Skip to main content
Geopolitics & DefenseNational Security

Denmark Warns of Rising Russian Hybrid Attacks on NATO States

Secure government facility with military or defense ministry building in daytime.

“DDIS assesses that Russia will intensify its hybrid war by carrying out more frequent attacks against the West and NATO, with greater consequences for the targeted countries than in the past.” — Danish Defence Intelligence Service (DDIS)

DDIS warns of more frequent hybrid attacks

The Danish Defence Intelligence Service (DDIS) published a nine-page intelligence threat report today, assessing that Moscow will step up hybrid operations against NATO member states in the coming months. The report frames the anticipated intensification not merely as an increase in volume but as a shift toward attacks that could impose “greater consequences for the targeted countries than in the past.”

That phrasing underpins the core of the DDIS judgment: activities that were once disruptive may now carry a higher risk of damage or casualties, and the agency explicitly couples cyber operations with kinetic sabotage as elements of this broadened campaign.

Cyber attacks and sabotage: the specific threats DDIS names

DDIS lists two principal modes of escalation. First, cyber attacks “that cripple societal functions” — a description that places emphasis on attacks aimed at public infrastructure and services rather than only on military or commercial networks. Second, the agency highlights “sabotage attacks that carry a high risk of casualties,” signaling concern about physically destructive operations against facilities or systems where people could be harmed.

In one illustrative passage the report suggests how these modes could be combined with plausible deniability: isolated strikes on infrastructure could be attributed to technical errors or third-party interference, while Moscow might claim that long-range weapons struck NATO territory only because they had been jammed by Ukraine.

Recent unexplained incidents and the Baltic Sea episode

DDIS points to a string of unexplained fires, explosions and damage at defense-linked facilities across Europe in recent months as the context for its assessment. The report singles out a Sept. 14 incident in the Baltic Sea — when a Russian frigate fired flares at a Danish military helicopter — and calls that episode the “most serious” example of Moscow’s increasingly aggressive posture toward NATO militaries operating in the area.

Those incidents, while often unexplained in public reporting, form the immediate evidence base the Danish report uses to warn of higher operational tempo and elevated risk for facilities tied to defense activity.

Risk of a limited military attack and the timeline for a larger invasion

While DDIS raises the prospect of a “limited military attack” becoming likelier, it characterizes that risk as still low. The report envisions such an attack taking the form of isolated strikes by long-range weapons against infrastructure critical for supporting Ukraine, rather than a full-scale interstate invasion.

Importantly, DDIS also states there is no indication the Kremlin is planning an “outright invasion” of a NATO country. The report adds a concrete timeline constraint: even in the event Moscow decided on a full invasion, it would — according to DDIS — require a minimum of six months of planning to assemble the necessary forces. The intelligence branch further judges there is “no prospect” of Russian forces achieving a significant breakthrough in Ukraine over the next six months.

How ASD of Europe, defense industries, and governments are reacting

Echoing the DDIS alarm, a spokesperson for the Aerospace, Security & Defense Industries Association (ASD) of Europe told Breaking Defense earlier this month that the uptick in sabotage incidents and attempts to target defense-related industries demands urgent vigilance. The ASD representative called for closer cooperation among industry, governments and security agencies to mitigate such attacks.

The ASD comment provides a direct line from DDIS’s public assessment to the private sector: trade groups and defense suppliers are already urging enhanced coordination to harden facilities and share threat information on the incidents the Danish report highlights.

DDIS’s report stitches together recent unexplained incidents, one sharply escalatory naval episode, and an intelligence judgment about intent and timelines. The agency forecasts a higher tempo of hybrid operations that combine cyber and physical sabotage, warns of a rising but still limited risk of targeted military strikes, and sets a specific six-month planning floor for any hypothetical full-scale invasion. Those specifics — the types of attack named, the Sept. 14 Baltic Sea episode, the six-month planning estimate, and the call from ASD for urgent cooperation — will shape how NATO militaries, European defense companies, and national security agencies plan and posture in the weeks ahead.

Original story