Sabotage Without War: Europe’s Struggle to Defend the Civilian Logistics Behind NATO

NATO's ability to reinforce its eastern flank rests on a civilian system that was designed for commerce, not for operations under attack. Commercial railways carry armour and ammunition. Privately operated ports receive ships. Cargo airports, road hauliers, fuel distributors, power grids, satellite services and digital traffic-management platforms sustain the movement. NATO estimates that civilian assets provide around 90 percent of transport for large military operations and that local commercial infrastructure and services account for roughly 75 percent of host-nation support.

That dependence creates an attractive target below the threshold of conventional war. An incendiary parcel in a freight depot, a damaged rail line, a compromised traffic-control network, a drone near a cargo aircraft or a severed cable can delay movement, force costly inspections and reveal how governments respond. Proxies, criminal recruits and deniable methods complicate attribution. The objective need not be to stop NATO outright. It may be enough to slow reinforcement, consume security resources, intimidate operators and test which nodes are indispensable.

Europe is responding. The European Union's proposed Military Mobility Regulation seeks a "Military Schengen," while NATO has expanded resilience planning and issued detailed guidance for public-private cooperation. EU states were required to identify critical entities by July 2026, and Brussels has mapped around 500 military-mobility hotspot projects. Yet much of the new architecture remains voluntary, nationally fragmented or dependent on future funding. Identifying critical infrastructure is not the same as securing its workforce, protecting its digital dependencies or guaranteeing rapid recovery.

Europe cannot guard every bridge, warehouse, rail junction and data connection. Its strategic task is to keep essential logistics functioning despite disruption. That requires redundant routes, pre-arranged commercial contracts, secure information sharing, trained repair capacity, credible attribution mechanisms and exercises that assume networks will fail. The measure of success is not the absence of sabotage. It is whether an attack can still alter NATO's deployment timeline.

The military front begins at a civilian loading dock

The image of NATO deterrence is usually military: brigades, aircraft, air-defence batteries and ammunition stocks. The system that brings those capabilities to the point of need is less visible. A reinforcement operation begins at commercial ports and rail terminals, passes through national road and energy networks, depends on civilian drivers and dispatchers, and is coordinated through privately operated communications and software.

This is not an incidental dependency. Following the Cold War, European governments reduced military owned lift and outsourced functions that had once been retained for mobilisation. Railways, ports, airfields, energy systems and telecommunications were privatised or reorganised around commercial efficiency. NATO now assesses that about 90 percent of transport for large operations comes from civilian assets chartered or requisitioned from the commercial sector. More than 70 percent of defence satellite communications are commercially provided, while around 95 percent of transatlantic internet traffic - including military communications - travels through mostly privately owned undersea cables.

The arrangement offers scale that no peacetime military could economically maintain. It also means that deterrence depends on companies whose incentives, security clearances, insurance arrangements and crisis obligations differ across jurisdictions. A port operator may understand container throughput but have limited access to classified threat intelligence. A railway company may know its network's fragile junctions but not NATO's priority routes. A government may possess military movement plans without having binding contracts for the locomotives, flatbed wagons, ferries, drivers and repair crews those plans assume.

The vulnerable object is therefore not a single bridge or port. It is the relationship between military demand and civilian delivery. Sabotage seeks to break that relationship at the moment when speed matters most.

August turned a structural risk into a visible warning

On 4 August 2026, an explosives-laden drone was discovered near a Ukrainian Antonov cargo aircraft at Leipzig/Halle Airport. The airport is a major European freight centre and a logistics hub used by NATO and Ukraine. As of the end of August, German authorities had not publicly attributed the apparent attack, and Moscow denied involvement. The incident nevertheless demonstrated how a low-cost device could threaten a strategic aircraft inside a civilian airport without crossing a border in a recognisably military formation.

French domestic intelligence chief Celine Berthon described the discovery as a warning that Europe must consider more direct and violent actions against essential companies and infrastructure. Two days later, Baltic Sea states announced plans for a joint drone-defence task force intended to accelerate information exchange. The initiative followed repeated episodes of suspected sabotage affecting undersea cables and pipelines and growing concern that small unmanned systems could approach ports, ships, power facilities and transport hubs with little warning.

