Below the Threshold: What the Baltic States Can Teach NATO About Countering Russia

Justinas Stankus for Tessera Research Collective. Views and potential mistakes belong to the author alone.

 

Key judgments

  • Russia is running a decades-long hybrid campaign against the Baltic states, calibrated to stay below the threshold that would trigger a unified NATO response.
  • Each Baltic state has faced — and adapted to — a distinct dimension of this campaign: Estonia (cyber and legal frontiers), Latvia (weaponized migration), and Lithuania (disinformation operations and sabotage).
  • With similar tactics now reaching Western European capitals, the Baltic states’ two decades of accumulated expertise in identifying and countering Russian hybrid threats is an undervalued asset of the alliance.

A NATO member can be subjected to sustained hostile activity for decades without a single incident crossing the threshold of war. That’s not a hypothetical. Estonia, Latvia, and Lithuania have lived under such conditions since the early 2000s, when Vladimir Putin consolidated power, and Russia’s security services extended their grip over the state. 

Baltic political leaders and defense experts, drawing on decades of experience countering hybrid threats, view recent incidents not as isolated episodes but as components of a sustained campaign to test NATO below the threshold of Article 5. Western responses have often treated such incidents individually, which can obscure their cumulative logic. That distinction is gradually narrowing as hybrid activity spreads across Europe, but the Baltic experience in recognizing patterns, adapting institutions, and responding to persistent pressure offers lessons that extend well beyond the alliance’s northeastern flank.

Much of the current debate about how to counter Russia treats Ukraine as the classroom. NATO now runs a dedicated centre in Poland to gather and apply lessons from Ukraine’s fighting, and analysts keep pointing to Ukraine’s wartime transformation as something that should inform European defense modernization in both technology and doctrine. But Ukraine’s war is a “hot” war, fought with tanks, missiles and drones. The pressure Russia exerts on the Baltic states takes a different form, resembling the old playbooks of the “cold” war. What is less appreciated is that the Baltic states offer a different kind of classroom: two decades of experience with Russia’s below-threshold pressure.

In early July, the EU identified the 16th Center of Russia’s FSB as responsible for years of malicious cyber activity affecting at least nine European countries, including intrusions into French and German government networks. The UK and EU also jointly attributed the December 2025 attack on Poland’s energy grid to the same unit; the failed attack could have left roughly half a million people without electricity.

Within days, in mid-July, Poland’s fighter jets intercepted Russian aircraft over the Baltic Sea: first an Il-20 reconnaissance aircraft operating over international waters near Poland’s maritime border, followed the next day by two Su-30 fighters from Kaliningrad conducting what the Polish defense minister described as aggressive surveillance of Polish air-defense exercises.

In light of these developments, Lithuania has responded by reinforcing the sites it views as most exposed. Chief of Defense Gen. Raimundas Vaikšnoras confirmed the deployment of additional troops to protect the country’s LNG terminal, its electricity interconnection with Poland, and other strategic infrastructure. He also characterized Russia’s rhetoric as aimed at eroding public trust in state institutions, even when direct confrontation is being avoided.

On 15 July, President Gitanas Nausėda and Latvian President Edgars Rinkēvičs jointly warned that intelligence services point to Russian planning for limited attacks on Baltic and Polish energy and transport infrastructure: “[planning is] taking place at the highest level, effectively in Moscow.” Polish Prime Minister Donald Tusk has issued similar warnings, believing that the coming months could prove critical, “particularly for the Baltic states.”

In early August 2026, Lithuanian officials further specified the risk as a possible false-flag operation using captured Ukrainian drones, prompting heightened physical security measures around critical energy and transport infrastructure across Poland and the Baltic states. On 14 August, NATO fighters shot down a drone over eastern Latvia that Latvian authorities attributed to Russian electronic warfare.

These incidents reflect the logic of hybrid warfare: pressure calibrated to remain below the threshold that would compel a conventional military response, combining disinformation, cyberattacks, economic coercion, sabotage and covert pressure. Russia employed a similar toolkit against Ukraine for years before its full-scale invasion in 2022.

This follows the logic Thomas Schelling described: pressure calibrated to remain just below the threshold that would trigger retaliation, allowing resolve to be tested without the cost of open conflict. With each near-miss around the Article 5 threshold, Russia tests how far it can push without provoking a conventional response, while NATO demonstrates that its defence guarantee remains credible without firing a shot.

