Testing Europe's Resolve: The Growing Threat Against European Energy
As the Hormuz crisis strains supplies, Russia is likely to test Europe's resolve this winter, with cyberattacks on energy infrastructure the most credible threat.
Ukraine and its European partners face one of their toughest winters since Russia's invasion in 2022. Yet Kyiv is better prepared than at any point in the war. It has exceeded its initial gas storage target, decentralised heating, water and electricity systems to limit strikes' impact, and erected reinforced concrete shelters around critical infrastructure.
Nevertheless, while Kyiv is better prepared, the rules have changed and Moscow is likely to test European resolve as much as Ukraine’s resilience.
In a rare public appearance at the Yalta European Strategy forum in Kyiv on 13 September, Jonathan Powell, the UK's national security adviser, said talk of Russian escalation was a 'sign of success' that Western sanctions were paying off, isolating the country globally and eroding its capacity to finance the war over the long run.
He warned that Europe must be prepared for 'real hardship' this winter, as Moscow seeks to exploit tightening gas supplies and rising energy prices following the blockade of the Strait of Hormuz, one of the world’s most critical energy waterways. Oil prices have increased 50% since the start of the blockade while gas prices surged 140% compared to a year earlier, raising the prospect of fuel shortages and further steep increases in household utility bills.
All this could amplify Russia's winter campaign, as Moscow seeks not only to freeze Ukrainian homes but test how much economic pain Europeans will tolerate before support for Kyiv frays. The threat to European energy infrastructure is therefore also likely to grow as winter approaches.
Any Russian campaign to increase political and economic pressure on Europe is likely ultimately aimed at the political foundations of support for Ukraine – testing how much economic pain Europe will tolerate, while exploiting that pressure to deepen divisions and strengthen political parties more aligned to Russia's position
This is driven less by a desire to cause disruption for its own sake than by the deepening Russia–Europe rift, Moscow's allegations of European support for strikes on its energy infrastructure, and mounting pressure over the stalled war. Moscow may see pressure on European infrastructure as deterrence: a warning that continued support for Ukraine carries escalating risks.
Rhetoric, Sabotage and Cyber Operations
Three vectors are particularly relevant: rhetoric, physical sabotage and cyber operations. Russian rhetoric is almost certain to remain threatening, particularly towards the Baltic states, seeking to cause anxiety, uncertainty and capital flight even where no physical action follows. Physical sabotage remains possible but is operationally difficult. Cyber operations therefore represent the most credible vector, likely targeted against electricity generation and distribution, followed by gas infrastructure.
Poland is likely to be a principal target, given its increasingly forceful rhetoric towards Moscow and significant material support for Ukraine. Germany and the Baltic states present different opportunities; pressure on Germany could exploit political divisions and concerns over the domestic costs of confrontation with Russia, while the Baltic states’ perceived vulnerability makes them attractive for efforts to undermine confidence in NATO. Norway's importance to European energy supplies similarly raises its threat level, despite attracting less direct hostility from Moscow. Other Central and Eastern European states, including Romania, remain relevant to Russia's efforts to probe NATO defences, but appear less prominent in the European energy threat picture.
Hacktivists, Criminals and Spies
The actors involved also matter. Russian state intelligence services, cybercriminal groups and hacktivists should not be treated as a single threat, as their capabilities, motivations and strategic significance differ considerably.
State-aligned but not state-directed hacktivist activity is likely to be geographically broad but of limited strategic effect. A 2025 operation by a pro-Russian hacktivist group targeting a Norwegian dam may have misfired, with the group disrupting the supply of water to fish farms but perhaps instead seeking opportunistic access to Norway’s large hydroelectricity sector. Nevertheless, the incident demonstrates that such groups pose a persistent and less predictable threat across the continent.
Criminal groups may provide Russia with additional access and deniability. The November 2025 arrest in Thailand of an allegedly former FSB (Federal Security Service) employee in connection with cyber operations against NATO states may provide further indications that Russian cybercriminal networks are operating, at least in some cases, at Moscow's behest, perhaps pointing towards greater involvement of FSB Centre 18, the unit historically associated with leveraging domestic cybercriminals. The use of such networks would provide Russia with a wider pool of more disposable assets, allowing it to conduct operations without compromising state tradecraft or its established accesses.
But the more significant concern is activity conducted by Russian intelligence services. The December 2025 operation against Polish energy infrastructure attributed to FSB Centre 16 is particularly significant. This was an attempted disruption of energy supplies to c.500,000 people during peak winter, but, just as importantly, it signifies the use of a unit typically involved in building access to critical infrastructure for both long-term espionage and disruptive operations in times of crisis – potentially indicative of a sharp uptick in Russian intentions or desperation, in which the immediate disruptive effect was finally deemed more important than preserving access for future objectives.
Intent is Not Outcome
This does not mean a successful attack on European energy infrastructure is imminent. Intent and outcome should not be conflated; Russia may seek to create pressure without succeeding. Cyber operations offer Moscow 'implausible deniability' and the ability to operate remotely, but are less reliable than other vectors given strong defences and constant threat monitoring. Nevertheless, Russia’s incentives to use hybrid pressure are increasing, raising the risk of further activity just as European energy markets come under greater strain.
The bigger picture is not purely about energy. Any Russian campaign to increase political and economic pressure on Europe is likely ultimately aimed at the political foundations of support for Ukraine – testing how much economic pain Europe will tolerate, while exploiting that pressure to deepen divisions and strengthen political parties more aligned to Russia’s position. Yet such efforts are likely to prove counterproductive, instead feeding the downward escalation spiral already under way: Russia increasing pressure to deter Europe; Europe interpreting it as confirmation of the Russian threat and responding with greater support for Ukraine; Russia then perceiving that response as justification for a further response with pressure. Where this leaves Europe’s longer-term security is unclear, but it suggests that this winter could test not only Ukraine’s resolve, but Europe’s as well.
© RUSI, 2026.
The views expressed in this Commentary are the authors', and do not represent those of RUSI or any other institution.
For terms of use, see Website Terms and Conditions of Use.
Have an idea for a Commentary you'd like to write for us? Send a short pitch to commentaries@rusi.org and we'll get back to you if it fits into our research interests. View full guidelines for contributors.
WRITTEN BY
James Coe
Guest Contributor
Dr Aura Sabadus
RUSI Associate Fellow, Energy and Security
- Jim McLeanMedia Relations Manager+44 (0)7917 373 069JimMc@rusi.org





