities towards a hybrid-war explanation. Then, last Wednesday, incendiary devices were thrown at a construction site in Munich, close to defence-sector companies.


Germany changes its tone


On 1 September, the German government formally concluded that Russia was behind the Leipzig operation. What has changed most is Berlin's language. Interior Minister Alexander Dobrindt went further than German governments typically have: "We are not at war, but we are a daily target of hybrid warfare. The government's assessment: Russia was behind it." Retaliatory measures have followed, including action against Russia's consulate in Bonn, ending the Russian House arrangement in Berlin, tighter checks on Russian nationals, and a push for further EU sanctions. Ursula von der Leyen has been vocal in her condemnation and in reaffirming support for Ukraine.


The planning behind this was clearly extensive: a small sabotage team working with intelligence support, not an improvised attack. I see it as part of the wider European "shadow war" rather than an isolated drone incident, and its purpose looks like an attempt to block the logistics pipeline supporting Ukraine, rather than to frighten the German public.


Britain pulled directly in


This is perhaps the most significant development for the UK. The Foreign Office summoned Russia's chargé d'affaires, Vasily Tsiganov, over the Leipzig incident, stating that "the UK stands in full solidarity with Germany following Russia's egregious and reckless attack," that Britain's commitment to NATO allies and Ukraine "is ironclad," and that it "will continue to expose Russian hostile activity at every level." The Russian Embassy hit back, calling the accusations "unsubstantiated and absurd" and "constructed in a surprisingly familiar British style," and warned that any escalation by Britain or other European states would draw an "adequate and calibrated response" from Moscow.


Britain has had no Leipzig-scale incident of its own publicly attributed to Russia, but the government is increasingly explicit that it faces the same phenomenon. It has identified Russian networks conducting cyber operations, disinformation, fake news websites, bot networks, deepfakes, attacks on democratic processes, espionage, and sabotage and other physical activity. In response, Britain is coordinating more closely with Germany, France, Poland and Brussels on a pan-European response.


Where things stand today


Attribution is increasingly explicit, but Russia remains skilled at deniability. Physical sabotage is a continuing concern, particularly for defence manufacturers and firms actively supporting Ukraine, such as DHL or long-range drone producers. Critical infrastructure is a very high concern; our power grids are vulnerable. Drones are a growing threat: the MoD reported 240 sightings over military establishments in the past year, and counter-terrorism intercepted a drone an Islamist group had weaponised to fly into GCHQ. Cyber attacks are relentless, daily, and rising fast. Last week, Manchester Airport Group, which includes three airports, was hacked, with criminals stealing the data of nine million customers; such criminals are known to be paid by hostile state agents. Information warfare remains insidious and serious.


This has pushed the government to sharpen its language, from "daily hybrid warfare" to "escalation in hybrid threats," and we should expect it to become more public in its responses.


My assessment


The German developments deserve close watching. Not every unexplained fire, power failure or infrastructure incident should be labelled Russian, though I am personally increasingly suspicious of the recent upsurge in such events. But the combination of an explosive drone, Ukrainian aircraft, defence targets, power-infrastructure sabotage, suspicious surveillance, cyber activity and information warfare is difficult to dismiss as simply a collection of unrelated events.


The strategic logic matters here: Russia does not need to destroy major infrastructure to have an effect. We are unlikely to see a missile fall on the Palace of Westminster. But creating uncertainty over whether the next incident is an accident, extremist activity, or Russian action can itself impose a real cost on government and infrastructure operators. The aim is to divide and demoralise Europe until the will to resist erodes. Note Moscow's evident delight at the AfD's success in the Saxony elections. The AfD is Russia-friendly and opposed to supporting Ukraine, and many in Saxony, formerly East Germany, still feel a closer affinity with Russia than with the West despite reunification in 1990.


