All news
AnalysisTeplice, Czech Republic

By Decent Cybersecurity, publisher of SynapseCommand®

What Are Hybrid Threats? Cyber, Disinformation, Sabotage and Coercion Explained

Hybrid threats are coordinated harmful activities carried out with malign intent to undermine a target such as a state or institution through a variety, and often a combination, of means. They can include cyber operations, information manipulation, sabotage, economic coercion, covert political activity and military pressure. Hybrid campaigns often exploit vulnerabilities, ambiguity and difficulties of detection and attribution, frequently while operating below the threshold of open armed conflict.

Conceptual illustration of hybrid threats including military pressure, cyber operations, disinformation, economic coercion and critical infrastructure
Conceptual illustration of hybrid-threat vectors across military, cyber, information, economic and infrastructure domains. Not an official NATO image and not a depiction of a specific operation or incident.

Hybrid threats are difficult to understand because they do not fit neatly into one security category.

A cyberattack may initially look like a technical incident. Damage to critical infrastructure may resemble an accident. An information operation may appear unrelated to economic pressure. Political interference may be concealed. Military activity may be presented as signalling.

The strategic picture changes when apparently separate activities reinforce a common objective.

The Council of the European Union describes hybrid threats as coordinated harmful activities planned and carried out with malign intent, using a variety and often a combination of means.

NATO describes hybrid threats as combining military and non-military, covert and overt means, including disinformation, cyber attacks, economic pressure, irregular armed groups and regular forces.

The key analytical question is not simply “What kind of incident occurred?” It is “Are apparently different activities connected by actor, intent, coordination or strategic effect?”

Key question

Hybrid threats at a glance

Short answers to the most common questions about hybrid threats.
QuestionAnswer
What are hybrid threats?Coordinated harmful activities using a variety, and often a combination, of instruments to undermine a target
Who can use hybrid methods?State and non-state actors
Must hybrid threats involve military force?No
Can military force form part of hybrid activity?Yes
Common instrumentsCyber operations, information manipulation, sabotage, economic coercion, political interference, proxies and military pressure
Are hybrid threats always below the threshold of war?No, although many campaigns deliberately exploit that space
Is every cyberattack a hybrid campaign?No. Context, intent, attribution and links to other activity matter
Are hybrid methods new?No. Their contemporary speed, scale and intensity have increased
Why are hybrid threats difficult to counter?Ambiguity, attribution problems, cross-domain activity and exploitation of vulnerabilities
Can hybrid activity trigger NATO Article 5?Potentially, but not automatically; circumstances and effects are assessed case by case

The shortest accurate explanation: hybrid threats use coordinated political, informational, cyber, economic, covert and potentially military instruments to create strategic effects while exploiting vulnerabilities and ambiguity.

What makes a threat “hybrid”?

There is no single universally binding definition covering every institution, actor and security environment. What follows is a useful analytical model rather than an official NATO definition.

Coordination

Activities may support a common strategic objective even when they are carried out by different actors, in different domains and at different times. An isolated cyberattack, sabotage incident, infrastructure failure or disinformation operation does not automatically establish the existence of a wider hybrid campaign.

Potential linking evidence can involve:

  • actors
  • infrastructure
  • financing
  • timing
  • narratives
  • technical indicators
  • targeting
  • strategic objectives

Correlation is not proof of coordination.

Key point

Combination

Hybrid campaigns may employ different instruments simultaneously or sequentially:

  • cyber operations
  • information manipulation
  • sabotage
  • economic pressure
  • political interference
  • proxy activity
  • military coercion

The EU describes a variety and often a combination of means. That wording matters: multiple instruments are common, but they are not a mandatory feature of every case.

Exploitation of vulnerabilities

Hybrid activity tends to work with weaknesses that already exist rather than creating them from nothing. Potential weaknesses involve:

  • institutions
  • cyber systems
  • infrastructure
  • supply chains
  • dependencies
  • democratic processes
  • information environments
  • crisis management
  • societal cohesion

Ambiguity

Ambiguity is often the point. Decision-makers are left holding questions such as:

  • Who is responsible?
  • Was the event intentional?
  • Are the incidents connected?
  • How confident is attribution?
  • Has a threshold been crossed?
  • What response is proportionate?

