Українською читайте тут.
Russia relies on pressure and sabotage, while China remains “behind the scenes,” focusing on digital espionage and controlling its own citizens abroad.
On August 19, 2026, Osavul, a company that researches artificial intelligence (AI) based on OSINT, held a webinar dedicated to hybrid threats in Scandinavia. Speakers engaged in research on international security issues were invited to the event. A recording of the webinar can be viewed at this link.
Anders Nemo Stjernström — Head of Strategic Communications at the Swedish Psychological Defence Agency. For the past five years, he has been involved in coordinating Sweden’s support for Ukraine.
Anders Nemo Stjernström (MPF, Sweden)
Etienne Soula — Research Fellow at the German Marshall Fund, a think tank based in Washington with offices across Europe. He is also a member of the GMF Europe Program.
Etienne Soula (Marshall Fund, Germany)
The Baltic–Scandinavian region is one of the most vulnerable in terms of hybrid threats originating from Russia, China, and Iran. The main areas of vulnerability for the Scandinavian and Baltic states are the underdeveloped system of undersea cables, the activities of Russia’s shadow fleet, as well as frequent cyberattacks on digital infrastructure. The webinar speakers share their views on hybrid threats that periodically emerge for Northern European states, assess the role of Russia, China, and Iran in fueling crises in the region, and also explain whether NATO can properly assess and adequately respond to external challenges.
The devil is in the details: how are Russia, China, and Iran undermining the security of the Baltic–Scandinavian states?
The cyber threat to the Baltic–Scandinavian region is one of the most sensitive issues that periodically appears on the agenda of countries such as Sweden, Finland, Denmark, as well as Estonia. Russia is the most active player when it comes to carrying out cyberattacks. As Nemo Stjernström notes, Sweden has become one of the European Union states experiencing the greatest number of attacks by Russian intelligence services. According to SEPO (the Swedish Security Service), the Russians use a combined approach when conducting hybrid operations, ranging from DDoS attacks (denial-of-service attacks) to recruiting representatives of third countries working at embassies. In particular, SEPO, mentioned above, issued a statement several weeks ago stating that it had disrupted an operation involving Russian intelligence whose aim was to deepen divisions surrounding key controversial issues in Swedish politics and, as a result, discredit Sweden in the eyes of its closest allies.
The role of China and Iran in these processes is significantly smaller than that of Russia; however, neglecting the subversive activities of the aforementioned actors in the Baltic–Scandinavian region creates dangerous conditions for this problem to develop into a chronic crisis. Although China and Iran are considered within the webinar as political actors primarily pursuing economic or, at times, ideological interests, both speakers agree that Moscow, Beijing, and Tehran constitute a single geopolitical axis aimed at weakening the so-called “collective West.”
The only obstacle to implementing such intentions is the lack of coordination in terms of tactics, methods, and geography of activity. As speaker Etienne Soula notes, Russia, due to its geographical proximity and, especially, the growing importance of regional security, is increasing hybrid pressure through sabotage of undersea communication cables, regular violations of the airspace of the Baltic states by drones, as well as bribery of local political elites, while China acts more cautiously, directing its resources toward digital espionage and the persecution of disloyal members of Chinese communities.
The network of undersea internet cables in the Baltic Sea. Source
At present, the response of the North Atlantic Alliance to such challenges consists of patrolling the territorial waters of the Baltic–Scandinavian region and protecting critical infrastructure facilities from sabotage. However, these measures do not reduce the region’s vulnerability to subversive activities by Moscow, Beijing, or Tehran. Moreover, the likelihood of escalation of the threats described above remains high.
The Scandinavian approach to countering hybrid threats
A logical question arises: how can immunity to such challenges be strengthened in the Baltic–Scandinavian states?
Both speakers agree that the priority in strengthening both domestic and European-wide security is to improve the institutional capacity of Scandinavian states to communicate with society, eliminating any barriers or distrust.
Etienne Soula, for example, in addition to obvious examples of government initiatives (such as the use of the same font in official information sources), draws particular attention to the importance of exporting the Scandinavian experience to other European Union states. Given the importance of the Scandinavian states to the European economy, the speaker emphasizes that their understanding of their own national security landscape will be useful to those states that may potentially become victims of a new hybrid war in the future. According to data from the “E-Governance Academy,” Estonia is a pioneer in creating platforms to protect government registries and data from external interference (X-Road and KSI), while Finland, for its part, has long implemented a “Comprehensive Security” model that involves coordinating the efforts of the state, business, and citizens to strengthen the system for protecting digital data.
The position of the North Atlantic Alliance and the unpredictability of United States policy remain ambiguous. Both Stjernström and Soula raise the question of the relevance of NATO’s “Article 5” — how effective would it prove to be if hybrid warfare ultimately escalated into a full-scale Russian invasion of one of the NATO member states?
The speakers’ answer was not specific. For example, Nemo, referring to “Article 5,” mentioned the high level of strategic communications among the alliance’s allies and the issue of credibility among its key adversaries. Etienne adds to his colleague’s point by noting such an important detail as the mutually exclusive approaches of the two opposing sides. In particular, according to the expert, blurring red lines in the context of responding to Moscow’s actions encourages the latter to intensify hybrid operations on the territory of European states in order to drive a wedge into transatlantic unity. An additional problem in this regard is the policy of the current US presidential administration, which recently considered the possibility of withdrawing a contingent of US troops from the states of Central and Eastern Europe, and also spent some time developing a Greenland-oriented foreign policy vector with a view to potentially annexing part of Denmark’s territory.
The number of NATO troops in the Baltic–Scandinavian region. Source
Thus, the discussion suggests that strengthening immunity to hybrid threats involves introducing new approaches to countering these threats, as well as revising the now outdated doctrinal provisions of the security alliance currently in operation, which is still considered one of the most effective defense alliances on the European continent.
Collage: Grok