Russian shadow warfare is a many-headed hydra. Its efforts can rise and fall in intensity, can close airports or menace heads of state, target electricity grids in midwinter and sever undersea cables.
The latest threat comes from Russia’s highly developed electronic warfare capabilities, which are being used to misdirect explosive-filled drones into NATO airspace. A May 19 incident over Estonia saw a NATO jet shoot down the device.
That, anyway, is the conclusion of the Ukrainian government. “Russia continues to redirect Ukrainian drones into the Baltics with the use of its electronic warfare,” Foreign Ministry spokesperson Heorhii Tykhyi said. “We apologize to Estonia and all of our Baltic friends for such unintended incidents.” Ukraine’s military only ever used Russian airspace for its attacks, he said.
Similarly, on May 15 Finnish authorities directed citizens in the Helsinki region to remain indoors due to suspicious drone sightings, which reportedly may have been the result of Russian GPS hijacking.
Although Russia denies involvement, Ukrainians blame an electronic warfare technique called “spoofing” for the breach. Russian forces began employing GPS-deception techniques against Ukrainian drones as early as 2022, with documented spoofing efforts becoming increasingly common by 2023. But it wasn’t until March 23 that the first case of a Ukrainian drone breaching NATO airspace due to Russian interference was recorded in Lithuania.
So, what exactly is spoofing? Spoofing, jamming, and meaconing are three terms that fall under the umbrella of electronic interference, and each poses its own risks.
Spoofing sends a counterfeit signal, which is interpreted as authentic by the receiver. Jamming blocks a receiver by producing a noisy signal, causing it to lose its position. Meaconing (a combination of the words masking and beacon) is a subtype of spoofing that uses real GNSS (Global Navigation Satellite System) signals, rather than fabricated ones, but introduces a delay to mislead a system on where exactly it is. Jamming is rather obvious; spoofing is difficult to detect, and meaconing is the most covert of the three.
Russia has been developing these techniques for years, even using such techniques during the Cold War. In 2017, several ships in the Black Sea experienced abnormalities with their GPS position, which showed them located at an airport.
This was an indication of spoofing efforts for drone defense — drones have geofencing rules that prevent them from flying over airports. By changing a drone’s position to an airport, the drone is programmed to reroute or land immediately.
Electronic interference affects more than just drones. Spoofing is an example of signal disruption, but jamming still poses a powerful threat. Russian satellites have jammed GPS signals across Europe on at least three occasions since 2019. Experts are unsure of the aim. While each interruption lasted less than 10 seconds, the military application of this technology is broad; jamming from a satellite has significantly more range than from the ground. But whether intentional or accidental, this disruption warrants serious concern.
The Baltic states have been scrambling to counter electronic warfare, but a widespread, reliable method of defense has yet to be implemented. Ukraine, however, is taking action to address the root cause. It has launched an investigation to determine how Russia is interfering with receiver signals, while also developing drones that can fly without satellite assistance and are thus less vulnerable to hostile interference. While individual NATO states have integrated spoofing defense strategies into their national security framework, alliance-wide coordination for an effective solution remains a challenge.
As long as Russia continues to avoid consequences, it will continue its electronic warfare efforts. While NATO has condemned Russia’s actions, a lack of clear repercussions has failed to alter the Kremlin’s cost-benefit assessment. Russia’s gray-zone toolkit goes beyond GPS spoofing to include cyberattacks, subsea cable cutting, and drone-induced airport closures. Shadow warfare or hybrid attacks against alliance states have more than tripled since 2023 and will undoubtedly continue to rise unless NATO acts. The logical next step for NATO members is to invoke Article 4.
Article 4 has been invoked seven times since NATO’s founding. It allows the parties to consult together, “whenever, in the opinion of any of them, the territorial integrity, political independence or security of any of the Parties is threatened.” Most recently, Poland and Estonia invoked Article 4 in early 2025, after Russian aircraft entered their airspace. Since then, Ukrainian drones spoofed by the Russians have breached NATO borders at least a dozen times.
If Article 4 is invoked when Russian aircraft enter NATO airspace, why not when Russian electronic interference causes Ukrainian drones to cross NATO borders? And why not in response to persistent gray-zone operations targeting critical infrastructure, in which Article 4 has not been invoked despite the operational investments NATO has made to counter such threats?
Whether or not NATO members choose to invoke Article 4, more Ukrainian drones will certainly enter allied airspace as a result of Russian interference. As Ukraine’s attacks on Russia succeed (the new offensive has struck dozens of targets up to July 24), NATO can expect Russian retaliation, and with it, spillover that further endangers NATO member states. Given that spoofing, jamming, and meaconing are as effective as they are low-cost, they are a phenomenon that is here to stay.
Erin Bailey is an intern at the Transatlantic Defense and Security program at CEPA.
Dr. Benjamin L. Schmitt is a Senior Fellow at the Department of Physics and Astronomy and the Kleinman Center for Energy Policy at the University of Pennsylvania, a Senior Fellow for Democratic Resilience at the Center for European Policy Analysis, a fellow of the Duke University “Rethinking Diplomacy” Program, and a Term Member of the Council on Foreign Relations. (Twitter: @BLSchmitt).
Europe’s Edge is CEPA’s online journal covering critical topics on the foreign policy docket across Europe and North America. All opinions expressed on Europe’s Edge are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.