These events did not emerge in isolation. In November 2025, Polish Prime Minister Donald Tusk said two Ukrainians working with Russian intelligence had carried out attacks on the Warsaw-Lublin railway, a major route towards the Ukrainian border. An explosive device was detonated as a freight train passed; a second mechanism intended to derail trains was found near Pulawy. The immediate physical damage was limited, but the choice of route was strategically legible. Poland is a central hub for assistance to Ukraine and for any reinforcement of NATO's northeastern flank.

In 2024, incendiary parcels ignited at courier facilities in Britain, Germany and Poland. European security officials said the devices were test runs for a Russian plot to cause fires aboard cargo flights to North America. The operation exploited normal logistics processes: ordinary-looking packages, commercial depots and international air freight. It threatened civilian workers and passengers while probing aviation security far beyond a military base.

The incidents vary in attribution and method. Some have been formally linked to Russian intelligence by national authorities; others remain suspected, contested or unexplained. They should not be collapsed into a single evidentiary category. Europe weakens its credibility if every accident, cable break or fire is labelled sabotage before an investigation. But analytical caution does not erase the pattern recognised by the EU: persistent hybrid activity involving sabotage, cyber operations, disruption of critical infrastructure and the use of proxies to undermine support for Ukraine.

Why sabotage fits the space below war

Conventional attack presents a visible aggressor, a defined target and an established framework for collective defence. Sabotage offers ambiguity at every stage. A local recruit may be paid through an intermediary without knowing the ultimate sponsor. Commercial equipment can be repurposed. A fire may initially resemble negligence. Digital intrusion can be discovered months after access was gained. Evidence sufficient for intelligence confidence may not satisfy a criminal court.

This ambiguity creates strategic time. Governments must investigate before attributing. Companies may withhold details to protect customers or liability positions. Allies receive different fragments of intelligence under different national rules. Public communication becomes cautious, allowing the sponsor to deny involvement and portray the accusation as political.

The direct physical effect may be secondary. Sabotage can compel authorities to search thousands of parcels after one incendiary device, patrol long stretches of railway after a small explosion or close an airport while a drone is assessed. It can make commercial providers reconsider high-risk contracts, increase insurance premiums and force the dispersal of police and air-defence resources. It can also generate reconnaissance value by revealing response times, backup routes and which facilities receive immediate protection.

The campaign's political design is equally important. Each incident is kept small enough to avoid producing the clarity and unity that an overt attack might create. The cumulative message is that European support for Ukraine carries a domestic cost, while responsibility remains contestable. This is coercion through friction rather than conquest.

The term "below threshold" should not imply harmlessness. A device intended to ignite aboard an aircraft or derail a passenger train can cause mass casualties. The relevant threshold is political and legal, not human. Europe is confronting actions that may be violent and strategically coordinated but are deliberately structured to avoid an obvious transition to armed conflict.

An efficient network is not automatically a resilient one

European logistics is dense, technologically advanced and commercially capable. Those strengths do not guarantee performance under deliberate disruption. Efficiency rewards centralised hubs, high asset utilisation, lean inventories and digital coordination. Resilience requires spare capacity, alternative routes, protected information, repair stocks and the ability to operate in degraded conditions. The two models overlap, but they are not identical.

Rail is a clear example. Heavy military equipment is difficult to move at scale by road, making specialised wagons, loading terminals and compatible tracks essential. Yet Europe still faces differences in rail gauge, axle load, signalling, electrification and operating rules. The available pool of flatbed wagons and locomotives is limited, while trained crews and maintenance facilities may be concentrated. Disabling one junction does not need to sever an entire corridor if the diversion lacks the clearance, capacity or permissions required for military cargo.

Ports and airports present similar concentration risks. A small number of roll-on/roll-off berths, cranes, fuel connections and secure storage areas may determine practical throughput. The surrounding roads, power substations, customs systems and communications links can be as important as the terminal itself. Protecting the perimeter while leaving these dependencies unexamined creates the appearance of security without continuity.

