Likelihood, two years4Likelyto end-2028
Likelihood, ten years5Highly likelyto end-2036
Systemic impact2Moderateglobal
National impact3Significanttypical highly exposed nation
OnsetGradual (months)
Duration (acute phase)1 year
Warning timeMonths
ScopeNational (regional cluster)
Recovery horizonYears
Capability loadHard 2/3Soft 2/3Economic 0/3domains loaded High
ConcurrencyStandalonetriggers 3 · triggered by 2
Confidence · movementmediumnew

Rated at Standard Severe. Likelihood type: idiosyncratic (clustered). Source of scores: ginc-desk-v0.2.

03Narrative

Dateline: November 2027

Nothing in the campaign is an act of war on its own. A data cable to the islands is cut by a dragging anchor; the ship's owner is a company registered six weeks earlier. Drones close the capital's airport for four hours twice in a month. A warehouse fire destroys a defence subcontractor's inventory; the arsonists were recruited on a messaging app for the price of a used car. GPS fails across the eastern region for days at a time, and the farmers' autosteer, the ambulances' dispatch and the airport's approach procedures fail with it. Migrants are bused to the border by a neighbouring government and the images are amplified by accounts that did not exist a month earlier. Each incident is investigated, attributed with 'high confidence' weeks later and answered with a sanctions designation. The public argument is whether the government is doing enough or exaggerating; both sides are supplied with evidence. Allies consult under Article 4 and agree to a statement. The campaign's purpose is not any single effect; it is the demonstration that the state cannot protect ordinary life, and that the alliance will not act on what it cannot prove.

The dateline is illustrative, not a forecast. The narrative is hypothetical; the historical anchors below are real events.

04Summary

A hostile state runs a sustained, deniable campaign below the threshold of war: sabotage of subsea cables and energy assets, drone incursions, GNSS jamming, arson and parcel incendiaries, assassination plots, cyber intrusions, instrumentalised migration and information operations, over 12 months. v0.2 added this as the publishable form of state aggression; conventional invasion stays out of the public Library. Eurasia Group's Top Risk 5 for 2026 ('Russia's second front') and the UK National Risk Register's state-threats theme describe the same pattern.

05Historical anchors

EventDateWhat happenedCalibrates
Baltic subsea cable damage17–18 November and 25 December 2024C-Lion1 and BCS East–West cables, then Estlink 2; the Eagle S detained by Finlandcable sabotage
Drone incursions into Poland9–10 September 2025Around 20 drones entered Polish airspace; some shot down; NATO Article 4 consultationsair incursions
Danish and Norwegian airport closuresSeptember 2025Drone sightings closed Copenhagen and other airportscivil aviation disruption
DHL parcel incendiariesJuly 2024Incendiary devices in air cargo in Leipzig and Birminghamsabotage of logistics
Nord Stream sabotageSeptember 2022Pipelines destroyed in the Balticenergy infrastructure
Belarus–Poland border2021Migrants flown in and pushed to the EU borderinstrumentalised migration

06Parameters

Shown at their preset values. Parameters are not adjustable in this release and nothing on this page is computed from them. Custom settings run (Phase B) but are labelled 'non-standard run' and excluded from comparisons.

Common sliders at Standard Severe · read-only

1. Severity
majorsevere (Standard Severe)extreme
2. Duration (acute phase)
30 days90 days1 year (Standard Severe)3 years5 years
3. Onset
suddenrapid (weeks)gradual (years) (Standard Severe)
Standard Severe: gradual (months)
4. Warning time
nonedaysmonths (Standard Severe)
5. Scope
national (Standard Severe)regionalglobal
Standard Severe: national (regional cluster)
6. Origin
naturalaccidentaladversarial (great power / neighbour / non-state) (Standard Severe)
Standard Severe: adversarial (great power or neighbour)
7. External support
fullpartial (Standard Severe)none
8. Concurrency
standalone (Standard Severe)plus one named scenarioplus two
9. Policy response assumed
none (pure exposure)current plans executed (Standard Severe)best practice
Standard Severe: current plans
10. Recovery horizon
monthsyears (Standard Severe)structural

Scenario-specific parameters · read-only

ParameterDefaultRange or optionsNote
Vectors active52–8—
Attribution clarityambiguousoptions: clear—
Kinetic threshold crossedno—Yes at Extreme
Alliance responseconsultationoptions: collective measures / none—
Campaign duration12 months6–36—
Domestic proxy recruitmenton——

07Transmission channels

  1. Incidents degrade infrastructure and services piecemeal.
  2. Attribution lag prevents proportionate response.
  3. Information operations convert each incident into political division.
  4. Security services are stretched across vectors.
  5. Alliance cohesion is tested by the gap between evidence and action.
  6. Deterrence erodes as incidents go unanswered.

