Baltic states get ready for Russian false-flag attack on Nato

Baltic states get ready for Russian false-flag attack on Nato

In recent months, European intelligence services have increasingly warned that, alongside its war in Ukraine, Russia is intensifying hybrid operations targeting Nato countries. Investigators in several states are dealing with suspected sabotage, arson attacks, damage to critical infrastructure, and the use of drones. According to Western officials, this is part of a broader Russian campaign aimed at intimidating European countries, undermining their security and weakening support for Ukraine. The latest warning came from Lithuania. Its military intelligence claims that Russia could use captured Ukrainian drones in attacks on critical infrastructure in the Baltic region in order to create the impression that Kyiv was behind them. “We are talking about a false-flag operation involving a fake Ukrainian drone… One of the aims is for Nato to hesitate and reduce its support for Ukraine. I can assure you that will not happen,” Lithuanian defence minister Robertas Kaunas said. Lithuania’s warning came as security services in the region were dealing with several drone-related incidents. In recent months, Ukrainian long-range drones have repeatedly entered the airspace of Lithuania, Latvia and Estonia after being diverted by Russian electronic jamming, according to Kyiv. Warning after drone found near Ukrainian Antonov aircraft Just one day before the warning was made public, German authorities launched an investigation into an incident at Leipzig/Halle Airport, where they found a drone containing explosives near a Ukrainian Antonov cargo aircraft carrying military ammunition. The investigation is ongoing, and German authorities have not said who was behind the incident. According to the ARD newspaper’s security journalist, Michael Götschenberg, identifying the person who operated the drone remains the most important question for the investigation. “As with every drone incident, the most important task here is to establish who its pilot was. Identifying the pilot is usually key to assigning responsibility, particularly if investigators are also examining a possible link to Russian hybrid warfare,” he told Denník N. Gitanas Nausėda (Source: European Council) In mid-July, Lithuanian president Gitanas Nausėda also said that the country’s intelligence services had received information about planned attacks on critical infrastructure. “We have received such signals from our intelligence services. They do not specify a particular location or time, because the adversary has not yet completed its planning, and we know only about the plan or the target itself,” he said in an interview with the BNS agency. He added that these could involve “various means intended to physically damage critical infrastructure ... anything that disrupts the operation of these facilities”. Lithuania subsequently tightened protection of energy and transport hubs as a preventive measure. And at a joint press conference in Vilnius in July, Latvian president Edgars Rinkēvičs warned allies of the same. “The information we receive from Lithuania, Latvia and other Nato Member States points to various attempts at sabotage and efforts to weaken the security of our countries,” he said. He added that if Russia’s fortunes on the battlefield in Ukraine deteriorated, it could seek to indirectly test Nato’s collective-defence mechanisms under Article 5 through hybrid operations. “We must be ready to respond to new threats,” he said. Keir Giles, a British expert on Russian hybrid operations at the London-based think tank Chatham House, believes that the way Lithuania made its warning public suggests the existence of specific intelligence. “The way this information is being released gradually suggests that intelligence services have specific knowledge of a new form of Russian attack, rather than merely an assessment of a hypothetical scenario,” he told Denník N. According to Giles, it is also no coincidence that Lithuania is speaking publicly about the possible operation before it can take place. “If this is a potential false-flag operation, it is important to get ahead of the disinformation and warn about it in advance. The media and decision-makers are then prepared for the spread of false information and are less likely to be misled by it,” he said. Lithuanian authorities have not yet disclosed the specific intelligence on which they base their warning. However, Giles warns that in similar operations, the main objective may not be the attack itself, but also the confusion that follows. “Russia has repeatedly succeeded in creating uncertainty over responsibility for individual incidents, including by attempting to attribute its own actions to Ukraine. Such confusion can delay decision-making, potentially giving Russia a significant advantage in a time-sensitive situation. It can also serve to undermine Ukraine’s credibility and weaken support for Kyiv, which is a long-term Russian objective,” he said. What could such an attack look like? According to security analysts at the International