July 12, 2023, sidelines of the NATO Vilnius Summit — an informal talk between the then-Prime Ministers of Lithuania (Ingrida Šimonytė), Latvia (Krišjānis Kariņš), and Estonia (Kaja Kallas).
Over the past few weeks, the leaders of the Baltic States have renewed warnings about the threat from Russia, but their perceptions of that threat rarely match those of Western allies. This divergence is precisely what hybrid warfare is designed to exploit: an act of sabotage, or the credible threat thereof, typically falls short of the threshold required to trigger Article 5 of the NATO treaty. Yet, it still allows Moscow to test the alliance’s response and gauge its political resolve.
The past few weeks have also illustrated this pattern in Poland. In mid-July, Polish fighter jets intercepted Russian aircraft over the Baltic Sea on consecutive days — first an Il-20 reconnaissance plane probing Polish air-defence systems, then a pair of Su-30 fighters from Kaliningrad, in what Poland’s defence ministry described as a deliberate test of NATO’s readiness. Days earlier, the EU and UK jointly attributed a decade of cyberespionage and sabotage across at least nine countries to the 16th Centre of Russia’s FSB. This includes a December 2025 attack that came close to cutting heat and power to roughly half a million people in Poland, and long-running intrusions into French and German government networks. Moscow has denied the allegations.
In light of these developments, Lithuania has responded by reinforcing the sites it views as most exposed. Chief of Defence Gen. Raimundas Vaikšnoras confirmed the deployment of additional troops to protect the country’s LNG terminal, its electricity interconnection with Poland, and other strategic infrastructure; he also characterised Russia’s rhetoric as aimed at eroding public trust in state institutions, even when direct confrontation is being avoided. On 15 July, President Gitanas Nausėda and Latvian President Edgars Rinkēvičs jointly warned that intelligence services point to Russian planning for limited attacks on Baltic and Polish energy and transport infrastructure: [planning is] “taking place at the highest level, effectively in Moscow.” Polish Prime Minister Donald Tusk has issued similar warnings, believing that the coming months could prove critical, “particularly for the Baltic states.” Interestingly, he links it to the changing character of the war in Ukraine, which begs a separate question – why or how would Moscow deem it adequate and appropriate to punish Poland or the Baltic States for Ukraine’s military operations deep inside Russian territory?
None of this constitutes conventional warfare — which is the point. Hybrid warfare operates by design below the threshold that would compel a conventional military response, combining disinformation, cyberattacks, economic coercion, sabotage and covert pressure. Russia employed a similar toolkit against Ukraine for years before its full-scale invasion in 2022, and the approach is being studied and adapted by other authoritarian states, including Iran, China and North Korea. The toolkit continues to evolve faster than the doctrine built to counter it, as artificial intelligence and social media reshape both how populations are targeted and how military recruitment and communication are conducted.
This is where the Baltic states are most relevant to the rest of the alliance — as its most experienced members. Each has spent roughly two decades confronting a distinct dimension of the same broader campaign, and each has developed a correspondingly distinct response. As a long-term observer and an expert on the region, Edward Lucas framed it in his book, The New Cold War: Putin’s Russia and the Threat to the West, arguing that this has been the New Cold War, while others could make an equally strong case that for the Baltic States the Cold War never really ended; it only paused as the Russian Federation underwent a rekindling of power during the 1990s.

Lithuania: the weaponisation of history, and a teenager paid €10,000 and a BMW
Moscow’s claim on the Baltic states rests as much on historical narrative as on strategic calculation: that Lithuania’s independence is an anomaly arising from the collapse of former empires, rather than a legitimate restoration of sovereignty. Kremlin-aligned media and officials periodically deny or minimise the country’s history of self-government, framing its independence as a Western imposition. This narrative campaign is directed less at Lithuanians, who are not persuaded, than at international audiences that Russia hopes will absorb the framing through repetition.
Where this shades into sabotage, the tactics are often inexpensive. In May 2024, an arson attack destroyed an IKEA warehouse in Vilnius, causing approximately €500,000 in damage. Lithuanian prosecutors attributed the attack to Russian military intelligence, which had recruited a teenager at a secret meeting in Warsaw, promising him €10,000 and a BMW; he was later apprehended en route to a second target in Riga. GRU-linked groups have also targeted Lithuanian critical infrastructure through direct cyberattacks, while Belarus has separately permitted hundreds of smuggling balloons to cross into Lithuanian airspace each year, repeatedly forcing the closure of Vilnius and Kaunas international airports. Individually, none of these incidents resembles an act of war; cumulatively, they weigh heavily on local institutions and are designed to erode confidence in the basic functioning of the state. Domestically, Russia has also sought to cultivate separatist sentiment among Russian-speaking communities, at times using the Russian Orthodox Church as an institutional channel for pro-Kremlin messaging.
