The State of Threats: A European View of What We Will Not Escape…

Author :

Pierre Brunet

10/05/2026

© Pixabay – Cyber attacks become more and more important

 

On July 1, Nouveau Monde éditions published « L’état des menaces 2026-2027 », an unusual book compiling reports from European intelligence bodies that analyze the threats we face and will face, whether we like it or not. The publication is significant for two reasons. First, it is a concrete expression of Europe’s ambition for strategic autonomy, at least in intelligence and analysis: until recently, CIA reports were the reference in this field. Second, the decision by the European authorities concerned to publish these reports is in itself a combative gesture: to name the threat is already to respond to it.

 

The agencies whose analyses are included come from Italy (AISE, AISI, DIS), the Netherlands (AIVD, MIVD), Denmark (FE), the United Kingdom (MI6), Sweden (MPF), Latvia (VDD), Estonia (VLA), and Europe (Europol, ENISA, the European Union Agency for Cybersecurity). For France, they are the DGSI (General Directorate for Internal Security), ANSSI (National Cybersecurity Agency), IRSEM (Institute for Strategic Research of the École Militaire), and VIGINUM (Service for Vigilance and Protection against Foreign Digital Interference). An American NGO, EPIC, specializing in data protection and digital freedoms, and a Czech think tank, the European Values Center for Security Policy, specializing in the fight against disinformation and foreign influence, are also cited. The whole sometimes looks like a heterogeneous assembly of disparate pieces, but an overall coherence emerges over the course of the reading.

 

© ANSSI – Technical Laboratory of the French National Agency for the Security of Information Systems

 

The book details a large number of threats across many domains. Here we summarize the most crucial ones, following the distinction between « systemic » threats and threatening actors.

 

 

Systemic threats

 

The European services consider a specific set of threats to be « priorities »: hybrid and cyber threats, critical infrastructure, organized crime, foreign interference and informational manipulation (including electoral manipulation), and economic and technological espionage, including in the defense sector. This comes in a context where « taboos » are falling, such as the prospect of an open conventional war between NATO and Russia, which is now openly contemplated. More broadly, as Blaise Metreweli, head of Britain’s MI6 (the external intelligence service), sums it up: « We are now operating in a space between peace and war… Some algorithms are becoming as powerful as states… Our world is being reshaped, and for the first time, we are all at the heart of this process. »

 

Crime

 

At the forefront of the fight against all forms of crime, EUROPOL (the European Union Agency for Law Enforcement Cooperation) has produced an exhaustive report on the evolution of organized crime. Its opening finding: « organized crime is progressively destabilizing our societies, is increasingly feeding online, and is being strongly accelerated by AI and other new technologies. » According to EUROPOL, AI, blockchain, and soon quantum computing act as catalysts, accelerators, and engines of crime. They allow unprecedented scale, sophistication, concealment, and speed, and they bring minors within reach of criminal organizations, whether as consumers or prey, or as perpetrators (for example, hitmen whose sponsors cannot be traced). They create the opportunity to develop a « crime-as-a-service » model, that is, the commission of crimes, cyberattacks, or sabotage on demand and for payment, thanks to encrypted systems, cryptocurrencies, evolving digital front companies, and the Dark Web. (We will return to the specific case of AI below.) This commodification of crime as a service allows hybrid threat actors to « subcontract » hostile actions with no possibility of tracing the « client, » and blurs the line between state and non-state actors and between profit-driven, ideological, and even strategic motivations. Moreover, EUROPOL stresses that data has become « an essential commodity that is increasingly stolen, traded, and exploited by criminal networks or hybrid threat actors (for instance hitmen whose client cannot be traced back)

© Flickr – More and more cyberattacks are occurring around the world

Finally, according to EUROPOL, the sophisticated money-laundering systems that crime employs are driving a rise in corruption and undermining our societies, filling in and « blurring » the gap between the licit and the illicit. The infiltration of the legal economy by the illegal one makes the latter more resilient and erodes the foundations of the former. As Roberto Saviano, the great Italian writer and specialist on the Mafia who lives under protection, put it in a recent interview: « It is not only the mafias that have capitalized, it is capitalism that has become mafia-ized. Criminal organizations are no longer the foreign body attacking the legal economy. They are the most reliable liquidity provider on the market: they ask for no guarantees, they pay in cash, and in a crisis, they arrive before the banks. And the legal economy has stopped asking where this money comes from. »

