Hybrid threats
The EU and its member states work together to prevent, counter and respond to hybrid threats and campaigns affecting Europe and its citizens.
What are hybrid threats?
Definitions of hybrid threats and campaigns vary, since they need to remain flexible in order to allow for proper responses to the evolving nature of the threat.
Hybrid threats usually refer to coordinated harmful activities that are planned and carried out with malign intent. They aim to undermine a target, such as a state or an institution, through a variety of means, often combined. These means may include information manipulation, cyberattacks, economic influence or coercion, covert political manoeuvring, coercive diplomacy, or threats of military force.
Hybrid tactics are used by both state and non-state actors and are growing in complexity and sophistication. In addition to the security risk, they pose a threat to democracy, targeting its core values and aiming to fracture society and undermine political decision-making.
Hybrid campaigns are designed in a way that makes detecting and defending against them difficult. They are devised to remain below the threshold which could constitute or be perceived as an act of war. Countering hybrid threats is therefore a complex and constantly evolving challenge that the European Union, its member states and its partners are facing.
A coordinated EU response to hybrid threats
While the primary responsibility for countering hybrid threats lies with the individual EU member states, they also take coordinated action to counter these threats collectively.
The hybrid toolbox
Following the adoption of the Strategic Compass for security and defence in March 2022, the EU established an EU hybrid toolbox. The toolbox comprises the preventive, cooperative, stability-building, restrictive and support measures, as set out in the Council conclusions (approved on 21 June 2022) on a framework for a coordinated EU response to hybrid campaigns.
The purpose of the toolbox is to:
- help identify complex and multifaceted hybrid campaigns
- coordinate tailor-made and cross-sectoral responses
Acting as an overarching framework, the hybrid toolbox brings in other relevant response mechanisms and instruments, such as the foreign information manipulation and interference (FIMI) toolbox. In addition to this, the EU has developed the cyber diplomacy toolbox to respond to cyber threats and attacks.
On 16 March 2026, the Council approved conclusions on advancing the EU’s capacity to counter hybrid threats, reaffirming the EU’s determination to use all available tools to prevent, deter and respond to hybrid campaigns targeting the EU, its member states and its partners, irrespective of their origin, scale and intensity.
The EU has also at its disposal EU crisis management mechanisms, including the Council's Integrated Political Crisis Response (IPCR) arrangements to support coordinated action in response to major, complex crises, and to exchange information, e.g. on interference in the 2024 EU elections.
- Council adopts conclusions on advancing the EU’s capacity to counter hybrid threats (press release, 16 March 2026)
- Council conclusions on a framework for a coordinated EU response to hybrid campaigns (press release, 21 June 2022)
- A Strategic Compass for security and defence
- Sanctions against cyber-attacks
- The integrated political crisis response (IPCR)
Hybrid response teams
In May 2024, the Council approved the guiding framework for the practical establishment of EU hybrid rapid response teams.
Hybrid rapid response teams are one of the instruments in the EU hybrid toolbox to support EU member states, partner countries, and CSDP missions and operations when countering hybrid threats.
More information on the EU framework on countering hybrid threats:
- 2016 joint framework on countering hybrid threats (EU official journal)
- 2018 joint communication on increasing resilience and bolstering capabilities to address hybrid threats (EU official journal)
- Annual progress reports on countering hybrid threats (European Commission)
Fighting disinformation
Disinformation campaigns and, more generally, foreign information manipulation and interference (FIMI) are often used by threat actors as part of a wider hybrid campaign, or on their own. The EU has various mechanisms at its disposal to counter foreign information manipulation and interference.
On 21 May 2024, before the European Parliament elections, the Council approved conclusions on safeguarding electoral processes from foreign interference. The conclusions called on EU institutions and member states to step up action to monitor attempts by foreign actors to interfere in the EU's democratic process, and to make use of all EU mechanisms, networks and tools to protect the integrity of elections, without impeding open democratic debate.
