NATO intelligence sharing Russia threat
Topics: NATO Russia hybrid war warning · Denmark intelligence Russia hybrid warfare escalation · Russia limited attack NATO border countries risk · NATO intelligence sharing increase 2026
The NATO Russia hybrid war warning issued on Thursday, September 24, 2026, was both reassurance and deterrence. Gen. Alexus Grynkewich, NATO's Supreme Allied Commander Europe, told Reuters the alliance was increasing intelligence sharing as it confronted apparent Russian-linked sabotage, drone activity and other pressure across Europe. His message to allies was that NATO has the institutions and force to manage the danger; his message to Russian President Vladimir Putin was blunter: do not test the alliance.
The warning did not amount to a declaration that a Russian attack was imminent. Grynkewich described a limited strike as unlikely, and Moscow denies involvement in sabotage, hybrid warfare or plans for a confrontation with NATO. But the public language matters because it came alongside a new Danish intelligence assessment forecasting more aggressive Russian activity in the coming months. Together, the statements show an alliance trying to close the space between a suspicious incident, a confident attribution and a coordinated response.
That is the central problem of hybrid conflict. It is designed to create damage and political pressure without supplying the clear evidence or scale that would make a conventional military response automatic. NATO's answer, at least for now, is faster information fusion, steadier public messaging and a warning that activity below the Article 5 threshold is not invisible or cost-free.
The Interview: What NATO’s Top Commander Actually Said
Grynkewich spoke in a Reuters phone interview while traveling to Norfolk, Virginia, for a NATO change-of-command ceremony at which a British Army general was due to replace a U.S. Navy vice admiral. The setting reinforced a point that ran through his remarks: NATO's response is institutional and multinational, not the policy of one capital or one commander.
Grynkewich’s NATO supreme commander Russia interview
Asked about a cluster of recent incidents, Grynkewich said, “It’s concerning.” He cited an attempted drone attack at Leipzig/Halle Airport in Germany and an episode in which a Russian ship fired flares toward a Danish military helicopter. The incidents differ in method and severity, but both fit the problem NATO is attempting to solve: how to detect intent, attribute responsibility and respond proportionately before an ambiguous act becomes a strategic surprise.
His public posture was deliberately controlled. NATO should be “calm and confident,” he said, because “the most powerful alliance in history” has the tools and mechanisms to manage the risk. That phrasing pushes back against two opposite dangers. Panic can magnify the political effect of a relatively limited operation; complacency can allow repeated probes to become normalized. Calmness without capability would look passive, while capability without restraint could accelerate escalation. Grynkewich's formulation tries to hold both.
On the possibility of a direct strike, he said a limited Russian attack was “unlikely but something that we can’t rule out.” That is not the language of imminent-war forecasting. It is a risk statement: probability remains low, but the potential consequence is too serious to ignore. The purpose of saying so publicly is partly to shape Russian calculations and partly to prepare allied governments for decisions that might have to be made quickly.
Grynkewich also said the United States would continue supplying “critical but more limited capabilities” to NATO. That phrase is an important burden-sharing signal. Washington is not describing withdrawal from the alliance; it is indicating that European states should expect fewer American resources in some conventional roles while the United States continues to provide high-value capabilities that are hard to replace quickly. Moscow, for its part, denies conducting hybrid attacks, sabotage or plotting a military confrontation with the alliance.
Denmark’s Threat Assessment
Denmark's defence intelligence service published its assessment on September 24, warning of “more frequent attacks against the West and NATO with greater consequences.” It judged that there was a “low but growing risk” of a limited attack on one or more NATO countries bordering Russia. The combination of those phrases is significant: the agency is not predicting a general invasion, but it is asking policymakers to treat a bounded military incident as a credible contingency rather than an abstract worst case.
