David Kagan
Good morning, good afternoon, and good evening, wherever you are joining us from today. My name is David Kagan. I’m the Senior Program Officer for the Democratic Resilience team here at CEPA. It is a pleasure to be here today discussing a new report CEPA just launched last month titled War Without End: Deterring Russia’s Shadow War. I’m joined here today by my colleagues and fellow authors of this report, going down the line. We have Minna Ålander, fellow with the Transatlantic Defense and Security program here at CEPA, who is joining us from Stockholm today. We have Matthew Boulègue, Senior Fellow with the Transatlantic Defense and Security program, joining us from New York City. And finally, we have Doug White, Senior Fellow with the Democratic Resilience team, who is joining us from Kyiv today. So, in classic CEPA fashion, we are joining from all corners of the transatlantic space. Before we get started, we’d ask that if you have any questions, please feel free to use the hand-raise function or drop any questions you have in the chat. I will turn it over to my colleagues here in a moment, but before we do that, I’d like to speak a bit about the genesis of this research and our objectives. With our analysis here over the course of the last year and a half, CEPA has undertaken an intensive study of Russian shadow war in Europe. In an effort to address this growing challenge, CEPA has convened a transatlantic task force comprised of national security professionals, forensic researchers, and investigative journalists charged with deepening our understanding of how Russian shadow war contributes to and expands Moscow’s war in Ukraine, the actors and governance structures involved in prosecuting Russia shadow war, the gaps in EU and NATO awareness and assessments of its vulnerabilities to Russian shadow war, and, perhaps most importantly, how the EU and NATO’s critical deterrent and retaliatory capabilities can be deployed to defend against, deny, and deter Russian shadow war. Now this, of course, brings me to the term shadow war itself, and I’m sure everyone here is thinking, “Yes, this is exactly what we need, another term to describe Russian hybrid war, active measures, gray zone conflict, what have you.” Well, I’m here to tell you that there is actually an important distinction in how we at CEPA define shadow war as compared to hybrid war. In a sense, it’s the latest iteration of hybrid war that severely accelerates a concerted campaign of physical assaults that fall just below the threshold that would trigger a military response from allies, and that is the deliberate objective of Russia. And whereas hybrid war, as we define it, emphasizes narrative and ambiguity, shadow war expands on that effort with distinctly kinetic attacks we’ve seen since the full-scale invasion of Ukraine; acts of physical aggression against Europe surged to new levels and new heights. Russia, unable to confront Europe with conventional warfare, is deploying diffuse and deliberately hard-to-attribute kinetic operations across European land, sea, and airspace, to degrade EU-NATO cohesion and readiness, and, perhaps above all else, their willingness to support Ukraine’s defense. So, this latest report, which was released at the end of last month, represents part two of a two-part study of Russian shadow war. The first report, which was published towards the end of 2025, was authored by my colleagues Andre Soldatov, Irina Borogan, and Sam Greene. That report takes stock of Russia’s shadow war ideology and purpose, taking a look at the historical implications of the shadow war philosophy going back to the Soviet era, and really characterizes the shadow war doctrine as a neo-Stalinist vision of perpetual war with the West. This latest report, authored by my colleagues and me, is a study that is designed first and foremost to develop a theory of deterrence for NATO and the EU. Within this report, we’ve identified three key domains around which we have authored case study chapters that make up the body of this report. One domain is the sabotage of critical undersea infrastructure. That chapter was authored by my colleagues, Minna and Matthieu. Another takes a look at the cyber domain, which was authored by Doug, and finally, we have the physical infiltration domain, which was authored by me. So, our findings show that deterrence of the Russian shadow war has largely failed for a number of reasons. First, we found that shadow war is persistently misclassified by allies. Sabotage is handled by national law enforcement, cyber incidents are considered technical concerns, and subsidy disruptions are considered maritime incidents; all of this has resulted in disjointed responsibility within the Alliance and has hampered the ability of allies to develop a cohesive strategy of response and deterrence. Secondly, we found that the tempo of responses has been far too slow and consistently lags behind. The pace of attacks, attribution, and responses has thus far been tethered to the legal process and courtroom standards of proof, which is further delaying response capabilities. And finally, allies have a fundamental fear of escalation. This has produced a reliance on ambiguity and a general aversion to developing clear thresholds for response and predictable consequences for Russia. So, with this report, CEPA has identified several key strategies for improving deterrence, which I’ll list out here very briefly, but we’ll get into that further down the line. First, deterrence must be based on cumulative pattern recognition, rather than isolated proof. Shadow war is reliant on deniability, and relying less on the legal process to attribute attacks to Russia is going to be key to developing more effective deterrence. Second, collective consultation among allies must become routine and normalized if we are to effectively deter Russian shadow war. Third, Russian shadow war and hyper threats need to be integrated into a single deterrence framework, rather than understood as disjointed, separate challenges. Fourth, allies need to develop and maintain a standing menu of consequences that are designed for speed and predictability. It is essential that Russia knows that every act of shadow war will be met with a response that directly constrains Russia’s warfighting capability and directly supports Ukraine’s defense. Fifth, the EU and NATO should work to harmonize readiness, capabilities, and political thresholds for action. To this end, we feel that there should be a division of labor in which NATO leads on detection, defense, and military response, and the EU can lead on financial pressure, border controls, law enforcement, export controls, and things of that nature. Sixth, responses to shadow warfare must be led by national security institutions, particularly the military and intelligence services, rather than law enforcement, which is less equipped to deter state actors. While criminal investigations remain important for targeting individuals, they should support faster coordinated political and security decision-making across Europe, rather than serve as the primary response framework. Seventh, allies must develop closer public-private coordination that is going to be an essential element of hybrid deterrence. And finally, allies must reassert political will and durability in the face of what will be certain Russian escalatory rhetoric that will come as a response to increased allied deterrence. So, I will stop there and open this discussion up to a general question for our colleagues here. What is your assessment of NATO and the EU’s ability to effectively deter shadow war at large? And is this a question of developing new tools, or is this entirely a political will issue? I would also be curious to get your sense of what developments are being made in the development of a deterrence doctrine, and if there have been any productive measures taken recently to build deterrence. So, maybe Minna, I’ll start with you, and then we’ll go around the horn.
Minna Ålander
Yeah, thanks, David. Thank you very much for having me here. I would say that the challenge in hybrid warfare is that it’s such a multi-level effort to deal with it, to respond to, and especially to deter it, and so it requires a very robust response capability on the level of the individual states that are affected. Then, well-functioning and well-coordinated smaller groups of countries, like, let’s say, in the Baltic Sea region, where we have seen a number of these cable cuttings and other such incidents. And then you also need both the EU and NATO, as David already mentioned. So, part of the challenge here is to sort of get this multi-level effort to function smoothly and to identify the right level of response, and even in some cases, the jurisdiction that they’re operating under. And that’s a particular challenge in the maritime domain, but I will maybe leave it there for now and give the floor to my colleagues.
David Kagan
Mathieu.
Mathieu Boulègue
Yeah, thank you very much, and great to be on the line. I wanted to emphasize the points that David and Minna made on the nature of what we’re seeing with shadow warfare. We are coming 15 years too late when it comes to pushing back against these activities. We used to call them hybrid, for lack of a better term, for lack of actually trying to find substance behind that term. Then it became the gray zone, and now we have shadow warfare as an umbrella term, but we can equally call them low-intensity warfare activities, or sub-threshold activities that fall below the threshold of attribution. But the way we really need to understand them is that it is a defining feature of how the Kremlin authorities define themselves in a conflict against the West and against NATO. This is highly unpalatable. This is not politically correct, in a way, to define ourselves at that threshold of conflict with Russia. Yet here we are. This is exactly how the Kremlin authorities are defining themselves against us, so we cannot be complacent about the very nature of these things, and shadow warfare is, by definition, the unchanging nature of war. What we used to call hybrid warfare was focusing on the character of war, which is the changing aspect of warfare. It is not a tool. It is the very definition of how the Kremlin is projecting itself against us. It is an operational framework that defines how the Kremlin is projecting its intentions against NATO, and this is precisely why it’s in the shadows, because it is a world of blurred attribution, of dissolved and diluted levels of response, of the lack of willingness to push back from us on our end, because of how unpalatable and complex, because we don’t really have a clear threshold. So, this situation is really forcing us to operate within the shadows, also because we cannot push the shadows with lights. There is a limit to how much we can push back into the light. We also need to operate a bit more in the shadows and understand what it means in terms of resolve, and therefore in terms of deterrence. But I think this is a very important distinction that we need to have gloves off and stop pretending that everything is rosy and that there is a chance to reach out to the Kremlin, or whatever we want to call it. This is, by definition, the nature of war and the nature of the conflict that the Kremlin authorities are defining themselves against us, so we should just once again have our gloves off and stop the complacency.
David Kagan
Doug, over to you.
