Introduction
On the 29th of August, 2023, Polskie Koleje Państwowe, the Polish State Railways (PKP), suffered an attack, bringing 20 trains across northwestern Poland to a standstill (Preston, 2023). The attackers carried out this attack very cheaply, using a simple radio-stop, or jamming, method to broadcast an emergency signal on a train radio system. This shut down critical rail links within Poland for several hours, repeatedly broadcasting a stop signal that could not be overridden while also playing recordings of the Russian national anthem and speeches by Putin (Ribeiro, 2023).
While not considered a cyberattack, jamming is within the realm of hybrid warfare and technology; as per experts at the Carnegie Mellon University’s Software Engineering Institute, it “is a denial-of-service attack where the attack transmits radio signals on the same frequency as the targeted communication, effectively disrupting or blocking the legitimate signals” and “can lead to service outages or operational disruptions” across networks (White & Bragg, 2025). The jamming attack interrupted Global System for Mobile Communications – Railway (GSM-R) communications, a critical infrastructure element for railway security (Gombac et al., 2022). When GSM-R is interrupted, emergency vehicle braking is triggered, stopping all trains within range of the respective broadcasting radio or radio station transmitting the signal (Ribeiro, 2023).
European railways are increasingly reliant on digital technology, thereby increasing their vulnerability to cyber threats, particularly regarding physical security measures, network security systems, and information security protocols (Ibadah et al., 2024, p. 1). As railway networks across Europe modernise, some of the most critical cybersecurity issues arise where legacy systems are integrated with new technologies (Ribeiro, 2023).
This paper will explore this increasing digitalisation and how Europe can better protect its rail infrastructure and military mobility from cyberattacks. European nations, when examining military logistics, cannot overlook the impact of cyberwarfare on critical railway infrastructure and the interoperability capabilities of European militaries, which depend on railways to move critical materiel, equipment, and soldiers.
To accomplish this, the paper will be split into four sections. Firstly, it will provide a conceptual framework that defines military mobility, dual-use infrastructure, and how cyberattacks constitute a form of hybrid warfare. Secondly, it explores several incidents demonstrating that this is a critical infrastructure issue. Thirdly, critical rail infrastructure chokepoints, particularly within Eastern Europe, will be addressed. Finally, it provides recommendations for how NATO and the European Union can strengthen rail security against cyber threats.
Conceptual Framework
This paper relies on several foundational frameworks to argue for increased cybersecurity measures to protect railway infrastructure and military mobility. The first of these is military mobility itself and what that entails regarding railways. Closely linked with military mobility is dual-use infrastructure. This section will also explore the changing nature of hybrid warfare and what role cyberattacks play in modern conflicts.
Military Mobility is an EU initiative that pushes the Union toward the concept of a Military Schengen, removing barriers to moving troops and military equipment across Europe to ensure swift responses in times of conflict or crisis, and integrating military elements into civilian infrastructure planning (EEAS, 2025). This initiative falls under the Permanent Structured Cooperation (PESCO) framework and reflects close cooperation between the EU and NATO to ensure integration across Europe (Fiott, 2019, pp. 55, 58).
NATO has pushed for military mobility and has cooperated with the EU since 2018, forming the Structured Dialogue on Military Mobility to address shared issues (NATO, 2025). The EU’s Military Mobility initiative closely reflects NATO’s general military infrastructure requirements; however, implementation faces challenges related to political issues and differences over sovereignty and implementation (Fiott, 2019, pp. 58, 60-61).
While there are still many barriers to military mobility, railroads are a cornerstone of the policy and its implementation, as trains move significant amounts of materiel, equipment, or personnel over long distances quickly and efficiently (van der Laan, 2025). Military Mobility exploits not just railways, but ports, airports, and roads, all of which constitute critical civil-military infrastructure (Horan et al., 2025, p. 30). The issue is that each country guarantees the security of this infrastructure to varying degrees, and to ensure military needs are met, an in-depth analysis of each nation’s requirements must be conducted (Majchut et al., 2026, pp. 1042, 1047).
Because critical infrastructure comprises public and private assets, cooperation between national governments and the private sector is essential to ensure smooth operations (Beckvard & Zotz, 2021, pp. 1-2). As the world digitalises, it has grown reliant on information technology (IT) and operational technology (OT) to control and monitor infrastructure, devices, and processes (Beckvard & Zotz, 2021, p. 2).
With the increasing probability of cyberattacks, NATO has taken steps to recognise cyberspace as a legitimate hybrid warfare domain, stating that “a cyberattack can cause damage comparable to that of an armed attack, and thus become a case for collective defence pursuant to Article 5” (Marrone & Sabatino, 2021, p. 4). One critical area hybrid warfare emphasises is digital attacks, which are treated with the same severity as physical attacks. While this can be observed across the world, this is perhaps best reflected in the Russian escalation of hybrid warfare.
About the author
Alexander Keuerleber is a Defense and Security research trainee at Finabel