Security1 publisher2 min readPublished
Insikt Group puts Russian sabotage and network intrusion in Europe under one escalating strategy
Recorded Future's Insikt Group says Russia-linked sabotage in Europe rose four-fold from 2023 to 2024 and held at that level in 2025. It expects Russia to escalate in the near term, possibly into a full-scale New Generation Warfare campaign.
The Watch · Security desk

What happened
- Recorded Future's Insikt Group assesses that Russia has escalated New Generation Warfare tactics across Europe since its February 2022 invasion of Ukraine, well beyond the former Soviet Union.
- From January 2018 to June 2025, sabotage fell most often on Germany, Estonia, Latvia, Lithuania and Poland, according to Insikt's tracking.
- Russian cyber operations against European targets typically go after internet-facing firewalls, VPNs, email services and web portals, Insikt says.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure An operator can be in the sabotage target class with no defense contract at all, because Insikt's description covers infrastructure that only indirectly supports European defense or aid to Ukraine.
- constraint Intrusions aimed at long-term access cause no outage, so monitoring that alerts only on disruption will not catch the firewall and VPN activity Insikt describes.
- precedent If Insikt's near-term escalation call holds, the 2024-2025 sabotage level is the lower bound for the next round of physical-security planning.
Thirty suspected violations over the five months from September 2025 through January 2026 is six a month [1]. The earlier 23 span 42 months, March 2022 through August 2025, or about 0.55 a month [2]. On Insikt's counts the recent rate is roughly 11 times the earlier one [3]. The group labels the recent violations suspected and the aircraft likely Russian drones or jets [4].
The sabotage series is a ratio. Insikt gives a four-fold rise from 2023 to 2024 and a flat 2025 [6], but the blog does not publish the incident counts behind it, so the size of the base is unknown. It attributes the attacks to "Russia-nexus individuals and entities" and says they aim to degrade infrastructure in NATO territory and weaken the alliance's collective response [8]. The targets are often civilian or dual-use infrastructure that supports European collective defense or Europe's material aid to Ukraine, directly or indirectly [9].
The cyber operations are for holding access. Insikt assesses that the work against edge devices and mail services [10] is likely meant to enable intelligence collection, operational reach and long-term access, not immediate disruption [11]. It calls the activity broad in scope, across multiple regions and sectors [11].
In Insikt's account, psychological, cyber and physical tactics sit in one kit. Its stated aims are to test defenses while Russia weighs escalation to kinetic war, to degrade critical infrastructure, and to sow fear that slows a government's response [3]. Cable targeting and territorial-waters violations are described the same way, as tests of NATO's resilience meant to keep it reactive [13]. The report does not document a case in which a network intrusion prepared a physical attack. On this evidence, planning for the two together rests on a shared strategy that names critical infrastructure as a target [3].
Germany and Poland are the only states on all three of Insikt's lists: most-targeted for sabotage, sites of airspace violations, and targets of influence operations [4]. The influence campaigns, among them Doppelganger, Operation Overload, Operation Undercut and CopyCop, have impersonated national and pan-European media outlets. They are aimed particularly at the UK, France, Germany and Poland, which Insikt says Moscow likely views as Kyiv's core European supporters [12].
Valeriy Gerasimov, Chief of the General Staff of the Russian Armed Forces, laid out New Generation Warfare in a 2013 article in Military-Industrial Kurier [2]. Insikt dates Russia's use of those tactics in Ukraine to the February 2014 annexation of Crimea and its aftermath [1].
What to watch
- Incident-level reporting, from Insikt or a national agency, that ties a Russian intrusion on a firewall or VPN to a later sabotage event.
- Insikt's 2026 sabotage count against the 2024-2025 level, the first test of its near-term escalation assessment.
- Whether suspected NATO airspace violations stay near six a month after January 2026.