Douglas White
Thanks, David, and I appreciate having the chance to speak with you all here today. I’m grateful for the opportunity to speak from the perspective of Ukraine, and what we see here with the cyber aspect of shadow war. I think I’ll echo a lot of what Matthieu has just said. What we see as cyber is no longer a supporting domain; it is central to how modern conflict is conducted. And the challenge for NATO and the challenge for the EU isn’t so much a lack of tools, but a lack of integration across policy defense and, especially in the cyber area, in private sector integration, Russia operates across all of those seams, and Ukraine is showing that when you are able to close those seams through real time coordination and operational resilience, you can withstand sustained pressure. The question now is whether allies can adapt quickly enough to do the same. NATO and the EU are definitely not starting from zero. They have strong capabilities. They have growing intelligence sharing. They have increasingly mature cyber defense frameworks. This issue is not one of a lack of tools. The real constraints are integration and political will. Russia operates across cyber, economic pressure, sabotage, and information operations as a single continuum, and NATO and the EU still respond through this sort of fragmented policy and institutional silos. So, deterrence tends to break down less because we lack capability on our side, and more because we lack this speed alignment and pre-agreed consequences. So, until cyber and shadow war activities are treated as a core national security priority on par with kinetic defenses, Russia will continue to exploit those teams.
David Kagan
Yeah, thank you, Doug; I appreciate that. And I think, getting to Matthew’s point about taking the gloves off, this is why we are really discussing the necessity for a standing menu of consequences. I mean, changing Moscow’s calculus is going to require predictable, escalating consequences that both establish red lines and tie every act of shadow war aggression to a tangible cost. And an essential element of that is going to be providing support for Ukraine as a response to these aggressive shadow operations. We can’t separate this out from the war in Ukraine. They’re fundamentally part and parcel of the same conflict, and I think it’s really essential that our allies are viewing it through that lens. So, Minna, maybe I’ll turn this over to you really quickly. Could you possibly explain the importance to us of the public-private collaboration in responding to the Russian shadow war that Doug just mentioned? What are the gaps in the government’s response capability that can be filled by private sector engagement in your field and in other fields?
Minna Ålander
Thanks, David. Well, especially because Matthew and I looked specifically at the critical undersea infrastructure in our chapter of the report, it’s particularly obvious that all this infrastructure is owned by private companies. So, there is no way to deal with this issue without very good functioning public-private partnerships. And what we found in the process of writing this report and interviewing officials in the Baltic Sea region was that there’s a lot of good and innovative thinking in this, and there are a lot of measures that are being tested out in this region, and the problem can also potentially become blueprints for best practices. So, this ranges from, for example, a new sort of national security law in Norway that allows the government to share information with even private companies in a completely new way. On the other hand, these private companies may sometimes have some underwater capabilities, like situation awareness capabilities, repair capacity, and other things that the government lacks. So, there’s this kind of synergy there. Lithuania developed a set of resilience and preparedness standards that companies have to meet. But interestingly, this whole process was initiated by the private sector. So, they approached the government and wanted to know how to go about this. So, we came across a number of these kinds of examples where you have a very clear connection there. Of course, it may be easier to do in the smaller, high trust societies, where people tend to know each other across the board than in other countries, and there are differences in political culture, to what extent it is politically correct for the government to work very closely with private entities, but this is essentially a challenge that all European countries, and why not North American as well, face in terms of especially offshore or underwater critical infrastructure that we have, and also onshore. So, this is absolutely key, and I think that all countries are sort of going about it in ways that suit their specific political system, but there is definitely a set of measures that we can identify based on this report that could become this kind of blueprint, as I mentioned.
David Kagan
Yeah, absolutely. And Mathieu, I might turn to you now and ask what developments you’ve seen in the subsea area that are indicative of progress, maybe not between public and private, but at the sort of national, multilateral level. Are you seeing progress there in that field, and what can you tell us about it?