This is where the Baltic states are most relevant to the rest of the alliance — as its most experienced members in countering hybrid warfare. RAND’s 2017 baseline study remains a useful framing of this spectrum — nonviolent subversion, covert violent action, and conventional aggression backed by political subversion. Its central insight remains relevant: pure hybrid tactics face real obstacles across the Baltics, leaving Russia’s main leverage in local conventional superiority paired with political cover.

Hybrid CoE’s 2024 working paper traces the intensification of this pattern from mid-2023 onward across Estonia, Latvia, Lithuania, Finland and Poland — disinformation, cyber, instrumentalised migration and sabotage. These are the same forms of pressure examined in the three national cases below. Each Baltic state has been confronting a distinct dimension of the same broader campaign, and each has developed a correspondingly distinct response.

As Edward Lucas argued in The New Cold War (2008), the Baltic states were among the first to recognize that a new confrontation between Russia and the West had begun under Vladimir Putin. Former Head of State of Lithuania Vytautas Landsbergis has similarly argued that, for the Baltic states, the Cold War never truly ended.

All three Baltic states host NATO multinational battlegroups led by framework nations — Germany in Lithuania, the UK in Estonia, and Canada in Latvia — under the alliance’s forward-presence architecture. These deployments are designed primarily to deter an overt Russian military attack on NATO territory — the Article 5 scenario. No Baltic state has faced such a conventional armed incursion since NATO established its forward presence in the region.

But conventional deterrence was never the tool for the pressure campaign this piece describes. Sabotage, cyberattacks and weaponised migration have not been deterred by troop presence; Russia’s campaign has instead remained largely below the threshold that would bring those brigades into action, suggesting that conventional deterrence has shaped the form of the pressure more than its existence. The tanks have held the line NATO built them for. The line hybrid warfare is testing runs somewhere else entirely.

Lithuania: The Weaponisation of History, and a €10,000 Arson Recruitment

Lithuania’s experience illustrates a central asymmetry of hybrid pressure: relatively cheap and deniable operations can impose substantial costs, making societal resilience a necessary — if imperfect — component of national defence.

Russian information operations against Lithuania have long relied on historical revisionism, portraying the country’s restored independence as a product of geopolitical upheaval rather than the restoration of legitimate sovereignty. Kremlin-aligned media and officials periodically deny or minimise the country’s history of self-government, framing its independence as a Western imposition.

Where information pressure shades into sabotage, the tactics can be remarkably inexpensive. In May 2024, an arson attack caused approximately €500,000 in damage to an IKEA store in Vilnius. Lithuanian prosecutors attributed the operation to individuals acting in the interests of Russian military and security structures. The perpetrator, a teenager at the time, had agreed at a secret meeting in Warsaw to attack shopping centres in Lithuania and Latvia in return for €10,000 and a BMW; he was later apprehended while travelling toward Riga. The recruitment method matters as much as the target: for €10,000 and a car, Russian-linked handlers could recruit a teenager for an attack causing hundreds of thousands of euros in damage.

Other forms of low-cost disruption have accompanied these operations. GRU-linked groups have targeted Lithuanian critical infrastructure through cyberattacks. Separately, repeated waves of contraband balloons originating in Belarus have crossed into Lithuanian airspace, repeatedly disrupting operations at Vilnius and Kaunas airports. The cumulative cost is not necessarily physical destruction alone: repeated disruption can expose weaknesses in the state’s capacity to protect infrastructure, maintain essential services and reassure the public.

At the more severe end of the spectrum, Lithuanian authorities charged thirteen people from several countries in April 2026 in connection with two attempted murders in Vilnius linked to Russia’s GRU. The intended targets were a Lithuanian citizen who had raised funds for Ukraine and a Russian dissident from the Bashkir minority granted asylum in Lithuania. This is a different order of provocation from arson-for-hire or airport disruption, but still below anything that would compel a conventional military response.

Lithuania’s response has therefore extended beyond military deterrence. Alongside record defence spending — 5.38 percent of GDP in 2026 — the state has invested in media literacy, public awareness, civil preparedness and institutional coordination.

