- French President Emmanuel Macron says Russia is intensifying hybrid attacks—cyber, sabotage, disinformation—against European nations.
- France will harden critical infrastructure and sensitive defense-industrial sites against drone and cyber threats.
- Interior Minister calls the threat "real and documented," though no major sabotage or drone incursions have been confirmed on French soil.
Rising Hybrid Threat
French President Emmanuel Macron on September 18 warned that Russia is "multiplying hostile, and criminal acts" against European nations, describing an escalating hybrid-threat campaign that includes cyberattacks, sabotage, disinformation, espionage, and possible drone activity. The remarks came after a meeting with French political leaders at the Élysée Palace, where Macron said the threat had intensified "in recent weeks" and vowed that Moscow's actions "will not go unanswered."
France's immediate response is a government protection plan for critical infrastructure, covering energy, transport, communications, and the most sensitive defense-industry and technology facilities. The plan focuses on resilience against cyberattacks and drones, according to officials familiar with the matter.
Interior Minister Laurent Nuñez subsequently called the threat "real and documented," noting that while France has not identified major sabotage or drone-overflight incidents on its territory, cyberattacks have been detected, and worrying incidents have occurred elsewhere in Europe.
Background of Allegations
The warning builds on a July 2026 French accusation that a Russia-linked campaign targeted government bodies, businesses, and service operators in roughly a dozen European countries for espionage and sabotage. France said it would summon Russia's ambassador and sanction nine individuals and four entities. Russia has rejected the allegations as unfounded, portraying them as anti-Russian hysteria.
European governments have increasingly pointed to a mix of coercive activities below the threshold of declared war—so-called hybrid warfare—including cyber intrusions, sabotage plots, drone sightings near sensitive areas, disinformation, and espionage. The common feature is ambiguity, allowing the alleged sponsor to deny responsibility while imposing costs and insecurity.
"This is about deterrence," a French defense official said, speaking on condition of anonymity. "We must raise the cost and difficulty of covert attacks while continuing to support Ukraine."
The issue has strengthened arguments for closer EU–NATO coordination on cyber defense, infrastructure protection, attribution, sanctions, and intelligence sharing. European Commission President Ursula von der Leyen has called for a stronger EU mechanism to respond to hybrid attacks attributed to Russia.
Economic and Business Implications
The heightened threat environment is likely to drive higher spending across several sectors. Operators in energy, rail, ports, telecommunications, water, health care, and digital networks may face increased outlays for cybersecurity, physical security, monitoring, redundancy, and emergency planning. Defense manufacturers and technology suppliers supporting Ukraine or European rearmament could see both increased protection and greater scrutiny, along with higher compliance and security costs.
Companies more broadly may face heightened risks of phishing, ransomware, supply-chain compromises, and espionage, particularly those providing essential services or defense-related goods. Insurers may adjust premiums for cyber and political risk coverage. Public finances will likely shift additional resources toward counterintelligence, cyber capacity, airspace surveillance, policing, and civil-resilience planning.
"Institutional investors are focused on regulatory stability," said a portfolio manager at a European asset manager, who asked not to be named. "But geopolitical risk is now a factor in infrastructure and defense allocations."
The societal debate is expected to center on proportionality: governments must improve security and expose foreign interference without creating unjustified fear or restricting civil liberties. Moscow's denials make public attribution politically consequential, requiring credible evidence and allied support.
Historical Context
The situation is rooted in Russia's full-scale invasion of Ukraine in 2022 and the subsequent expansion of European support for Kyiv. France has cited a longer record of alleged Russian cyber activity, including a 2025 attribution of attacks on French interests to the GRU-linked APT28 group, which targeted about a dozen French entities since 2021. The group has been associated with the 2015 TV5Monde disruption and efforts to destabilize France's 2017 election.
In the near term, France is expected to finalize and operationalize infrastructure-protection measures, increase intelligence and police coordination, and conduct more security reviews of defense supply chains. Diplomatic escalation—summons, sanctions, public attributions, and expulsions—remains likely if new incidents are attributed to Russia.
Other European states, including Germany, Poland, and Denmark, are also tightening security amid reports of suspected drone incursions, sabotage, arson, and surveillance of defense facilities. The longer-term outcome is likely a more security-focused Europe, with greater defense spending, stronger civilian preparedness, tougher cyber rules, and deeper EU–NATO cooperation.
The more serious risk is miscalculation. Repeated covert or ambiguous incidents can blur the lines between criminal activity, proxy action, espionage, and state-directed sabotage, increasing the chance of escalation even where neither side seeks direct military confrontation. French officials emphasize that they are responding to a documented cyber threat and a deteriorating security environment, not declaring that France is under conventional attack.
This article was updated to clarify that no major sabotage or drone attack inside France has been publicly confirmed.