Resilience of critical infrastructure
Since 2022, the EU has stepped up its efforts to protect critical infrastructure. On 8 December 2022, the Council adopted new legislation to ensure that critical sectors such as energy, water, transport and health were able to prevent, protect against, respond to, cope with and recover from hybrid attacks, among other things (critical entities resilience directive). The rules aim to reduce the vulnerabilities and strengthen the physical resilience of critical entities.
In addition, in December 2022, in the wake of the acts of sabotage against the Nord Stream pipeline, the Council adopted a recommendation on the resilience of critical infrastructure.
The recommendation stepped up the EU’s capacity to protect its critical infrastructure and covers three priority areas: preparedness, response and international cooperation.
In June 2024, the Council adopted a recommendation on a blueprint to coordinate a response at EU level to disruptions to critical infrastructure with significant cross-border relevance. The recommendation put in place an EU critical infrastructure blueprint which aims to promote shared situational awareness of the origin and consequences of an incident, to facilitate the coordination of public communications and to ensure an effective response.
- EU resilience: Council adopts a directive to strengthen the resilience of critical entities (press release, 8 December 2022)
- Council recommendation of 8 December 2022 on a Union-wide coordinated approach to strengthen the resilience of critical infrastructure (EU official journal)
- Critical infrastructure: Blueprint for protecting EU citizens and the internal market (press release, 25 June 2024)
Security of network and information systems
On 28 November 2022, the Council adopted the directive on measures for a high common level of cybersecurity across the EU. The new rules further improve the resilience and incident response capacities of both the public and private sector and the EU as a whole, including with regard to hybrid attacks.
The new directive, called ‘NIS2’, replaced the previous rules on security of network and information systems (the NIS directive).
Working with partners to counter hybrid threats
Working together with EU partners and organisations is key to countering hybrid threats.
EU-NATO cooperation
The EU-NATO strategic partnership is crucial to maintaining security and stability in the Euro-Atlantic area. EU-NATO initiatives in the field of countering hybrid threats include:
- common proposals for cooperation related to hybrid threats
- a structured dialogue on resilience beginning in 2022
The EU and NATO also carry out joint exercises in the field of crisis management, called parallel and coordinated exercises (PACE). The 2024 exercise aimed to strengthen the EU’s ability to respond to potential hybrid crises, both inside and outside the EU.
- EU-NATO cooperation
- EU Integrated Resolve 2024: EU concludes wide crisis response exercise (press release, 25 October 2024)
Support for partner countries countering hybrid threats
The EU is committed to supporting its partner countries with countering hybrid threats. The EU Partnership Mission in the Republic of Moldova (EUPM Moldova) is a prime example of such cooperation.
The mission was launched in May 2023 to help strengthen Moldova’s crisis management structures and assist in enhancing its resilience to hybrid threats and its cybersecurity.
Russia's and Belarus' hybrid activities against the EU
Russia
The EU strongly condemns Russia’s persistent hybrid activities which include sabotage, disruption of critical infrastructure, cyberattacks, information manipulation and interference (FIMI) and attempts to undermine democracy and the electoral process.
These malicious activities illustrate Russia’s reckless and irresponsible behaviour and its disregard for the rules-based international order and international law. They form part of broader, coordinated, and long-standing hybrid campaigns aimed at threatening and undermining the security, resilience and democratic foundations of the EU, its member sates and its partners.
The EU and its member states will continue to draw on the full range of tools available (including sanctions) to protect, prevent, deter from and respond to such malicious behaviour.
Russia's hybrid activities: EU sanctions
Belarus
The EU condemns Belarus’ intensified hybrid attacks against the EU and its member states, including the instrumentalisation of migrants and the violations of EU airspace
The violations of airspace pose serious security and safety risks, primarily to civil aviation and aim to destabilise an EU member state and to intimidate European citizens through direct threats posed to civilian aviation. The EU calls on the Belarusian regime to immediately stop all these actions.
Sanctions on the Belarusian regime have been imposed, and the EU is prepared to take further appropriate measures should such actions continue. The EU will not tolerate any hybrid campaigns directed against the EU or any of its member states.
Belarus' hybrid activities: EU sanctions
See also
European defence readiness
EU defence in numbers
EU sanctions against Russia: questions and answers
Last review: 16 March 2026