The scale of this campaign became clearer in April 2026, when Lithuanian and international authorities charged thirteen people across seven countries with plotting two murders in Vilnius on behalf of the GRU. The intended targets were a Lithuanian citizen who had raised funds for Ukraine and a Russian dissident from the Bashkir minority granted asylum in Lithuania; one suspect was apprehended armed outside his target’s home. This is a different order of provocation, even if still short of anything that would compel a conventional military response.
Lithuania’s response has combined increased spending with institutional coordination. Defence expenditure has reached a record 5.38 percent of GDP in 2026. The Ministry of National Defence runs media-literacy and public-awareness campaigns aimed at pre-empting disinformation, and Lithuania is a contributing nation to NATO’s Strategic Communications Centre of Excellence in Riga. Underpinning these measures is a ‘Total Defence‘ doctrine that treats civilian resilience — a public able to recognise a hybrid provocation without panicking — as an integral component of national defence rather than a supplementary one.
That doctrine faced its first real test on 20 May 2026, when a drone alert sent Vilnius residents underground for the first time in any EU or NATO capital since 2022 — triggered by debris linked to the wider war rather than a direct Russian strike. The test exposed gaps rather than readiness: shelters were locked or unmarked, and then-Prime Minister Inga Ruginienė later apologised publicly for the confusion. It’s a useful corrective against reading Total Defence as already resilient in practice.
Estonia: a cyberattack that never really ended, and a legal argument still unresolved
Estonia’s formative experience came in 2007, when a dispute with Moscow over the relocation of the Bronze Soldier, a Soviet-era war memorial, triggered a cyberattack that disabled government, banking and media websites for twenty-two days — one of the first instances of a state being substantially disrupted through cyberspace alone. Estonia’s response was to position itself, deliberately, as the ally other states turn to on this issue: it now hosts NATO’s Cooperative Cyber Defence Centre of Excellence in Tallinn, and the city lends its name to the Tallinn Manual, the most authoritative existing account of how international law applies to cyber warfare.

Estonia has also pushed the legal frontier further than most allies find comfortable. In May 2019, President Kersti Kaljulaid used the CyCon cyber-conflict conference to argue that states not directly targeted by a cyberattack should be entitled to apply countermeasures on behalf of an affected ally — a position without settled precedent in international law. France’s declaration on the application of international law to cyberspace, issued that September, did not adopt this position, and the question remains unresolved among Western states. The stakes extend beyond doctrine: without some form of collective countermeasures, a state hit by a serious cyber intrusion has few lawful options of its own, and international law — built for more clearly bounded conflicts — has yet to catch up with the ambiguity hybrid operations are designed to exploit. In practice, the gap is currently filled by collective EU and NATO tools such as attribution and sanctions, of exactly the kind used against FSB Centre 16 this month — a substitute for, rather than an instance of, settled law.
Estonia has also tested the alliance’s other lever short of Article 5. On 19 September 2025, three armed Russian MiG-31 jets entered Estonian airspace over the Gulf of Finland and remained for nearly twelve minutes before NATO aircraft intercepted them — the country’s fifth violation that year, and by its foreign minister’s account the most brazen yet. Prime Minister Kristen Michal requested consultations under NATO’s Article 4, the mechanism for convening allies over a threat to a member’s security without triggering collective defence; the North Atlantic Council met days later, the second such meeting in a fortnight, after Poland had invoked the same article over a mass drone incursion on 10 September. Article 4 carries no enforcement obligation of its own, but its use here confirms that the graduated response this piece describes is not theoretical. It is already standing procedure.
Estonia’s exposure runs through the seabed as well as the sky. On 31 December 2025, Finnish authorities boarded a cargo vessel found within Finland’s exclusive economic zone, suspected of dragging its anchor across cables located in Estonia’s exclusive economic zone, one of at least eleven such incidents since 2023 linked to Russia’s shadow fleet. The European Commission responded in February with a €347 million package under its new Cable Security Toolbox — a tacit admission that maritime law, like the cyber-law gap Estonia has spent two decades highlighting, was not built for plausibly deniable sabotage.