Mathieu Boulègue
Thank you, David. And to further Minna’s answer, we have seen some progress. It’s not like we have been completely complacent to the Russian threat and have been sitting like ducks doing nothing. So, when it comes specifically to critical underwater infrastructure, there was a kind of wake-up call, I think, a few years ago. It started with Norway and the cuts of the Svalbard cable, and then it continued into the last few months with the Baltic Sea in particular. I think the world discovered that the Internet doesn’t come from satellites or the ether but actually runs through cables that have been laid out with the technology inherited from 100 years ago, initially with telegram cables, and further to fiber optic, energy, and power cables. But what we have been doing is looking at the different layers of what we call attribution and the different responses that have been taking place across these three layers of attribution. So, the first one is the technical attribution, which is the ability to gather irrefutable technical evidence through the use of technology, whether it is remote sensing, different sensing capabilities, space-based capabilities, domain awareness capabilities, or uncrewed systems at sea, in the air, and on the ground, to really go up those breadcrumbs of evidence to attribute to a nefarious actor, whether it is Russia, whether it is China, or whether it is really an accident, because accidents do indeed happen. The majority of damage that we see on cables these days is generally linked to fishing incidents or accidents, but technical attribution is really important to have that smoking gun, and we have also lowered the threshold of what a smoking gun can look like, not least, looking at the behavior of specific vessels like the shadow fleet. The second aspect is the legal attribution that Minna alluded to as well: the legal framework that allows states and coalitions of states to really attribute from a public perspective, also from a private perspective, with cable operators and repair facilities, to really give that holistic approach to cable and infrastructure damage. And the third aspect is the political attribution, which is the hardest. It’s the willingness, from a national and multinational perspective, to call out the responsible party based on that technical evidence and that legal framework, while managing the risk of escalation, because once you attribute politically, you always have the fallout in terms of the political response. And this is really where the policy wind is not blowing in the right direction when it comes to political attribution, because there is still plenty of hesitation to attribute nefarious actions and behaviors specifically to Russia, but also further to China. For instance, in the South China Sea, there are still plenty of rebuttals, just because we don’t have the smoking gun. Just because we have not clearly identified the Kremlin specifically as a culprit, there is still a lot of policy hesitation, a lot of ignorance, or, even worse, a lot of trolls and idiots who still think that the Kremlin is up to something good. So, we also have to push back against it. And I would argue that we need to start treating Russia as guilty until proven otherwise, instead of doing what we do now, which is to assume that the Kremlin is innocent until proven guilty. So, there really needs to be that mental shift on projecting irresponsibility onto the Kremlin, just because we assume that Russia is not always up to no good, but we also know that Moscow is never really up to anything good in the first place. So, I think there is a mental shift that we need to have regarding that layer of attribution.
David Kagan
Absolutely. Thank you for that, Matthieu. I might take a moment here to talk about developments we’ve had in the aerospace domain, and maybe where those gaps are. So, I’d say it’s clear that the rate and brazenness of these airspace incursions are on the rise. In the last year, we’ve seen several instances of Russian drones and jets intruding into NATO airspace, even as far west as Belgium and Ireland, when several drones tracked and followed President Zelenskyy’s flight on approach to Dublin. And these persistent airspace incursions are not just irritants; they are stress-testing allied systems and readiness and response capabilities in the air. But I should note that NATO is indeed waking up to this issue. We saw the establishment of Operation Eastern Century, which represents a concerted effort to augment NATO’s air defense posture on the eastern flank through the provision of additional allied fighter rotations, radar ISR assets, and information sharing. All of this is a really important first step. It sends an important message to the Kremlin about how seriously allies are taking the aerospace issue. But in its current form, it seems to me to be a bit of a half measure. On the one hand, it improves what NATO sees and theoretically improves readiness and response capabilities, but it’s still fundamentally a defense posture, not a deterrence strategy. And in reality, NATO air defense systems are still largely limited by national caveat gaps that limit the availability of rapid response force capabilities or limit the availability of rapid response force capabilities. Member states still retain sovereignty over the deployment of military assets for NATO. What’s great about the Eastern Century framework is that it offers an opportunity to chip away at the institutional barriers, to establish some semblance of pre-agreed commitments from member states, who can pledge assets in advance under certain conditions to mitigate national disruption at a moment of crisis. And this would result in much faster decision-making and more credible deterrence. So, this is the kind of step I think we’d like to see NATO and other agencies take to, to use Matthew’s line again, take the gloves off and prove how serious they are about deterrence in this field. Doug, if you have anything to add on your end on that, please feel free. But I might ask you as well, given the multi-domain impact of cyber-attacks, what changes are needed to move cyber defense out of siloed policy buckets and treat it as a fully integrated national security priority across defense, economic policy, governance, and things of that nature?
