Egidio
Report · mechanism only

Understanding the mechanism of a hybrid threat

This report isn't meant to comment on current geopolitical events. It explains a mechanism, as defined by the European bodies that study it — and why it can, in some cases, end up in an ordinary text inbox.

Protect my phone with Egidio Free for calls · 100% on your phone · no account needed

A definition, not an accusation

Hybrid CoE (the European Centre of Excellence for Countering Hybrid Threats, an intergovernmental body based in Helsinki) defines a hybrid threat as an action, carried out by a state or non-state actor, that aims to weaken a target by influencing its decision-making — at the local, regional, national or institutional level. The Council of the European Union specifies that these actions combine several means at once: information manipulation, cyberattacks, economic pressure, discreet political maneuvering. This report describes that combination mechanism — it doesn't name any specific actor.

Source: Hybrid CoE · Council of the European Union, "Hybrid threats" page.

What characterizes the mechanism

The combination

A single isolated tool (a cyberattack, a piece of false information) isn't a hybrid threat. It's the combination of several means, coordinated toward one goal, that defines it.

The threshold

These actions deliberately stay below the threshold that would trigger a classic, clear-cut response — that's part of the mechanism, not chance.

The ambiguity

Attribution is often hard to establish with certainty, which complicates the response and is built into the calculation of the actor behind the action.

The broad target

Institutions and infrastructure, but also public opinion and citizens' trust in information, can be targeted simultaneously.

FIMI: information manipulation as a tool

The European diplomatic service (EEAS, the European External Action Service) proposed the term FIMI in 2021 — Foreign Information Manipulation and Interference — to describe behavior, most often not illegal in itself, but deceptive and coordinated, aimed at influencing a decision or perception. ENISA and the EEAS jointly published an analysis of the link between FIMI and cybersecurity, documenting how these campaigns sometimes rely on compromised digital infrastructure to amplify their reach.

Source: ENISA & EEAS, Foreign Information Manipulation and Interference (FIMI) and Cybersecurity — Threat Landscape.

Why this mechanism can land in a text message

ENISA's latest annual threat-landscape report documents a phenomenon it calls "hacktivism-as-cover": disinformation campaigns that sometimes overlap with operations that look purely criminal, with spikes in activity observed around elections or other politically sensitive events. For an individual, this can translate very concretely: a mass text, a fake account relaying misleading information, or an automated call — the same channels, and sometimes the same technical infrastructure (SIM farms, spoofed numbers), as those documented elsewhere in this Laboratory for classic financial fraud.

Source: ENISA, Threat Landscape 2025. See also the SIM farms & criminal call centers report.
🔒 The targeting mechanism — a message that mimics a legitimate source to influence a decision — is the same, whether the goal is financial or informational. Recognizing the pattern remains the best individual defense. See how Medusa works.

Frequently asked questions

What is a hybrid threat, in one sentence?

An action that combines several means at once (disinformation, cyberattack, economic pressure...) to weaken a target, while staying below the threshold that would trigger a classic, clear-cut response.

What is FIMI?

Foreign Information Manipulation and Interference: a term proposed in 2021 by the European diplomatic service to describe behavior, most often not illegal in itself, that aims to influence a decision or perception at scale.

How does this affect an individual?

Large-scale disinformation campaigns sometimes use the same channels as ordinary scams — mass texts, fake accounts, automated calls — especially around sensitive events like elections. Recognizing a suspicious pattern protects against both.

Other markets we cover

The mechanism described above isn't specific to one region — national security and cyber agencies elsewhere describe the same combination of tactics, in their own words.

🇦🇺Australia — over 1,700 warnings issued in a single year

ASD's Australian Cyber Security Centre notified Australian entities more than 1,700 times about potentially malicious cyber activity in FY2024–25, an 83% increase on the previous year — activity it links to actors combining network intrusion with attempts to disrupt critical services, not isolated one-off attacks.

Australian Signals Directorate, Annual Cyber Threat Report 2024–25, October 2025.

🇬🇧United Kingdom — a record 204 nationally significant attacks

The National Cyber Security Centre handled 204 nationally significant cyberattacks in the year to September 2025, more than double the 89 recorded the year before. GCHQ's Director publicly described a pattern of "daily hybrid activity" — propaganda, cyberattacks, deception and sabotage combined against critical infrastructure, democratic processes, supply chains and public trust.

National Cyber Security Centre, Annual Review 2025; GCHQ Director Anne Keast-Butler, public remarks, May 2025.

🇨🇦Canada — cyber operations "increasingly" combined with disinformation

The Canadian Centre for Cyber Security's national threat assessment states that nation-state actors are increasingly integrating cyber operations with online influence and disinformation campaigns and the targeting of critical infrastructure toward the same disruptive goal. A 2025 update on threats to the democratic process flagged AI-generated disinformation as a specific risk around the federal election.

Canadian Centre for Cyber Security, National Cyber Threat Assessment 2025–2026; Cyber Threats to Canada's Democratic Process — 2025 Update.

🇮🇳India — "adversaries... do not always come with traditional weapons"

Inaugurating a security-technology conference in March 2025, India's Defence Minister told the country's security establishment it must adapt to hybrid threats specifically: "cyber-attacks, misinformation campaigns, and space-based espionage are emerging as new-age threats that require advanced solutions." Diaspora communities are frequently identified as a specific target of this kind of interference — see our report on the scams that target them.

Press Information Bureau, Government of India, March 4, 2025.

Go further

Cite this page Egidio — The Threat Laboratory, "Hybrid threats: understanding the mechanism", egidio.app/en/laboratoire/hybrid-threats/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.