In a recent webinar, RANE analysts unpacked how Russia and Iran use hybrid warfare to probe defenses and impose costs while staying below the threshold of open conflict. Here's what businesses need to know.
Russia blends disinformation, cyber operations, sabotage, and assassination — tools honed over decades.What's changed is the audacity: arson and sabotage incidents in Europe have roughly tripled since 2022, and ordinary companies, not just government targets, are increasingly caught up in it.
● Disposable agents: With diplomats expelled after 2022, Russia now recruits criminal intermediaries via Telegram, often people who don't know who they're really working for.
● Shadow fleet: An estimated 1,300 tankers with murky ownership double as drone launch platforms and communication relays.
● Cyber:Russian-linked actors increasingly target routers, VPNs, and border cameras, and research employees to reach new companies.
● Information manipulation: With elections across Europe this year and US midterms ahead, Russia continues exploiting social divisions, now amplified by AI.
Iran combines cyberattacks, sabotage, propaganda, and proxies into a long-term strategy — attribution can take Western governments months to confirm. Since the Middle East war escalated, Iranian operations in Europe have increasingly targeted Jewish and Israeli communities and Western-linked organizations. In June 2026, roughly two dozen governments linked such attacks to Iran's Quds Force and intelligence ministry.Groups like Harakat Ashab al-Yamin function as an "operational brand," letting independent criminals act under an ideological banner while keeping Tehran at a distance.
Russia runs a broad campaign to weaken NATO- and Ukraine-supporting infrastructure and meddles widely in elections. Iran is more selective and identity-driven, escalating mainly against high-value targets. Both benefit from permissive domestic tech sectors— Russia, for example, has never banned VPNs, letting its hacktivists operate abroad with cover.
Analysts see a gap between Iran's intent (long-term intelligence access) and actual destructive impact — no evidence yet of capacity for widespread physical damage to US industrial systems, though a notable exception was an attack on medical device maker Stryker. Russia has gone further, with European governments disclosing cases of malware being activated, not just planted, against dams and power grids.
Responses have layered up over time: public attribution, expulsions and prosecutions, hardened infrastructure (NATO's Baltic Sentry patrols), sanctions (the EU's 21st package added dozens more shadow fleet vessels), and a shift toward "deterrence by denial." But Europe won't retaliate symmetrically, can't fully protect vast infrastructure, and risks eroding NATO's credibility each time it raises, then doesn't act on, Article 4 or 5 — as when Romania declined to invoke Article 4 after a Russian drone hit an apartment building.
Three pathways analysts flagged: accidental (GPS-jammed drones straying off course, like a Ukrainian naval drone that exploded near a Romanian oil depot), delegated (loosely controlled proxies acting with more violence than intended), and deliberate (a low-likelihood, high-impact shift toward assassinations or major cyberattacks, especially if Iran's regime feels existentially threatened). Analysts cautioned that assumptions about Russia being too "bogged down" to escalate echo similar assumptions from just before 2022's invasion.
● Map your geopolitical exposure — targeting is decoupled from obvious sectors (Stryker, a medical device maker, was a notable target).
● Know your people — proxies are sometimes recruited from within targeted organizations.
● Build redundancy and contingency plans for identified liabilities.
● Run multi-incident simulations so leadership can manage simultaneous threats with one coordinated response.
● Integrate security teams — cyber and physical security functions should share information so a coordinated campaign doesn't look like isolated incidents.
● Remember claimed attacks can be as disruptive as real ones — actors can trigger costly defensive responses just by taking credit for unrelated incidents.
This summary is based on a RANE Insights webinar featuring Matteo Ilardo, Freddy Khoueiry, and Dana Masalimova, moderated by Sam Lichtenstein.