Introduction
Since the onset of Russia’s full-scale invasion of Ukraine in February 2022, European states supporting Kyiv have experienced a growing range of hostile activities falling below the threshold of conventional armed conflict.
“These gray-zone operations, encompassing sabotage, cyber intrusion, intimidation, and hybrid plots, are designed to impose cumulative costs while preserving deniability and managing escalation risks.”
This report analyzes such operations through a structured and conservative empirical lens. Rather than attempting to catalogue every suspected incident, the analysis focuses on a curated set of events for which attribution to Russian state actors, intelligence services, or proxy networks can be assessed with medium or high confidence. This approach enables a more defensible assessment of Russian strategic behavior and reduces the analytical noise associated with ambiguous or unresolved cases. The central question guiding the analysis is not simply whether Russian gray-zone activity has increased, but how its tempo, severity, sophistication, and targeting logic have evolved over time, and what this evolution implies for European security and U.S. interests.
Methodology and Data Scope
The empirical foundation of this report is an original Excel-based dataset developed by the author. Each incident is coded across multiple dimensions, including date, location, target category, method, physical consequences, casualties, estimated material losses, execution status, operational modality, and attribution confidence. Casualties are defined conservatively as the sum of injuries and fatalities, rather than fatalities alone. This definition reflects standard conflict-analysis practice and avoids understating human harm. Executed incidents and foiled plots are treated as analytically equivalent outcomes, on the grounds that interdicted operations often provide critical insight into intent, targeting preferences, and acceptable risk thresholds. Inclusion in the dataset requires corroborated evidence linking an incident to Russian actors. Acceptable evidence includes formal government attribution, prosecutorial action, arrests or judicial proceedings, or consistent reporting by reputable investigative outlets citing official or intelligence sources. Incidents widely suspected but lacking sufficient evidentiary grounding were excluded. This methodological posture results in a dataset that is narrower than those produced by ACLED or referenced in IISS surveys. However, it allows for stronger causal inference and clearer interpretation of Russian operational logic.
Temporal Dynamics: Sustained Pressure Rather Than Episodic Escalation
A longitudinal examination of the dataset reveals a pattern of sustained pressure rather than isolated spikes in activity. In 2022 and 2023, Russian gray-zone operations appear limited in volume but already diverse in form, encompassing cyber disruption, reconnaissance, and early sabotage attempts. These initial incidents establish a baseline of experimentation and signaling. From 2024 onward, the tempo and diversity of activity increase. Arson attacks, logistics sabotage, and explosive-parcel plots become more frequent, and operations increasingly span multiple jurisdictions simultaneously. By 2025, the dataset reflects layered and overlapping activity across physical and cyber domains, indicating deliberate pacing rather than reactive escalation. This temporal pattern supports the interpretation of gray-zone activity as a long-term coercive strategy aimed at persistence rather than crisis generation.
Severity and Consequence Profile
Despite the growing tempo and diversification of methods, the dataset exhibits a striking consistency in outcome severity. With one targeted assassination as an outlier, executed incidents produce virtually no casualties when casualties are defined as injuries plus fatalities. Instead, severity is expressed through infrastructure damage, economic losses, supply-chain disruption, emergency response costs, and political signaling effects. This pattern holds across arson attacks, logistics sabotage, cyber interference with satellite and water systems, and damage to critical infrastructure. The absence of mass-casualty outcomes reflects not operational incapacity, but deliberate calibration. Harm is constrained to avoid triggering escalatory responses while still imposing meaningful costs on targeted states. In aggregate, the campaign’s severity lies in its cumulative disruptive effect rather than immediate human harm.
Escalation in Sophistication and Tactical Diversity
Over time, Russian gray-zone operations demonstrate clear qualitative evolution. Early incidents rely on relatively simple methods, such as basic cyber disruption or opportunistic sabotage. Later operations display increased sophistication, including multi-country logistics chains for explosive parcels, cyber intrusions into industrial control systems, and hybrid operations combining digital reconnaissance with physical action. A notable feature of this evolution is the reliance on third-country nationals recruited through online platforms. This approach enhances deniability and scalability while increasing exposure to detection and failure. The resulting pattern, simultaneous growth in executed and foiled operations, is therefore a structural feature of the operational model rather than an anomaly.
Expansion of Target Scope
The dataset shows a progressive broadening of target categories over time. Early activity tends to focus on symbolic or opportunistic targets. Later incidents increasingly involve defense-industrial actors, logistics networks supporting Ukraine, transportation hubs, and critical civilian infrastructure such as water, energy, and telecommunications systems. Geographically, incidents cluster in states that are politically supportive of Ukraine and operationally central to aid flows, but the campaign is not confined to a single sub-region. The dispersion of incidents across multiple European states suggests a pan-European pressure strategy rather than a series of bilateral disputes.