Denmark intelligence: Russia hybrid warfare escalation
Intelligence chief Thomas Ahrenkiel described several forms such a test could take. They included an isolated drone or missile strike against infrastructure supporting Ukraine, a false-flag operation using Ukrainian-made drones, or a small troop deployment into a NATO border area, perhaps justified by Moscow as protection for a Russian-speaking minority. “The aim is not to take over the country, but to divide NATO,” Ahrenkiel said.
That distinction goes to the heart of the threat assessment. A limited operation would seek political leverage greater than its military footprint. Its success would depend on disagreement inside NATO: whether the act was deliberate, who was responsible, whether it met the armed-attack threshold and what response was proportionate. A false-flag operation would add a second layer of uncertainty by making the instrument of attack appear Ukrainian even if the operator were not.
The Danish warning also used a time horizon that is operationally relevant. “The coming months” overlaps Europe's autumn and winter energy-risk period, when pressure on electricity networks, ports, transport and communications can produce outsized political effects. That does not prove that a particular incident is planned. It explains why European governments are focused on the resilience of civilian systems that support both daily life and aid to Ukraine.
The Incidents Driving the Alarm
Germany has attributed the attempted drone attack at Leipzig/Halle Airport to Russia, and European Union members are discussing sanctions. Leipzig/Halle is a major logistics hub, so even a failed or interrupted operation carries a wider message: infrastructure connecting civilian commerce, military mobility and support for Ukraine can be probed without the mass and visibility of a conventional attack.
Leipzig/Halle airport drone attack and Russia blame
Attribution remains the decisive step. A drone's components, flight path and target can produce evidence, but those details must be combined with intelligence about operators, communications and sponsorship. Sanctions discussions show the EU attempting to convert technical attribution into a political cost. If the evidence is persuasive across multiple capitals, a coordinated response becomes easier. If it is slow, contested or selectively disclosed, deniability remains an advantage for the suspected actor.
The second highlighted incident involved a Russian vessel firing flares toward a Danish military helicopter. Flares are not the same as missiles, but they can create danger at close range and communicate hostility while preserving ambiguity about intent. The episode is part of a broader summer pattern of drone sightings and airspace violations that has kept allied forces on alert. In one of the most visible responses, NATO jets were scrambled over Poland and Romania during Russian strikes on Ukraine.
The NATO Military Committee met in Copenhagen on September 18 and 19. Its chair, Adm. Giuseppe Cavo Dragone, condemned Russian airspace violations, drone incidents, hybrid activity and efforts to test allied resolve. The meeting connected events that can otherwise look isolated. NATO's strategic case is that the pattern — rather than any single incident — is the relevant unit of analysis.
Why This Matters
The most important development is not simply that a senior commander used tough words. It is that the officer responsible for NATO's European military operations paired a specific action — increased intelligence sharing — with unusually direct deterrence language. Reuters framed the message as: “Putin better not try attack on my watch.” That formulation turns a technical countermeasure into a public commitment.
NATO intelligence sharing increase in 2026
Faster sharing is intended to reduce the interval in which uncertainty can paralyze a collective response. A radar track in one country, a cyber indicator in another, and maritime reporting from a third may look inconclusive alone. Fused quickly, they can establish a pattern, narrow the range of plausible actors and give political leaders a common factual base. In a 32-member alliance, that shared picture is itself a form of deterrence because an adversary has less room to exploit contradictory national assessments.
Hybrid methods intentionally operate below Article 5, the treaty provision that treats an armed attack on one ally as an attack on all. But “below Article 5” does not mean outside NATO's concern. Allies can consult under Article 4 when any member believes its security is threatened, and they can take national or collective measures short of full-scale war. The gray zone is therefore not a legal vacuum; it is a contest over evidence, speed and political cohesion.
Background
Russia's 2014 seizure of Crimea remains the textbook reference for hybrid warfare. Armed personnel without insignia — the “little green men” — helped seize key sites while Moscow initially denied that they were Russian forces. The method delayed a unified response, blurred the line between internal unrest and external intervention, and demonstrated how facts created on the ground can outrun diplomatic decision-making.