 

 

Terrorism

© Evelyn Arleth – The use of drones by jihadist groups in the Sahel region is very common

For the VDD (Latvia’s State Security Service), everything indicates that « the terrorist threat remains constant » for European countries. Beyond that, according to the VDD, Hamas is prepositioning supporters and weapons caches for planned actions in Europe. The use of drones, remote-controlled devices, and the Internet/AI as a recruitment tool and a means of creating and spreading targeted propaganda (but also as a tool for planning and executing attacks, even for anticipating the authorities’ response) has now been adopted by terrorist groups. The VDD identifies the Sahel region as « the world’s main hub of terrorism, » which represents « a serious threat to European countries and Western citizens for the foreseeable future »; finally, conflicts in the Sahel risk « encouraging a larger influx of migrants from third countries to Europe. »

 

The concerns of the Latvian VDD echo those of the Italian intelligence community (the AISE, AISI, and DIS agencies) on the impact of destabilization in the Sahel (« one of the main operational nodes of global jihadism« ), the Horn of Africa, and Libya. The Italians add the Middle East, Gaza, the Houthis of Yemen and, to a lesser degree, the « Afghan area, still the main refuge for national and international jihadist groups. » The Italian agencies also underline the increase in the « risk arising from Hamas activities on European soil » and warn of a rise in antisemitism that is « increasingly international and cutting across different extremist ideologies, » with a twofold risk of attacks and of « the trivialization and normalization of fear. »

 

The « Youth bulge »

 

The Italian services pay particular attention (the country is on the front line of migrant arrivals…) to the demographic threat arising from Africa, namely the « youth bulge »: a massive widening of the base of the age pyramid (the young), in a context of strong instability in sub-Saharan and tropical Africa, combined with growing urbanization… and with an inability of national institutions and markets to absorb this expansion and meet its needs (education, health, work, resources…). The result: over the next five years, strong volatility will affect our southern and eastern neighborhood, driving and amplifying migration flows toward our countries and multiplying opportunities for hostile actors to interfere in our societies. According to the Italian agencies, this could extend over one or two decades. We may note that this summer’s « submersion » of the Spanish enclave of Ceuta from the Moroccan shore, whether spontaneous or organized, illustrated this outlook and served as a « trailer » for more uncontrollable scenarios in the future.

Cyberthreat

 

Perhaps slightly behind the services of the Baltic countries, which have been on the front line of these dangers for several decades, France’s ANSSI (National Cybersecurity Agency) states plainly the prospect it is preparing for: « A massive increase, by 2030, in so-called ‘hybrid’ attacks, of which cyberattacks form a major part, with concrete and even destructive effects on our critical infrastructure, in parallel with a major deployment of the French armed forces outside the national territory. » And again: « …the boundaries that traditionally exist between state actors and cybercriminals have continued to erode… A technological and organizational fog is taking hold as a consequence of more pronounced capability sharing between these actors. » ANSSI thus writes that it must « look through a smokescreen. » The agency also notes the increase in « ransomware » attacks and in « data exfiltration/compromise, » and warns of the growing vulnerability of « Cloud » data storage environments used by public services, companies, and organizations.

 

 

The (big) problem with AI

 

We have addressed AI as an accelerator and multiplier of crime and terrorism; other threats linked to this « new frontier » are cited by the European agencies:

 

