From Disruption to Destruction: Russia's Escalating War on European Infrastructure- 211
June 23, 2026
For years, Russia's cyber proxies made noise without making damage — waves of denial-of-service attacks that knocked websites offline for hours before normal service resumed, leaving little trace beyond headlines. That era is over. A pattern of incidents confirmed across Sweden, Poland, Norway, Denmark, and Ukraine over the past eighteen months reveals a deliberate tactical shift: Russia-linked groups are no longer probing European infrastructure to demonstrate capability. They are attempting to destroy it.
In April 2026, Sweden's Minister for Civil Defense Carl-Oskar Bohlin confirmed publicly what his country's security service had established months earlier: a pro-Russian hacker group with links to Russian intelligence had attempted to breach the operational technology systems of a thermal power plant in western Sweden during the spring of 2025. The attack failed — the facility's built-in protections held — but Bohlin's statement was notable less for what it revealed about the Swedish incident than for what it acknowledged about the broader trajectory. "These groups that once carried out denial-of-service attacks are now attempting destructive cyberattacks against organizations in Europe," he said. The targeted system was not a website or a database. It was an OT environment — the industrial software that governs the physical behavior of the plant itself. Had the intrusion succeeded, its consequences would have been measured not in hours of downtime but in physical disruption to civilian heating and power supply.
The Swedish incident did not occur in isolation. Bohlin noted that similar reconnaissance operations had been recorded in Norway and Denmark. Poland had experienced a far more severe attack. In December 2025, Sandworm — the Russian military intelligence unit responsible for some of the most destructive cyberattacks in history, including the 2015 and 2016 BlackEnergy attacks on Ukraine's power grid — deployed a wiper variant designated DynoWiper against more than thirty sites across Poland's energy infrastructure, targeting wind farms, solar installations, and combined heat and power plants. A total blackout was avoided, but the malware permanently destroyed critical control hardware and degraded operator communications across multiple facilities. The attack was not an attempt to steal data or establish persistence for future espionage. Its purpose was destruction.
In Norway, the escalation took a different form. Hackers successfully breached a dam's industrial control systems and briefly hijacked the operational technology to open floodgates, discharging large volumes of water before plant operators could regain manual control. The incident illustrated precisely the concern that Bohlin articulated in Stockholm: when OT systems are remotely controlled by a hostile actor, the consequences are no longer confined to the digital domain. They become physical events with physical consequences — flooding, power loss, loss of heat — affecting civilian populations who have no visibility into the cyber dimension of what is happening to them.

The precedent for this approach was established in Ukraine, where Russia has used its eastern neighbor as both a testing ground and an operational theater for its most destructive cyber capabilities. In early 2024, a Russian cyber intrusion severed heating infrastructure in Lviv, cutting heat and hot water to hundreds of apartment buildings for several days during sub-zero winter temperatures. The attack was not militarily decisive, but that was not its purpose. Its purpose was to make civilians cold, to make them afraid, and to demonstrate to European audiences that the same could happen to them. Ukraine has also reported persistent cyber operations against its energy sector in which intrusions appear designed less to cause immediate disruption than to gather targeting intelligence for subsequent missile strikes — a convergence of cyber and kinetic operations that represents perhaps the most operationally significant integration of the two domains observed in any conflict to date.
The campaign extends beyond malware and network intrusion into the electromagnetic spectrum. Throughout 2025 and into 2026, Russia dramatically expanded its GPS spoofing infrastructure operating out of Kaliningrad, increasing the number of transmission antennas from three to thirty-six. The expanded system projects continuous signal distortion across a radius of approximately 450 kilometers, covering Poland, Lithuania, Latvia, Estonia, Finland, and Sweden — the entire eastern flank of NATO's Baltic exposure. The effect is not to disable GPS entirely but to introduce calculated inaccuracy into navigation systems, misleading commercial aviation, maritime traffic, and military positioning systems simultaneously. Unlike a cyberattack on a specific facility, GPS spoofing is an ambient, persistent form of infrastructure warfare — one that is difficult to attribute with legal certainty, impossible to patch, and whose effects accumulate gradually across thousands of dependent systems.
What emerges from this pattern is a doctrine of graduated infrastructure warfare operating deliberately below the threshold that would compel a formal NATO response. Each individual incident — a failed power plant intrusion in Sweden, a wiper attack on Polish wind farms, a dam hijack in Norway, GPS distortion across the Baltic — can be characterized as isolated, ambiguous, or deniable. Taken together across eighteen months, they describe a systematic campaign to map, probe, and selectively degrade the physical infrastructure of countries that support Ukraine, with the dual purpose of imposing real costs on civilian populations and signaling that escalation remains available should Western support for Kyiv continue.
European governments are responding, but the adaptation is uneven. Sweden, Norway, and Poland have each moved to strengthen OT security mandates, implement harder segmentation between IT and industrial control networks, and accelerate hardware-level protections for critical facilities. The challenge is structural: most of Europe's critical infrastructure was built in an era when operational technology and information technology were separate domains with no internet connectivity between them. That separation no longer exists in most modern facilities, and the attack surface it has created took decades to accumulate. Closing it will take years — years during which Russia's campaign continues to probe and, where possible, to strike.
The Swedish minister's words in Stockholm deserve to be read not as a disclosure about one failed attack on one unnamed power plant, but as a statement of a new reality: the boundary between digital disruption and physical warfare has dissolved, and European civilian infrastructure is now a front in a conflict that most Europeans still understand primarily in terms of events happening in Ukraine.