From sabotage to GPS jamming
The 2026 tempo includes suspected railway sabotage, arson, cyberattacks, drones, GPS interference and the flare incident near the Danish helicopter. Not every disruption should automatically be attributed to the Russian state, and democratic governments need evidentiary discipline precisely because accusations can carry economic or military consequences. The strategic concern is that repeated low-level actions can reveal defenses, consume resources and cultivate public fatigue even when no one episode crosses the war threshold.
Grynkewich's own language has hardened. In December 2025, he called hybrid threats “a real issue” and discussed the need to be “proactive” and create “dilemmas” for Russia, while stressing that NATO is defensive. In June 2026, he said Russia was “not looking for conflict.” Fewer than 100 days later, his September warning emphasized that Putin should not test the alliance.
Those statements are not necessarily contradictory. A government may want to avoid general war while still using coercion, sabotage and deniable operations. The shift suggests that the commander's estimate of near-term behavior changed as new incidents accumulated, not that NATO concluded Russia had abandoned every restraint. It also reflects a basic deterrence paradox: saying conflict is unlikely can reassure the public, but saying it too comfortably may encourage an adversary to probe for weakness.
Who Wins, Who Loses, and What Critics Say
For the Baltic states and Poland, the warning offers reassurance. Countries bordering Russia have long argued that seemingly small events should be interpreted as parts of a campaign, not handled as disconnected law-enforcement matters. A senior allied commander publicly validating that view makes it harder for larger, more distant members to treat every episode as purely local.
Security services and defense firms gain urgency
Intelligence services gain a stronger mandate for deeper, faster fusion across borders. That can improve warning, but it also raises questions about standards, oversight and how much sensitive evidence governments can disclose when asking the public to accept an attribution. Defense companies serving counter-drone, air-defense, electronic-warfare and infrastructure-protection missions are likely to see stronger demand as governments translate concern into procurement.
The United States gains leverage in its long-running push for European burden sharing. “Critical but more limited capabilities” implies continued American support in areas such as strategic intelligence, command-and-control, nuclear deterrence and other high-end enablers, paired with reduced expectations that U.S. forces will fill every conventional gap. European allies gain time and reassurance, but they also inherit a sharper obligation to fund munitions, air defense, mobility and readiness.
Moscow loses some deniability when allied governments pool evidence and publicly connect events. Yet it can also argue domestically that Russia's pressure is commanding Western attention and forcing NATO to spend more. The deterrence contest is therefore partly about narrative: NATO wants to show that probing creates unity and cost; the Kremlin can try to present the same reaction as evidence that its methods are effective.
The central caveats
Critics can point to three risks. First, intelligence sharing without visible consequences may improve awareness but not deterrence. Second, a “low but growing risk” is hard to falsify: if no strike occurs, officials can say deterrence worked; if one occurs, they can say the warning was justified. Third, efforts to create “dilemmas” for Russia may invite reciprocal actions and increase the chance of miscalculation. The sound policy test is not whether a warning sounds forceful, but whether the response is lawful, evidence-based, proportionate and clearly communicated.
The Numbers Behind the Warning
NATO has 32 members, and consensus among them is both its strength and a potential target. A limited operation need not defeat NATO militarily to produce strategic effect; it would only need to delay agreement long enough to expose conflicting risk tolerances. That is why intelligence sharing and preplanned consultation matter: they reduce the number of questions that leaders must answer from scratch during a crisis.
Under 100 days from reassurance to warning
The rhetorical escalation occurred in fewer than 100 days, from Grynkewich's June statement that Russia was not seeking conflict to his September warning against testing the alliance. The interval is short enough to suggest that the change was driven by a developing operational picture rather than a slow doctrinal review. But public statements are also tools of deterrence, so the tonal change should not be read as a numerical probability forecast.
