Mark Rutte Tells NATO Allies to Blame Russia Even Without Proof: The ‘Almost Sure’ Standard

Oct 4, 2026 | WAR: By Design

NATO blame Russia attribution

NATO Secretary-General Mark Rutte told member states this week that near-certainty is a sufficient threshold for publicly attributing incidents to Russia, a statement that has drawn scrutiny for the evidentiary bar it sets when accusing a nuclear power of sabotage. The remarks were made at a joint press conference with Lithuanian Prime Minister Mindaugas Sinkevicius and represent the clearest public articulation yet of an alliance posture that treats presumption as a workable substitute for proof.

What Rutte Actually Said

Rutte’s words were direct. Quoting NATO Supreme Allied Commander Europe Alexus Grynkewich, who had addressed a European Parliament committee the day before, Rutte said: “You have heard the Supreme Allied Commander yesterday saying, ‘Hey, when able, when you are sure it is the Russians, or almost sure it is the Russians, attribute it to the Russians’, exactly like Estonia did today. I applaud it.”

General Grynkewich had framed public attribution as a “deterrent” against what he called the “Russian threat.” Rutte went further, praising Estonia’s accusation against Moscow and urging other NATO governments to follow that example by actively sharing intelligence with one another.

The press conference took place in the context of what Rutte called “malign grey zone activities”, a catch-all phrase NATO applies to incidents ranging from suspected arson and sabotage to cyber intrusions and misinformation campaigns that member states attribute, with varying degrees of evidence, to Russian state actors.

The Estonia Case: A Template Without Evidence

The specific incident Rutte applauded involved Milrem Robotics, an Estonian company that manufactures unmanned military vehicles supplied to Ukraine. Estonian authorities say an arson attack occurred at a Milrem facility in the Lasnamäe district of Tallinn on the night of August 14-15. Estonian Foreign Minister Margus Tsahkna stated that, based on findings from the country’s Internal Security Service, “we can conclude with certainty that the arson attack was an act of sabotage ordered by the special services of the Russian Federation.”

Estonian Internal Security Service chief Margo Palloson told broadcaster ERR that the perpetrators were Latvians who had been living in Russia and had taken part in previous attacks. Three suspects were arrested in Latvia and extradited to Estonia. Palloson also acknowledged that “individuals recruited for such operations may be misled or manipulated and may be given false or fabricated justifications for their actions in an effort to conceal the involvement of the Russian state.” That caveat alone raises a methodological question: if recruited individuals can be manipulated to obscure who is truly directing them, how does attribution to the Russian state reach the level of certainty Tsahkna claimed?

Russia denied involvement. Moscow has consistently rejected allegations of hybrid warfare attacks across Europe, characterizing the accusations as unfounded.

Why the Evidentiary Standard Matters

The gap between “almost sure” and “certain” is not a semantic quibble. Research published by NATO’s Cooperative Cyber Defence Centre of Excellence in Tallinn found that without sufficient attribution, it is impossible to enforce regulations, laws, or treaties. The same research noted that false-flag operations in the cyber domain are significantly easier to execute than in the physical world, and that many technical methods of attribution can be deceived. A 2020 paper in the journal Cybersecurity found that false-flag campaigns apply covert tactics to deliberately misguide attribution attempts, either hiding traces or actively implicating a third party.

In short, the harder question is not whether an attack happened, but whether the chain of evidence connecting it to a specific state actor is solid enough to withstand scrutiny. Rutte’s formulation skips that question and turns public blame into a deliberate policy instrument.

Attribution as Strategy, Not Investigation

Grynkewich’s framing before the European Parliament committee made the strategic logic explicit: public attribution is meant to function as a deterrent, not simply as a factual record. That is a significant admission. It means that naming Russia serves a signaling purpose regardless of whether the evidence meets a legal or investigative standard. The accusation itself is the policy tool.

Rutte reinforced this by calling Estonia’s approach an example worth copying. He urged other NATO members to adopt the same posture and share intelligence to support it. The effect is to normalize a process in which the political decision to attribute precedes, or at least runs parallel to, the evidentiary work of establishing who is responsible.

