{
  "id": "S06",
  "slug": "hybrid-campaign",
  "title": "Hybrid campaign by a hostile state",
  "version": "0.2.0",
  "status": "active",
  "orientation": "downside",
  "family": "B",
  "short_title": "Hybrid campaign",
  "thematics": [
    "resilience-crisis-preparedness",
    "ai-cyber-digital",
    "information-integrity-social-cohesion"
  ],
  "likelihood_type": "idiosyncratic",
  "likelihood_note": "clustered",
  "scores": {
    "likelihood_2y": {
      "band": 4,
      "rationale": "For a given nation in the exposed cluster (Europe, Baltic and Nordic states, Moldova, Taiwan); the global per-nation base rate is lower, and the Edition should show the cluster explicitly."
    },
    "likelihood_10y": {
      "band": 5,
      "rationale": ""
    },
    "impact_systemic": {
      "level": 2,
      "rationale": "Diffuse."
    },
    "impact_national": {
      "level": 3,
      "rationale": "Erosion rather than collapse, but persistent."
    },
    "confidence": {
      "level": "medium",
      "reason": "Attribution limits the evidence base."
    },
    "priority": 12,
    "tier": "II",
    "source": "ginc-desk-v0.2"
  },
  "scorecard": {
    "onset": "gradual (months)",
    "duration": "1 year",
    "warning": "months",
    "scope": "national (regional cluster)",
    "origin": "adversarial (great power or neighbour)",
    "external_support": "partial",
    "policy_response": "current plans",
    "recovery_horizon": "years"
  },
  "summary": "A hostile state runs a sustained, deniable campaign below the threshold of war: sabotage of subsea cables and energy assets, drone incursions, GNSS jamming, arson and parcel incendiaries, assassination plots, cyber intrusions, instrumentalised migration and information operations, over 12 months. v0.2 added this as the publishable form of state aggression; conventional invasion stays out of the public Library. Eurasia Group's Top Risk 5 for 2026 ('Russia's second front') and the UK National Risk Register's state-threats theme describe the same pattern.",
  "narrative": {
    "dateline": "November 2027",
    "text": "Nothing in the campaign is an act of war on its own. A data cable to the islands is cut by a dragging anchor; the ship's owner is a company registered six weeks earlier. Drones close the capital's airport for four hours twice in a month. A warehouse fire destroys a defence subcontractor's inventory; the arsonists were recruited on a messaging app for the price of a used car. GPS fails across the eastern region for days at a time, and the farmers' autosteer, the ambulances' dispatch and the airport's approach procedures fail with it. Migrants are bused to the border by a neighbouring government and the images are amplified by accounts that did not exist a month earlier. Each incident is investigated, attributed with 'high confidence' weeks later and answered with a sanctions designation. The public argument is whether the government is doing enough or exaggerating; both sides are supplied with evidence. Allies consult under Article 4 and agree to a statement. The campaign's purpose is not any single effect; it is the demonstration that the state cannot protect ordinary life, and that the alliance will not act on what it cannot prove."
  },
  "anchors": [
    {
      "shock_id": "baltic-subsea-cable-damage-2024",
      "date": "17–18 November and 25 December 2024",
      "event": "Baltic subsea cable damage",
      "what_happened": "C-Lion1 and BCS East–West cables, then Estlink 2; the Eagle S detained by Finland",
      "calibrates": "cable sabotage"
    },
    {
      "shock_id": "drone-incursions-into-poland-2025",
      "date": "9–10 September 2025",
      "event": "Drone incursions into Poland",
      "what_happened": "Around 20 drones entered Polish airspace; some shot down; NATO Article 4 consultations",
      "calibrates": "air incursions"
    },
    {
      "shock_id": "danish-and-norwegian-airport-closures-2025",
      "date": "September 2025",
      "event": "Danish and Norwegian airport closures",
      "what_happened": "Drone sightings closed Copenhagen and other airports",
      "calibrates": "civil aviation disruption"
    },
    {
      "shock_id": "dhl-parcel-incendiaries-2024",
      "date": "July 2024",
      "event": "DHL parcel incendiaries",
      "what_happened": "Incendiary devices in air cargo in Leipzig and Birmingham",
      "calibrates": "sabotage of logistics"
    },
    {
      "shock_id": "nord-stream-sabotage-2022",
      "date": "September 2022",
      "event": "Nord Stream sabotage",
      "what_happened": "Pipelines destroyed in the Baltic",
      "calibrates": "energy infrastructure"
    },
    {
      "shock_id": "belarus-poland-border-2021",
      "date": "2021",
      "event": "Belarus–Poland border",
      "what_happened": "Migrants flown in and pushed to the EU border",
      "calibrates": "instrumentalised migration"
    }
  ],
  "parameters": {
    "common": {
      "severity": {
        "major": "major",
        "severe": "severe",
        "extreme": "extreme"
      },
      "duration": {
        "major": null,
        "severe": "1 year",
        "extreme": null
      },
      "onset": {
        "major": null,
        "severe": "gradual (months)",
        "extreme": null
      },
      "warning": {
        "major": null,
        "severe": "months",
        "extreme": null
      },
      "scope": {
        "major": null,
        "severe": "national (regional cluster)",
        "extreme": null
      },
      "origin": {
        "major": null,
        "severe": "adversarial (great power or neighbour)",
        "extreme": null
      },
      "external_support": {
        "major": null,
        "severe": "partial",
        "extreme": null
      },
      "concurrency": {
        "major": null,
        "severe": "standalone",
        "extreme": null
      },
      "policy_response": {
        "major": null,
        "severe": "current plans",
        "extreme": null
      },
      "recovery_horizon": {
        "major": null,
        "severe": "years",
        "extreme": null
      }
    },
    "specific": [
      {
        "name": "Vectors active",
        "default": "5",
        "range": "2–8",
        "unit": null,
        "note": null
      },
      {
        "name": "Attribution clarity",
        "default": "ambiguous",
        "range": "options: clear",
        "unit": null,
        "note": null
      },
      {
        "name": "Kinetic threshold crossed",
        "default": "no",
        "range": null,
        "unit": null,
        "note": "yes at Extreme"
      },
      {
        "name": "Alliance response",
        "default": "consultation",
        "range": "options: collective measures / none",
        "unit": null,
        "note": null
      },
      {
        "name": "Campaign duration",
        "default": "12 months",
        "range": "6–36",
        "unit": "months",
        "note": null
      },
      {
        "name": "Domestic proxy recruitment",
        "default": "on",
        "range": null,
        "unit": null,
        "note": null
      }
    ]
  },
  "transmission": [
    "Incidents degrade infrastructure and services piecemeal.",
    "Attribution lag prevents proportionate response.",
    "Information operations convert each incident into political division.",
    "Security services are stretched across vectors.",
    "Alliance cohesion is tested by the gap between evidence and action.",
    "Deterrence erodes as incidents go unanswered."
  ],
  "loading": [
    {
      "dimension": "Hard",
      "domain": "defence-security",
      "load": "High",
      "channel": "air defence against drones, counter-intelligence, maritime surveillance"
    },
    {
      "dimension": "Hard",
      "domain": "strategic-infrastructure",
      "load": "High",
      "channel": "cables, pipelines, grid, airports, GNSS dependence"
    },
    {
      "dimension": "Hard",
      "domain": "critical-technology",
      "load": "Medium",
      "channel": "GNSS alternatives, cyber defence"
    },
    {
      "dimension": "Soft",
      "domain": "government-effectiveness",
      "load": "High",
      "channel": "attribution, legal tools, crisis communication, inter-agency coordination"
    },
    {
      "dimension": "Soft",
      "domain": "human-capital",
      "load": "Low",
      "channel": "public anxiety; emergency services strain"
    },
    {
      "dimension": "Soft",
      "domain": "influence-cohesion",
      "load": "High",
      "channel": "information integrity, social trust, alliance diplomacy"
    },
    {
      "dimension": "Economic",
      "domain": "macro-financial",
      "load": "Low",
      "channel": "insurance and risk premia"
    },
    {
      "dimension": "Economic",
      "domain": "industry-trade-supply",
      "load": "Medium",
      "channel": "logistics disruption"
    },
    {
      "dimension": "Economic",
      "domain": "energy-resources",
      "load": "Medium",
      "channel": "energy asset sabotage"
    }
  ],
  "stakeholders": {
    "government": {
      "exposure": "Protection of undersea and energy assets, attribution speed, legal thresholds",
      "actions": [
        "A single hybrid-response doctrine",
        "Pre-authorised responses",
        "GNSS backup",
        "Whole-of-society communication"
      ],
      "watch": [
        "Incident counts by vector",
        "Attribution lag"
      ],
      "relevance": 5
    },
    "technology": {
      "exposure": "Cables, data centres, telecoms, GNSS-dependent services",
      "actions": [
        "Route diversity",
        "PNT resilience",
        "Insider-threat programmes"
      ],
      "watch": [
        "Cable faults",
        "Jamming maps"
      ],
      "relevance": 4
    },
    "investors": {
      "exposure": "Infrastructure and insurance",
      "actions": [
        "Price sabotage into infrastructure assets in exposed regions"
      ],
      "watch": [
        "War-risk and sabotage exclusions"
      ],
      "relevance": 2
    },
    "public": {
      "exposure": "Service disruptions and disinformation",
      "actions": [