Are hybrid threats new?

No. Propaganda, espionage, sabotage, deception, economic pressure, coercion and the use of proxies are long-established instruments of statecraft and conflict.

What NATO emphasises in its current formulation is that hybrid threats have increased in speed, scale and intensity, driven by technological change and global interconnectedness. That is a statement about the environment, not a claim that hybrid warfare is a wholly new phenomenon.

Hybrid threats vs hybrid warfare

The two terms are related and frequently used loosely. Neither NATO nor the EU applies one universally binding taxonomy, so the comparison below is analytical.

Analytical comparison of hybrid threats and hybrid warfare.
Hybrid threatsHybrid warfare
ScopeBroad spectrum of malign hybrid activityGenerally used in a more conflict-oriented context
Military dimensionMilitary force is not requiredDefinitions vary; NATO describes hybrid warfare as combining military and non-military means
Can occur below armed-conflict threshold?FrequentlyYes
Can accompany conventional warfare?YesYes
Typical instrumentsCyber, information manipulation, sabotage, economic pressure, political interference, proxies and military pressureSimilar military and non-military instruments used in a more explicitly conflict-oriented setting
Universally fixed definition?NoNo

Hybrid CoE treats hybrid threats as a broad spectrum ranging from influence and interference through to hybrid warfare. “Hybrid warfare” is generally used in a more conflict-oriented context, but there is no universally fixed boundary between the terms.

Applying “hybrid warfare” to every cyberattack, information operation or economic disagreement reduces the analytical usefulness of the term. If everything is warfare, the word stops distinguishing anything.

Hybrid threats vs grey-zone activity

“Grey zone” is an analytical term rather than a universally codified NATO category.

Hybrid generally refers to methods or combinations of instruments. Grey zone generally refers to an ambiguous competitive environment below overt armed conflict. The concepts overlap, but they are not exact synonyms.

Commentary published in NATO Review has examined grey-zone terminology and the risk of treating “hybrid warfare” as a catch-all label. NATO Review is analysis and commentary; it is not formal NATO policy.

Why are hybrid campaigns difficult to detect?

Detection is hard less because the individual activities are invisible and more because responsibility for seeing them is fragmented across organisations that each hold one fragment:

  • cybersecurity team: a network incident
  • police: suspected sabotage
  • intelligence: foreign influence
  • election authority: information manipulation
  • infrastructure operator: unexplained disruption
  • defence: coercive military behaviour

Assessment therefore moves through stages rather than arriving in one step:

  • INDIVIDUAL INCIDENTS
  • ↓ POSSIBLE RELATIONSHIPS
  • ↓ CORROBORATED INDICATORS
  • ↓ ASSESSED CAMPAIGN

Similarity is not enough. Timing is not enough. Political usefulness to an adversary is not enough. Evidence matters.

Cyber operations

NATO and the EU both explicitly identify malicious cyber activity as a potential hybrid instrument. Possible objectives include:

  • espionage
  • disruption
  • theft or compromise of information
  • compromise of systems
  • interference with communications
  • support to broader strategic pressure

A cyberattack is not automatically evidence of a broader hybrid campaign. Relevant assessment factors include the actor, intent, target, timing, infrastructure, attribution, relationship with other events and strategic context.

Disinformation, information manipulation and FIMI

Disinformation and Foreign Information Manipulation and Interference, or FIMI, are related but not synonymous. Disinformation describes false or misleading content spread deliberately. FIMI is narrower and more structural.

The European External Action Service uses FIMI as a framework for intentional and coordinated foreign manipulation of, and interference in, the information environment. Its 4th Annual Report on FIMI Threats, published on 12 March 2026, and accompanying EEAS material place increased attention on the networks, infrastructure and enabling architecture behind FIMI operations.

Potential effects can include confusing audiences, undermining trust, polarisation, obscuring responsibility, influencing perceptions and weakening confidence in institutions.

False or misleading content alone does not prove a coordinated state-backed hybrid campaign. The behaviour, coordination and infrastructure behind the content carry the analytical weight.

