Russia's Hybrid War on Europe: Water, Energy and Drones Now Share One Playbook
TL;DR what: Recorded Future's Insikt Group documents Russia running cyber sabotage, drone incursions and AI-generated disinformation against European states that back Ukraine. impact: Water and wastewater systems in
TL;DR
- what: Recorded Future's Insikt Group documents Russia running cyber sabotage, drone incursions and AI-generated disinformation against European states that back Ukraine.
- impact: Water and wastewater systems in Norway and Poland and Polish energy infrastructure have already been hit, and drones have been flown near Estonia and Romania's Neptun Deep offshore gas facility.
- fix: Enforce phishing-resistant MFA and harden internet-facing firewalls, VPNs, email and web portals, the initial access points Russian operators favor.
- who: Critical infrastructure operators, plus logistics, dual-use and specialized equipment makers whose work supports Ukraine, face the highest targeting risk.
Russia is running a cyber and physical pressure campaign against Europe, and the targets are the systems people depend on every day. Recorded Future's Insikt Group links attacks on water and wastewater infrastructure in Norway and Poland, attacks on Polish energy infrastructure attributed to Russia-aligned actors, and drone incursions near Estonia and Romania to one doctrine. The pieces are not yet coordinated. Insikt assesses that Russia could turn them into a coordinated campaign over the next two years.
For defenders, the headline is not a new exploit. It is a shift in who gets targeted and why. Insikt's answer: proximity to Ukraine's war effort.
What Insikt Group documented
The report groups Russian activity in Europe into three categories that now run in parallel.
- Cyber sabotage: intrusions into water and wastewater systems in Norway and Poland, and attacks on Poland's energy infrastructure attributed to Russia-aligned actors.
- Physical probing: Russian drones violating NATO airspace near Estonia's border, and a Russian drone intercepted by Romania near the Neptun Deep offshore gas facility in the Black Sea. Other reporting cites alleged attempts to use drones and explosives against cargo infrastructure at a German airport.
- Information operations: AI-generated disinformation that impersonates European media outlets to push false narratives.
The Gerbera drone referenced in the reporting is roughly 2 meters long, weighs about 18 kilograms and flies at around 160 km/h. It is cheap, expendable and built to test air defenses and response times, not to win a battle. Recon, not assault.
The doctrine behind it
Russian officials described this approach in 2013 as "New Generation Warfare." The goal is to test an adversary's defenses, degrade its infrastructure and create fear inside its government and population without a kinetic invasion. A tampered water system, a disrupted power asset and a drone over a gas platform each look minor alone. Taken together they measure how fast European states detect, attribute and respond, and whether the public loses confidence while that happens.
⚠️ The escalation window — Insikt describes current activity as disconnected elements. Its assessment is that Russia could escalate into a coordinated campaign within two years. Organizations that treat each incident as isolated will be planning for the wrong threat.
Who is actually at risk
Chelsea Cederbaum, senior threat intelligence analyst at Recorded Future, put the key risk metric plainly: a company's "proximity to providing material support to Ukraine's war effort." That widens the target set well beyond utilities.
- Critical infrastructure operators: water, wastewater, energy, gas.
- Logistics firms moving goods into or across Europe, including airport cargo operations.
- Dual-use manufacturers whose products serve both civilian and defense customers.
- Specialized equipment makers: subsea cable repair, marine navigation systems, industrial defense components.
If your company ships, builds or maintains anything that reaches Ukraine, directly or through a supplier, assume you are on the list. Mid-size suppliers are attractive precisely because they have less security staff than the utilities and defense primes they serve.
How the cyber side gets in
The initial access pattern is well known and still works. Russian operations prioritize internet-facing firewalls, VPN concentrators, email systems and web portals. Those edge devices are where credentials are phished, where unpatched appliances get exploited and where a single stolen session opens a path into IT and then into OT. Water and small energy operators often expose remote access for vendors and on-call staff, and that remote access is the bridge.
Recorded Future's top recommendation is phishing-resistant multifactor authentication. SMS codes and push approvals can be relayed or fatigued. FIDO2 security keys and platform passkeys bind the login to the real site and defeat the adversary-in-the-middle kits used against VPN and email portals.
What the report does not give — The public reporting names no CVE, no malware family and no patched version. The defensive guidance is control-level: hardened edge devices, phishing-resistant MFA and segmentation. The checks below are built around those controls, not a single vendor fix.
What to do this quarter
- Inventory every internet-facing firewall, VPN, mail gateway and web portal. Patch or retire anything past vendor support.
- Move admin and remote-access accounts to FIDO2 or passkeys first, then the rest of the workforce. Remove SMS as a fallback for privileged roles.
- Confirm no OT protocol ports (Modbus 502, S7 102, DNP3 20000, EtherNet/IP 44818) answer from the internet or the corporate LAN.
- Run a tabletop that combines a cyber intrusion with a physical event at the same site, such as a drone sighting during a SCADA outage. Hybrid means both teams need one playbook.
- Map your Ukraine exposure: which customers, shipments and suppliers tie you to the war effort. That map is your threat model.
Bottom line
Russia is probing Europe's water, energy and logistics layers with low-cost tools and deniable actors. The campaign is not yet coordinated, and the defenses that matter are not exotic: locked-down edge devices, MFA that cannot be phished and OT networks that cannot be reached from the internet. Organizations that close those gaps now will be harder targets if the two-year escalation Insikt describes arrives.
Originally published on RedEye Threat Intelligence.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.