The real takeaway from Leipzig is that London now accepts Germany's problem is Britain's problem too, and Europe's. But Europe remains split between firmly pro-NATO governments and parties more sympathetic to Moscow, including France's National Rally, Austria's FPÖ and Slovakia's SNS; in Italy, Georgia Meloni is firmly pro-NATO, but her coalition partner Matteo Salvini of The League is not.


President Trump's ambivalence has not helped. His pressure on allies is weakening deterrence and raising the risk of war. His envoy, Steve Witkoff, has met Putin in person eight times (sometimes with Jared Kushner present), yet only made his first visit to Kyiv, to meet President Zelensky, last weekend. Moscow will likely feel emboldened to continue its political manipulation and step up its hybrid campaign.


This is the wrong moment to make life easy for Putin. Europe has largely pulled together behind Germany. Meanwhile, Putin is under real pressure: his economy is straining, and his people can see Ukraine is far from beaten. That may argue for a tougher line now, while he is weaker than at any point in the war. But a Russia under stress after four years of failing in Ukraine may also lash out harder to fracture NATO unity and ease the pressure on itself. Either way, we should brace for intensified hybrid warfare, carefully calibrated to stay just below the Article 5 threshold.


Is the UK ready?


How safe is our critical national infrastructure from drone attack, and how well is Britain adapting? For now, the government remains cautious about attributing individual UK incidents, but concern inside government is real, particularly around critical national infrastructure: airports, ports, railways, the electricity grid and power stations. There is growing concern about how to respond to hostile drones; language has shifted from "daily hybrid warfare" to "escalation in hybrid threats," and coordination and sanctions are increasing. Whether that is enough is an open question. Denmark, for one, has reported Russian intelligence attempting to recruit agents to help plan sabotage.


The UK's greatest exposure includes:


Cyber attacks, which are high, persistent, and growing sharply. They hit state entities (Manchester Airport, a week ago) and the private sector alike, and are probably Britain's biggest immediate threat. British intelligence assesses, as of July 2026, that Russian GRU military intelligence units are conducting sustained cyber and information operations against the UK. Poland came close to a mass blackout from a cyber attack on its energy infrastructure, leaving thousands in freezing conditions before it was intercepted; the same could happen here, and succeed.


Undersea cables, which are constantly surveilled and genuinely vulnerable, given how heavily Britain's communications with the outside world depend on them. The UK is stepping up monitoring of Russian undersea activity, including Akula-class submarines and specialised deep-sea vessels, in UK waters and the North Atlantic, with RAF aircraft tracking Russian vessels linked to undersea intelligence-gathering.


Espionage and reconnaissance, at an all-time high, reflected in the 240 drone sightings over military sites noted above.


Russian sabotage activity across Europe roughly tripled between 2023 and 2024, and is likely higher still now. Moscow typically works through criminals, marginalised individuals, immigrants and online recruits: people needing money, some of whom may not fully understand who is really behind the task. My overall assessment is that Russia is testing its ability to attack Europe just below the threshold of all-out war.


A case for a UK 2026 Incident Audit


Too many UK incidents are still being waved through as "accidents". The latest was an admitted cyber attack that closed a small power station for four days. I am uneasy about how readily unexplained but out-of-the-ordinary events get dismissed, including the recent run of arson attacks at sites such as Glasgow Central Station and Edinburgh's Princes Street.


I would like to see a genuine UK 2026 Incident Audit: not a news summary, and not a board that has never been asked to look for the real cause of unusual events, including the British Rail Investigation Board. Every significant incident deserves open-minded, probing scrutiny, alongside a thorough overhaul of security, across:


  • Power stations and electricity transmission

  • Railway signalling and overhead lines

  • Unexplained fires and explosions

  • Airports and drones

  • Defence companies

  • Ports

  • Telecommunications (some work already under way)

  • Undersea cables (as above)

  • Military installations (drones and espionage)

  • Suspicious reconnaissance


A separate paper will look more deeply at UK critical infrastructure security. There are strong UK companies working on this, but in truth, we have not yet reached the level of preparedness seen in Germany, Poland and the Baltic states.

 
 
 

Comments


bottom of page