Denmark’s Defence Intelligence Service has warned that Russia is likely to intensify its hybrid warfare against NATO and Western countries in the coming months, raising concerns about sabotage, cyberattacks and other activities below the threshold of conventional war.
The warning was contained in a new threat assessment released by the Danish Defence Intelligence Service, known by its Danish abbreviation FE, on Thursday, September 24.
The assessment also identifies a low but increasing risk of limited Russian military attacks against a NATO member, although it says a full-scale Russian invasion of a NATO country remains unlikely.
Danish intelligence expects more hybrid activity
FE said Russia is expected to further escalate its hybrid warfare against NATO and the West in the coming months.
Hybrid warfare generally refers to the use of methods such as cyberattacks, sabotage, disinformation, influence operations and other coercive activities that can be conducted without launching a conventional military assault.
Danish intelligence has previously assessed that Russia is already conducting hybrid warfare against NATO and Western countries.
The latest assessment indicates that the agency expects the intensity of those activities to increase.
Risk of a limited military attack is increasing
The assessment goes beyond hybrid activity.
FE said there is a low but growing risk that Russia could carry out a limited military attack against a NATO country, even while the war in Ukraine continues.
At the same time, the intelligence service said it considers an actual Russian invasion of a NATO country unlikely, although it can no longer completely rule out such a scenario.
The distinction is important because the assessment does not say that Denmark or another NATO member is facing an imminent invasion.
Instead, it describes a changing security environment in which the possibility of limited military action is assessed to be higher than previously.
Sabotage remains a major concern
Sabotage is one of the principal areas covered by Denmark’s broader assessment of Russian hybrid activity.
Previous Danish intelligence assessments have identified elevated risks to authorities, companies and organisations involved in supporting Ukraine.
FE has said that Russia has used individuals who are not directly linked to Russian intelligence services to conduct sabotage operations in Europe. Such operations can involve relatively simple acts designed to damage infrastructure or disrupt economic and military activity.
The Danish intelligence service has also previously assessed that Russia was responsible for destructive cyberattacks against Danish targets.
In December 2025, FE said it believed a pro-Russian group was responsible for a destructive cyberattack against a Danish water utility in 2024 and that another pro-Russian group had conducted distributed denial-of-service attacks against Danish websites.
Cyberattacks form part of the wider threat
Cyber operations are another component of the hybrid threat.
FE’s previous assessment identified destructive cyberattacks as a medium-level threat to Denmark.
The agency said Russia-aligned groups had increasingly targeted Western critical infrastructure with disruptive cyber operations since 2023.
The Danish intelligence service has linked some of these activities to wider efforts aimed at creating uncertainty and undermining Western support for Ukraine.
The latest assessment indicates that Denmark expects this broader pattern of pressure to continue.
NATO cohesion is a central concern
Danish intelligence chief Thomas Ahrenkiel said Russia’s objectives include creating divisions within NATO, according to Reuters.
That concern is linked to the broader nature of hybrid operations.
Unlike conventional military attacks, activities such as cyberattacks, sabotage and disinformation can be conducted at a lower level of intensity and can create uncertainty about who is responsible and how governments should respond.
The Danish assessment therefore treats hybrid warfare as part of a broader challenge to Western security and political cohesion.
Denmark has already strengthened its security response
The warning comes after Denmark and other European countries have reported a series of incidents involving suspected Russian-linked hybrid activity.
Denmark has also increased cooperation between government authorities, researchers and companies developing defence technologies.
In July, FE announced a partnership with the Technical University of Denmark and the Industriens Fond aimed at accelerating the development of technologies that could strengthen Denmark’s ability to respond to emerging security threats.
The initiative reflects a broader European effort to improve protection of critical infrastructure and develop capabilities against cyber and other non-conventional threats.
European concerns are increasing
Denmark’s assessment comes amid similar warnings from other European governments.
France has said it is preparing measures to respond to what it describes as intensifying Russian hybrid threats, including cyber and drone-related activity.
Lithuania has also been strengthening the physical protection of critical energy infrastructure because of concerns about potential sabotage and drone attacks.
The developments show that concerns about hybrid activity are no longer limited to countries closest to Russia’s borders.
Moscow rejects accusations of hybrid warfare
Russia has repeatedly denied Western allegations that it is conducting a coordinated campaign of hybrid attacks against European countries.
The Danish assessment therefore represents the judgment of Denmark’s intelligence service rather than an independently established finding that every suspected incident attributed to Russia was carried out by the Russian state.
This distinction is important because attribution can be difficult in cyber operations, sabotage cases and influence campaigns.
The Ukraine war remains central
FE’s assessment places the Russian threat within the wider context of the war in Ukraine.
Russia’s military resources remain heavily engaged in the conflict, while European governments continue to provide military and financial support to Kyiv.
Danish intelligence has previously assessed that the war affects Russia’s willingness and ability to conduct activities against NATO countries.
At the same time, the latest assessment indicates that hybrid activity can continue even while Russia remains engaged militarily in Ukraine.
What the warning means
The Danish assessment does not announce that Russia is preparing an imminent attack on Denmark.
Instead, it identifies a deterioration in the wider European security environment and warns that hybrid activity is likely to increase.
The most immediate areas of concern include sabotage, cyberattacks, influence operations and other activities designed to create disruption or pressure without triggering an open military confrontation.
The assessment also highlights a growing, but still low, risk of limited military action against a NATO member.
For Denmark and its NATO partners, the warning points to the continued importance of protecting critical infrastructure, improving cyber defences and maintaining coordination among member states.
Community
Comments
Keep discussion respectful and relevant. Comments never affect rewards.
No comments yet. Start a respectful conversation.