# European Intelligence Services Unite Against Russian Election Interference
As critical elections approach across the European Union, intelligence services throughout the continent are confronting an unprecedented wave of Russian interference operations designed to destabilize democratic processes. At a conference held in Stockholm on August 20, Estonian Defense Minister Hanno Pevkur issued a stark warning to international partners, noting that with elections imminent in Sweden and Latvia, and Germany’s scheduled for March 2027, Russia would inevitably seek opportunities to influence societies and incite tensions. Pevkur was joined by Polish Foreign Ministry official Henrika Mościcka-Dendys, who emphasized that elections provide ideal opportunities for adversaries to sow distrust and test the resilience of democratic institutions, while stressing the critical importance of collective vigilance and coordinated action across European nations.
The warning came just two days after Sweden experienced a coordinated disinformation campaign targeting its electoral process, when a series of fake videos bearing the logos of Swedish and German national media outlets circulated on social media platform X. These fabricated reports alleged electoral fraud and corruption involving Prime Minister Ulf Kristersson, and were rapidly identified by the disinformation monitoring group Antibot4Navalny as part of a broader Russian influence operation codenamed “Matryoshka,” which has been detected across multiple European countries. Swedish authorities, including the Psychological Defense Agency, assessed that the campaign’s objective was not necessarily to convince voters of specific falsehoods but rather to saturate the information environment with suspect content, thereby undermining trust in legitimate news sources and democratic institutions through sheer volume rather than persuasive messaging.
## The Expanding Threat Landscape Across Europe
The scope of Russian interference extends far beyond social media manipulation. In February, the Norwegian Institute for Defense Research revealed that pro-Russian hackers had attempted to interfere with Norway’s parliamentary elections scheduled for September 2025, specifically targeting the Conservative Party’s digital infrastructure. While investigators concluded that the cyberattack ultimately failed to achieve meaningful impact on electoral outcomes, the incident demonstrated clear intent to directly target democratic processes throughout the region. Danish intelligence agencies subsequently warned of the risk of Russian-backed disinformation campaigns designed to promote Russian interests and erode public support for Ukraine, while also flagging potential consequences for individual candidates and parties participating in elections, particularly those taking strong positions on Eastern European security matters.
Germany, as Europe’s leading provider of military and financial assistance to Ukraine, has emerged as a particularly prominent target. In a concerning incident on August 4, authorities at Leipzig Airport discovered an explosives-laden drone in a secure cargo area near Ukrainian cargo planes, with reports indicating that at least one additional device was directed at a DHL aircraft and a third was later found in an adjacent field. German Chancellor Friedrich Merz, who had until that point remained publicly restrained in assigning blame, issued a firm statement warning that those responsible would “pay a price for their actions.” Federal Defense Minister Boris Pistorius acknowledged the growing threat, noting that while definitive evidence linking Russia to every incident remains elusive in formal legal terms, intelligence assessments indicate a clear pattern of Russian involvement. The attacks have become part of a broader pattern of sabotage and subversion targeting German infrastructure, with the Federal Criminal Police Office recording more than 320 destabilization attempts throughout 2025, including acts of sabotage, theft, burglary, and attacks on critical infrastructure.
## The Hybrid Warfare Debate Intensifies
The term “hybrid warfare” itself has come under increasing scrutiny among security experts and defense officials who argue that the terminology risked downplaying the severity and directness of Russian aggression. Politico reports that the European Commission defines hybrid threats as the combination of coercive and subversive activities, utilizing both conventional and unconventional methods across diplomatic, military, economic, and technological domains, deployed by state or non-state actors to achieve specific objectives while remaining below the threshold of formally declared war. This definitional approach has traditionally provided Western governments with legal and political flexibility in responding to hostile actions without triggering broader conflict escalation. However, critics contend that this framework has become dangerously permissive, allowing Moscow to conduct aggressive operations against European nations with relative impunity while maintaining plausible deniability.
Camille Grand, former NATO Assistant Secretary General and current head of the Aerospace, Security and Defence Industries Association of Europe, used the metaphor of boiling a frog to describe the gradual escalation that has characterized Russian operations: “What was shocking to us yesterday becomes the norm tomorrow, and so on until you find yourself in a much more intense situation… They are testing the limits.” Grand’s assessment reflects growing frustration among European security officials who believe that Western responses have consistently lagged behind Russian provocations, creating a cycle in which Moscow feels empowered to push boundaries ever further. The debate over terminology, however, has significant practical implications, affecting everything from intelligence prioritization to legal authorities for countermeasures and the degree of public attention devoted to the threats.
## Secret Intelligence Networks and the Berne Club
European governments rarely speak with one voice in responding to foreign interference, yet their intelligence services have developed increasingly sophisticated cooperation mechanisms through both formal channels and informal networks. The so-called Berne Club, which brings together intelligence agencies from the United Kingdom, Switzerland, Norway, and European Union member states, has emerged as the primary multilateral forum for confronting shared threats. One senior French intelligence official described it as “the only multilateral forum that really matters for the continent’s collective security,” speaking to the depth of trust and operational cooperation achieved within this framework. The club convenes regularly in various European capitals, with participation structured flexibly depending on the topics under discussion and the sensitive nature of the intelligence being shared.
This intelligence cooperation has proven essential in identifying and disrupting Russian operations across the continent. European services have mapped the command structure of Moscow’s interference campaigns, with French Interior Ministry officials identifying Sergei Kiriyenko, deputy chief of staff of the Russian Presidential Administration, as playing a central coordinating role in destabilization efforts. According to intelligence assessments, directives from the Kremlin establish “a general mandate, and each Russian intelligence structure then carries out possible actions in accordance with the access it has, the information it has or the opportunities that arise.” This decentralized execution model makes Russian operations particularly difficult to predict and counter, as individual intelligence services and proxy actors pursue independent lines of operations within broadly defined parameters against all countries deemed “enemy states” by Moscow.
## Sanctions and Strategic Responses
In a rare demonstration of coordinated Western action, France, the European Union, and the United Kingdom jointly imposed sanctions on July 13 against nine Russian nationals and four entities linked to the FSB, Russia’s Federal Security Service, marking one of the most significant coordinated responses to election interference to date. British authorities additionally added 24 individuals to their sanctions list, including GRU military intelligence leadership and members of Rybar LLC, a Russian disinformation network that has been implicated in orchestrating election interference operations across Europe and targeting Ukraine with propaganda. European Union foreign policy chief Kaja Kallas emphasized the evolving nature of the threat landscape, noting that “today’s wars are not only fought with tanks and drones, but also with lies and algorithms. Compared to last year, the use of AI tools in FIMI incidents has increased exponentially. AI is now fully embedded in Russian and Chinese FIMI operations.”
These sanctions followed investigations into operations targeting French political figures, including reports that the Paris prosecutor’s office had opened investigations into suspected Russian interference against several politicians, including former Prime Ministers Gabriel Attal and Édouard Philippe and European Parliament member Raphaël Glucksmann. Reports of fabricated health problems and corruption allegations circulated through coordinated disinformation campaigns, although French digital interference monitoring agency Viginum noted that the publicity surrounding detection efforts had actually served to amplify content that had reached relatively few citizens. This highlights the delicate balance facing European governments as they seek to expose and counter Russian operations without inadvertently increasing their impact through media attention, a challenge that has become increasingly central to Western counter-disinformation strategy as Russia continues to refine its approaches and adapt to Western countermeasures.