These measures sit within Lithuania’s broader ‘Total Defence’ approach, which treats continuity of essential services, information resilience and civilian preparedness as components of national defence alongside military capability. Yet resilience on paper does not guarantee resilience in practice. On 20 May 2026, a drone incursion prompted authorities to order Vilnius residents to seek shelter and temporarily disrupted air and rail traffic. The alert exposed practical shortcomings in civilian preparedness, including confusion over access to shelters. The episode demonstrated why resilience requires continual testing and adaptation.

Estonia: Cyber Vulnerabilities and the Unresolved Legal Challenge

Estonia’s experience shows how repeated exposure to below-threshold threats has driven institutional and legal adaptation — while leaving important questions of collective response unresolved.

Estonia’s formative experience came in 2007, when a dispute with Moscow over the relocation of the Bronze Soldier, a Soviet-era war memorial, was followed by a twenty-two-day wave of cyberattacks that disrupted government, banking and media websites. Estonia subsequently invested heavily in cyber-defence institutions and expertise. Tallinn now hosts NATO’s Cooperative Cyber Defence Centre of Excellence, while the Tallinn Manual has become the leading non-binding expert articulation of how existing international law applies to cyber operations.

Estonia has also pushed the legal frontier further than many allies. In May 2019, President Kersti Kaljulaid used the CyCon cyber-conflict conference to argue that states not directly injured by a cyberattack should be permitted to take countermeasures in support of the affected state. The position remains contested. France’s declaration on the application of international law to cyberspace, issued later that year, expressly rejected collective countermeasures by non-injured states.

The disagreement matters because international law is considerably clearer about countermeasures taken by an injured state than about whether other states may take them on its behalf. That uncertainty becomes particularly consequential when hostile activity is serious enough to demand a response but remains below the threshold for the use of force. In practice, Western states have relied on other tools — coordinated attribution, diplomatic measures and sanctions — without resolving the underlying legal question.

Estonia has also demonstrated how existing alliance mechanisms can be used below the Article 5 threshold. On 19 September 2025, three armed Russian MiG-31 aircraft entered Estonian airspace over the Gulf of Finland and remained there for nearly twelve minutes before NATO aircraft intercepted them. Prime Minister Kristen Michal requested consultations under NATO’s Article 4, which allows allies to consult when a member believes its security is threatened without triggering collective defence. The North Atlantic Council met days later — its second Article 4 meeting in a fortnight, after Poland had invoked the same provision following a mass drone incursion on 10 September. Article 4 carries no enforcement obligation of its own, but provides a mechanism for collective consultation below Article 5.

Estonia’s exposure also extends beneath the Baltic Sea. On 31 December 2025, Finnish authorities boarded a cargo vessel suspected of damaging a telecommunications cable connecting Finland and Estonia by dragging its anchor. The incident formed part of a wider series of cable-damage cases in the Baltic since 2023, several involving vessels associated with or suspected of belonging to Russia’s shadow fleet. The European Commission responded to the wider vulnerability with a €347 million package under its Cable Security Toolbox.

ICDS and FOI had already examined this maritime dimension in a September 2025 policy paper, proposing stronger naval presence, greater use of drones and possible roles for NATO’s Standing Maritime Groups.

Latvia: Testing Alliance Credibility Under Hybrid Pressure

Latvia’s experience shows how below-threshold pressure can strain state institutions and produce political consequences, while also illustrating how responsibility for responding is divided between national authorities, the EU and NATO.

The clearest sustained case is the instrumentalisation of migration. Since 2021, Belarus has facilitated and organised migrant flows toward the EU borders of Latvia, Lithuania and Poland, conduct that European and NATO institutions have described as hybrid action. In mid-July 2026, Latvia recorded 111 attempted crossings in a single day, compared with only two in Lithuania, despite Lithuania sharing a border with Belarus almost four times longer. Prime Minister Andris Kulbergs described the surge as a deliberate attempt to find “a weak link” and argued that pressure was being redirected toward Latvia.

The vulnerability created by a sudden concentration of border pressure is not uniquely Baltic. In a different political context, a mass crossing from Morocco into Spain’s North African enclave of Ceuta on 30 July 2026 similarly forced Madrid to deploy additional police and troops to reinforce local authorities.

