An 18-Month Pattern of Maritime Incursions Across Europe
Between August 2024 and February 2026, a coordinated series of low-altitude aerial incursions probed defense installations, civilian transport hubs, and energy facilities across Europe. An exhaustive dataset compiled by the International Institute for Strategic Studies (IISS) documented 144 distinct uncrewed aerial vehicle (UAV) incidents spanning 13 European nations—12 NATO member states alongside Ireland. Rather than isolated acts of hobbyist interference, the operational footprint revealed deliberate, organized surveillance designed to map air defense responses while remaining beneath the threshold required to trigger NATO Article 5 collective defense mechanisms.
The pace of operations accelerated sharply in late 2025. Between September and December 2025, reported sightings surged from an average of four incidents per month to 22.5 per month. Germany bore the brunt of this escalation, recording 58 separate incidents across military and dual-use logistics centers. Across the broader campaign, 48% of recorded sightings occurred directly over military installations, 26% over critical energy and maritime port infrastructure, and 18% over civilian airports.
Repeated low-altitude intrusions forced operational shutdowns at primary European aviation hubs. On September 22, 2025, Copenhagen Airport suspended all flight operations for four hours after unauthorized drones infiltrated controlled airspace. Similar incursions repeatedly disrupted air traffic control operations at Brussels, Munich, Oslo, and Vilnius airports.
While open-source investigations by groups like Dronewatch Europe emphasize that public telemetry, recovered wreckage, or unencrypted command-link intercepts linking every single flight to Russian state control remain sparse in the public domain, the aggregate operational pattern tells a distinct story. High non-confirmation rates and public reporting noise align directly with asymmetric operational design: creating intentional ambiguity that masks targeted reconnaissance within background electronic signal clutter.
Targeting NATO Nuclear Share Infrastructure and Submarine Bases
The primary focus of these low-altitude flights was Europe's nuclear deterrence infrastructure. Incursions repeatedly targeted Kleine-Brogel Air Base in Belgium and Volkel Air Base in the Netherlands. Both sites store American B61-12 thermonuclear gravity bombs under NATO nuclear sharing agreements. Drone teams tracked flight paths directly over hardened aircraft shelters and weapons storage areas, testing low-altitude perimeter detection capabilities.
Similar reconnaissance targeted British facilities housing allied nuclear assets. In November 2024, multiple uncrewed aircraft probed RAF Lakenheath and RAF Mildenhall in the United Kingdom. These surveillance flights occurred ahead of the official return of United States nuclear weapons to Lakenheath in July 2025. Nearby RAF Fairford, a primary European operating location for U.S. Air Force heavy strategic bombers, experienced concurrent airspace intrusions.
Strategic naval assets faced identical pressure. On December 4, 2025, French security forces detected five uncrewed aerial vehicles operating over the Île Longue naval base in Brittany. Île Longue serves as the home port and operational hub for the French Navy's Triomphant-class ballistic missile submarines (SSBNs), which carry France's ocean-based nuclear deterrent.
In December 2025, four drones targeted an Irish naval patrol vessel operating off the coast of Ireland immediately following an official visit by Ukrainian President Volodymyr Zelensky. The tactical positioning of these flights over sovereign military platforms highlights how low-altitude aerial surveillance was used to monitor executive movements and naval escort readiness across Western Europe.
Shadow Fleet Tankers and Offshore Launch Logistics
To conduct low-altitude surveillance without relying on compromised land-based launch sites within NATO borders, operations relied heavily on commercial maritime platforms. A network of non-cooperative commercial vessels—often referred to as the Russian shadow fleet—loitered in international maritime corridors while operating dark with Automatic Identification System (AIS) transponders turned off.
Several specific vessels were tracked in close geographic and temporal proximity to major airspace intrusions:
- Boracay: On September 28, 2025, French naval commandos boarded this shadow fleet oil tanker off Denmark following the Copenhagen Airport shutdown. A boarding inspection revealed a Chinese master alongside two Russian nationals employed by Moran Security Group, a Russian private military company.
