Sittings · Document

DRAFT REPORT (2026/2024(INI)) 2026-05-08

On hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure

Committee on Security and Defence · Rapporteur: Rasa Juknevičienė

MOTION FOR A EUROPEAN PARLIAMENT RESOLUTION

on hybrid warfare and the protection of the EU’s territorial integrity and critical security and defence infrastructure

(2026/2024(INI))

The European Parliament,

having regard to the UN Charter and the fundamental principles of international law,

having regard to the Treaty on the Functioning of the European Union (TFEU),

having regard to Title V of the Treaty on European Union (TEU), in particular Chapter Two, Section Two thereof on provisions on the common security and defence policy,

having regard to Articles 42(7) and 222 TEU,

having regard to its previous resolutions on Ukraine, Russia and Belarus, in particular those adopted since Russia’s annexation of the Crimean Peninsula in February 2014 and Russia’s full-scale invasion of Ukraine in February 2022,

having regard to the international legal framework for preventing and fighting terrorism, including UN Security Council Resolution 2341 on protection of critical infrastructure against terrorist acts, adopted on 13 February 2017,

having regard to Regulation (EU) 2019/452 of the European Parliament and of the Council of 19 March 2019 establishing a framework for the screening of foreign direct investments into the Union1,

having regard to the ‘Strategic Compass for Security and Defence – For a European Union that protects its citizens, values and interests and contributes to international peace and security’, approved by the Council on 21 March 2022 and endorsed by the European Council on 25 March 2022,

having regard to the Final Assessment Report of 29 June 2023 by the NATO-EU Task Force on the Resilience of Critical Infrastructure,

having regard to the report of 30 October 2024 by Sauli Niinistö entitled ‘Safer Together – Strengthening Europe’s Civilian and Military Preparedness and Readiness’ (Niinistö report),

having regard to the joint communication from the Commission and the High Representative of the Union for Foreign Affairs and Security Policy of 21 February 2025 entitled ‘EU Action Plan on Cable Security’ (JOIN(2025)0009),

having regard to the Commission communication of 18 February 2026 on the EU’s eastern regions bordering Russia, Belarus and Ukraine (COM(2026)0082),

having regard to the joint white paper from the Commission and the High Representative of the Union for Foreign Affairs and Security Policy of 19 March 2025 entitled ‘Joint White Paper for European Defence Readiness 2030’ (JOIN(2025)0120),

having regard to its resolution of 12 March 2025 on the white paper on the future of European defence2,

having regard to its resolution of 9 October 2025 on a united response to recent Russian violations of the EU Member States’ airspace and critical infrastructure3,

having regard to its resolution of 21 January 2026 on the implementation of the common security and defence policy – annual report 20254,

having regard to its resolution of 18 December 2025 on the continuous Belarusian hybrid attacks against Lithuania5,

having regard to the Council conclusions of 16 March 2026 on advancing the European Union’s capacity to counter hybrid threats,

having regard to Rule 55 of its Rules of Procedure,

having regard to the report of the Committee on Security and Defence (A10-0000/2026),

A. whereas the intensity and scope of hybrid attacks against the EU have escalated significantly since the start of Russia’s war of aggression against Ukraine, with incidents repeatedly linked to Russia, Belarus, China, Iran and North Korea;

B. whereas the severity of these attacks has increased drastically, representing a blatant violation of Member States’ sovereignty, the EU’s territorial integrity and international law;

C. whereas hostile state actors target the EU’s territorial integrity on two fronts: through direct physical attacks against Member States and through political operations aimed at engineering Member States’ withdrawal from the EU;

D. whereas these attacks aim to create chaos, destabilise the political situation in the Member States, sow fear and public distrust among EU citizens, test defence readiness and weaken the EU’s support for Ukraine;

E. whereas EU Member States have so far failed to develop a coordinated and coherent response to hybrid attacks;

F. whereas sabotage activities are increasingly being carried out using intermediaries, proxies and ‘disposable agents’, thereby complicating attribution and response;

G. whereas significant increases in Member States’ defence spending, in combination with the EU’s defence initiatives, are beginning to address long-standing capability shortfalls, but a faster translation into concrete operational capabilities is needed to better protect the EU and its citizens against hybrid attacks;

Hybrid warfare: between war and peace

1. Affirms that hybrid operations are continuous, coordinated attacks carried out by state and non-state actors across multiple domains; stresses that they are designed to resemble isolated incidents in order to stay below the threshold of armed conflict, while producing effects comparable to those of conventional aggression;

2. Underlines that the primary objective of hybrid warfare is to erode the EU’s defence readiness by disrupting its defence industrial base and critical infrastructure, undermining public and political support for EU defence, and installing governments favourable to the perpetrators through systematic interference in democratic processes;

Information warfare and cognitive security

3. Underlines that information warfare is one of the core elements of hybrid warfare; expresses concern at the growing scale of foreign information manipulation and interference (FIMI), which aims to erode trust, polarise societies and undermine public support for European security and defence, including support for Ukraine; highlights that AI tools – deepfakes, algorithmic amplification and automated account networks – are making such influence operations faster, cheaper and harder to detect;

4. Notes that the EU’s response to FIMI remains largely reactive and insufficiently operational, due to the lack of permanent real-time monitoring, attribution and response capabilities; insists that FIMI must be treated as a serious security threat requiring an operational approach, including early detection, predefined response options and stronger protection of democratic processes;

5. Calls on the Member States to adopt whole-of-government and whole-of-society approaches, prioritising resilience and preparedness as emphasised in the Niinistö report; urges the Member States and calls for the EU institutions to invest in democratic resilience;

