/

Europe’s Shadow War: Proxy Violence and Hybrid Threats Surge Across the Continent

A wave of low-cost attacks and covert operations linked to Iran and Russia is testing Europe’s security, resilience, and political cohesion

4 mins read
[Image: European Parliament]

Europe is confronting a rapidly evolving security crisis as hybrid threats—ranging from proxy violence to cyberattacks—spread across the continent, exposing deep vulnerabilities in national defenses and social cohesion. A recent stabbing in London has become the latest flashpoint in what analysts warn is a broader campaign of low-cost, deniable aggression tied to geopolitical tensions stemming from the U.S.-Israeli-led war on Iran. According to research from The Soufan Center, these developments reflect a dangerous convergence of tactics long used by Russia and now increasingly adopted by Iran.

The attack in Golders Green, a predominantly Jewish area of north London, left two men injured and was quickly classified as a terrorist incident by authorities. While investigations into the motive are ongoing, the assault fits a growing pattern of antisemitic violence and asymmetric activity seen across Europe since the escalation of conflict in the Middle East. This trend has unfolded alongside a broader rise in both antisemitism and Islamophobia in Western societies following the October 7, 2023 attacks by Hamas.

Security officials and analysts say the evolving threat landscape is increasingly defined by the use of proxy actors—often recruited online and drawn from marginalized or criminal backgrounds—to carry out attacks that are inexpensive, difficult to trace, and strategically disruptive. These so-called “disposable agents” allow state actors to maintain plausible deniability while amplifying fear and instability within targeted communities.

In the United Kingdom alone, authorities have identified a sharp rise in suspected Iran-linked plots. Ken McCallum revealed that more than 20 potentially lethal Iran-backed schemes had been tracked within a single year. In one recent case, British police arrested individuals allegedly planning to firebomb Jewish targets, a plot widely suspected by experts to have Iranian connections, though definitive proof has yet to emerge.

Adding to the complexity, a little-known group calling itself Harakat Ashab al-Yamin al-Islamia has claimed responsibility for multiple attacks across Europe, including the London stabbing. While these claims remain unverified, the group has also taken credit for incidents in Belgium and the Netherlands, targeting synagogues and Jewish institutions. Experts believe such claims—whether authentic or opportunistic—serve a broader purpose: spreading fear, sowing confusion, and inflaming communal tensions.

European leaders are increasingly alarmed. Keir Starmer has warned of a growing threat from proxy attacks supported by foreign states, while the UK has raised its national threat level to “severe.” Yet Iran is not the only actor shaping this environment. The tactics now appearing across Europe bear a striking resemblance to a hybrid warfare playbook that Russia has refined over years of operations targeting Western societies.

From France to Estonia, Russian-linked activities have included disinformation campaigns, recruitment of local operatives for acts of vandalism, and even attempted assassinations. The Soufan Center’s research indicates a dramatic surge in such incidents, with Russian-linked proxy activity increasing by more than 250 percent across several European countries between 2023 and 2024. In Lithuania, authorities recently charged multiple individuals in connection with attempted killings tied to Russian intelligence, while in the UK, prosecutors have described plots involving foreign nationals recruited to carry out arson attacks.

These operations are designed to impose disproportionate costs on targeted countries. By forcing governments to divert resources toward internal security and counterintelligence, adversaries can weaken their ability to respond to more conventional threats. The cumulative effect is a steady erosion of stability and public confidence.

Beyond proxy violence, the hybrid threat extends into cyberspace and critical infrastructure. Russia, along with Iran and China, has been linked to a series of cyberattacks targeting energy systems, transportation networks, and government institutions across Europe. In Sweden, a heating plant was compromised in a suspected Russian-linked attack, while similar incidents have been reported in Poland, Denmark, and Norway. These operations aim not only to disrupt essential services but also to create a pervasive sense of insecurity.

Military and maritime domains have also become arenas for hybrid confrontation. Russian naval activity in European waters has increased, with frequent incursions and probing maneuvers designed to test NATO’s response thresholds. Despite warnings from Starmer about taking action against Russia’s so-called shadow fleet—used to circumvent sanctions—implementation has been uneven, highlighting the challenges of responding decisively without escalating tensions.

At the same time, European responses have begun to evolve. Joint defense initiatives, including naval cooperation between the UK and Norway, signal a growing recognition of the need for coordinated action. New multinational partnerships are being developed to counter maritime and undersea threats, reflecting lessons learned from years of Russian activity.

However, analysts warn that Europe now faces a dual challenge. As it continues to grapple with Russia’s entrenched hybrid campaigns, it must also confront an expanding Iranian presence that is exploiting the same vulnerabilities. Tehran’s growing use of proxy networks, cyber capabilities, and psychological operations suggests a deliberate effort to replicate and adapt Moscow’s methods.

This convergence is particularly concerning given Europe’s past struggles to respond quickly to emerging threats. Bureaucratic delays, legal constraints, and political divisions have often slowed countermeasures, allowing adversaries to gain momentum. Experts stress that avoiding these pitfalls will be critical as the threat landscape evolves.

Research from The Soufan Center emphasizes the importance of resilience as a key line of defense. Transparent attribution of attacks, where possible, can help counter disinformation and hold perpetrators accountable. Equally important is raising public awareness about common hybrid tactics, enabling communities to recognize and resist manipulation.

As Europe stands at this critical juncture, the stakes are high. The rise of hybrid warfare—blending physical attacks, cyber operations, and psychological strategies—represents a fundamental shift in how conflicts are fought. No longer confined to distant battlefields, these confrontations are unfolding within European cities themselves, targeting civilians, institutions, and the very fabric of society.

The challenge for European governments is not only to respond to individual incidents but to adapt to a new era of persistent, low-level conflict. Failure to do so risks allowing these shadow wars to intensify, further destabilizing a continent already under strain from geopolitical rivalries and internal divisions.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog