Charlotte Marchandise, Martin McKee
Europe is under attack, not through conventional warfare, but from a sustained Russian campaign of hybrid warfare that brings serious risks to health. Hybrid warfare blends conventional military force with non-traditional tactics such as cyberattacks, disinformation campaigns, economic coercion, and sabotage. Unlike traditional warfare, hybrid operations often occur below the threshold of armed conflict, exploiting vulnerabilities in democratic societies to sow confusion, erode trust, and destabilise institutions. These tactics are deliberately ambiguous, making attribution difficult and response complex. Europe’s health systems are increasingly being targeted in this campaign, yet they remain peripheral in defence planning despite their importance for sustaining resilient societies. Cyberattacks, disinformation, and sabotage against health services can destabilise nations just as effectively as conventional threats. For this reason alone, integrating health into strategic defence frameworks makes sense, enabling faster responses, coordinated protection, and stronger deterrence. However, health also makes a critical contribution to defence, with health facilities caring for those injured in conflict, and better population health reducing the appeal of the disinformation being spread by hostile governments seeking to undermine national resilience. It is now clear that no country in Europe is safe from these attacks. In June 2024, a ransomware attack on Synnovis, a pathology services provider for London hospitals, disrupted blood testing across the UK’s National Health Service. Several sources, including the former head of the UK’s National Cybersecurity Centre, have identified the Russian Qilin organisation as the perpetrator [1, 2]. The consequences were severe, with over 10 000 cancelled appointments, and the disruption has been implicated in at least one patient death [3]. Also in 2024, a Russian group claimed responsibility for a cyberattack on the main hospital in Zagreb, Croatia, as part of a campaign against what they called “Russo-phobic” countries [4]. In Poland, hospitals and water systems have faced repeated cyber intrusions, prompting the government to allocate €1 billion to bolster cybersecurity. A 2023 assessment by the European Union Agency for Cybersecurity (ENISA) on threats to Europe’s health sector reported denial-of-service attacks on hospitals in the Netherlands, Denmark, Sweden, and Spain [5]. These attacks exploit the health sector’s underinvestment in digital defences and its reliance on outdated systems. The perpetrators’ goals are both financial gain and disruption, demoralisation, and destabilisation. Russia’s hybrid campaign extends beyond cyberspace. In Germany, drones suspected to be Russian-operated have been observed over hospitals and energy facilities, suggesting reconnaissance for future sabotage. Similar drone flights that paralysed Danish airports have been linked to Russian ships [6]. In Sweden, mobile phone masts, which must now be considered critical elements for health security, have been damaged in sabotage operations thought to be linked to Russia [7]. In the Baltic Sea, undersea cables, essential for internet connectivity, have been cut by ships in Russia’s shadow fleet, comprising ships employed in sanctions busting whose ownership is obscured [7]. These attacks are strategic. They probe Europe’s defences, test its response capabilities, and aim to create uncertainty. The targeting of health infrastructure is particularly insidious, given its centrality to public welfare and its symbolic importance in democratic societies. Alongside physical and digital assaults is a relentless disinformation campaign. Russian troll networks have flooded social media with false narratives about vaccine safety, pandemic origins, and the efficacy of European health systems [8], amplified by bots and fringe influencers [9]. More recently, narratives suggesting Western complicity in global health crises have gained traction, amplified by bots and fringe influencers [10]. The result is a fragmented information environment where truth competes with conspiracy. In this context, health security must be elevated from a public health priority to a strategic imperative. Europe needs a concerted, integrated strategy that treats hospitals, laboratories, and health data systems as critical infrastructure and sees civil society organisations and the public health workforce serving as one of the first lines of defence against disinformation. As a conference convened by WHO argued, “public health authorities need to develop, validate, implement, and adapt tools and interventions for managing infodemics in acute public health events” [11]. Public health agencies must therefore prioritise disinformation countermeasures, including rapid-response teams to debunk false health narratives. However, a strong, diverse, and trusted health workforce is important for sustaining societal resilience in other ways, engaging in surveillance, and sustaining the cross-sectoral structures that are necessary for response to a crisis. Their voices must be present everywhere that strategic decisions are made, from Brussels to the towns and villages on the European Union’s Eastern borders. Moreover, by empowering the frontline health workforce by clearly communicating risks to them, they can serve as ambassadors within their communities. Equipping them to share recommendations while enabling feedback from the population will allow us to act faster, adapt better, and respond more effectively. Europe cannot afford to leave health at the margins of security debates. A continent-wide health security initiative, integrated into broader public health and defence strategies, is now essential. The European Commission, NATO, national governments (including the UK and Switzerland outside the EU), and public health leaders in all roles, including civil society, must act decisively. While the EU and NATO do recognise health security as a strategic concern, coordination remains fragmented. The EU’s Health Emergency Preparedness and Response Authority (HERA) and the European Centre for Disease Prevention and Control (ECDC) offer platforms for joint action, while NATO’s Emerging Security Challenges Division increasingly addresses cyber threats to critical infrastructure. While recognising the political challenges, and especially the fact that not all EU Member States are in NATO, there is a strong case for establishing joint task forces and developing interoperable contingency plans. Health systems are now on the frontline as targets in a sustained hybrid war, and their protection must be elevated to a strategic priority. Yet, hospitals, laboratories, and health data systems must be recognised as more than critical infrastructure. They are also symbols of trust between governments and citizens. They need to be seen as part of a wider public health ecosystem, where challenges are interconnected and solutions must be coordinated across sectors and levels of governance. Protecting them requires a whole-of-society approach, where civil society and public health professionals are given a seat at the table alongside defence and security actors. Some things can be done at once, while others will take longer. Europe must prioritise short-term measures such as mandatory cybersecurity standards and rapid-response disinformation teams while laying the groundwork for long-term investments in workforce development and health diplomacy. The European Commission has a critical role in coordinating efforts and funding preparedness from existing EU health and digital resilience programmes, even while legislative pathways take longer, such as amendments to the EU Critical Entities Resilience Directive to embed health security within broader defence frameworks. In the face of hybrid threats to Europe, resilience is not just about recovery; it is about readiness for threats that are already upon us. Conflict of interest: None declared. None declared. Not required. Not applicable.