Sabotage and critical infrastructure

In its conclusions of 16 March 2026, the Council of the European Union specifically highlighted sabotage, including against critical infrastructure, malicious cyber activity, FIMI, election interference and the instrumentalisation of migration.

Critical sectors can include:

  • energy
  • communications
  • transportation
  • logistics
  • food and water
  • medicine
  • government services
  • information flows
  • critical supply chains
  • space-based services supporting essential functions

Not every disruption is sabotage. Infrastructure fails for mundane reasons, and early reporting is often wrong. The wider principle still holds: hybrid activity may seek not only direct physical damage but wider political, economic, military or psychological effect.

Economic coercion

NATO refers to economic pressure among hybrid means, while the EU uses the term economic coercion. Possible vulnerabilities include strategic dependencies, raw materials, supply chains, energy, market access, financing and critical technologies.

Not every tariff, sanction, trade dispute or commercial disagreement is a hybrid threat. Intent and strategic context matter, and economic statecraft is a normal part of international relations.

Political and election interference

NATO lists political interference among hybrid means, and the Council's March 2026 conclusions record specific concern about election interference.

Possible mechanisms can include covert influence, information manipulation, cyber compromise, intermediaries and concealed support networks.

Legitimate political activity, public diplomacy and ordinary foreign policy engagement are not automatically hybrid activity. Concealment, coordination and malign intent are what distinguish interference from influence.

Proxies and irregular actors

Hybrid activity is often carried out through proxy or intermediary organisations rather than directly. Relationships may involve varying degrees of direction, financing, infrastructure, intelligence, technical support, logistical support and political protection.

The operational actor and ultimate sponsor may not be identical, and not all proxy relationships involve direct command and control. Some are opportunistic, tolerated or encouraged rather than tasked.

Military pressure and coercive signalling

Hybrid activity is not synonymous with non-military activity. NATO includes both regular and irregular forces among possible hybrid means.

Potential coercive military behaviour can include coercive deployments, force movements, demonstrations of capability, coercive posture and threatening or coercive rhetoric. Military exercises may form part of coercive signalling depending on their context and purpose, but an exercise is not inherently hybrid activity.

Hybrid does not mean non-kinetic.

Key point

How different tools can form one hybrid campaign

The following sequence is a hypothetical illustration. It does not describe a specific state, campaign or real incident.

  • unusual cyber activity against energy infrastructure
  • ↓ service disruption
  • ↓ coordinated false narratives online
  • ↓ amplification through proxy networks
  • ↓ economic pressure
  • ↓ coercive military signalling

None of these facts individually proves a coordinated hybrid campaign. Investigators would need evidence connecting infrastructure, financing, actors, timing, narratives, targeting and objectives.

A hybrid campaign cannot be identified simply by counting forms of pressure. The relationships between the activities matter.

Key point

Why attribution is difficult

Attribution is rarely binary. Assessments carry confidence levels, and those levels can change as evidence accumulates or is reinterpreted.

Potential attribution obstacles include:

  • proxies
  • intermediaries
  • compromised infrastructure
  • false identities
  • anonymous accounts
  • covert financing
  • misleading indicators
  • information laundering
  • mixed state and non-state involvement

Attribution matters because it shapes what can follow: policing, sanctions, diplomacy, public communication, military planning, alliance consultations and deterrence. EU policy treats attribution as a sovereign political decision, informed by all-source intelligence and considered case by case.

Observing an incident is not the same as attributing the campaign behind it.

Key point

How hybrid threats exploit the threshold of armed conflict

The EU's framing is precise: many hybrid campaigns seek to remain below a threshold that could constitute or be perceived as an act of war, because staying below it complicates the response.

That is a tendency, not a rule. Hybrid methods can also be used before conventional conflict, during conventional conflict, alongside overt military operations and after major hostilities decline.

Hybrid threats and critical infrastructure resilience

NATO's guidance for enhancing public-private cooperation for resilience, published on 16 July 2026, underlines that much critical infrastructure is privately owned and deeply interconnected, including supply chains, space-based dependencies and essential services.

