- Category
- World
Russia’s Hybrid War Has Already Hit Britain. Hospitals, Businesses, and Infrastructure Are Paying the Price

Russia is openly threatening the UK over its support for Ukraine. But while Moscow warns Britain of “consequences,” Russian-linked cyberattacks, sabotage, and covert operations are already bringing its hybrid warfare to British shores.
Russia has threatened the UK with “consequences” after British-made drones were reportedly used in Ukrainian strikes inside Russia. London would “inevitably” have to answer over its support for Ukraine, the Russian Embassy in London claimed.
“We are not fair-weather friends,” UK Prime Minister Andy Burnham responded. “We will be there in Ukraine's hour of need, and that won't change.” Russia’s warning is the latest in a string of threats against the UK over its support for Ukraine
While Russia continues its own attacks on Ukraine's civilian infrastructure using foreign-procured weapons—the latest being on the night of August 19–20, when Russia launched North Korean missiles at Kyiv, killing 12 and injuring a dozen—in the UK, Moscow wages a different kind of war already.
Russia does not need tanks rolling over borders or air-dropped bombs to attack the UK. Russia is using cyber operations, sabotage, proxies, espionage, and information warfare against the UK, the government warned. Russia’s hybrid war is reaching hospitals, warehouses, computer networks, logistics systems, and critical infrastructure, with consequences already impacting everyday civilian life.
How Russia's hybrid warfare against the UK works
A hospital patient receiving cancer treatment. Switching on the heating during winter. Millions logging onto the internet for work. Flights leaving airports. Basic goods, foods, and medicines passing through ports. Most people rarely consider the infrastructure connecting these everyday activities, or how vulnerable it can be to adversaries. Russia does not need to invade with military action to disrupt them.
Russia has established a Special Activity Service (SSD) incorporating Russia’s military intelligence agency (GRU) Unit 29155, tasked with conducting operations against the West using a hybrid toolkit including sabotage, assassination, and cyberattacks, the UK Government reported.

Unit 29155 is already familiar to the UK after the group was linked to the attempted assassination of Sergei and Yulia Skripal using a nerve agent in Salisbury in 2018—an attack that also resulted in the death of an innocent British citizen, Dawn Sturgess.
Other GRU units specialise in cyber operations. Its military Unit 26165—also known as APT28 or Fancy Bear—is among those the UK says Russia deploys in pursuit of its military and foreign-policy objectives.
The UK Government connected this group to its role in conducting online reconnaissance on civilian shelters, leading to the artillery strikes on Mariupol Drama Theatre in March 2022, killing an estimated thousand civilians sheltering there, including children.
Cyber attacks on UK hospitals
In June 2024, Synnovis, which provides pathology services to NHS hospitals across London, was hit by ransomware. Computer systems became unusable, and patient information was stolen. Five NHS trusts and healthcare providers across several London boroughs were disrupted.
The incident contributed to the death of a patient. More than 11,000 outpatient appointments and elective procedures were delayed or postponed, including 97 cancer treatments, and organs had to be diverted elsewhere. The financial damage was estimated at £32.7 million, demonstrating that interfering with digital infrastructure can translate into consequences far beyond a computer screen. The attack was attributed to Qilin, a Russian cybercriminal group, former NCSC chief Ciaran Martin reported.
In January 2026, the UK’s National Cyber Security Centre warned that Russian state-aligned hacktivist groups were persistently targeting British organisations with the aim of disrupting their networks. Local government and operators of critical national infrastructure were among those urged to strengthen their defences.
Then, in April 2026, the NCSC exposed another method, the APT28 or Unit 26165, which had compromised vulnerable internet routers, manipulating internet traffic and potentially harvesting login details, passwords and emails. The attacks themselves do not necessarily need to be technologically spectacular to cause severe disruption.
By overwhelming important websites and online systems, these attacks can prevent people from accessing the essential services they depend on every day.
Jonathan Ellison
NCSC Director of National Resilience
Last year, UNITED24 Media reported how Russian nationals behind the hacker group "8Base,” extorted millions of dollars from victims—including children's hospitals—by holding sensitive data at ransom. Ransomware attacks on healthcare not only caused disruption but also put lives at risk.
A Wagner-linked sabotage plot hit London
On March 20, 2024, a warehouse stocking humanitarian aid and Starlink satellite equipment went up in flames. The Wagner Group had recruited Dylan Earl and Jake Reeves to set fire to the warehouse in east London, with Earl organising the arson and recruiting others to carry it out, British prosecutors established.

