Your Compass in the Security Nexus


The Threshold Trap: Reading Russia's Hybrid Campaign Correctly

Author: The Security Nexus, LLC
Date: August 23, 2026
Categories: Hybrid Warfare, Deterrence
Estimated read time: 9 min


Germany is calling it daily hybrid warfare. Latvia's president says it has already started. The CIA has warned European partners that Russian services are eyeing sabotage against Baltic infrastructure, and a Congressional Research Service report puts the tally at 151 Russian hybrid incidents across Europe since February 2022, with the rate roughly quadrupling and then tripling year over year (Legis1 2026). Every one of those data points is being read the same way in Berlin, Riga, and Washington: NATO's deterrent is eroding, and the alliance needs to respond before the erosion becomes irreversible. That reading gets the diagnosis wrong. The incident count is not the variable that tells you whether deterrence is failing. The variable that matters is the ceiling Russia still hasn't crossed, and on that measure the pattern looks less like a collapsing deterrent and more like one that is working, at a cost, exactly as gray-zone theory predicts it should.
The Trigger
The immediate spark for this argument is the explosive-laden drone found at Leipzig/Halle Airport on August 5, a hub German officials say facilitates military logistics support to Ukraine. German Interior Minister Alexander Dobrindt used the incident to declare that "we're not at war, but we are the daily target of hybrid warfare" (Reuters 2026). Within days, Latvian President Edgars Rinkevics told reporters near the Belarusian border that Russia's hybrid war in Europe "is not something that will start sometime in the future... it's happening now" (Insurance Journal 2026a). Bloomberg reported that a European intelligence official, backed by CIA assessment, warned that Russian services may be preparing sabotage or false-flag operations in the Baltics and Poland (Insurance Journal 2026b). Germany's cabinet responded on August 11 by approving legislation expanding domestic intelligence authority to counter cyberattacks, espionage, and sabotage (ZeroFox 2026). None of this is invented alarm. The activity is real, documented, and worth taking seriously. The question is what conclusion it licenses.
The Measurement Problem
Gray-zone and hybrid-warfare scholarship has spent a decade arguing about definitions, and the argument matters here because loose definitions produce loose threat assessments. Wirtz frames the relevant category as "short-of-war" strategy: fait accompli, proxy action, and the exploitation of ambiguous deterrence situations, or what earlier strategists called salami tactics (Wirtz 2017, 108). His central point is structural, not incidental. Defense postures built on deterrence are especially vulnerable to these strategies regardless of how credible the underlying deterrent is, because deterrence by definition draws a line, and any line invites probing just below it (Wirtz 2017, 111). A rising incident count near that line is therefore not automatically evidence the line has moved. It can just as easily be evidence the line is holding, and an adversary is testing its exact location rather than crossing it.
Sanz-Caballero adds the legal dimension driving this ambiguity: hybrid threats are built to fall short of what international law recognizes as an armed attack, which means the same act that would trigger collective defense in one framing can be waved off as sabotage or criminal activity in another (Sanz-Caballero 2023). That indeterminacy is not a bug in Russian tradecraft. It is the entire point of operating in the gray zone rather than outside it, and it means that counting "incidents" without a shared legal or operational baseline produces a number that looks alarming in aggregate while telling you almost nothing about whether the underlying deterrent relationship has actually shifted.
What the Restraint Actually Shows
The sharpest empirical challenge to the eroding-deterrence narrative comes from Gannon, Gartzke, Lindsay, and Schram, who built a formal model distinguishing deterrence failure from deterrence success in gray-zone conflict and then tested it against Russian behavior since the 1990s. Their finding: Russian gray-zone activity appears, in part, to be restrained by NATO's deterrent threat, meaning the sub-threshold conduct observed is better read as a constrained substitute for open aggression than as evidence the constraint has failed (Gannon et al. 2024, 233). If that model is right, the drone incursions and infrastructure probing that dominate this month's headlines are not a preview of invasion. They are what a deterred adversary's next-best option looks like when the top option, direct military confrontation with NATO, remains too costly to attempt.
This is not an argument for complacency, and the same model contains its own warning against reading it that way. Gannon and colleagues also show that when a defender builds up gray-zone conflict capabilities of its own, in Europe's case new intelligence authorities, drone-defense investment, and hardened critical infrastructure, the result can go either of two directions. It can lock in a more peaceful equilibrium by raising the cost of probing further. Or it can look enough like escalation that it provokes the challenger to jump the gap and escalate to open conflict rather than accept a worse position in the gray zone (Gannon et al. 2024, 258). Which outcome follows depends on calibration Europe hasn't yet demonstrated it has, particularly with cease-fire negotiations over Ukraine still unresolved and Russian risk tolerance an open empirical question rather than a fixed constant.
The Institutional Risk of Overcorrecting
There is a second cost to the current framing that has nothing to do with Russia and everything to do with what "countering hybrid warfare" does to the countering institutions. Mälksoo's analysis of EU and NATO hybrid-threat practice argues that defining the threshold for an Article 5 response, and building the resilience architecture around that definition, collapses ordinary daily security management into what she calls ontological security management: an exercise aimed less at deterring specific acts than at managing the anxiety of not knowing where the line is (Mälksoo 2020, 140). Her sharpest point is the paradox this creates for what she terms militant democracy. The more thoroughly a democratic state organizes itself to detect and pre-empt ambiguous threats, the harder it becomes to distinguish that posture from the permanent war-readiness it was designed to avoid (Mälksoo 2020, 141). Germany's new intelligence powers, passed within a week of a single drone incident, are a live test case for exactly this dynamic, and whether they represent proportionate adaptation or reflexive overcorrection will not be visible for another year or more.
Çalışkan and Liégeois's interviews with serving NATO officials suggest the alliance's own practitioners share some of this unease, though for a narrower reason. Their respondents describe "hybrid warfare" as a concept that clouds NATO's strategic thinking more than it clarifies it, functioning primarily as a tool for strategic communication rather than a precise military category, and in the process eroding the analytical distinction between war and peace that deterrence theory depends on (Çalışkan and Liégeois 2021, 313). A term this elastic is politically convenient. Officials can invoke it to justify almost any defensive measure, from new legislation to new procurement, without having to specify exactly what threshold triggered the response. That convenience is also the mechanism by which threat inflation happens.
The More Precise Alternative
If aggregate incident counts and elastic terminology are the wrong tools, Maass offers a more usable one. His framework of legal deterrence by denial argues that defenders should use international law and norms not as a static baseline for defining the gray zone but as an active instrument for raising the cost of specific gray-zone acts, denying the legal ambiguity that gray-zone aggressors depend on rather than reacting to the aggregate volume of activity (Maass 2025, 61). Applied here, that means European responses to the Leipzig drone or Baltic infrastructure probing should be built around establishing clear, public attribution and legal consequence for each discrete act, not around a general expansion of surveillance and intelligence authority justified by the overall trend line. The former targets the specific mechanism Russia is exploiting. The latter targets a mood.
Conclusion
The evidence coming out of Germany, Latvia, and the CRS this month is real, but it is being asked to answer a question it cannot answer on its own. A rising count of sub-threshold incidents does not by itself tell you whether NATO's deterrent is failing, because gray-zone theory predicts exactly this pattern of behavior from an adversary that is being successfully deterred from anything larger. The question worth tracking is not how many incidents occur this quarter. It is whether the ceiling holds: whether Russia continues to confine itself to deniable sabotage and airspace probing, or whether some future incident crosses into the kind of unambiguous, attributable force that the current architecture is actually designed to deter. Europe's policy response should be built to answer that question with precision, through targeted legal deterrence by denial aimed at specific acts, rather than through open-ended institutional expansion justified by an incident count that, properly read, may be evidence the current strategy is working.