Resilience is usually described as the ability to:

  • WITHSTAND
  • ADAPT
  • CONTINUE
  • RECOVER

Potential resilience measures include redundancy, continuity planning, backup communications, alternate suppliers, cyber defence, exercising, resilient supply chains, rapid repair, cross-sector coordination and secure information sharing.

Resilience does not guarantee prevention. What it can do is reduce the strategic benefit an adversary gains from disruption.

What role does artificial intelligence play?

AI is an amplifier, not a defining characteristic of hybrid threats.

NATO's approach to counter information threats, agreed in 2024, notes that artificial intelligence and deepfakes can amplify hostile information activity. On the defensive side, the same policy points to monitoring, analysis and assessment of information threats.

Claims beyond that should be treated carefully. Automated systems do not autonomously establish attribution or determine hostile intent. More automation does not automatically produce more certainty.

How NATO responds to hybrid threats

NATO organises its counter-hybrid work around three high-level lines:

  • PREPARE
  • DETER
  • DEFEND

Publicly documented milestones include:

  • 2015: NATO strategy for its role in countering hybrid warfare
  • 2018: Counter Hybrid Support Teams agreed
  • 2022: additional preventive and response options endorsed
  • 2025: Special Coordinator for Hybrid Threats role created

Supporting activity includes intelligence sharing, hybrid analysis within the Joint Intelligence and Security Division, resilience work, political consultation, military preparedness and support to individual Allies on request. There is no single counter-hybrid instrument; the response is distributed by design.

Could a hybrid attack trigger NATO Article 5?

A hybrid attack does not automatically trigger NATO Article 5.

NATO states that significant malicious cyber activities and other hybrid attacks could, in certain circumstances, be considered an armed attack. That assessment is made case by case by Allies, on the basis of the nature and effects of the activity.

Sufficiently serious hybrid activity could, depending on its nature and effects, lead Allies to determine that an armed attack has occurred. The judgement is political and collective, not mechanical. Further detail is set out in NATO's page on collective defence and Article 5.

How the European Union responds to hybrid threats

The Council of the European Union adopted conclusions on advancing the EU's capacity to counter hybrid threats on 16 March 2026. The instruments referenced across EU policy include the EU Hybrid Toolbox, the Cyber Diplomacy Toolbox, legislation, restrictive measures, resilience and critical-infrastructure work, FIMI capabilities, international cooperation and cooperation with the private sector, academia and civil society.

The Hybrid Toolbox groups measures that are:

  • preventive
  • cooperative
  • stability-building
  • restrictive
  • support

The underlying principle is straightforward: a cross-domain threat requires a cross-domain response.

NATO and EU responses: what is the difference?

NATO tools can include collective defence, military planning, deterrence, intelligence cooperation, resilience and political consultation.

EU tools can include legislation, regulation, sanctions, economic policy, cyber diplomacy, FIMI frameworks, infrastructure policy and financial instruments.

The two sets of instruments can be complementary, but the mandates are not identical and neither substitutes for the other.

How organisations can build resilience against hybrid threats

Understand critical dependencies

Map what the organisation genuinely depends on: suppliers, connectivity, energy, data, key personnel and the systems that carry authority. Dependencies that nobody has written down are the ones that fail first.

Preserve provenance

Record where information came from, when, through which route and with what handling caveats. Provenance is what allows an assessment to be revisited honestly when the picture changes.

Exercise cross-domain incidents

Exercise scenarios that cross the internal boundaries: a cyber incident with a physical consequence, an information operation during a supply disruption. Single-domain exercises rehearse single-domain responses.

Build redundancy

Alternate suppliers, backup communications and continuity plans reduce the effect of disruption even when its cause remains unclear.

Share information appropriately

Timely, lawful sharing with authorities, sector partners and relevant agencies is often what turns isolated incidents into a recognisable pattern.

Prepare to decide under uncertainty

Decisions rarely wait for certainty. Separating the following four categories, explicitly and in writing, keeps judgement honest:

  • KNOWN FACTS
  • ASSESSMENTS
  • ASSUMPTIONS
  • REMAINING UNCERTAINTY

Where SynapseCommand fits

SynapseCommand is not a hybrid-threat attribution system. It does not determine state responsibility, identify hostile governments, autonomously detect hybrid warfare, replace intelligence analysis or law enforcement, or perform national-security attribution, and it is not a NATO system.