Douglas White
Great question, and thank you for it. I wouldn’t frame the current situation as Russia winning, but they are absolutely setting the pace in cyber, and I think in shadow warfare more broadly. What they’re doing effectively, as we’ve spoken about, is they are operating just below that threshold for collective response. They exploit that ambiguity and the deliberative processes that are part of our collective response, which slows decision-making. So, the NATO and EU kinds of capabilities are there, but again, what we see is that they’re not organized in many ways and treat cyber as a supporting function and not a central domain. And so, until that changes, Russia is going to continue to find this space to operate successfully. While we’ve made a lot of strides in attribution, I would argue that attribution doesn’t have to be perfect. It relies on credible consequences in the first place, and even when attribution isn’t immediate, those patterns of behavior in cyber are quite clear. I think it is true in other domains as well, but in cyber, the behavioral patterns leave a digital trail of breadcrumbs. It’s not difficult to discern. The difficulty is the political will to publicly attribute and levy adequate consequences. So, it’s whether we do that, how we do that, and then whether we do that consistently, once we’ve identified what those consequences are supposed to be. Right now, that’s uneven. These adversaries in Russia take advantage of it. And again, the problem isn’t that we don’t know what to do. The problem is we’re not organized to do that fast enough. So, I think that a scaled set of consequences following that attribution would make sense, and then a harmonized set of shared understandings as to when those consequences are triggered would be most useful.
David Kagan
Terrific. Thank you for that, Doug. We have a few questions in the chat from Lisa Volk from BBC Russia. I’m going to go in reverse order here. Maybe Minna or Matthieu, you can take a stab at this one. Do you feel that the issue of attribution could be politically problematic? Arguably, one of the most famous cases of sabotage was the destruction of the NordStream pipeline. Initially, everyone assumed Russia was responsible, but it later turned out that the trail led to Ukraine-connected perpetrators. Minna, Mathieu, I welcome your responses to this one.
Minna Ålander
Well, I can maybe go first, and then Mathieu, happy to hear your thoughts. I’m a bit ambivalent when it comes to attribution, because I think that it is necessary, but not sufficient as a measure. And I think that we should have done more attribution five years ago, and before that, when Russia cared more about being named, shamed, or called out, when Russia was making a bigger effort to hide the traces of direct involvement. I think that there has been a shift in Russian behavior, in the sense that they don’t seem to care as much anymore. And sometimes attribution can even be useful for Russia, because it amplifies this sense of the Russian threat that can have an information effect. However, I think that it is still necessary for our political systems, and especially for the legal base, for other reactions and how to calibrate the reaction correctly, so that is one important part of it from our own perspective. On the other hand, especially in the maritime area, it’s completely possible and not even that difficult to make a technical attribution. You can definitely prove beyond doubt that it was this ship that dragged its anchor and that caused the damage. But then, for this kind of political attribution, in terms of proving intent, that’s very often impossible in any kind of court of law. So, sometimes it also doesn’t matter so much whether you can prove the intent or not, because, nevertheless, these kinds of cable cuttings, and the shadow fleet as a wider phenomenon, need to be dealt with. And there are a number of hazards that it poses: navigational, environmental, and this whole infrastructure issue. So, attribution is, in my opinion, sometimes or often necessary, but not a sufficient condition for responding. But over to you, Mathieu.
Mathieu Boulègue
No, I think it’s a great answer, thank you. And I think there are already a lot of questions in the chat, so I think it might be good to open the floor to the chat, but maybe very quickly on this for the pop culture moment. I think Russia has the Taylor Swift reputation. It doesn’t really care about its reputation, yet it really does care about its reputation. So, the more we put emphasis on creating fewer shadows and more light onto Russian activities by being, once again, gloves off and calling a spade a spade when it comes to the shadow war activities, then the more we can deny the deniability that Russia is imposing against us and onto us. It really is, in a way, a psychological game of attribution and a psychological game of who has more to lose, and if we remove the shadows, if we create more light with more presence, more deterrence, more attribution, more visibility on these actions and more political willingness, specifically political bravado and courage, then we will leave less space for these shadows, and therefore less space for Russian agents and Russian literacy activities to continue.
David Kagan
Thank you, Matthew. Maybe a question for the entire group here, and Doug, I might turn to you first. What do you think is the most underreported part of these efforts, and what should journalists be focused on in reporting this?