08Capability loading

High: capability band shifts expected under current plans. Medium: band shifts under 'none' policy response only. Low: strain without band shift. Loads are judgement-based until the Atlas connects. Domains link to the Atlas.

DomainLoadChannel
Hard
Defence and securityHighair defence against drones, counter-intelligence, maritime surveillance
Strategic infrastructureHighcables, pipelines, grid, airports, GNSS dependence
Critical technologyMediumGNSS alternatives, cyber defence
Soft
Government effectivenessHighattribution, legal tools, crisis communication, inter-agency coordination
Human capitalLowpublic anxiety; emergency services strain
Influence and cohesionHighinformation integrity, social trust, alliance diplomacy
Economic
Macro-financialLowinsurance and risk premia
Industry, trade and supplyMediumlogistics disruption
Energy and resourcesMediumenergy asset sabotage

09Stakeholders

Government

Relevance 5/5
Exposure
Protection of undersea and energy assets, attribution speed, legal thresholds
Actions
  • A single hybrid-response doctrine
  • Pre-authorised responses
  • GNSS backup
  • Whole-of-society communication
Watch
  • Incident counts by vector
  • Attribution lag

Technology

Relevance 4/5
Exposure
Cables, data centres, telecoms, GNSS-dependent services
Actions
  • Route diversity
  • PNT resilience
  • Insider-threat programmes
Watch
  • Cable faults
  • Jamming maps

Investors

Relevance 2/5
Exposure
Infrastructure and insurance
Actions
  • Price sabotage into infrastructure assets in exposed regions
Watch
  • War-risk and sabotage exclusions

Public

Relevance 3/5
Exposure
Service disruptions and disinformation
Actions
  • 72-hour household preparedness (the EU standard)
Watch
  • Official incident advisories

10Regional exposure

RegionExposureRationale
North AmericaLow—
EuropeHighThe active theatre
ChinaLowLow as target
Indo-PacificMediumTaiwan's cables; Philippine waters
South AsiaMedium—
Gulf and Middle EastMediumProxy and drone warfare
AfricaLow—
Latin America and CaribbeanLow—
Russia and EurasiaMediumUkraine's strikes; Moldova, Georgia, Armenia as targets

11Early-warning indicators

IndicatorSourceThreshold
Subsea cable fault countsICPC—
GNSS interference mapsgpsjam.org, EASA—
Drone incursion reports——
Sabotage and arson prosecutions linked to foreign services——
Article 4 consultations——
Coordinated inauthentic behaviour takedownsplatform transparency reports—
Border crossing anomalies——

12Compounds

Triggers
Triggered by
Amplifying trends
polarisationinfrastructure ageingGNSS dependenceplatform-mediated information
Key trends

From the GINC 250: trends rated Very high or Critical for this scenario. All S06 trend scores.

13Rating rationale

RatingBand or levelWhy
Likelihood, two years4LikelyFor a given nation in the exposed cluster (Europe, Baltic and Nordic states, Moldova, Taiwan); the global per-nation base rate is lower, and the Edition should show the cluster explicitly.
Likelihood, ten years5Highly likely—
Systemic impact2ModerateDiffuse.
National impact3SignificantErosion rather than collapse, but persistent.
ConfidencemediumAttribution limits the evidence base.

Source of scores: ginc-desk-v0.2. Confidence refers to the rating, not the scenario. Calibration sources are listed with the anchors above and on the methodology page.

14Open questions

Contested assumptions for the panel to resolve.

  • Whether the likelihood should be published per cluster rather than per nation.
  • Whether cyber intrusions belong here or in S12 when they are part of a campaign.
  • How to rate a nation that is the campaign's author rather than its target.

15Commentary

No signed commentary in this build.

16Version and citation

Version
0.2.0 · active
Change log
0.2.0 · 2 October 2026 · Entered the Library at v0.2 with GINC desk scores.
Full change log
Cite asGINC (2027). Scenario S06 Hybrid campaign by a hostile state, Scenario Library v0.2. scenarios.ginc.org/library/hybrid-campaignContent and data are published under CC BY 4.0.