Executed Versus Foiled Operations as Strategic Indicators
The relatively high proportion of foiled operations, particularly from 2024 onward, is analytically significant. Rather than indicating declining Russian capability, this pattern reflects the trade-offs inherent in a proxy-based operational model. Decentralized recruitment and low-cost tasking increase operational reach while simultaneously raising exposure to counterintelligence and law-enforcement intervention. From an analytical standpoint, foiled operations are indispensable. They often reveal intended targets, preferred methods, and acceptable escalation thresholds more clearly than executed incidents, which may reflect constrained outcomes rather than original ambition. Taken together, the evidence supports the conclusion that Russian gray-zone operations in Europe constitute a coherent and sustained coercive strategy. The campaign is characterized by deniability, modular escalation, and careful calibration of effects. Targets are selected to generate political and economic friction rather than mass casualties, and operations are structured to probe detection thresholds, response mechanisms, and alliance cohesion. Each incident, whether executed or interdicted, yields information for Russian planners while imposing real costs on targeted states.
Implications for U.S. Interests
The European pattern documented in this dataset has direct relevance for U.S. domestic and overseas interests. The logic of targeting observed in Europe is readily transferable. Defense manufacturers, logistics firms, ports, air-cargo hubs, energy and water utilities, and cyber-dependent public services supporting Ukraine represent plausible targets for similar gray-zone activity. Abroad, U.S. facilities and contractors embedded in European supply chains or operating alongside allied partners face comparable exposure.
“The evidence suggests that the most plausible threat to U.S. interests is not a singular catastrophic attack, but persistent, low-visibility disruption combining cyber and physical methods.”
Europe should therefore be understood not as an isolated theater, but as a testing ground for a broader coercive playbook.
Conclusion
By privileging attribution certainty over breadth, this report provides a conservative but analytically robust assessment of Russian gray-zone operations in Europe. While broader datasets capture a larger universe of suspected activity, the approach adopted here enables clearer inference about intent, operational design, and strategic logic. The findings indicate a sustained campaign of calibrated disruption rather than episodic escalation. For U.S. policymakers and security planners, the European record offers both warning and insight: the same methods, targets, and constraints are applicable beyond Europe and should be treated as indicators of future risk rather than retrospective anomalies.
References
Gurcov, N. (2025). Testing the waters: Suspected Russian activity challenges Europe’s support for Ukraine. Armed Conflict Location & Event Data Project (ACLED).
International Institute for Strategic Studies. (2025). The scale of Russian sabotage operations against Europe’s critical infrastructure. IISS.
Reuters. (2025, October 21). Russia’s suspected sabotage campaign steps up in Europe. Reuters.
Reuters. (2025, March 19). Exclusive: U.S. suspends some efforts to counter Russian sabotage as Trump moves closer to Putin. Reuters.
List of cases
24 February 2022 – Cyberattack disables Viasat’s KA-SAT satellite network across Europe, disrupting communications and wind-energy operations at the outset of Russia’s full-scale invasion of Ukraine. Reuters.
8 October 2022 – Coordinated sabotage cuts Deutsche Bahn fiber-optic cables in Germany, halting long-distance and freight rail traffic for several hours. Reuters.
August 2023 – Radio-signal interference halts multiple trains in north-west Poland after attackers exploit unsecured railway frequencies; Polish authorities describe the act as state-sponsored sabotage. Reuters.
October 2023 – Damage to the Balticconnector gas pipeline between Finland and Estonia is discovered; authorities investigate deliberate external interference. Reuters.
February 2024 – Russian defector and former helicopter pilot Maxim Kuzminov is found shot dead in Spain; Western officials assess the killing as a targeted assassination. BBC.
20 March 2024 – Arson attack destroys a warehouse in east London linked to Ukrainian military supplies; British authorities later link suspects to Russian proxy recruitment. BBC.
March/April 2024 – Explosive and incendiary parcels linked to a Russian-directed plot ignite at logistics facilities in Europe; authorities say the devices could have caused aircraft disasters if undetected. CNN.
8 May 2024 – IKEA store in Vilnius is set on fire after closing hours; Lithuanian prosecutors later attribute the arson to Russian intelligence coordination. The Guardian.
11 May 2024 – Massive arson destroys the Marywilska 44 shopping centre in Warsaw; Polish authorities conclude the attack was ordered by Russian intelligence. BBC.
Late 2024 – Multiple undersea telecommunications and power cables in the Baltic Sea are severed, including the Estlink 2 power cable; Finnish authorities investigate sabotage involving a Russian-linked vessel. NPR.
January 2025 – NATO confirms a foiled Russian plot to assassinate the CEO of Rheinmetall, a major supplier of weapons to Ukraine. CNN.
June 2025 – Several Rheinmetall military trucks are set on fire in Erfurt, Germany, in what authorities describe as a Russian-linked sabotage attack. Barron’s.
October–November 2025 – Polish authorities arrest multiple suspects accused of preparing sabotage and reconnaissance against critical infrastructure on behalf of Russian handlers. BBC.