Germany's chancellor said Europe must be ready for serious Russian hybrid operations, while NATO's secretary general warned that sabotage and arson could persist across the alliance.

Merz warns Russian hybrid attacks will escalate as Europe enters a winter shaped by sabotage risk, military rearmament and the continuing war in Ukraine. German Chancellor Friedrich Merz told an audience in Münster that Europe was preparing for further hybrid attacks from Russia, including serious ones, and said Berlin would continue backing Ukraine through what is likely to be its harshest winter since the full-scale invasion began in 2022.
Speaking as NATO received the 2026 Westphalian Peace Prize, Merz paired the warning with a longer-term diplomatic objective. Germany still wants to rebuild stable, predictable relations with Russia, he said, but sees no sign that Moscow is ready to end the war. He said Germany did not want to humiliate the Russian people or destabilize the Russian state, while insisting that Russia must stop the war and refrain from hybrid attacks on Europe.
NATO Secretary General Mark Rutte delivered a parallel warning in Münster on October 1. He urged allies to assume that hostile activity attributed to Russia — including sabotage and arson — would continue, and told governments to remain vigilant and alert. Dutch Prime Minister Rob Jetten said German-Dutch intelligence cooperation was expanding “to an unprecedented level,” an indication that the response is moving beyond speeches into deeper information-sharing.
Why this matters: pressure below the threshold of open war
Hybrid operations are strategically useful because they can impose real costs without creating the clarity of a conventional attack. A drone near an airport, a cyber intrusion, a warehouse fire or an interrupted rail link may be disruptive enough to shape public behavior and government spending, yet ambiguous enough to complicate attribution and collective defense. The problem is not only stopping individual incidents. It is deciding when a pattern becomes a coordinated campaign and what proportional response follows.
That uncertainty can favor the attacker. Governments must investigate before accusing another state, operators must restore service before a full forensic picture is available, and alliance members may disagree about evidence or thresholds. Defenders face a resource problem: protecting every airport, cable, power substation, port and software system is more expensive than probing one weak point. Merz's warning matters because it treats those incidents as a sustained security contest rather than isolated crimes.
The risk is not abstract for Ukraine. German support helps supply weapons, air defense and budget stability while Russia continues attacks on Ukrainian infrastructure. If European states divert political attention and scarce defensive systems to incidents at home, Kyiv could face its harshest winter of the Ukraine invasion with partners under pressure on two fronts. If closer intelligence work prevents disruption and improves attribution, Europe may protect its own networks without weakening support for Ukraine.
Westphalian Peace Prize NATO speech carries a deliberate contrast
The setting in Münster was unusually symbolic. The city is associated with the Peace of Westphalia, the seventeenth-century settlements that ended the Thirty Years' War, and the 2026 prize honored NATO as a security alliance. Merz used that setting not to announce a peace process, but to argue that resilience and military capacity are preconditions for a stable European order.
Germany has set aside hundreds of billions of euros to rebuild its armed forces after decades in which defense readiness competed with other budget priorities. The scale signals that Berlin now sees deterrence as a long-term national investment, not a temporary response to one winter. The policy benefits defense manufacturers, cyber specialists, infrastructure operators and allies seeking a stronger German contribution. It imposes fiscal tradeoffs on taxpayers and ministries competing for the same public money.
Merz's line about eventually restoring stable relations with Russia separates opposition to Moscow's current conduct from a policy of permanent isolation or regime change. Supporters will see that distinction as preserving a future diplomatic exit. Critics may see it as too vague: predictable relations require both a change in Russian behavior and agreement about what security guarantees would make renewed contact credible.

Münster NATO sabotage warning builds on a month of alerts
The October 1 speeches extended a warning building across Europe. On September 26, European and U.S. officials described Russia as testing NATO through drones, cyber operations, sabotage and arson. Our earlier report examined the widening pattern of hybrid-attack warnings across NATO, including the difficulty of distinguishing a state-directed campaign from criminal acts, accidents and copycat incidents.
Belgian Defence Minister Theo Francken sharpened the seasonal frame on September 30, warning of a “dark winter” in which Europe could face intensified drone and sabotage pressure while Ukraine's energy system remained under attack. Our analysis of Francken's dark-winter warning details the air-defense, attribution and stockpile constraints behind that concern.
Gen. Grnkewich also warned in September about Russia's destabilizing activity and the need for stronger public attribution. Taken together, the messages show an emerging allied approach: share intelligence faster, harden civilian systems, name patterns when evidence supports doing so and avoid giving ambiguous incidents more certainty than investigators possess.
Leipzig airport drone sabotage shows the attribution problem
German authorities accuse Russia of conducting a wider hybrid campaign that includes drone and cyber attacks. They point in part to an attempted drone attack at Leipzig airport in August 2026. An airport combines civilian safety, cargo logistics and national security in one target: even a short disruption can ground flights, delay freight and force security resources into a costly search.
Yet the phrase Leipzig airport drone sabotage must be handled with precision. Germany has made an accusation; Moscow rejects the allegations. Public reporting does not automatically reveal the intelligence chain, direction or level of state control behind every incident. A responsible response has to hold two ideas at once: the pattern may be strategically significant, and each event still requires evidence strong enough to support attribution.
That is why the NATO Rutte sabotage arson warning focused on persistence and readiness, not a declaration that every fire or drone sighting is an act of war. Security services can cooperate on technical signatures, financing, travel, communications and recurring methods. Political leaders then have to decide how much evidence can be released without exposing sources, and how to preserve public trust when uncertainty remains.