SOURCES
Çalışkan, Murat, and Michel Liégeois. 2021. "The Concept of 'Hybrid Warfare' Undermines NATO's Strategic Thinking: Insights from Interviews with NATO Officials." Small Wars & Insurgencies 32 (2): 295–319.
Gannon, J. Andrés, Erik Gartzke, Jon R. Lindsay, and Peter Schram. 2024. "The Shadow of Deterrence: Why Capable Actors Engage in Contests Short of War."
Journal of Conflict Resolution 68 (2–3): 230–268.
Insurance Journal. 2026a. "Russia Is Already Waging Hybrid War in Europe, Latvia Says." August 18, 2026.
https://www.insurancejournal.com/news/international/2026/08/18/881958.htm.
Insurance Journal. 2026b. "Russia Eyeing Sabotage, Other Attacks in Europe, Officials Warn." August 13, 2026.
https://www.insurancejournal.com/news/international/2026/08/13/881353.htm.
Legis1. 2026. "Russian Operations in Europe Outpace Policy, CRS Says." August 11, 2026.
https://legis1.com/news/russian-hybrid-warfare-1-congress-examines-151.
Maass, Richard W. 2025. "Legal Deterrence by Denial: Strategic Initiative and International Law in the Gray Zone."
Texas National Security Review 8 (3): 54–73.
Mälksoo, Maria. 2020. "Countering Hybrid Warfare as Ontological Security Management: The Emerging Practices of the EU and NATO." In
Ontological Insecurity in the European Union, 126–144. London: Routledge.
Reuters. 2026. "Germany Warns of Daily 'Hybrid Warfare' after Suspected Drone Attack." August 9, 2026.
https://www.reuters.com/world/german-minister-warns-daily-hybrid-warfare-after-suspected-drone-attack-2026-08-08/.
Sanz-Caballero, Susana. 2023. "The Concepts and Laws Applicable to Hybrid Threats, with a Special Focus on Europe."
Humanities and Social Sciences Communications 10 (1).
Wirtz, James J. 2017. "Life in the 'Gray Zone': Observations for Contemporary Strategists."
Defense & Security Analysis 33 (2): 106–114.
ZeroFox. 2026. "European Intelligence Seeks Broader Authority to Defend Against Russian Hybrid Warfare." August 2026.
https://www.zerofox.com/intelligence/flash-report-european-intelligence-seeks-broader-authority-to-defend-against-russian-hybrid-warfare/.