Security incidents have also produced unusually direct political consequences in Latvia. In May 2026, two stray Ukrainian drones entered Latvia from Russian airspace and exploded at an oil-storage facility. Ukrainian officials attributed their diversion to Russian electronic warfare. The incident exposed shortcomings in Latvia’s anti-drone preparedness and triggered a political crisis. Prime Minister Evika Siliņa dismissed Defence Minister Andris Sprūds over the response; his Progressives party subsequently withdrew its support from the governing coalition, depriving Siliņa of her parliamentary majority. She resigned days later. A relatively limited security incident had produced consequences at the highest level of government.

Latvia’s immediate response to renewed border pressure has remained principally national. On 11 August 2026, Kulbergs launched Operation Vilkatis (“Werewolf”), increasing personnel and deploying drones and helicopters while strengthening information-sharing among border guards, police, the military and security services. Latvian troops have also used tear gas and warning shots to stop forced crossings.

The response extends beyond Latvia. The European Commission, alongside Lithuania and Poland, has treated Belarusian-directed migration as “instrumentalisation” and a hybrid threat since 2021, while EU border, migration and law-enforcement instruments support the affected member states. NATO has likewise treated the instrumentalisation of migration along allied borders as a hybrid security concern.

The contrast with air defence is instructive. On 14 August 2026, an Italian fighter deployed under NATO’s Baltic Air Policing mission shot down a Ukrainian drone that had entered Latvian airspace from Belarus. Latvian authorities subsequently said they suspected Russian electronic warfare may have diverted it off course. Latvia has no fighter aircraft of its own, making air policing an established allied function.

Instrumentalised migration is recognised as a shared security challenge but managed principally through Latvian and EU border, migration and law-enforcement instruments; military airspace protection, by contrast, activates an established NATO capability.

A Shared Playbook

Together, the Baltic states offer NATO one of its richest bodies of practical experience in responding to sustained pressure below the threshold of armed conflict. As similar tactics increasingly affect other allies, that accumulated experience is becoming an alliance-wide strategic asset. The challenge is to translate those lessons into NATO practice. Analysts suggest three practical steps.

  1. The most immediately actionable comes from PISM’s May 2026 white paper, which calls for closer coordination among military and civilian agencies, a dedicated information-exchange system, clearer attribution, and common rules for monitoring and responding to recurring Russian operations. These measures require coordination more than new institutional authority.
  2. The harder step is the shift from resilience and denial toward more systematic cost-imposition. ICDS’s 2022 paper, A Better Balance, argues that NATO should identify and signal in advance the kinds of costs it is prepared to impose for different levels of hybrid activity, rather than responding to each incident ad hoc. Its proposed framework combines resilience and denial with graduated punitive measures while seeking to keep escalation below the threshold of conventional war.
  3. The most structurally demanding is the proposal in CEPA’s War Without End for a standing menu of consequences, designed so that recurring shadow-war activity produces predictable costs. CEPA also calls for a clearer division of labour, with NATO leading on detection, defence and military response, and the EU on financial pressure, borders, law enforcement and export controls.

The three Baltic cases point to complementary forms of experience rather than a single model. Lithuania shows the importance — and practical difficulty — of building societal resilience against persistent, low-cost disruption. Estonia shows how repeated exposure can drive institutional and legal adaptation ahead of broader allied consensus. Latvia adds the operational experience of managing sustained below-threshold pressure at the border: repeated surges, rapid interagency mobilisation, and the political consequences that can follow when preparedness proves inadequate. These are lessons accumulated through repeated exposure rather than abstract doctrine.

The geography of these tactics is widening. Sabotage, cyber operations, airspace violations and disruptive drone activity are increasingly confronting states well beyond NATO’s northeastern flank, a pattern also documented in recent assessments of Russian hybrid warfare across Europe. NATO and its member states cannot ensure that Moscow will stop applying this kind of pressure. They can, however, become better at tallying individual incidents as parts of a cumulative campaign while drawing more systematically on two decades of Baltic experience instead of relearning the same operational lessons state by state.

 

This is the first article in a three-part series. It provides a general overview; subsequent articles will examine Lithuania, Estonia and Latvia in greater depth. Each case warrants a fuller account.

Published 20 July 2026, corrected and updated 30 July 2026 and 19 August 2026.