German-Dutch intelligence cooperation becomes the operational test
Jetten's description of German-Dutch intelligence cooperation as “unprecedented” is more consequential than the superlative alone. Germany and the Netherlands share energy, transport, digital and military networks. Faster exchange can help investigators connect an attempted intrusion in one country with financing, equipment or personnel observed in another before incidents are treated as unrelated.
The hard part is converting cooperation into decisions. Intelligence may be persuasive without being publishable. Police need evidence suitable for court, infrastructure operators need practical warnings, and elected governments need a standard for sanctions, expulsions or other responses. Too little disclosure can look evasive; too much can compromise investigations or turn preliminary assessments into political facts.
Russia rejects hybrid campaign accusations and argues that Western governments use the label to blame Moscow without proof. That denial is relevant, but it does not settle the question. Evidence must be tested incident by incident while the cumulative pattern is evaluated across jurisdictions. Europe loses if every event is reflexively attributed to Russia; it also loses if uncertainty becomes a reason never to identify a coordinated campaign.
Putin's factory comments add a second signal from the same day
At the Valdai discussion forum on October 1, Russian President Vladimir Putin said Moscow was not about to attack foreign factories producing weapons for Ukraine, while adding that Russian intelligence must track them closely. The first half was reassurance; the second made clear that industrial support networks remain inside Russia's intelligence picture.
The distinction is important. Monitoring a factory is not the same as attacking it, and Putin said Russia was not preparing such attacks. But European governments are likely to treat the comment alongside warnings about sabotage, cyber operations and Russian red lines. In a climate of suspicion, an ambiguous industrial incident could quickly be interpreted through the lens of hostile intent.
The same Valdai appearance included Putin's rejection of a proposed halt to long-range strikes. Our report on Putin's refusal of a long-range strikes ceasefire explains why attacks on refineries, shipping, energy and logistics are likely to continue into winter. The two stories intersect around industrial vulnerability, but they should not be collapsed: a conventional strike inside the war zone and a covert act on NATO territory raise different legal and strategic questions.
AfD Ukraine aid criticism turns security policy into a domestic contest
The AfD's victories in two eastern German state elections last month give Merz's policy a stronger domestic opposition. The party criticizes the billions spent on military aid for Ukraine and calls for relations with Moscow to be repaired, including restoration of Russian oil and gas flows. That position can appeal to voters who associate rapprochement with lower energy costs and question open-ended support for Kyiv.
Merz's coalition and NATO-aligned parties answer that energy dependence and military weakness created vulnerabilities that cannot be solved by returning to the prewar model. They argue that rearmament, diversification and aid to Ukraine reduce the chance that coercion succeeds. The disagreement is over which costs count. The AfD emphasizes household bills, industry and fiscal burden. The government emphasizes deterrence, infrastructure security and the longer-term cost of a successful war of aggression.
Who benefits depends on the evidence this winter. The AfD gains if energy prices rise, aid fatigue deepens or officials make sabotage claims they later cannot substantiate. Merz gains if intelligence cooperation prevents attacks, German readiness improves and Ukraine survives the winter without a crisis demanding still greater support. Ukraine loses if German debate turns every aid package into a referendum on domestic hardship. German voters lose if legitimate scrutiny is reduced to a choice between complacency and alarmism.
Harshest winter Ukraine invasion: four scenarios to watch
Resilience without major disruption. European intelligence services identify plots early, infrastructure operators improve defenses and Ukraine's partners maintain aid. Hybrid pressure continues, but its operational effect stays limited. In this scenario, the warnings look preventive rather than predictive.
A visible but contained attack. Sabotage or a cyber incident disrupts transport, energy or communications in one or more NATO states without mass casualties. Governments respond with arrests, sanctions, expulsions and stronger protection while avoiding a military spiral. Attribution becomes the center of public debate.
Compounding winter pressure. Russian strikes strain Ukraine's power system as European states contend with drone incursions, cyberattacks or suspected sabotage at home. Air-defense demand, repair capacity and public patience become linked constraints. The political effect may exceed the physical damage if people believe authorities cannot secure essential services.
A serious incident creates an alliance test. An attack causing deaths or prolonged infrastructure failure could force NATO members to debate collective measures below the threshold of conventional invasion. The alliance would need to balance resolve with evidence, avoiding both paralysis and premature escalation.
The next indicators are practical: arrests and forensic disclosures from German investigations; defenses adopted at airports, ports and energy sites; the speed of German-Dutch intelligence exchange; continuity of military and financial support for Ukraine; and whether Moscow's operations and rhetoric change. Merz's warning will be judged not by how stark it sounded in Münster, but by whether Europe can reduce vulnerability while keeping channels open for the stable relations he says Germany still wants.
Sources
- Reuters — Merz warns of more Russian hybrid attacks as he reaffirms support for Ukraine (October 1, 2026)
- AFP via Clash Report — NATO chief warns Europe to prepare for more Russian sabotage and arson (October 1, 2026)