← Research & Articles
Defense

Below the Threshold: A Decade of Russian Pressure on Europe Since Crimea

July 15, 2026 · 10 min read

When Russian forces seized Crimea in early 2014, many in Europe treated it as a contained, regional crisis — a violation of international law, certainly, but one confined to Ukraine’s borders. More than a decade later, that containment never held. What began with unmarked soldiers on a peninsula has grown into a sustained, continent-wide campaign of pressure that rarely rises to the level of open war but consistently stays just short of it — sabotage, cyberattacks, disinformation, energy coercion, airspace violations, and occasional acts of outright violence on European soil. Security analysts increasingly describe this as “hybrid warfare” or “sub-threshold” conflict: a deliberate strategy of imposing costs and sowing fear while avoiding the clear, unambiguous act of aggression that would trigger a unified NATO response. Tracing this pattern from 2014 to the present makes clear that Europe has not experienced a series of unconnected incidents, but a single, evolving campaign.

From Crimea to Full-Scale Invasion

The 2014 annexation of Crimea and the simultaneous outbreak of war in the Donbas region, fought through Russian-backed separatists in a deliberately deniable arrangement, established the template Moscow would use repeatedly in the years that followed: use force or covert pressure to change facts on the ground, deny direct involvement even when evidence is overwhelming, and calibrate the aggression to stay below whatever threshold might trigger a unified Western military response. Sanctions followed, but they did not reverse the annexation or end the low-intensity war in eastern Ukraine, which simmered for eight years until Russia’s full-scale invasion in February 2022 transformed the conflict’s scale entirely.

The invasion did not just escalate the war in Ukraine — it triggered a parallel escalation of pressure campaigns against the rest of Europe, on the apparent theory that punishing the countries supporting Ukraine, and testing how much they would tolerate, served Russia’s interests almost as directly as battlefield gains in Ukraine itself.

Weaponizing Energy

The most immediate and widely felt pressure came through energy. In the months following the invasion, Russia progressively cut gas flows to numerous European countries, officially citing technical and contractual disputes while European governments widely understood the moves as retaliation for sanctions and support for Ukraine. The resulting price shock hit European households and industry hard through the winter of 2022, and the still-unresolved 2022 Nord Stream pipeline explosions — whoever ultimately proves responsible — demonstrated starkly how vulnerable European energy infrastructure was to sabotage, seaborne or otherwise. Russian authorities have accused the United States or United Kingdom of carrying out the Nord Stream attack, while some Western officials have floated theories involving Ukraine or a Russian false-flag operation intended to sever European-Ukrainian solidarity, and responsibility remained formally unresolved years later. Regardless of who ultimately caused that specific explosion, the episode crystallized for European policymakers just how exposed critical infrastructure was, accelerating the diversification strategy described elsewhere in Europe’s broader energy security planning.

A Sustained Sabotage Campaign

Western governments and intelligence agencies allege that Russian military and intelligence services have organized a wide range of sabotage acts across Europe since the full-scale invasion, including arson, assassination plots, railway damage, vandalism, and electronic interference such as GPS jamming, largely coordinated by Russian military intelligence and executed through covert operatives or locally recruited proxies, while Russian authorities have denied responsibility and blamed other actors. European officials reported that suspected sabotage incidents surged through 2023 and 2024, targeting infrastructure ranging from gas pipelines to undersea communication cables, and by 2025 NATO was describing the level of sabotage threats as “record high.”

Intelligence reports point to a four-fold increase in Russian sabotage operations across Europe in 2024 compared with the year before, a trend that continued accelerating through 2025. Investigations in Poland, Germany, and Lithuania during 2025 uncovered overlapping sabotage networks linked to Russian military intelligence, frequently operating through proxies and criminal intermediaries specifically to preserve deniability. The targets have been telling: railways, logistics hubs, and commercial infrastructure connected to supply chains supporting Ukraine, alongside defense production facilities and transport corridors more broadly. This is not random vandalism; it is a deliberate effort to raise the cost, in both money and nerves, of continued European support for Kyiv.

Testing the Skies and the Seas

Since late 2025, this pressure has visibly extended into European airspace and territorial waters. Insikt Group tracked 30 suspected or confirmed Russian violations of NATO airspace between September 2025 and January 2026 alone, compared with 23 total violations across the entire period from March 2022 through August 2025 — meaning more violations occurred in four months than in the preceding three and a half years combined. While Poland and Romania have historically been the most frequent targets, violations have increasingly occurred well outside Russia’s traditional sphere of concern, including in Germany, the UK, Denmark, and Norway, most often targeting military bases and airports.

Drone incursions have produced some of the most visible disruptions of ordinary civilian life: unexplained drone activity forced airport closures around Copenhagen and Oslo in 2025, sitting alongside sabotage, arson, and even suspected assassination attempts as part of a hybrid campaign explicitly aimed at punishing Europe for its support of Ukraine and destabilizing European societies internally. Across ten months of 2025, airspace violation incidents alone outnumbered the entire 2022–2024 period combined, a trend one research group attributes partly to ambiguous Western responses that Moscow appears to interpret as tolerance rather than deterrence. Notably, in a small share of cases, Russian officials have responded to these incidents by attributing them to “unknown actors” or local “grassroots activists” rather than acknowledging state involvement — the same pattern of calculated deniability seen in the 2014 Donbas playbook.