Douglas White
I’ll be a little self-serving here and say I think that the story that is underreported here is the success of Ukraine in terms of demonstrating resilience, not only in cybersecurity, but simply as a society. Part of the reason why cyber as a domain has been so successful for Russia, initially, was first-mover advantage, but very quickly, Ukraine gained a lot of experience against what was being deployed against them and recovered from it well. It was through that process of how they recovered from the different TTPs that were tactics, techniques, and procedures being deployed against them by some very advanced actors from Russia that Ukraine began to demonstrate some expertise that is unique and valuable in a lot of ways. With the fact that the society of the city that I’m in can still function under the pressure that it is constantly under, cyber is a very cheap way to undermine the continuity of government, to make it appear to a public that their government is not able to provide them with the basic services that civilization requires, digital infrastructure, water, heat, and light, and they have come at critical infrastructure successfully for years now. And the Ukrainians continue to build it back, and they continue to build it back better. They need a lot more resources to build it back more effectively, but the approaches that they have and the integration across government and between government and state-owned enterprises that operate critical infrastructure, between government and the private sector operators who support the digital infrastructure, these are roadmaps that we need to become very familiar with in Europe and in other locations as soon as possible. So, I think what is underreported is what happens right after a boom in this country, because it’s how quickly they are able to recover and the different strategies that they are able to operationalize in terms of resiliency. I think that’s underreported. It’s a constant target, but the fact that they are as successful as they are in thwarting some of these major events and continue to function and be able to provide services for the public, I think that’s a story worth exploring more.
David Kagan
Thanks, Doug. I will take a crack at this and say of the three sections that make up the infiltration report, one that I think is not getting as much coverage as it could, and I’m also going to attempt to answer the first question about the reliance on disposable agents with this, is this recruitment of proxy intermediaries to carry out sabotage, arson, and the like on behalf of the Kremlin. Seeing as skirting attribution is elemental to the shadow war doctrine, these cases underscore a core feature of the Kremlin’s infiltration strategy, which is outsourced coercion that is exploiting Europe’s open society, legal protection, and trust in the public space, while shielding Moscow behind layers of deniability. They’re really banking on the fundamental difference between authoritarian societies and democratic societies and the legal processes that go along with that, and we see this as well in the area of forced migration. Moscow and Minsk operate without legal or humanitarian or political constraints, whereas democratic states are bound by the rule of law, asylum frameworks, judicial oversight, and public scrutiny. The Russian and Belarusian strategy is built precisely on that imbalance, and it forces democracies to choose between decisive action and upholding their own rules. So, this is the kind of push and pull that we’re seeing a lot in the infiltration domain. To go back to the forced migration point, the decisive steps that were taken by Finland, Lithuania, and Latvia in times of border crisis between 2021 and 2023 triggered a lot of unease in Brussels because it risked breaching the EU asylum and humanitarian rights obligations, and it’s a real strain on these systems, because the moral burden falls disproportionately on border states. And I think that question of the moral burden, particularly with the legal process, is one that cuts across all of our reports here, particularly in the cases of forced migration. In some cases, with proxy agreement, it’s fueling far-right narratives and political movements and is challenging the credibility of the EU governance model. And that goal alone is central for Russia and Belarus, to answer your question more directly about whether this is a hybrid strategy, or whether the spies are not working for Moscow anymore. It’s less about the spies not working for Moscow anymore. More so, this is a really effective strategy for Moscow because they’ve been able to exploit these legal systems, as we’ve all described here. So, I wouldn’t call it a hybrid system, because I think they’re leaning more on these disposable agents now, mostly because it’s pretty easy and cheap for them to do this, and it is very rare that these attacks are quickly attributed to Russia, for all the reasons that my colleagues here have mentioned. Okay, so we will move forward to Chloe Craft from The Scope, who is asking: Could you elaborate on suggestions for allied intelligence surveillance into counter proxy activity and infiltration? I’m so glad you asked this. It now gives me the opportunity to get into that. So, obviously, this is a clear challenge for the EU and NATO with no easy fix. There are a few areas of focus we’ve identified as key in addressing this issue. Just to name a couple, we have recommended the expansion of a joint task force to monitor online recruitment networks on encrypted platforms a lot more closely. This is something that I think the EU is doing already, but not at a level that it could. And this could take the form of something modeled after Europol’s Joint Investigative Team, but with a more dedicated EU and NATO leadership role using all the resources that those agencies have at their disposal. Furthermore, I think a key focus of this must be disrupting the proxy financing, and that’s going to take a severe increase in monitoring cross-border transfers, both in cash and crypto. I think we’re seeing that crypto is an increasingly used medium for recruitment, and EU oversight over crypto monitoring is not as strong as it could be. A question from Katie Stallard at the New Statesman: how would you situate the US under the current administration compared to European allies in terms of focusing on the scope and scale of the threat? Any takers on that one? Minna, Mathieu?