Institute for Strategic Studies, the information effect is as important as the attack itself in modern hybrid operations. If the scenario warned of by both Lithuania and Giles were to materialise, the operation could unfold in several stages. In the first stage, the target could be a site whose damage would immediately attract public attention — such as an electricity substation, railway junction, port, airport or logistics centre supplying the military. According to Lithuania, the attack could use a captured or modified drone that would appear to be a Ukrainian unmanned aerial vehicle. Immediately after the incident, an investigation would begin, alongside an information battle over the first interpretation of events. While security forces cordoned off the attack site, secured the drone wreckage and gathered the first evidence, the media would broadcast images from the scene and politicians would demand an explanation. According to Lithuanian officials, this is precisely the period that would offer the greatest scope for information operations. Even before investigators were able to confirm the origin of the technology used, claims attributing responsibility to Ukraine or questioning its control over its own weapons systems could emerge on social media or in pro-Russian information channels. The forensic investigation itself — from analysing components and the method of navigation to identifying the operator — could take days or even weeks. Lithuania considers this gap between the spread of the first claims and the verification of evidence to be the greatest risk. If an impression that Ukraine was behind the attack could be created in the meantime, the operation’s aim might not be limited to material damage, but could also include undermining trust among allies and calling into question continued support for Kyiv. This is why Lithuanian officials are speaking so openly about the threat. Lithuania's Nausėda warned that intelligence indicated that “this planning is taking place at the highest level, effectively in Moscow”. Latvia's president Rinkēvičs warned that “the coming months, perhaps even the whole of the following year, will be decisive for the security of the Baltics”. According to him, Russia is already “testing our preparedness and vigilance”, and said allies must be ready to respond to new hybrid threats. From explosive parcels to more sophisticated operations European security services also warn that the nature of Russian hybrid operations has changed in recent years. While cyberattacks and disinformation campaigns initially dominated, cases of physical sabotage have become increasingly frequent. One of the most serious investigations concerned parcels containing incendiary devices that caught fire at logistics centres in Leipzig, Birmingham and Poland in 2024. European security services suspected that this may have been a trial operation ahead of planned attacks on cargo aircraft bound for the United States and Canada. Polish authorities and other partner countries suspect Russia’s military intelligence service, the GRU, of organising the operation, an allegation Moscow denies. Investigators have also dealt with a series of incidents involving damage to undersea electricity and telecommunications cables in the Baltic Sea. Although several cases remain unresolved, the repeated incidents have prompted Nato to strengthen monitoring of the region and protection of critical infrastructure. Growing concerns about hybrid operations have already led to concrete steps by the Alliance. Following a series of incidents in the Baltic Sea, including damage to undersea infrastructure, Nato launched Operation Baltic Sentry earlier this year to strengthen the protection of critical infrastructure and improve surveillance of the region. The operation includes more intensive patrols by ships and aircraft, the use of unmanned systems and closer intelligence-sharing among allies. During a visit to Lithuania in February, Nato secretary general Mark Rutte said that the Alliance was responding to the changing nature of threats. He noted that, alongside strengthening ground forces, it was developing the Baltic Sentry initiative to protect undersea infrastructure and increasing preparedness for hybrid threats on the eastern flank. “Nato makes Lithuania safer, and Lithuania makes Nato stronger,” he said. British analyst Giles also warned that if Moscow continues testing the limits of what individual countries are willing to tolerate without serious consequences, it will have no reason not to escalate this strategy. And he said the critical moment was knowing when Russia had crossed the line. “If we set aside the information noise and isolated acts of sabotage, many of them appear to be preparation or reconnaissance for large-scale disruption of logistics and communications networks that could support a larger Russian operation. The key task for intelligence services will be to recognise the moment when preparations turn into an actual attack,” Giles said.

Original Source

Read the full article at Euobserver →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.