Disinformation and Election Interference

Alongside physical sabotage, Russia has run a sustained influence and disinformation campaign aimed at European public opinion and elections specifically. Following the EU’s blocking of Russian state media outlets like RT and Sputnik, Russian propaganda has adapted through proxy outlets and operations such as “Matryoshka,” which employ deepfakes and AI-generated manipulation, as documented in Moldova and Romania during 2024 and 2025. Key targets have included pivotal elections, such as Hungary’s April 2026 vote and German state elections, with propaganda exploiting migration and energy anxieties specifically to amplify pro-Russian populist movements.

Suspected Russian influence operations were reported in Germany, Romania, and Moldova through 2025, with further elections in Hungary and Sweden in 2026 seen as likely future targets. The EU has responded with targeted sanctions, imposing measures in January 2026 against six Russian individuals involved in disinformation campaigns under its Foreign Information Manipulation and Interference framework, though critics describe this response as reactive rather than sufficient to counter what they characterize as an existential threat to European democratic cohesion.

Intimidating Individuals, Not Just Institutions

This pressure campaign has, at points, targeted specific people rather than only infrastructure and institutions. The direct threats reportedly made against the CEO of Germany’s Rheinmetall, a major arms manufacturer supplying Ukraine, were widely read as sending an explicit message that individuals and companies supporting Ukraine’s war effort could face personal consequences. In recent months, European authorities have disrupted sabotage plots against rail lines and exposed assassination attempts linked to Russian operatives, alongside cyberattacks on critical infrastructure traced back to Moscow’s security services — a pattern officials increasingly describe not as isolated provocations but as the deliberate expression of a long-standing Russian intelligence doctrine of “active measures,” updated for the present moment.

A Deliberate Strategy of Staying Below the Threshold

According to European security services, this sabotage campaign has been deliberately calibrated to produce low casualties and moderate levels of destruction specifically to reduce the risk of provoking a direct NATO military response. NATO’s Deputy Secretary-General stated in 2024 that allies had communicated “red lines” to Russian authorities regarding sabotage, implying that especially aggressive actions — those causing civilian deaths or crippling vital infrastructure — could provoke direct confrontation, and at the 2023 Vilnius summit, member states agreed that certain hybrid attacks, particularly cyberattacks on infrastructure, could in principle trigger Article 5 collective defense.

Yet the pattern since then suggests these red lines have functioned more as statements of intent than active deterrents. Analysts argue the restrained European response to repeated airspace violations by aircraft and drones since late 2025, combined with the absence of a clearly defined, unified EU-level approach, has reinforced a Kremlin perception that hybrid coercion carries minimal cost and disproportionate political payoff — and that as long as this remains true, Moscow is further incentivized to continue and intensify these operations rather than scale them back.

Why This Strategy Persists

Part of the explanation for this sustained campaign lies in Russia’s own military and fiscal position. With Russia’s conventional military options increasingly constrained by battlefield attrition and fiscal strain — its energy revenues, which account for roughly half of state income, fell 34% year-on-year in November 2025 — hybrid warfare has become not just an affordable tool but, in the view of some analysts, close to Moscow’s only remaining means of imposing costs on the West and projecting continued strength. Because Putin’s political legitimacy has been built substantially on restoring perceived Russian greatness, a peace settlement that cannot credibly be presented as victory is treated internally as an unacceptable outcome, making continued escalation, in this reading, less a strategic choice than a political necessity for the regime’s own survival.

This does not mean the campaign has been static. Hybrid-warfare incidents in Europe, excluding drone incursions specifically, actually declined somewhat in 2025 after peaking in 2024, and analysts offer several possible explanations: European intelligence services may have gotten better at disrupting plots before they succeed, or Moscow may be temporarily prioritizing a negotiated settlement with Washington over continued pressure on Europe. Whether this represents a genuine tactical pause or simply a shift in method appears likely to depend heavily on how negotiations over Ukraine ultimately unfold — should talks collapse, or should American support for Ukraine and NATO diminish further, most analysts expect hybrid operations to resume at greater scale and ambition rather than fade away.

Europe’s Uneven Response

Perhaps the most consistent criticism from security analysts is not of Russia’s strategy but of Europe’s response to it. One defense technology expert argues that Europe is already living in a state of “permanent low-threshold confrontation” with Russia, whether or not its political leaders are willing to describe it in those terms, and that a credible response would require explicit, collective red lines based on sustained patterns of behavior rather than reactions to single incidents. Crucially, that expert argues, credibility depends on reciprocity: because hybrid activities persist precisely because they are perceived as low-cost and low-risk for Moscow, Europe needs to be prepared not only to name its red lines but to respond in kind — through exposure, coordinated attribution, and proportionate non-kinetic countermeasures — for deterrence to actually function.

Some analysts frame 2026 as a decisive test of whether Europe moves beyond simply recognizing the scale of the threat toward genuinely acting on it — through new sanctions, faster and more robust military buildup, increased defense spending, and further reduction of Russian diplomatic presence across the EU — rather than another year of gesturing toward undefined red lines without enforcing them.

Conclusion

What began in Crimea in 2014 as a regional territorial seizure has, over a decade, evolved into a continent-wide campaign of pressure that touches nearly every sector examined elsewhere in this series — energy, infrastructure, telecommunications, cyber defense, elections, and public trust in institutions generally. The through-line connecting the annexation of Crimea to today’s drone incursions over Copenhagen and sabotage plots against Polish rail lines is a consistent strategic logic: impose real costs and psychological pressure on Europe for supporting Ukraine, while staying just below the threshold that would force a unified, forceful response. Whether that strategy continues to succeed depends less on Moscow’s persistence, which shows no clear sign of exhausting itself, than on whether Europe finally treats this as the single, sustained campaign the evidence increasingly shows it to be, rather than a long series of separate, unfortunate incidents to be managed one at a time.