Moscow’s Response and NATO’s Own Rhetoric

Russia has dismissed the broader body of NATO accusations about a supposed “Russian threat” as “nonsense” and has maintained it has no intention of attacking any alliance member. Moscow has also warned that NATO’s military buildup along Russia’s western borders, combined with the alliance’s public rhetoric, increases the risk of direct confrontation.

Rutte’s own record on Russia-related statements is not neutral. Last week, speaking at a Chicago Council on Global Affairs event in Iowa, he offered to help “protect the United States from threats of Russia.” At the same press conference with Sinkevicius where he endorsed the “almost sure” standard, he stated that NATO should be doing “even more for Ukraine, and not less.”

That context matters. Rutte is simultaneously the alliance’s chief spokesperson, its policy driver on Ukraine, and now the person publicly setting the evidentiary floor for blaming Russia. Those roles are not cleanly separable.

The Pattern Across Europe

According to BBC reporting, August 2026 alone saw Russia accused or suspected in a string of incidents: an explosive-laden drone found near Ukrainian cargo planes at Leipzig airport in Germany, a major fire at a Bulgarian defense firm warehouse, a large explosion at a munitions factory outside Rome, an attempted arson attack on a Ukrainian-owned drone manufacturer in Slovakia, and two suspicious fires in Poland. French President Emmanuel Macron called the pattern “a dangerous escalation by Russia.”

Each accusation followed the same structure: an incident occurred, authorities pointed toward Russia, and Russia denied it. No public trial, no detailed forensic record released to the press, no independent verification. Macron’s language, like Rutte’s, treated the attribution as settled before any such record was made public.

An Open Question the Alliance Has Not Answered

When attribution is framed as a deterrent tool rather than a factual conclusion, the natural question is what happens when the attribution turns out to be wrong. NATO’s own research body in Tallinn has documented how false-flag operations are specifically designed to produce credible-looking evidence pointing at an innocent party. If the alliance’s stated policy is to attribute incidents to Russia when members are “almost sure,” the margin for a consequential error is built directly into the doctrine.

Rutte has not addressed that margin publicly. Neither has Grynkewich. The question of what recourse exists, for the accused state or for alliance credibility, if a high-profile attribution later collapses, remains open.

This article draws on reporting from RT, News.by, and BBC News, as well as research from the NATO CCDCOE and the open-access journal Cybersecurity via Springer.

What did NATO Secretary-General Mark Rutte say about blaming Russia?

Rutte said that being ‘almost sure’ it is Russia is sufficient grounds to publicly attribute an incident to Moscow, quoting NATO Supreme Allied Commander Alexus Grynkewich and praising Estonia for doing exactly that without presenting detailed public evidence.

What was the Estonia incident that NATO applauded?

Estonia accused Russian special services of ordering an arson attack on Milrem Robotics, a defense company in Tallinn that supplies unmanned vehicles to Ukraine. The attack occurred on the night of August 14-15 and three Latvian suspects were arrested and extradited to Estonia.

Why is NATO treating public attribution as a deterrent rather than a finding of fact?

NATO Supreme Allied Commander Grynkewich explicitly described public attribution as a ‘deterrent’ against Russia, meaning the act of naming Russia is intended to serve a strategic signaling purpose, separate from whether the evidence meets an investigative or legal standard.

Want to go deeper? Ask NEX, the Decrypted Matrix research assistant, about the documents behind this story. It indexes every article here the day it is published and cites its sources.

Related Posts

Iran War Ecocide: Toxic Contamination, Satellite Blackouts, and the Environmental Cost of Operation Epic Fury

Iran War Ecocide: Toxic Contamination, Satellite Blackouts, and the Environmental Cost of Operation Epic Fury

U.S. and Israeli strikes during Operation Epic Fury have generated over 300 documented environmental harm incidents across 12 countries, emitted greenhouse gases equivalent to Iceland’s annual output in just two weeks, and blanketed Tehran’s 9 million residents in toxic black rain — all while a U.S.-directed satellite blackout limits independent verification of the full damage.

read more