Latvia: the ally that tests whether allies actually show up
Latvia has been a NATO member since 2004, thirteen years after regaining independence from Soviet rule, and before that, Russian imperial rule. Article 5 guarantees a collective response to a conventional armed attack, but hybrid tactics are designed specifically to avoid triggering it — which makes Latvia’s position a test of alliance credibility rather than capability. Two broad explanations are typically offered for why alliances hold together under this kind of pressure: constructivist accounts, which emphasise shared democratic identity and norms, and neoliberal-institutionalist accounts, which emphasise long-term self-interest and established habits of cooperation. Sustained grey-zone pressure functions, in effect, as a live test of which explanation is doing the actual work.
Latvia’s own experience of this pressure has taken a different form from Lithuania’s arson-for-hire or Estonia’s cyberattack: the engineered movement of people. Since 2021, Belarusian President Aliaksandr Lukashenka has directed migrants from the Middle East and Africa toward the EU’s eastern border; in mid-July, Latvia recorded 111 attempted crossings in a single day, against two into Lithuania on the same day, despite Lithuania’s border with Belarus being four times longer. Prime Minister Andris Kulbergs — who took office in May 2026 after his predecessor resigned over a Ukrainian drone incident in Latvian airspace — has described the surge as a deliberate attempt to find “a weak link,” timed, in his account, to divert attention from Russian losses in Ukraine. It also coincides with campaigning ahead of Latvia’s October elections. Whether the timing is opportunistic or coordinated, the effect matches the pattern this piece describes throughout: pressure calibrated to stay below the threshold of an armed attack while still straining a state’s institutions — here, as pressure on Latvia’s border produces secondary migration into Lithuania, testing whether Lithuania will impose its own border controls, a step both governments have so far refused.
Against this pressure, Canada has made a concrete commitment consistent with the constructivist account. Operation REASSURANCE, the Canadian Armed Forces’ largest overseas deployment, is based in Latvia, and Canadian forces lead the NATO Multinational Brigade tasked with deterring aggression along this stretch of the eastern flank — part of a deepening partnership. This is a costly and visible way of signalling that allied guarantees extend beyond formal commitments — though, by the same design that makes hybrid tactics effective, it is a guarantee those tactics are engineered never quite to test.

On 30 June, this signalling deepened into institutional restructuring. NATO split the command responsible for the Baltic states and northern Poland, assigning Estonia’s and Latvia’s multinational divisions to a new corps headquarters under the German-Netherlands Corps in Münster, freeing Multi-National Corps Northeast in Szczecin to focus on Poland alone and allowing more troops to be committed to the Baltic sector specifically. Outgoing US General Chris Donahue framed the move at the change-of-command ceremony in Valga in terms that echo the constructivist account of alliance cohesion — deterrence built through presence rather than declarations. But German Defence Minister Boris Pistorius’s framing, delivered days after President Trump had again accused European allies of under-spending, cuts the other way: less an expression of shared identity than a demonstration to a skeptical Washington that Europe will shoulder more of the burden itself. The episode reads less as confirmation of either theoretical account than as a live negotiation between them.
None of this is unique to how Russia approaches the Baltic states; it more closely resembles a manual that other authoritarian states are actively annotating. Governments now confronting drone incursions over Copenhagen or Munich are facing a question that Lithuania, Estonia and Latvia answered years earlier, out of necessity. There is a reasonable case that, in this region, the Cold War never fully concluded — it simply changed its instruments, from tank counts and missile inventories to balloons, arson-for-hire, and unresolved arguments over what a state is permitted to do when it is attacked without quite being attacked.
The three national cases warrant a fuller account than a single article allows, and so this piece serves as an introduction to a three-part series examining Lithuania, Estonia and Latvia in turn. The series will draw on national threat assessments, including Lithuania’s 2026 National Threat Assessment, investigative reporting from regional outlets, the legal record built around the Tallinn Manual, and interviews with experts and witnesses across the region. The provocations are likely to continue, in whatever form proves cheapest and most deniable. What the Baltic states have already demonstrated, in real time and at real cost, is how a small, determined democracy distinguishes a genuine threat from a bluff — and builds the resilience to treat both consistently.
Tessera Research Collective. Published 20 July 2026. Updated 24 July 2026.