  • ENISA (the European Union Agency for Cybersecurity) is concerned about the growing use of generative AI as « bait, » through fraudulent sites used to spread malware. Moreover, ENISA notes the first signs of consumer AI models being hijacked through intrusion for malicious purposes.
  • ENISA also warns of « the emergence of autonomous malicious AI systems since the beginning of 2025. » This is a terrifying anticipation of a criminal, autonomous AI, beyond control through the mere fact of its « recursive self-improvement, » and it is confirmed by Europol, which stresses that « the emergence of fully autonomous AI could pave the way for criminal networks entirely controlled by AI, marking a new era in organized crime. » The hypothesis of AI-designed pathogens is thus considered in a recent text by Jakub Pachocki, chief scientist at OpenAI, who warns: « AI is more integrated than expected… its functioning escapes us, and some (AI) agents will continue to pursue their own objectives »…
  • Finally, although these threats are not cited in the book (probably because for now they mainly affect the United States), the risk of « AI riots » is growing, with violent revolts against the massive job losses increasingly caused by AI fused with robotics, and physical attacks targeting data centers and various installations, which, moreover, provoke rejection from environmental movements because of their enormous electricity and water consumption.
© Anderseidesvik (Wikimedia Commons) – Activists from the group « Stop AI » protest outside OpenAI’s headquarters in San Francisco on September 26, 2025

The end of the war in Ukraine: when peace is an opportunity for criminal networks

 

EUROPOL details a particular threat that is rarely discussed: the end of the Russo-Ukrainian conflict as an opportunity for criminal actors. The agency observes that « the war has fostered the widespread proliferation of weapons, which will persist even after an agreement is concluded. The demobilization of military forces will lead to surplus weapons being diverted to the black market, exacerbating security challenges across Europe and beyond. » In addition, according to EUROPOL, « many former soldiers, particularly those facing economic hardship, could turn to organized crime, be offered criminal activities by established criminal networks, or seek to create private military organizations. » The agency also stresses that, in the prospect of large-scale reconstruction of Ukraine with foreign capital, « recovery funds could provide fertile ground for criminal networks to flourish… the risk of corruption and financial crime is heightened. » Finally, according to EUROPOL, a Russo-Ukrainian peace could lead either to cooperation between Russian and Ukrainian criminals, notably networks that have developed cybercriminal ecosystems, or to competition, which would exploit vulnerabilities linked to economic reconstruction and demilitarization.

 

Threatening actors

 

Russia

 

For the AIVD (the General Intelligence and Security Service of the Netherlands), « In Russia’s eyes, the war in Ukraine is clearly part of a broader, existential conflict with the West. » It is « a conflict between two opposing and irreconcilable worldviews, based on contradictory systems of values and norms: the perverse and decadent West against unique Russian civilization. » Russia is presented by its authorities as « a separate civilization, endowed with a messianic mission, » and they consider that « the West is trying to detach countries like Ukraine from Russia, to integrate them into Western institutions such as NATO and the EU, and is thereby advancing toward Russia’s borders. » Ukraine’s NATO membership is « out of the question » for Moscow. To « resist » the Western enterprise, Putin is « prepared to pay a high price » (human and economic losses), and, while Europe invests to prepare for a possible military escalation with Russia, « the Kremlin sees these investments as confirmation of Europe’s offensive and hostile ambitions. » The mirrored logical trap is perfect…

© NATO – 2025 NATO Summit in The Hague, during which the issue of Chinese and Russian hybrid threats was addressed

In this context, VIGINUM, France’s Service for Vigilance and Protection against Foreign Digital Interference, has published a report on the activity of a Russian IOM (Informational Operating Mode) known as Storm-1516. This group of cyberactivists, linked to the GRU (Russian military intelligence), works to discredit the Ukrainian government. Storm-1516 has also been identified as targeting various elections in Europe and even in the United States, with the aim of manipulating information, weakening certain candidates or parties, and supporting those favorable to Russian interests.

 

The VLA (Estonia’s foreign intelligence service) highlights the GRU’s action in another area, Russia’s circumvention of Western sanctions. It « plays a significant role in facilitating the entry of sanctioned goods into Russia, » through an elaborate network of import-export shell companies.