Digitalisation adds another layer. Timetables, cargo manifests, port community systems, positioning signals, maintenance platforms and access controls improve normal operations but connect physical movement to cyber availability. GPS jamming in the Baltic region has already disrupted civil aviation, and the EU has sanctioned actors it says facilitated Russian electronic-warfare activity. A cyberattack need not destroy infrastructure if it prevents operators from locating cargo, allocating paths or validating safety.

Commercial ownership further fragments responsibility. A strategic route can cross several countries and involve infrastructure managers, terminal operators, rolling-stock lessors, energy suppliers, telecom providers and subcontracted security companies. Each may meet its sectoral obligations while the end-to end military function remains fragile. No single balance sheet naturally pays for redundancy across the whole corridor.

Europe is building a response, but much of it is still prospective

The EU's Military Mobility Package is the most ambitious attempt to reduce this fragmentation. Proposed in November 2025, it aims to create an EU military-mobility area by 2027. It would harmonise movement requests, impose a maximum three-working-day processing time, simplify customs formalities and establish emergency procedures that give military movements priority access to infrastructure.

The package also recognises that speed is an engineering problem. The Commission and member states identified around 500 hotspot projects on four priority corridors, including bridges requiring reinforcement, tunnels requiring widening and ports or airports needing greater capacity. The 2021-2027 Connecting Europe Facility allocated approximately EUR 1.69 billion to 95 dual-use projects. Demand exceeded available funds, and the Commission proposed EUR 17.65 billion for military mobility in the 2028-2034 budget period.

In June 2026, the Council agreed its negotiating position on the proposed regulation, supporting faster authorisations, more resilient infrastructure and secure access to transport assets. This is significant progress. It is not yet an operational guarantee. Much of the larger funding would begin only in 2028, while the security environment is already deteriorating. The European Court of Auditors previously found complex governance, overlapping responsibilities, a lack of central coordination and inconsistent alignment between project selection and strategic priorities.

The Critical Entities Resilience Directive adds a broader civilian framework. By 17 July 2026, member states were required to identify critical entities across sectors including transport, energy and digital infrastructure. Those entities must assess risk, implement technical and organisational measures and report significant incidents. The regime is valuable because it treats resilience as more than cybersecurity and includes intentional, cross-border and cross-sector threats.

Still, an entity can be critical to civilian life without understanding its role in a classified reinforcement plan. Conversely, a small subcontractor, specialist repair company or software vendor may be essential to military movement without meeting a national threshold for designation. Civil regulation, national security policy, EU transport planning and NATO defence planning remain separate systems that must be deliberately connected.

NATO's July 2026 guidance on public-private cooperation addresses precisely this seam. It calls for standing coordination structures, end-to-end supply assurance, crisis contracts, war-risk and liability arrangements, shared threat information, joint exercises, route-clearance capacity and pre-planned repair. The guidance is detailed and strategically sound. It explicitly creates no new legal obligations. Implementation therefore depends on national law, budgets and the willingness of firms to accept costs before a crisis makes them unavoidable.

The attribution gap is also a deterrence gap

Europe's response to sabotage is often organised as a sequence: police investigate, prosecutors build a case, intelligence services assess foreign direction, governments consider attribution and the EU or NATO discusses a collective response. This protects the rule of law, but an adversary can exploit the time and evidentiary differences between institutions.

Criminal conviction and strategic attribution serve different purposes. A court must establish individual guilt to a demanding standard. A government deciding on sanctions, expulsions, travel restrictions or defensive measures can act on a broader intelligence assessment. Conflating the two allows a campaign to continue until evidence is courtroom-ready; separating them carelessly risks politicised accusation.

Europe needs a standing mechanism that can combine law-enforcement evidence, intelligence reporting, commercial telemetry and allied assessments without exposing sources. The objective is not automatic public attribution after every incident. It is a graduated decision process with shared confidence levels and pre-agreed response options.