Minna Ålander
May I just also briefly come in on the other question from Chloe on what you think journalists are missing? Specifically, reporting on topical breaking news, like Russian shadow food vessels in the Irish Sea, for example. I think I would like to emphasize the continuity. Of course, it’s challenging when you’re reporting breaking news, but it would be great to get more mentions in those reports of how this has happened before, maybe in some other context. But it’s a long-running gag in Norway about these fishing vessels that goes back to the Cold War. There’s even a famous TV sketch about the Russian fishermen. So, there’s a longer history for many of these, and I think I do like the term hybrid, in the sense that it suggests that there is a combination of old and new, and that is the case in many of these incidents, such as the instrumentalized migration. Very few people remembered in 2023 when Russia started another push at the Finnish border that this happened 10 years earlier in 2015 and 2016 at the Finnish and Norwegian borders. So, that was the first time that Russia tested this. And there’s very often this kind of pattern that Russia has tested something before, and then it does it again. And I appreciate the challenge of connecting these dots, especially in news reporting, but sometimes it would be really useful to have that context in there.
David Kagan
Excellent, thank you.
Mathieu Boulègue 41:26
If I can piggyback on this, I will not comment on the current US administration, but I can definitely comment on what reporting could look like, and a different kind of reporting, maybe on these issues, is really to track Russian behavior. Even if there is no presence of Russia, there will always be a presence of Russia. And to further this point on the Russian trolls, or the presence of the Russian fishing fleet, it’s really the modern-day Flying Dutchman. It exists, and it doesn’t exist at the same time. And everybody pretends they’ve seen it, but nobody has really seen it. The vessels are there; whether they are close to a cable or close to infrastructure is irrelevant. They are always there. And when they’re here, present at sea, or even on flights in the air, they’re up to no good, because they are systematically conducting nefarious operations, whether for the preparation of sub-threshold physical activities, or military intelligence gathering, and so on. They are definitely up to no good. So, it really is about exposing the track record of behavior that we see and the anomalies in behavior, taking, for instance, a great investigative journalist, one of my good colleagues from South Africa, who has done some amazing work at the Daily Maverick to expose Russian behavior in the Antarctic and the presence of the Russian fishing fleet and Russian activities in the Antarctic by tracking the GPS position and the AIS VMs positions of these vessels to really expose the weird behavior that we see, because there is a difference between, for instance, in the cable community, there is a difference between anchoring damage or an accidental anchoring damage of a fishing vessel that was not supposed to be there in the first place, but just dropped its 10 ton anchor onto a cable. Oops. Accidents happen. And the pattern of behavior we see of the same fishing boat doing the same rounds in the water, or following the same layout 100 times across the cable, is abnormal, and that is what needs to be reported. For instance, because the data is out there, the AIS VMs data is not always present, but mostly present. And there is enough declassified space-based satellite imagery to have access to. So, there is definitely a different kind of reporting that can take place on the more technical side of things.
David Kagan
Thanks for that, Matthieu. Katie, I’ll take a quick stab at answering your first question here, particularly in the airspace domain. Obviously, NATO is a defense organization that is led by the United States, and we have an American speaker here. So, this Operation Eastern Century is, in one way or another, where, however the administration feels about European security, it’s a NATO initiative. It’s an American initiative. And I think in the current state, the US is going to continue to support NATO’s efforts in deterring these threats. I will move down to a new question. Doug, you might have a chance at answering this one. Could Ukraine use this experience with hybrid shadow warfare, similar to how it has used its drone experience, to secure diplomatic deals with new partners? Wondering if there’s a case for that in the cyber domain.