SynapseCommand's relevance is at the decision-intelligence layer: working with authorised multi-source operational information, preserving provenance, reconstructing decision context and supporting structured course-of-action development and comparison.

That positioning is relevant to hybrid threats for one narrow reason. Where information arrives from many authorised sources and the situation is contested, the quality of a decision depends on knowing what is recorded, where it came from and how the picture changed over time. Related material is available on SynapseCommand interoperability and in the explainer on the Common Operational Picture.

Hybrid threats: the bottom line

Hybrid threats are not defined by one weapon, one domain or one type of actor. Their significance lies in the use of different instruments to exploit vulnerabilities and achieve strategic effects while often complicating detection, attribution and response. These instruments can include cyber operations, information manipulation, sabotage, economic coercion, political interference, proxy activity and military pressure.

Hybrid methods are not new. What has changed is partly the environment in which they operate. Digitally connected societies, interconnected infrastructure and global information systems can increase the speed, reach and scale of malicious activity.

The most useful analytical question is not simply “Was there a cyberattack?” It is “What happened, what is known, what remains uncertain, who may be responsible, are apparently separate activities connected, what strategic effect is being sought, and what response is justified?”

Understanding hybrid threats requires connecting evidence without jumping to conclusions. Countering them requires both the capacity to recognise coordinated hostile activity and the resilience to continue functioning when prevention fails.

Frequently asked questions

What are hybrid threats?

Hybrid threats are coordinated harmful activities carried out with malign intent to undermine a target such as a state or institution through a variety, and often a combination, of means, including cyber operations, information manipulation, sabotage, economic coercion, covert political activity and military pressure.

What are examples of hybrid threats?

Commonly cited instruments include malicious cyber activity, foreign information manipulation and interference, sabotage including against critical infrastructure, economic coercion, election interference, instrumentalisation of migration, the use of proxies and coercive military pressure.

What is hybrid warfare?

NATO describes hybrid warfare as combining military and non-military as well as covert and overt means, including disinformation, cyber attacks, economic pressure, the deployment of irregular armed groups and the use of regular forces.

What is the difference between hybrid threats and hybrid warfare?

There is no universally fixed boundary. “Hybrid threats” is generally used for a broad spectrum of malign hybrid activity, while “hybrid warfare” is generally used in a more conflict-oriented context.

What is grey-zone activity?

“Grey zone” is an analytical term rather than a universally codified NATO category. It generally describes an ambiguous competitive environment below overt armed conflict, whereas “hybrid” generally refers to the methods or combination of instruments used.

Is every cyberattack a hybrid threat?

No. A cyberattack is not automatically evidence of a broader hybrid campaign. Actor, intent, target, timing, infrastructure, attribution, strategic context and any relationship with other activity all matter.

Are hybrid threats always below the threshold of war?

No. Many campaigns deliberately seek to remain below a threshold that could be perceived as an act of war, but hybrid methods can also be used before, during and alongside overt armed conflict.

Are hybrid threats new?

No. Propaganda, espionage, sabotage, deception, economic pressure and the use of proxies are long established. NATO notes that the speed, scale and intensity of hybrid threats have increased with technological change and global interconnectedness.

What is FIMI?

FIMI stands for Foreign Information Manipulation and Interference. The European External Action Service uses it as a framework for intentional and coordinated foreign manipulation of, and interference in, the information environment. It is more specific than the general term disinformation.

Can hybrid threats target critical infrastructure?

Yes. In its March 2026 conclusions the Council of the European Union specifically highlighted sabotage, including against critical infrastructure, alongside malicious cyber activity, FIMI, election interference and instrumentalisation of migration.

Why is attribution difficult?

Proxies, intermediaries, compromised infrastructure, false identities, covert financing, misleading indicators and mixed state and non-state involvement can all obscure responsibility. Observing an incident is not the same as attributing the campaign behind it.

Can AI be used in hybrid campaigns?

