Go back

PDB Afternoon Bulletin | September 29th, 2026: Russia Carries Out an Attack on NATO Soil & Iran’s Cryptocurrency Network

14m 5s

PDB Afternoon Bulletin | September 29th, 2026: Russia Carries Out an Attack on NATO Soil & Iran’s Cryptocurrency Network

European governments are intensifying efforts to counter what they describe as Russia’s hybrid warfare tactics, including sabotage and arson attacks on defense facilities like Milgram Robotics in Estonia. Authorities now believe these acts—though not full-scale warfare—are deliberate, coordinated, and linked to Russian intelligence services, prompting calls for a unified EU response framework to attribute and respond to such incidents. The debate centers on defining proportionate retaliation without overstepping NATO’s Article 5 thresholds, especially when attacks fall short of conventional military action. Meanwhile, a Senate investigation reveals that Iran has exploited USDT stablecoin to bypass U.S. financial sanctions, using it for oil sales, military equipment purchases, and transactions involving its central bank. Evidence suggests the network remains active despite enforcement efforts, with Iran adapting by shifting to alternative methods. The findings have led to formal requests for the U.S. Justice and Treasury Departments to examine Iran’s compliance with sanctions. Both the European and U.S. responses underscore growing concerns about digital and asymmetric threats, highlighting the need for clearer policies, faster coordination, and stronger deterrence mechanisms in the face of evolving hybrid and financial warfare.