- Zhigulevsk: On February 26, 2026, Swedish military forces active off Malmö engaged and jammed an active drone launched directly from the Russian signals intelligence (SIGINT) vessel Zhigulevsk. The UAV was heading toward the French aircraft carrier Charles de Gaulle during a scheduled Swedish port call—marking the clearest public attribution of a maritime launch platform during the 18-month window.
- Seasons I: The shadow fleet oil tanker (IMO 9308950) transited eastbound through the Dover Strait along East Anglia concurrently with the November 2024 drone intrusions over RAF Lakenheath and RAF Mildenhall.
- HAV Dolphin: The cargo ship (IMO 9073854), under active investigation by German and Dutch law enforcement for spring 2025 military base overflights in northwestern Germany, was docked in Hull, UK, during the November 2024 base incursions.
- Vezhen: The Maltese-flagged cargo vessel was positioned nearby in Irish waters when four drones probed the Irish naval vessel in December 2025.
By leveraging loitering tankers in international waters, operators established mobile launch and recovery stations. This maritime launch mechanism bypassed terrestrial border sensors and complicated legal intercept authorities.
Securing Strategic Infrastructure Against AI Cybersecurity Threats
Securing strategic infrastructure against ai cybersecurity threats in 2026 requires bridging physical security and digital signal defenses. As low-cost uncrewed systems adopt autonomous flight capabilities, traditional manual radio-frequency (RF) jamming faces strict limits. Understanding these operational vectors is central to analyzing modern threat intelligence. Overcoming legacy system constraints when modernizing infrastructure for autonomous agents is essential for maintaining persistent tactical visibility.
Modern counter-drone architectures depend on integrated sensor fusion. Security teams combine passive RF monitoring, electro-optical/infrared (EO/IR) tracking, and micro-Doppler radar to detect non-cooperative targets carrying small radar cross-sections. When an uncrewed platform operates with an autonomous navigation agent or onboard computer vision, standard command-link jamming fails because the drone requires no active ground connection.
Securing installations against automated aerial threats requires implementing complete defensive engineering practices:
- Automated Signal Disruption: Modern counter-UAS platforms deploy adaptive RF countermeasures capable of identifying frequency-hopping telemetry and severing satellite navigation signals.
- Endpoint and Telemetry Protection: Hardening base networks prevents attackers from intercepting local telemetry or deploying malicious firmware to counter-drone sensors.
- Agentic System Isolation: When autonomous systems process real-time tactical feeds, security architectures must isolate AI model inferencing nodes to prevent adversarial data injection or command hijacking.
Frameworks developed by threat intelligence groups and research teams at enterprise organizations like IBM highlight that securing edge sensors is just as critical as protecting core cloud infrastructure. Integrating guidance from published resources, such as the CISA Cybersecurity Best Practices tutorial guide, helps military and civilian airport operators establish resilient operational protocols across hybrid threat environments. Furthermore, understanding how automated vulnerability discovery impacts defense networks aids teams in anticipating software vulnerabilities across connected counter-UAS platforms.
Countermeasure Defenses and the Limits of Maritime Jurisdiction
Europe's military response exposed significant gaps in low-altitude air defense and maritime domain awareness. In late 2025, the Royal Air Force deployed its specialized ORCUS Counter-Uncrewed Aerial System (C-UAS) to Denmark and subsequently to Brussels Airport in Belgium to safeguard commercial flight operations against rogue drone disruptions.
While point-defense systems like ORCUS provide tactical protection for individual airfields, broader defensive initiatives face structural limitations. The planned European Drone Defence Initiative—commonly known as the "Drone Wall"—is aiming for initial operational capability by late 2026. However, its legal and operational mandate is strictly confined to domestic European airspace.
The Drone Wall cannot legally interdict or board non-cooperative commercial ships loitering in international maritime corridors without explicit flag-state consent or proven hostile intent. As long as dark-sailing shadow fleet vessels operate freely in international waters outside territorial seas, the offshore launch platforms enabling these low-altitude reconnaissance flights remain active. Closing this strategic gap requires NATO and European maritime authorities to expand international maritime surveillance, enforce mandatory AIS tracking, and tightly coordinate counter-drone defenses between naval forces and civil aviation authorities.