The conspiracy also included plans for another arson attack and the kidnapping of the owner of businesses connected to the warehouse, the Crown Prosecution Service (CPS) stated.
Britain has since strengthened its legislation against state threats. In July 2026, the government formally designated Russia's GRU Volunteer Corps as a threat to national security, saying it forms part of a network through which Russian military intelligence can recruit, organise and deploy proxy forces.
Targeting UK undersea cables and critical infrastructure
Some of Britain's most important infrastructure is not visible at all. Undersea cables carry around 99% of the UK's international telecommunications and data traffic, while seabed infrastructure is also critical to the country's energy supply, and Russia knows this.
Russia conducted a covert submarine operation in waters near the UK that posed a potential threat to critical energy pipelines and data cables, UK Defense Secretary John Healey revealed in April 2026. The operation involved an Akula-class submarine and two specialized deep-sea submarines associated with Russia's Main Directorate of Deep-Sea Research, known as GUGI. “The greatest threats are often unseen and silent,” Healey said. The incident underscored growing concern among Western officials that Russia is increasingly focused on undersea infrastructure as part of hybrid warfare.
The cables beneath Britain's waters carry the data behind everyday communications, businesses, and financial transactions. Their importance makes the seabed another potential front in a confrontation that most British civilians will never see. The government subsequently announced plans to strengthen protections for Britain's subsea cables following an increase in suspicious activity by Russian vessels.
How much is Russia’s hybrid war costing the UK?
Russia’s hybrid confrontation is already imposing a financial cost on the UK, even without conventional war reaching its shores.
While there is no public estimate on how much Moscow spends conducting these hybrid operations, Russia budgets more than £1 billion ($1.6 billion) a year for state propaganda alone. Individual acts of sabotage in Europe can be outsourced for hundreds—leaving Western governments to spend vastly more investigating attacks and protecting the infrastructure they target.

Britain is already spending heavily to defend against those threats. As Russian activity around critical undersea infrastructure increases, the UK has committed an additional £100 million ($136 million) for P-8 submarine-hunting aircraft, alongside Operation Atlantic Bastion, to strengthen Britain’s ability to detect underwater threats.
The government has also announced more than £5 billion ($6.8 billion) for drones and autonomous systems, while nearly £600 million ($818 million) in additional funding has gone to Britain’s intelligence services amid growing state threats. Not all of this spending can be attributed to Russia alone, but the government repeatedly identifies Moscow as a major threat driving Britain’s changing security posture.
The potential cost of successful attacks is greater still. Of more than 200 cyber incidents affecting UK critical national infrastructure and its supporting ecosystem were conducted by state actors from January to May 2026, around 75% were conducted by state actors, NCSC chief Richard Horne revealed.
“Hostile states, such as Russia, China and Iran, are increasingly targeting the systems that underpin the UK’s essential services,” Dr Horne warned. “In cyberspace, we are not preparing for tomorrow’s conflicts, to some degree we are fighting them today.”
Cyberattacks already carry an enormous price tag for Britain. Almost 85,000 UK businesses were estimated to have experienced a significant cyber attack in 2024, costing £14.7 billion ($20 billion) at the economy-wide level—around 0.5% of annual GDP—a UK-Government commissioned modelling study estimated. The study also found that in some cases, attacks could directly financially impact individuals; attacks on retail stores, for example, could directly affect storecard holders.
Critical infrastructure raises the stakes further. A major rail cyberattack could cost £1.8 billion ($2.5 billion) for just one week's disruption, says the UK government.
And the risk is not hypothetical. The NCSC established that Russia’s GRU Unit 26165 has been conducting a cyber campaign against Western logistics and technology organisations since 2022, specifically tasked with targeting organisations involved in the co-ordination, transport and delivery of support to Ukraine. Targets have included the defence, IT services, maritime, airports, ports and air-traffic-management sectors.
The costs of Russia’s hybrid threat to Britain are therefore measured not only in the millions spent protecting networks, waters and infrastructure. Successful attacks can disrupt businesses, public services and transport—and, as the ransomware attack on Synnovis demonstrated, the consequences can ultimately reach individual civilians.
Ukraine has experienced the most devastating consequences of Russian aggression. And many of the methods Russia has developed alongside its conventional war do not stop at Ukraine's borders.
Discuss this article:

-46f6afa2f66d31ff3df8ea1a8f5524ec.jpg)
-c8d1816dd0c107b377577ba9be2c81e0.jpg)