 

© LCI – Map of « the Narva downfall » in the 8pm journal

 

But beyond that, one subject stands out: Russian sabotage, which is crossing an alarming threshold. The Dutch AIVD stresses its increase, and « Russia’s increased propensity to take risks, » which translates into « Russia accepting that acts of sabotage could potentially cause casualties or material damage. » The reason, according to the AIVD, is that the Kremlin holds the West responsible, through its support for Ukraine, for the increase in Ukrainian deep strikes into Russian territory. According to the AIVD, Russia is even allowing itself to go further by « drawing up sabotage action plans aimed at causing loss of life… The plans to assassinate the head of the German arms manufacturer Rheinmetall are a striking example. »

 

Recent examples illustrate the dangerous Russian audacity the AIVD describes: the discovery of a drone fitted with an explosive device on the tarmac of Germany’s Leipzig/Halle airport, on the night of August 4 to 5, right next to an aircraft of the Ukrainian cargo company Antonov Airlines, an action clearly attributed to Russia on September 1 by the German Interior Minister and Foreign Minister. Céline Berthon, Director General of France’s DGSI, stated on this occasion: « The discovery of an explosive drone in Leipzig, which in all likelihood was meant to target an aircraft intended to support the Ukrainian army, is a signal that we must consider more direct and violent hostile actions as possible on our national territory. »

 

Another case: the Bundeswehr’s Mechernich military site in Germany spotted two drones on August 6. At this site, equipment is stored in a deep underground depot, and it also houses elements of the American Patriot air defense system, designed to intercept cruise and ballistic missiles as well as aircraft… Beyond retaliatory measures, Germany is drawing conclusions from these events: the chairman of the German parliamentary intelligence oversight committee recently proposed authorizing the Federal Intelligence Service and the Federal Office for the Protection of the Constitution to carry out preventive cyberattacks against Russian factories producing unmanned aircraft… And on September 2, the German navy tested an Israeli-made LORA ballistic missile, which would give it a new long-range strike capability…

© Fastboy (Wikimedia Commons) – Fleet of Russian military ships stationed at Baltiysk, in the Russian exclave of Kaliningrad bordering Lithuania and Poland (2010)

The Baltic zone is where tension with Russia crystallizes (see the excellent account by Alain Boinet, back from these countries, in the previous edition of Défis Humanitaires). For the FE (Denmark’s military intelligence service), « the situation in the region is becoming increasingly tense, with Russia prepared to use its naval and air forces aggressively against NATO countries in order to deter them from taking measures that could challenge its interests »; but, according to the FE, « if such confrontations were to occur, they would not necessarily lead to a full-scale war between Russia and NATO. » Russian military activities and provocations in the area are already becoming increasingly threatening, and Russia « continues to jam GPS signals there, disrupting maritime and air traffic. » The FE anticipates that once the war in Ukraine is over, Russian military capabilities will increase in the Baltic zone, as well as in the North Sea, where the waters between Greenland, Iceland, the Faroe Islands, and the United Kingdom (the GIUK Gap), considered vital by Russia, will see stronger Russian submarine activity; the Kremlin seeks to « restrict the freedom of movement of NATO surface ships, and to sabotage or attack critical undersea infrastructure… In a conflict with NATO, Russia would seek to disrupt supply lines between the United States and Europe by deploying attack submarines capable of crossing the GIUK Gap undetected. » This mapping of the seabed is also being carried out in the Baltic Sea and in Danish waters « in order to identify potential targets for acts of sabotage or attacks against critical undersea infrastructure, such as power and Internet cables, in the event of escalation of the conflict or war with NATO. » Finally, the Arctic region, strategic for the United States, Russia, and China alike, is becoming a zone of growing competition and confrontation. Russia, still the strongest military power in the region, « has continued to expand its military infrastructure there and modernize its forces, » but faces increasing competition from America and Europe. According to the FE, China, in order to gain access to maritime routes and natural resources, is taking advantage of this race to ally with Russia and make it its « gateway » to the region.

 

By way of illustration, the Reuters agency revealed that recently, a joint operation by the United States, Norway, and the United Kingdom near Norway’s Svalbard archipelago in the Arctic « confronted » Russian submarines that were conducting a training exercise for an attack on sensitive cables with a « secret weapon, » and led to the Russian units leaving the area.