Douglas White
I’m not aware of a case specifically right now, but there is a lot of discussion in our community here about the fact that Ukraine’s experience is valuable in terms of what they see, in terms of trends, tactics, techniques, and procedures that are deployed against them by Russia. The commodity here is called Cyber Threat Intelligence, CTI, and Ukraine has a very unique body of that, and it exists and is correlated and analyzed by the Computer Emergency Response Team of Ukraine and the State Service for Special Communication and Information Protection, the SSCIP. And one of the things I’m trying to encourage them to think about is how the body of cyber threat intelligence constitutes a set of equities that they should consider what they can exchange from the private sector for. There’s a lot of interest in Ukraine in terms of telemetry, cyber threat intelligence, and the overall experience of what Ukraine is seeing deployed against its critical infrastructure, its government networks, and its civilians through different phishing campaigns of some magnitude of success or another, even those that have been deployed on encrypted apps like WhatsApp and Signal to some degree of success. So, Ukraine’s got a lot of information, which, if you’re Google, if you’re CrowdStrike, if you’re Microsoft, you’ve got a specific commercial interest in being able to deploy solutions that reduce the vulnerability of your client base to those types of attacks, and it is very often cited that Ukraine, in many cases, can be seen as a forward deployed node in what the digital aspects of conflict are going to look like and how they’re going to be shaped going forward. So, from what we see here, there is a strong case to be made for Ukraine, where it presently needs a lot of assistance in terms of trusted hardware and partners to provide trusted software, ideally at fees that are less than market rate, because this is the Government of Ukraine, whose entire budget is dedicated to warfighting, first responders, and teachers. At this point, how Ukraine can leverage those equities that are the cyber threat, intelligence, and telemetry data sets in an exchange with the private sector, particularly the major tech companies in the States, and how they can exchange that for value here in Ukraine, because what is not under question is that Ukraine has gathered unique value in this and that these threats and these deployments are coming to a theater near you.
David Kagan
Absolutely, thanks for that. A question from Radio Africa Group. Mathieu, I might have you try to answer this one. Many African states, including Kenya, have tried to maintain balanced relations with both Western partners and Russia. Does this neutrality create vulnerabilities to shadow influence?
Mathieu Boulègue
It’s a very good question. I’m glad that it’s been brought up. So, dealing with the Kremlin means that you’re losing your neutrality. You’re complacent. So, there is no neutrality in dealing with the current leadership in the Kremlin, and furthering relations with Russia means that you are complacent with Russia’s policy, and therefore with furthering the war against Ukraine and, in a way, furthering Russian shadow activities and more overt activities. Specifically in Africa, this would be the revamp of the Wagner group and the transformation into the Africa Corps, which is really a local regime enabler. I wouldn’t call it a security provider, but a regime stability enabler for a lot of African countries. We’ve seen it in Niger, Sudan, Mali, Burkina Faso, and CAR, so in a lot of countries in Sub-Saharan Africa and the Sahel. And yes, we know that one of the main entry points of the Kremlin is to use informational warfare activities, cognitive warfare operations, and psychological warfare operations directly on the populations of these countries, to keep instability or war-torn countries even more unstable, and to further facilitate Russian entry into that fold. We have seen the damage it has done, for instance, in Sudan. We have seen the damage it has done in CAR and in Mali in the context of France’s withdrawal from the region, and how the Africa Corps is really becoming a key element for some countries, in terms of their own regime survival and stability. And this really started with that whole layer of info ops, but also economic activities, and so on, the sort of mining against the protection scheme. And maybe to follow up on this really good question about African recruits, I think it is very much an underreported thing that Russia is exploiting the economic precarity of young men, specifically in African countries. And there was some really good work done, including by Radio Africa, on how thousands of young Africans found themselves, instead of being recruited to the Africa Corps, shipped away to the war front in Ukraine, only to be killed, unfortunately, in that situation. And I think this is definitely part of, not shadow warfare, but very much war recruitment, which is in the shadows, because it is underreported and not enough of it is in the limelight. But I wouldn’t call it shadow warfare in the sense that it is directly part and parcel of how Russia is recruiting people for the meat grinder in Ukraine. That’s definitely something worth discussing and pushing.
Minna Ålander
If I may just very briefly add to this, because there is this challenge that if you want to work together with both China and Russia in certain areas, it’s very important to keep in mind that they do tend to potentially weaponize any kind of dependencies that exist. Russia has a long history of doing this in the energy field. China has become sort of infamous for the debt traps that it has set for a number of countries. So, there are these kinds of considerations that are short of this direct, unfortunate contribution to the war in the form of these recruits.
David Kagan
Absolutely. Thank you both so much for that. If there are no more questions, I think we will wrap it up there. Thank you all so much for joining us today for a tremendously interesting conversation. Michael, I will turn it over to you for any final thoughts.
Michael Newton
Thanks very much, David. Thanks, everyone, for joining, and thanks to all of our speakers. For reference, there will be an auto-generated transcript and recording sent out after this briefing later today. If you have any other questions that you’d like to ask our experts, please do not hesitate to reach out to me at michael.newton@cepaorg.pages.dev or our press email, press@cepaorg.pages.dev, and we’ll do our best to connect you. And please keep a lookout. We are continuing to report on this topic, and we’ll have other Russia-related projects coming out later this year, so please stay tuned for that. So, thank you very much and have a great day. Goodbye.