        "72-hour household preparedness (the EU standard)"
      ],
      "watch": [
        "Official incident advisories"
      ],
      "relevance": 3
    }
  },
  "regions": [
    {
      "region": "north-america",
      "exposure": "Low",
      "rationale": null
    },
    {
      "region": "europe",
      "exposure": "High",
      "rationale": "The active theatre"
    },
    {
      "region": "china",
      "exposure": "Low",
      "rationale": "Low as target"
    },
    {
      "region": "indo-pacific",
      "exposure": "Medium",
      "rationale": "Taiwan's cables; Philippine waters"
    },
    {
      "region": "south-asia",
      "exposure": "Medium",
      "rationale": null
    },
    {
      "region": "gulf-middle-east",
      "exposure": "Medium",
      "rationale": "Proxy and drone warfare"
    },
    {
      "region": "africa",
      "exposure": "Low",
      "rationale": null
    },
    {
      "region": "latin-america",
      "exposure": "Low",
      "rationale": null
    },
    {
      "region": "russia-eurasia",
      "exposure": "Medium",
      "rationale": "Ukraine's strikes; Moldova, Georgia, Armenia as targets"
    }
  ],
  "indicators": [
    {
      "name": "Subsea cable fault counts",
      "source": "ICPC",
      "threshold": null,
      "cadence": null
    },
    {
      "name": "GNSS interference maps",
      "source": "gpsjam.org, EASA",
      "threshold": null,
      "cadence": null
    },
    {
      "name": "Drone incursion reports",
      "source": null,
      "threshold": null,
      "cadence": null
    },
    {
      "name": "Sabotage and arson prosecutions linked to foreign services",
      "source": null,
      "threshold": null,
      "cadence": null
    },
    {
      "name": "Article 4 consultations",
      "source": null,
      "threshold": null,
      "cadence": null
    },
    {
      "name": "Coordinated inauthentic behaviour takedowns",
      "source": "platform transparency reports",
      "threshold": null,
      "cadence": null
    },
    {
      "name": "Border crossing anomalies",
      "source": null,
      "threshold": null,
      "cadence": null
    }
  ],
  "compounds": {
    "triggers": [
      {
        "id": "S12",
        "note": null
      },
      {
        "id": "S07",
        "note": null
      },
      {
        "id": "S08",
        "note": "instrumentalised"
      }
    ],
    "triggered_by": [
      {
        "id": "S01",
        "note": null
      },
      {
        "id": "S05",
        "note": "regional war"
      }
    ],
    "amplified_by": [],
    "triggered_by_other": [],
    "amplifying_trends": [
      "polarisation",
      "infrastructure ageing",
      "GNSS dependence",
      "platform-mediated information"
    ]
  },
  "open_questions": [
    "Whether the likelihood should be published per cluster rather than per nation.",
    "Whether cyber intrusions belong here or in S12 when they are part of a campaign.",
    "How to rate a nation that is the campaign's author rather than its target."
  ],
  "commentary": null,
  "overview": {
    "source": "ginc-desk-v0.2",
    "lenses": {
      "political": "Allies consult under Article 4 and agree **a statement**. The public argues over whether government is doing too little or exaggerating.",
      "economic": "Costs are diffuse: **insurance and risk premia**, disrupted logistics, a subcontractor's inventory destroyed by arson.",
      "social": "Each incident is converted into **political division**. The point is to show the state cannot protect ordinary life.",
      "technological": "**GPS fails** for days at a time. Cables are cut, drones close airports and cyber intrusions run alongside.",
      "legal": "**Attribution** comes weeks later, 'with high confidence', and is answered with a sanctions designation.",
      "environmental": "Sabotage reaches **subsea cables and energy assets**; pipelines and the grid are targets."
    },
    "regions": {
      "north-america": "Rated **Low** as a target.",
      "europe": "**The active theatre**: Baltic cables, drone incursions, airport closures and parcel incendiaries.",
      "china": "Rated **Low** as a target.",
      "indo-pacific": "**Taiwan's cables** and Philippine waters.",
      "south-asia": "Campaigns below the threshold of war are plausible between **neighbours**.",
      "gulf-middle-east": "**Proxy and drone warfare**.",
      "africa": "Rated **Low**.",
      "latin-america": "Rated **Low**.",
      "russia-eurasia": "Ukraine's strikes; **Moldova, Georgia and Armenia** as targets."
    }
  },
  "history": [
    {
      "edition": 2027,
      "rank": null,
      "L2y": 4,
      "L10y": 5,
      "impact_systemic": 2,
      "impact_national": 3,
      "confidence": "medium"
    }
  ],
  "changelog": [
    {
      "version": "0.2.0",
      "date": "2026-10-02",
      "change": "Entered the Library at v0.2 with GINC desk scores."
    }
  ],
  "citation": "GINC (2027). Scenario S06 Hybrid campaign by a hostile state, Scenario Library v0.2. scenarios.ginc.org/library/hybrid-campaign"
}