The phrase “critical but more limited” does more analytical work than it first appears. “Critical” points to the nuclear umbrella, strategic intelligence, long-range logistics, command systems and other high-end American capabilities that underpin NATO's deterrent. “More limited” points toward a smaller U.S. footprint in roles European forces can supply. The formulation ties the immediate Russia warning to Europe's decade-long rearmament debate: deterrence credibility depends not only on declarations, but on stockpiles, deployable units, resilient infrastructure and political willingness to use them.
What Happens Next: Three Scenarios
1. Managed pressure below the threshold
The most likely path is continued probing without a clear armed attack. Drones may appear near sensitive sites, GPS interference may disrupt transport, cyber operations may target public services, and suspicious sabotage attempts may continue. NATO would respond with surveillance, police investigations, sanctions, expulsions and selective public attribution. This scenario keeps pressure on allied defenses while allowing Moscow to deny sponsorship and avoid the predictable costs of open conflict.
2. A limited strike and an Article 4 test
A drone or missile could hit infrastructure in a NATO border state, whether deliberately or through a purported targeting error. The affected country would likely call consultations under Article 4 while investigators worked to establish origin and intent. Allies would then debate whether the event qualified as an armed attack under Article 5 or required a different collective response. Air defenses could be reinforced, forces moved forward and economic measures accelerated even without an Article 5 declaration.
The hardest case would be a strike using equipment designed to suggest Ukrainian responsibility. Technical evidence would have to be assessed alongside intelligence about launch location, control links and motive. Public credibility would depend on releasing enough evidence to support the judgment without compromising sources and methods. This is precisely the kind of scenario in which preparation and trusted intelligence channels can matter more than the size of the initial blast.
3. Miscalculation collapses the gray zone
The least likely but most dangerous outcome is an ambiguous action that kills allied personnel or brings down a civilian airliner. Casualties could compress decision time, harden public demands and make a calibrated response politically difficult. The gray zone would collapse because intent might matter less than consequence. Military leaders would have to prevent a second incident while political leaders decided how to impose costs without allowing the crisis to become uncontrolled escalation.
Developments in Ukraine will shape all three scenarios. President Volodymyr Zelenskyy's warning about artificial intelligence and the accelerating battlefield reflects the speed with which cheap systems can create strategic effects. Meanwhile, the dispute at the U.N. Security Council over Russia's rejection of a pause shows how far apart the parties remain on the war itself.
The Bottom Line
NATO did not declare a crisis on September 24. It adopted a watchful deterrence posture: increase intelligence sharing, reassure exposed allies, retain confidence in the alliance's military weight and tell Moscow that ambiguity will not guarantee inaction. The importance lies in the convergence of three elements — a direct warning from the supreme commander, a Danish intelligence assessment with a near-term timeline, and a documented series of incidents demanding attribution.
The coming months will show whether that combination changes Russian behavior. If the incidents diminish, NATO may argue that preparedness and clarity narrowed the space for coercion. If they continue, allies will face pressure to attach faster and more visible consequences to attribution. If one causes major casualties, the alliance may have to make the decision hybrid tactics are designed to postpone: where the gray zone ends and collective defense begins.
Sources
- Reuters: NATO steps up intelligence sharing over Russia threat, top commander says, September 24, 2026.
- Reuters: U.S. to provide critical but more limited capabilities to NATO, top commander says, September 24, 2026.
- Reuters, Copenhagen, Soren Jeppesen, “Denmark expects Russia to escalate hybrid warfare in coming months, intelligence service says,” September 24, 2026.
- Danish Defence Intelligence Service assessment, September 24, 2026, via Reuters.
- U.S. Army / DVIDS imagery: LANDEURO keynote speaker Gen. Alexus Grynkewich.
- U.S. Air Force biography: Gen. Alexus G. Grynkewich.
- Wikimedia Commons: NATO headquarters Agora, Brussels.