Critical infrastructure

6. Condemns the hybrid warfare attacks targeting the EU’s critical infrastructure; welcomes the focus on the protection and resilience of military mobility infrastructure in the Commission proposal for a regulation on military mobility (COM(2025)0847); calls on the Member States to take adequate measures to ensure this infrastructure is protected;

7. Is concerned about the EU’s dependence on high-risk non-EU countries, particularly China, for the supply of network-connected hardware and software; stresses the urgent need to address these vulnerabilities and calls on the Commission to extend supply chain security assessments systematically, across all critical infrastructure sectors, and to accelerate efforts to reduce such strategic dependencies;

8. Stresses that submarine cables represent a key strategic vulnerability; commends the 2024 Commission Recommendation on Secure and Resilient Submarine Cable Infrastructures6 and the 2025 Joint Communication of the EU action plan on cable security as important first steps towards strengthening the security and resilience of submarine cables;

9. Recognises that a significant share of critical infrastructure linked to essential public services and military capabilities is privately owned or operated; calls for permanent and structured public-private cooperation frameworks to be established, including for information sharing, contingency planning and coordinated crisis response; calls for defence requirements to be systematically integrated into civilian infrastructure planning, design and funding as a condition for EU support;

From fragmentation to coordinated and decisive response

10. Notes that the sovereignty and territorial integrity of all Member States are foundational principles of the EU; considers that the EU must move from a reactive to a proactive strategy that credibly raises the cost of hostile action; stresses that any violation of Member States’ sovereignty must be met with immediate retaliation; calls on the Commission and the Council to develop a cross-domain action plan against hybrid warfare, including calibrated EU retaliatory options proportionate to the severity of hostile activities and clear response chains complementing those of NATO; calls on the Member States, in coordination with NATO allies, to review rules of engagement across all threat domains in order to ensure timely and adequate responses to attacks on their sovereignty or critical infrastructure;

11. Highlights the EU’s unique added value in aggregating cross-border data to detect patterns of coordinated hybrid campaigns that no Member State can identify on its own; calls for this cross-border pattern-recognition function to be formally recognised as a core EU competence; insists that a permanent Russian crisis cell be established; believes that intelligence sharing needs to be urgently advanced;

12. Insists on the need to urgently advance towards a genuine European Defence Union, complementing NATO;

13. Stresses that a range of Russia’s hybrid activities against the EU amounts to state-sponsored terrorism; encourages the Member States to use all available legal tools to counter them, including the solidarity clause (Article 222 TFEU); regrets that while the solidarity clause has been operationalised, it has never been invoked, despite major terrorist attacks within the EU that could have warranted its activation;

14. Calls for both the solidarity clause and the mutual assistance clause (Article 42(7) TEU) to be further operationalised in hybrid and armed aggression scenarios, including through regular exercises simulating their activation; calls on the Commission and the Council to issue guidelines clarifying the conditions and procedures for activating the mutual assistance clause; calls on the Commission, together with the Member States, to develop a decision-making playbook for severe crisis scenarios, setting out the catalogue of civil and military means and capabilities available to the Governments of the Member States under both clauses, as well as the activation thresholds and the EU institutional roles;

15. Deplores the fact that the EU sanctions framework is fragmented across different hybrid threat vectors, thereby reducing its deterrent effect; calls for the immediate establishment of a horizontal EU sanctions framework, specifically designed for hybrid threats; calls for the EU FIMI Toolbox to be strengthened;

16. Welcomes the Commission communication on the EU’s eastern regions bordering Russia, Belarus and Ukraine, and its explicit recognition that the EU’s eastern border regions face structural and sustained threats from Russia and Belarus; calls on the Commission to translate this recognition into binding security obligations and dedicated funding streams under the 2028-2034 multiannual financial framework;

17. Welcomes the Commission’s announcement of a new global EU security strategy and calls for hybrid warfare to be included in its scope;

EU and NATO coordination and cooperation

18. Reaffirms that NATO remains the cornerstone of collective defence for its members; calls for increased EU-NATO cooperation to strengthen European defence and deterrence;

19. Welcomes NATO’s Hybrid Tracking Mechanism, an intelligence aggregation tool updated monthly via NATO’s Joint Intelligence and Security Division, which provides allies with a consolidated threat picture, drawing on national intelligence services;

20. Stresses the important role of NATO’s Baltic Sentry and Eastern Sentry in responding to hybrid threats within operationally relevant timeframes; notes that their effectiveness is constrained by the high cost of intercepting drones, gaps in situational awareness and the fragmentation of regulatory frameworks across the Member States; calls for the implementation of the EU action plan on drone and counter-drone security7 to be accelerated and for its systematic alignment with NATO operational requirements, ensuring harmonised, adequately resourced counter-drone capabilities across the Member States;

21. Calls on the Commission, the European External Action Service and NATO to develop a common definition of hybrid warfare covering sabotage and related activities;

Partner countries: cooperation and support

22. Emphasises that strengthened cooperation with Ukraine, Moldova, Armenia and the EU’s Western Balkan partners is a strategic necessity, as they act as primary testing grounds for Russia’s hybrid tactics; calls on the Member States to adopt lessons learned from these countries, including Ukraine’s capacity to maintain essential services and societal functioning under sustained attack; welcomes the EU’s active contribution to supporting their resilience to hybrid attacks;

23. Commends Moldova’s whole-of-government response to Russian FIMI ahead of its 2025 elections as an operational model, including its use of law enforcement action against networks conducting hybrid operations on behalf of a foreign state power; calls on the Member States and the Commission to develop EU-level frameworks enabling comparable enforcement responses;

24. Notes Taiwan’s extensive experience in defending itself against China’s hybrid attacks; calls for stronger cooperation, in this regard, on countering FIMI and the sabotage of undersea cables;

°

° °

25. Instructs its President to forward this resolution to the Council and the Commission.