NATO notes that artificial intelligence and deepfakes can amplify hostile information activity. AI can also support monitoring, analysis and assessment of information threats. AI is an amplifier rather than a defining characteristic of hybrid threats.

Can a hybrid attack trigger NATO Article 5?

Not automatically. NATO states that significant malicious cyber activities and other hybrid attacks could, in certain circumstances, be considered an armed attack. Allies assess the nature and effects of the activity case by case.

How does NATO counter hybrid threats?

NATO works across prepare, deter and defend, including intelligence sharing and hybrid analysis, resilience, political consultation, military preparedness, Counter Hybrid Support Teams and support to individual Allies.

How does the EU counter hybrid threats?

The EU uses instruments including the EU Hybrid Toolbox and the Cyber Diplomacy Toolbox, legislation, restrictive measures, resilience and critical-infrastructure work, FIMI capabilities and cooperation with partners, the private sector, academia and civil society.

Does SynapseCommand detect or attribute hybrid attacks?

No. SynapseCommand is not a hybrid-threat attribution system. It is positioned as a decision-intelligence layer that works with authorised multi-source operational information, preserves provenance, reconstructs decision context and supports structured course-of-action development and comparison.

Primary sources

  • NATOUpdated 29 January 2026

    Countering hybrid threats

    NATO's official overview of hybrid threats, the military and non-military means involved, the prepare, deter and defend framework, Counter Hybrid Support Teams and the Special Coordinator for Hybrid Threats.

    Read NATO on countering hybrid threats
  • Council of the European Union16 March 2026

    Council adopts conclusions on advancing the EU's capacity to counter hybrid threats

    Current EU conclusions covering the definition of hybrid threats, sabotage against critical infrastructure, malicious cyber activity, FIMI, election interference, instrumentalisation of migration and the EU Hybrid Toolbox.

    Read the March 2026 Council conclusions
  • Council of the European Union21 June 2022

    Framework for a coordinated EU response to hybrid campaigns

    EU framework covering attribution as a sovereign political decision, the role of military force within hybrid activity and campaigns that seek to remain below the threshold of open armed conflict.

    Read the EU coordinated response framework
  • Council of the European Union

    Hybrid threats policy

    EU policy background on hybrid threats and the instruments available through the EU Hybrid Toolbox.

    Read the EU hybrid threats policy page
  • European Centre of Excellence for Countering Hybrid Threats

    Hybrid threats as a phenomenon

    Hybrid CoE explanation of coordination, synchronisation, systemic vulnerabilities, detection and attribution, and of a spectrum extending towards hybrid warfare.

    Read the Hybrid CoE explanation
  • European External Action Service12 March 2026

    4th EEAS Report on Foreign Information Manipulation and Interference Threats

    EEAS reporting on FIMI, with attention to the networks, infrastructure and enabling architecture behind information manipulation operations.

    Read the 4th EEAS FIMI report
  • NATO16 July 2026

    Guidance for enhancing public-private cooperation for resilience

    NATO guidance on resilience through public-private cooperation, covering interconnected infrastructure, supply chains, essential services and space-based dependencies.

    Read the NATO resilience guidance
  • NATO18 October 2024

    NATO's approach to counter information threats

    NATO policy on information threats, including the amplifying role of artificial intelligence and deepfakes and the use of monitoring, analysis and assessment.

    Read NATO's approach to information threats
  • NATO

    Collective defence and Article 5

    NATO's official explanation of Article 5, including the case-by-case assessment of whether significant cyber or other hybrid attacks amount to an armed attack.

    Read NATO on collective defence and Article 5
  • NATO Review

    NATO Review

    NATO's analysis and commentary platform, used here only for debate about grey-zone terminology and the risk of applying “hybrid warfare” as an overly broad label. NATO Review is commentary, not formal NATO policy.

    Read NATO Review

SynapseCommand® is developed by Decent Cybersecurity, a European defence deeptech specialising in sovereign AI, post-quantum cryptography and quantum-resistant blockchain. This article explains publicly documented NATO and European Union positions using official primary sources; it does not imply NATO, the European Union or any government endorses SynapseCommand, and SynapseCommand is not a hybrid-threat attribution system. Download the capability brief.