Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagehacktivist-operationstate-sponsored-disruptiongovernment-diplomatic-threat

Geopolitically Driven Cyber Activity and Hybrid Operations Escalate Across Europe and Major Events

Updated 2mo agoFirst seen Feb 22, 202619 sources

Multiple reports describe an uptick in state-linked and politically motivated cyber activity in Europe, framed as part of broader hybrid warfare. Dutch intelligence (AIVD/MIVD) warned that Russia is intensifying a mix of cyberattacks, sabotage, disinformation, covert influence, and espionage designed to stay below the threshold of open conflict while testing Western red lines and undermining support for Ukraine. Related policy commentary notes growing calls from European and NATO officials for stronger “strike back” or offensive cyber capacity, but argues that political will and proportional response options—especially against proxy-driven sabotage—remain the limiting factors rather than technical capability.

Separately, threat reporting tied to the 2026 Winter Olympics indicates increased hacktivist mobilization and targeting chatter against Olympic-adjacent entities (e.g., transportation, sponsors, and overlapping supply chains), alongside continued targeting of the defense industrial base by a mix of hacktivists, state actors, and cybercriminals. A case study on Venezuela’s Caracas outage during “Operation Absolute Resolve” cautions against attributing major disruptions to “cyber-only” effects when available evidence also indicates substantial kinetic/physical damage to substations, underscoring that modern operations may integrate cyber and physical actions and that misframing can distort infrastructure security priorities.

Share:
Geopolitically Driven Cyber Activity and Hybrid Operations Escalate Across Europe and Major Events
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

19 events from the most recent confirmed update back to the earliest known activity.

19 EVENTS
Apr 22, 20262mo ago

Dutch intelligence says China has reached U.S.-level cyber capability

In its annual report, the Dutch MIVD warned that China has likely achieved parity with the United States in offensive cyber capabilities and that only a limited portion of Chinese operations against Dutch interests are detected. The report also said Chinese actors accessed routers at smaller Dutch hosting and internet providers in 2025 and warned of increased 2026 campaigns targeting edge devices and strategic Dutch sectors.

China’s cyber capabilities now equal to the US, warns Dutch intelligence | The Record from Recorded Future News
Apr 21, 20262mo ago

EU sanctions Euromore and Pravfond over Russian influence operations

The European Union imposed sanctions on the pro-Russian organizations Euromore and Pravfond, accusing them of supporting Kremlin-aligned disinformation and hybrid influence operations targeting Europe and Ukraine. The measures freeze any EU-based assets and bar EU citizens and companies from providing the groups with funds or economic resources.

EU targets two Russian propaganda networks with new sanctions | The Record from Recorded Future News
Mar 31, 20263mo ago

Report says Russia intensifies hybrid influence ahead of Armenia election

A report published on 2026-03-31 said Russia had stepped up hybrid warfare tactics in Armenia ahead of the June 7 parliamentary election, including information operations, influence campaigns, and support for opposition forces with strong Russian ties. The article framed the vote as a pivotal contest over Armenia's geopolitical orientation toward the West or continued Russian influence.

Political battle for Armenia's future intensifies ahead of June parliamentary election | Eurasianet
Mar 27, 20263mo ago

U.K. prepares tighter political donation rules over foreign interference

The British government began preparing reforms to political donation rules after the Rycroft Review and a cross-party parliamentary report warned that foreign interference in U.K. democracy is becoming more sophisticated across financial and information channels. Proposed measures included a temporary ban on cryptocurrency donations and a £100,000 annual cap on contributions from overseas voters.

UK weighs new limits on political donations as reports warn of hard-to-trace foreign interference | The Record from Recorded Future News

Latvia accuses Russia of disinformation campaign targeting Baltic states

Latvia's Defense Ministry said Russia was running a coordinated disinformation campaign against Latvia, Lithuania, and Estonia by falsely claiming the Baltic states enabled Ukrainian attacks on Russia from their territory or airspace. Latvian officials said the effort aimed to discredit NATO, undermine trust in state institutions, and weaken support for Ukraine, including through social media bot activity.

Latvia accuses Russia of of disinformation campaign targeting Baltic states | The Record from Recorded Future News
Mar 23, 20263mo ago

Report alleges Russian influence campaign in Hungary's 2026 election

Reporting published on 2026-03-23 alleged that Russia was conducting a covert influence operation to help Viktor Orban ahead of Hungary's April 12 election, including online attacks on opposition leader Peter Magyar and other election manipulation tactics. The report also cited an alleged internal SVR document discussing extreme scenario planning, including a fake assassination attempt, as part of efforts to preserve a key Russian ally inside the EU.

Operaci�n salvar al 'camarada Orban' | Internacional
Mar 16, 20263mo ago

Pro-Kremlin campaign exploits Ukraine energy blackouts

By mid-March 2026, EUvsDisinfo reported that pro-Kremlin foreign information manipulation campaigns were using Russia’s strikes on Ukraine’s energy infrastructure to depict Ukraine as collapsing, socially unstable, and abandoned by Europe. The report said these narratives were contradicted by polling, continued government aid, and grassroots fundraising and energy support across Europe.

Targeting the grid, shaping the story: Russia’s dual assault on Ukraine - EUvsDisinfo
Mar 13, 20263mo ago

Pro-Kremlin disinformation pivots to Iran war to undermine Ukraine

EUvsDisinfo reported that Kremlin-aligned information operations rapidly shifted to the Iran/Middle East conflict, pushing false narratives that portrayed Ukraine as a destabilizing actor and suggested Kyiv might stage provocations to regain attention. The campaign also circulated fabricated claims, including a fake Euronews story about an Iranian missile strike on property allegedly linked to an aide of Ukraine's commander-in-chief.