 

One interesting point: Russian President Putin invokes the Great Patriotic War (World War II) against Nazism to justify the war in Ukraine and against the West, and at the same time, Blaise Metreweli, head of Britain’s MI6, invokes the audacity of the SOE (Special Operations Executive) against the Nazis during World War II, in connection with the Russian threat we must prepare for. The mirror, again…

 

China

 

According to the MIVD (the Netherlands’ Military Intelligence and Security Service), the world order China wishes to establish « aims to reduce Western influence in the world, particularly that of the United States, but also that of Europe. » To do so, it « uses its economic power to exert geopolitical pressure. » Its unspoken « cooperation » with Russia in the Ukrainian conflict allows it to benefit from the experience of the Russian army, which, in the perspective of the « integration » of Taiwan into the People’s Republic of China, by force if necessary, allows it to « evolve toward high-level armed forces. » The MIVD thus considers that the link China has established between the theaters of operations in Europe and East Asia « means that the threat emanating from China is expanding and intensifying. »

 

But the MIVD stresses that « China is prioritizing the development of military assets such as quantum technology, artificial intelligence, and biotechnology, » specifying that « China is now probably on a par with the United States in cyber capabilities, » and observes « structured Chinese cyber-espionage targeting the Western defense industry. » The leadership position in quantum technologies that China is aiming for could allow it, « within ten to fifteen years, » to develop a computer capable of decrypting all encrypted data, which would give it a decisive advantage over its adversaries.

© Lukasz Kobus (Wikimédia commons) – Tiktok’s CEO Shou Zi Chew during a meeting with European Commission

The Czech think tank European Values Center for Security Policy has published a study on the role and dangers of the Chinese app TikTok, a Chinese weapon of « cognitive warfare, defined by NATO as a new unconventional form of hybrid warfare, in which the human mind becomes the main battlefield. » The think tank stresses that « In the EU, the number of TikTok users has grown so much that, in many countries, elections are won or lost on the Chinese platform, » and observes that « Under the pretext of defending freedom of expression, we allow TikTok’s algorithm to influence our societies from an early age, » and concludes that « democratic societies must recognize the threat, move beyond passive observation, and take proactive and preventive measures to protect their information ecosystems, national security, and electoral integrity. »

 

Economic warfare and conspiracy

 

At the end of the book, two chapters address economic warfare, as well as the threats linked to conspiracy movements and the anti-elite sentiment that often aggregates around them. We do not develop them here.

 

Consequences for humanitarians

 

Humanitarians are by nature immersed in the chaos of the world. Nevertheless, a few warning points found in this book will certainly concern them:

 

Humanitarian organizations will increasingly face the issue of migration and its « weaponization, » as well as drug and human trafficking, prostitution networks, and child sexual exploitation.
They will increasingly face cybercrime (data corruption and theft, notably through use of the Cloud, ransomware aimed at humanitarian organizations, etc.), and the risk of disruption to communication capabilities.

 

They will increasingly face the excesses of AI, « deepfakes, » and the manipulation of information about their own positions and decisions.

 

They will increasingly face, in post-emergency situations, fighter demobilization, and reconstruction, the risks of corruption and expanding crime.

 

Finally, by way of conclusion, humanitarian organizations will not be able to avoid a thorough overhaul of their approaches, « processes, » and protocols, in a world that openly considers scenarios of open war between NATO and Russia (possible, according to French Chief of the Defense Staff General Mandon, by 2029-2030), and in which their place and role will then need to be reaffirmed…

 

Pierre Brunet

Biography

Pierre Brunet

Pierre Brunet is a novelist and Vice-President of the NGO SOLIDARITES INTERNATIONAL. He became involved in humanitarian work in Rwanda in 1994, then in Bosnia in 1995, and has since returned to the field (Afghanistan in 2003, Calais Jungle in 2016, migrant camps in Greece and Macedonia in 2016, Iraq and North-East Syria in 2019). Pierre Brunet’s novels are published by Calmann-Lévy: “Barnum” in 2006, “JAB” in 2008, “Fenicia” in 2014 and “The triangle of uncertainty” in 2017. A former journalist, Pierre Brunet regularly publishes articles of analysis, opinion, or columns.

Our latest articles