MACIEJ MAKULSKI: You’ve spent quite a few time studying, researching, and writing about hybrid threats or grey-zone activities. I was wondering whether we could start by looking at this problem from the position of a process, an evolution in which Russia has gradually increased force on Europe and made it more and more costly and hard for us to adjust. Do you callback any peculiar minute or event erstwhile you realised or thought: okay, this is surprising, this is something qualitatively new, and we now truly request to think about how to adjust to this threat?
ELISABETH BRAW: I think a minute that truly stood out for me was the uncovering of the game involving parcel bombs that were delivered to a DHL facility in Leipzig [in 2024]. It led to Russia and active gig, or hired, agents. I know Poland was targeted as well. It was specified a devious scheme, and 1 that could have caused crucial failure of life if those parcel bombs had been successful, if they had exploded as intended. This was completely different from what we saw 5 or 10 years ago from Russia in the grey-zone domain.
I know many people say “hybrid threats” or “hybrid attacks”. I like “grey zone” or “sub-threshold”, due to the fact that “hybrid” involves kinetic and non-kinetic means. erstwhile we talk about these threats, they are non-kinetic. They are below the threshold of armed military violence, but they are serious. What this DHL game demonstrated was that you can origin crucial harm in the grey region by utilizing average people and tools that are easy found in the criminal world. That was fresh because, 10 or 15 years ago, erstwhile we thought about, studied or discussed Russian grey-zone aggression or sub-threshold aggression, it truly was cyber, disinformation, election interference…
The information war?
Exactly. And that’s serious enough, but it didn’t affect people being blown up. It didn’t affect companies losing crucial amounts of money in sabotage. Today, what we’re seeing is that, yes, Russia inactive does those things – disinformation, election interference, cyber – but it has besides expanded into another areas, where it blows things up, sets things on fire. We have seen an arson attack against the buying mall in Poland. There have been sabotages on railways. This is completely different and shows how comfortable Russia is in the grey zone. If you’re Russia, you don’t even care present whether the targeted country yet has evidence showing that you were behind it. So we have 2 crucial developments here: first, Russia’s expansion into truly violent acts that could origin failure of life and have already caused crucial financial losses for the companies targeted; and, second, the fact that Russia does not care if we find out that it was behind these activities.
You made the discrimination between hybrid and grey-zone activities. I think it helps as we’ve seen that, at the political level, we are now struggling with definitions, notions and concepts and on how to decently name the threat. With all the events you mentioned, we can besides add to the list the fresh news about attempts to cut undersea cables utilizing technology that is very hard for us to track. The key question, then, is about this transition, this minute erstwhile we halt talking about grey-zone activities or hybrid threats. What would be the next stage, and where is this border as you see it right now?
Well, first of all, it is truly crucial that you mentioned the sub-sea cables and pipelines, since this is precisely what I have been working on very intensely for the past couple of years in The Undersea War, my book which comes this month. It follows the incidents and investigations into suspicious cable activity we’ve seen in the Baltic Sea region and elsewhere in fresh years. It is extraordinary that, all of a sudden, just as Russia was becoming more active in the sub-threshold, hybrid, or grey-zone domain, we started seeing these incidents of suspicious cable cuts in the Baltic Sea and elsewhere, involving merchant vessels that sail across the Baltic Sea. All of a abrupt they started dragging their anchors in a very dangerous manner which caused cables to be damaged or cut. We hadn’t seen that before. Suddenly, we had respective major incidents in a row, and that’s what the book is about. So thank you for mentioning that.
And erstwhile is the border crossed and it is no longer a grey-zone activity?
If you want a word another than grey zone, hybrid or sub-threshold, we could besides say subversion. Russia wants – and possibly another countries do too, China is active as well, as are Belarus, Iran and North Korea – but here, in this part of the world, we are mostly afraid about Russia, due to the fact that it is the country that is most active in the grey region against us. It truly is simply a war of subversion. Russia wants to harm our countries without having to usage military force, due to the fact that if it were to usage military force, evidently NATO would respond. If it doesn’t usage military force, NATO isn’t in charge of responding, and it is besides totally unclear who should respond and how. That is our dilemma. erstwhile I wrote a book about grey-zone aggression, I called it The Defender’s Dilemma. Russia wants to origin financial losses to our companies and make it very hard for them to keep operating. If you keep sustaining losses, how are you expected proceed operating as a company? Russia besides wants to undermine citizens’ trust in our authorities. We gotta remember that in a liberal democracy, the social contract is that we place trust in our authorities. We voluntarily trust our authorities to act on our behalf. But what if we lose trust in our authorities? That is what Russia aims to accomplish through its disinformation and sabotage campaigns. If we, as citizens, proceed to experience sabotage against critical installations and operations in our countries, then we’ll say: well, hang on, why can’t our authorities halt this? Their occupation is to keep us safe; they are not keeping us safe. So this, too, is part of the war of subversion against our countries. The same applies, of course, to disinformation, election interference and all of the another forms of sabotage, as each specified act causes disruption, losses and inconvenience. It prevents us from doing what we request to do due to the fact that something has been disrupted, and yet it’s not an act of war.
The question truly is then, how can we deal with all of this? What should our consequence be? Let’s focus on the function of the expert community, for example. What can we do? What should our task be?
I think open-source intelligence can be 1 area where civil-society can assist the authorities. It’s not that we request to interfere with what the authorities are doing. They have their job. The civilian society has its function as well. But there is an chance here to aid analyse the people active in these activities. Who are they? What companies keep doing business with Russia and why is that to the detriment of our countries? We shouldn’t hang our fellow citizens out to dry, but people within our countries who act against our countries’ own interests are worth investigating. We can besides aid with what I call extremist transparency. Citizens in our countries request to understand, and be told as much as possible about, the war of subversion being waged against our countries. This is an area where NGOs and news media can contribute by uncovering information, establishing facts and sharing those facts with the wider public, so that people know precisely what is going on, or at least as much as possible. The more they realize how widespread and intense it is, the more they will realise that they have a part to play in trying to keep it distant from our countries and limit the harm.
This interview took place during the 2026 Riga Conference, held September 10-11, 2026.
Elisabeth Braw is a elder fellow at the Atlantic Council, focusing on geopolitics and the globalized economy as well as grey-zone and hybrid threats. her latest book The Undersea War is set to release in October 2026.
Maciej Makulski is the task lead at the In Between Analytical Group and a contributing editor with fresh east Europe.
New east Europe is reader-supported. If you value independent coverage of Central and east Europe, delight consider supporting our work.
Click here to donate.