Russian FIMI and the war in Iran - EUvsDisinfo
Mar 9, 20264mo ago

Attacks on Jewish and Israeli-linked sites raise Iranian hybrid threat concerns

Beginning on 2026-03-09, a series of low-casualty attacks targeted Jewish and Israeli-linked sites in Belgium, the Netherlands, and the United Kingdom. Analysts said the incidents, claimed by the previously unknown HAYI group and amplified through pro-Iranian online networks, may indicate likely Iranian-backed hybrid activity in Europe, though definitive proof was not established.

Hybrid Threat Signals: Assessing Possible Iranian Involvement in Recent Attacks in Europe | International Centre for Counter-Terrorism - ICCT
Feb 20, 20264mo ago

Dutch intelligence warns Russia is intensifying hybrid attacks

AIVD and MIVD publicly warned that Russia is stepping up cyberattacks and other hybrid operations across Europe while preparing for a long standoff with the West. The agencies said a direct Russia-NATO clash remains unlikely but is no longer unthinkable.

Hacktivist communities escalate Olympic-related cyber coordination

Threat intelligence reporting around the 2026 Winter Olympics identified increased hacktivist chatter, mobilization, and operational coordination tied to protests and geopolitical tensions. Online communities referenced Olympic-related targets such as transportation infrastructure and sponsors.

Feb 19, 20264mo ago

CyberScoop report challenges cyber-only narrative of Caracas outage

CyberScoop reported that publicly available evidence points to substantial kinetic damage during the January 3 Caracas outage and that no public confirmation from the Pentagon or U.S. Cyber Command supports a cyber-only explanation. Experts said cyber activity may have played a supporting role rather than being the sole cause.

Jan 3, 20266mo ago

Evidence emerges of kinetic damage at Caracas substations

Public videos, photos, journalist accounts, and Venezuelan government statements described destroyed equipment, bullet impacts, blown doors, oil leaks, and fires at substations including Panamericana, Escuela Militar, and Fuerte Tiuna. Analysts and experts said the visible physical damage alone could plausibly explain the localized outages.

Operation Absolute Resolve triggers Caracas power outage

A major power outage struck Caracas on January 3 during Operation Absolute Resolve. Early reporting widely characterized the disruption as a precision cyberattack affecting Venezuela's power grid.

Jan 1, 20251y ago

Poland discloses 2025 cyber intrusions at five water treatment facilities

Poland’s Internal Security Agency (ABW) said attackers breached water treatment facilities in five Polish towns during 2025 and in some cases accessed industrial control systems, creating a direct risk to continuity of water supplies. ABW did not publicly attribute the incidents to a specific actor, though it said hostile activity against Poland had intensified with particular emphasis on Russian services.

Polish intelligence warns hackers attacked water treatment control systems | The Record from Recorded Future News
Sep 1, 20242y ago

Attack on Dutch police steals officers' contact details

A Russian-linked group later dubbed Laundry Bear carried out a September 2024 attack on Dutch police systems, stealing work contact details of police officers. Dutch intelligence later highlighted the intrusion as a notable example of Russian cyber activity targeting the Netherlands.

Jan 1, 20242y ago

Russia's risk tolerance in hybrid operations increases

According to Dutch intelligence, Russia became more willing in 2024 to accept physical damage and potential casualties in its operations against Europe. The shift was cited as evidence of a more aggressive hybrid campaign.

Dec 1, 20233y ago

Russia-linked hybrid activity in Europe rises sharply

Dutch intelligence assessed that Russian hybrid operations across Europe, including cyberattacks, sabotage, disinformation, covert influence, and espionage, increased significantly starting in late 2023. The agencies said this marked the beginning of a more sustained confrontation below the threshold of open war.

Jan 1, 20233y ago

Ukraine reports rise in Russian-directed sabotage-for-propaganda scheme

Ukrainian prosecutors and security officials said sabotage incidents in Ukraine have increased since 2023 and are suspected to be orchestrated by Russian intelligence through the online recruitment of vulnerable individuals via social media and Telegram. Officials and researchers said the acts are then amplified by pro-Russian propaganda networks to falsely depict a broad anti-government underground movement, despite no evidence of a nationwide resistance.

In Ukraine, Contract Saboteurs Fuel Propaganda About a Pro-Moscow Resistance | OCCRP
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

74 LINKEDOpen in app
Affected products
8 linked
TelegramAndroidFortigateTiktokAndroidGoogle SearchIosIos
Organizations
50 linked
GoogleFinancial TimesCheck Point Software TechnologiesRoyal United Services InstituteAXAFoundation for Defense of DemocraciesThe TelegraphPalo Alto NetworksDeepseekSecurityWeekAllianzKasperskyFortinetOpenaiXNaftogazAppleIntel 471The Washington PostVercelTelegramNewsGuardCyberScoopPoliticoReform U.K.Foundation for the Support and Protection of the Rights of Compatriots Living AbroadEuromoreDDoS-GuardEuronewsMediumUnsplashThe ObserverOrganized Crime and Corruption Reporting ProjectAmpyx CyberINPOWERDAirwarsCorporación Eléctrica NacionalOODA LoopUnited States Agency for International DevelopmentInternational Centre for Counter-TerrorismXNetworkSACC by EJCTGStatBrunel UniversityNews FrontTashir GroupEurasianetSistema PJSFCEuroview MediaJoin Ukraine
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Geopolitically Driven Cyber Activity and Hybrid Operations Escalate Across Europe and Major Events | Mallory