Those options should extend beyond statements. Arrests and prosecutions matter because local proxies make the system work. So do asset freezes, sanctions on organisers and enabling entities, diplomatic expulsions, restrictions on intelligence platforms and coordinated disruption of recruitment and payment networks. Where a pattern is established, responses should be cumulative: repeated low-level attacks should not reset the political clock each time.

Deterrence also requires denial. If a damaged rail segment is restored quickly and cargo reroutes without revealing a major delay, the attack yields little strategic return. If operators receive timely warnings and screen suspect parcels without paralysing the network, the sponsor loses leverage. Punishment raises the expected cost; resilience reduces the expected benefit.

Protect the function, not every facility

Europe cannot place military guards at every warehouse or air-defence system beside every terminal. Nor would doing so address cyber compromise, insider access or fragile subcontractors. Protection must begin by defining the functions that must continue and the maximum disruption NATO plans can tolerate.

First, governments and operators should map end-to-end dependencies at an appropriate classification level. A corridor assessment should include not only tracks and bridges but traction power, signalling, fuel, cranes, data systems, workforce access and repair supply chains. Sensitive military routes cannot be published indiscriminately, yet companies cannot prepare for requirements they are never told. Cleared liaison teams and tiered information products can bridge this problem.

Second, redundancy must be exercised rather than assumed. Alternative ports, inland waterways, roads and rail routes should be tested with real loads. Exercises need to include border officials, private dispatchers, energy providers, communications companies, insurers and local authorities - not only headquarters staffs. A route that works on a map may fail because a bridge lacks capacity, a locomotive is unavailable or a commercial contract cannot be activated.

Third, contracts should purchase continuity, not merely peacetime capacity. Agreements need clear crisis triggers, priority rules, liability protection, security requirements, workforce obligations and compensation for maintaining spare capacity. Smaller suppliers may require public support to finance redundant systems or security clearances. Governments cannot expect commercial firms to absorb open-ended war risk while serving civilian customers and shareholders.

Fourth, rapid repair should be treated as a deterrent capability. Pre-positioned bridge components, signalling equipment, power systems, cranes and cyber-recovery tools can reduce outage time. Engineers, railway specialists and utility crews should be integrated into exercises and protected as critical personnel. Repair capacity dispersed across several sites is harder to neutralise than a single national reserve. Fifth, Europe should measure operational resilience. Useful indicators include time to detect disruption, time to attribute at a strategic confidence level, hours required to activate an alternative route, percentage of planned throughput restored within 24 or 72 hours, availability of specialised transport assets and the number of critical suppliers with tested continuity plans. Counts of cameras, fences or designated entities reveal activity, not whether forces can still move.

From infrastructure protection to contested logistics

The deeper shift is conceptual. Europe has traditionally treated military mobility as a peacetime enablement problem: improve bridges, harmonise permits and reduce border delays so units can travel faster. It has treated critical-infrastructure security as a civil-protection problem: prevent incidents and restore essential services. Sabotage connects the two. The network may be physically intact yet strategically unreliable because an adversary can disrupt it at selected moments.

Contested logistics assumes that movement will be observed, digitally probed and periodically attacked before and during a crisis. It asks not only whether a brigade can cross Europe under normal conditions, but whether it can do so when satellite navigation is unreliable, a freight terminal is closed, false warnings circulate online and commercial staff fear becoming targets. It treats delay as an operational effect.

This approach also changes secrecy. Concealing every route is unrealistic in a commercially visible system. Trains, ships and convoys leave signatures; contractors and local authorities require notice. Security should combine operational discretion with structural unpredictability: several usable corridors, variable schedules, dispersed staging, rapid substitution and deception about which nodes are indispensable.

The same logic applies to political signalling. NATO need not label every act an armed attack to make clear that persistent sabotage is strategically consequential. Article 3 resilience, national counterintelligence, EU law and collective diplomatic or economic measures provide a wide response space below Article 5. Using that space consistently is essential. If Europe treats each deniable incident as isolated crime, the sponsor enjoys campaign-level effects while facing incident-level consequences.