Transcription

2095 Words, 13100 Characters

English
It's Tuesday, the 29th of September. Welcome to the PDB afternoon bulletin. I'm Mike Baker, your eyes and ears on the world stage. Let's get briefed. First up, in alleged Russian attack on NATO's soil is adding urgency to Europe's effort to build a common response to Russian sabotage and other hybrid attacks. Later in the show, a new Senate investigation says Iran has relied heavily on cryptocurrency to move money around US sanctions, exposing a digital workaround in the regime's shadow banking network. But first, today's afternoon spotlight. European officials are once again confronting a familiar problem. How do you respond when Russia is accused of attacking a NATO country in a manner that falls short of outright warfare and when it's difficult to ascertain with certainty who the culprit is? The latest case in what has become known as Putin's hybrid war against the EU comes from a story where authorities now say an arson attack last month against the defense company Milgram Robotics wasn't random vandalism. Authorities say it was a deliberate act of sabotage commissioned by Russian security services. The fire broke out on the 15th of August at a building used by Milgram in Tallinn, that's the Estonian capital. The damage was limited, but the target was significant. Milgram builds unmanned ground vehicles and other military systems, including equipment supplied to Ukraine. Three Latvian suspects were arrested in the days after the attack and later transferred to Estonian custody. Estonia's domestic intelligence service now says the operation was planned in advance and directly attributable to Russia. Now you ask yourself, "I wonder if the Kremlin denies those accusations?" Well, let me think. Yes, the Kremlin has denied those accusations. Now as we've been covering for quite some time here on the PDB, European governments are seeing a growing pattern of sabotage, arson, cyber attacks, and other disruptive operations that they believe are designed to weaken support for Ukraine, intimidate governments, and test how far Moscow can push things without provoking a conventional military response. Estonia's foreign minister says Russia is effectively testing Western democracies step by step, looking to see what it can get away with and how NATO will react. Estonia is now pushing allies to publicly condemn and attribute attacks when they believe Moscow is responsible and to establish clearer consequences for those operations, without all sounds fairly reasonable. European defense ministers are now considering a new common framework for responding to so-called hybrid attacks, operations that maybe hostile, deliberate and damaging, but still fall below the level of an armed attack that would clearly trigger NATO's Article 5 mutual defense clause. The European Commission has proposed what it calls an emergency security protocol, along with a broader counter-hybrid playbook designed to help governments coordinate quickly when one member status hit by sabotage or cyber attacks or other forms of interference. Officials are also discussing what a proportional response might actually look like, and that is where a complicated situation gets more complicated. If Russian forces cross Estonia's border with tanks, NATO's response would be relatively straightforward. But what happens when someone sets fire to a defense contractor? What happens when a railway line is sabotaged? A drone appears over sensitive infrastructure or a criminal intermediary carries out an operation that intelligence services later trace back to Moscow. Those incidents can be serious, they can disrupt military production, damage critical infrastructure, and undermine public confidence. But individually, they may not look like acts of war. That ambiguity is part of what makes hybrid operations worthwhile from Moscow's perspective. They create pressure without necessarily creating the kind of clear-cut event that forces NATO to respond collectively. European governments have been wrestling with this for years, and the problem has grown since Russia's full-scale invasion of Ukraine. Authorities across Europe investigated a large number of suspected sabotage incidents linked to Russia, although the strength of the public evidence varies from case to case. Estonia says the Millworm attack fits that broader pattern. The challenge now is deterrence. European officials want Moscow to believe that these operations will carry a real cost, but they also have to decide, well, what that cost should be. More sanctions, diplomatic expulsions, some form of coordinated retaliation against Russian intelligence networks, and that's the key question confronting European governments. What is proportionate, appropriate, response, when there is sufficient evidence to time Moscow to an act of hybrid warfare within the EU or targeting NATO allies? Clearly, the standard harshly worded memo or the stern look from a diplomat is not going to change Putin's stripes. And there's another complication. Any common EU mechanism would have to complement NATO rather than create a competing system. Some European officials are already warning that another layer of decision-making could make responses slower instead of faster. But the Millworm case now helps explain why the debate is happening now. If Estonia's assessment is correct, Russian security services commissioned an attack inside a NATO country against a company helping arm Ukraine. The fire itself did not cause catastrophic damage at the facility, but the larger question is whether Moscow believes it can keep carrying out operations like this because the West has never clearly defined what happens next. All right, coming up next, Senate investigators say Iran is lead heavily on digital dollars to help bypass sanctions and keep money moving through its shadow-backing network. I'll be right back. Hey, Mike Baker here. Now, I've been a business owner for many years, and I want to take just a moment to talk to all you small business operators out there. Here's the thing. Running any small business means dealing with constant, unexpected expenses, you know what I'm talking about. Whether it's upgrading an IT system or repair costs or managing payroll, there's always something. And you cannot afford to let traditional bank red tape slow your momentum. That's why you need Cardiff. America's favorite small business lender. With over $12 billion funded to small businesses nationwide, they specialize in high-speed liquidity. Unlike legacy banks, Cardiff's simple application takes only three minutes, come out three minutes, has absolutely no impact on your personal credit, then offers same-day funding up to $500,000. If you've been in business for a year or more with at least $20,000 a month in revenue, get the capital you need today. Your business deserves a partner that moves as fast as you do. Approval in minutes, funding same day, visit Cardiff.co/PDB. That's Cardiff.co/PDB. Real growth, fast funding, Cardiff. Borrow better. Hey, Mike Baker here with an important message to homeowners. Now, one of the most frustrating things about owning a home is that major repairs never happen at a convenient time, right? Your water heater quits, an electrical issue pops up, your AC goes down during the hottest week of the summer, it's never during winter, is it? Suddenly, you're scrambling to find help, and you're hoping that the repair bill isn't a disaster. These home issues and breakdowns often cost more than car repairs, and standard insurance, as you know, won't cover the wear and tear. That's why HomeServe is a game changer. It's like a subscription for your home, starting at $4.99 a month. Trust me, if I had a breakdown, HomeServe is who I'd want. They've got Naples raiding with a better business bureau and a 24/7 hotline, so they're always within reach. Look the truth is, your next costly home repair is coming. That's just how life works. Act now and get protected with a plan through HomeServe. For 50% less on your first year, go to HomeServe.com/DailyBrief to find the plan that's right for you. That's HomeServe.com/DailyBrief for 50% less. Savings are compared to renewal price, void and Florida. Welcome back to the afternoon bulletin. Washington has spent years trying to squeeze Iran out of the global financial system, but a new Senate investigation says the regime has found a new way to move money outside the traditional banking system, and it involves one of the largest names in cryptocurrency. The report comes from the Senate Permanent Subcommittee on Investigations. Investigators examined 846 cryptocurrency wallets that had already been sanctioned or targeted for seizure by the US or Israel because of alleged connections to Iran and its regional proxies. According to the report, 84% of those wallets conducted all or nearly all of their transactions using a cryptocurrency called USDT issued by the company Tether. Now for those of you not fully up to speed on the ins and outs of cryptocurrency, Tether issues what's known as a stablecoin called USDT. Unlike Bitcoin which can swing wildly in value, one USDT is designed to stay worth well about one US dollar. It's a digital dollar that can be moved around the world without going through a traditional banking system. American sanctions are designed in part to cut Tether run all from banks that rely on dollars and access to the US financial system. The Senate report argues that USDT has given Iranian entities another way to move funds, conduct trade, and access something resembling dollars without relying on those same financial institutions. Investigators say the network has been used for everything from moving money into and out of Iran to supporting the real and facilitating oil sales. The report also says USDT has appeared in networks connected to Iran's regional proxies and the purchasing sale of drones and other military equipment. Now one of the stranger pieces of the investigation involves Iran's central bank. Documents reported earlier by the journal appeared to show an Iranian company arranging the purchase of tens of millions of dollars worth of USDT on behalf of the central bank of Tehran. Blockchain and analysts later linked some of that cryptocurrency to money stolen during the roughly one and a half billion dollar hack of the Buybit crypto exchange and attack attributed to North Korea. Unlike some cryptocurrencies, USDT is issued by a centralized company. That means Tehr can freeze USDT that's sitting in specific wallets. The company has worked with law enforcement and has frozen some wallets tied to sanctioned or criminal activity. But Senate investigators argue that Tehran has not always acted quickly or consistently enough when sanctioned wallets were identified. Tehran did not respond to the journal's request for comments on this report. And Iran may already be adapting. The journal cites blockchain data showing that USDT accounted for a much smaller share of activity across Iran linked wallets this August than it did in previous years. It likely means that enforcement pressure is already pushing Iranian networks toward other methods. But the Senate investigators say USDT still appears repeatedly in wallets most recently targeted by the US, including wallets linked to Iran's central bank and oil sales networks. Senator Richard Blumenthal of Connecticut has now referred the findings to the Justice Department and Treasury Department and asked both to examine Tehran's sanctions and anti-money laundering compliance. And that, my friends, is the PDB afternoon bulletin for Tuesday the 29th of September. Now if you have any questions or comments and I hope you do just reach out to me at PDB at thefirsttv.com. And to listen to the show Add Free, you can do that. It's very simple. Just become a premium member of the president's daily brief by visiting PDBpremium.com. Now I'm Mike Baker and I'll be back tomorrow until then stay informed. Stay safe. Stay cool. Hey Mike Baker here. With a word about personal health and weight loss. Now of course everybody's been talking about weight loss injections right because the results have been so dramatic. They work by lowering blood sugar and reducing appetite. But what if you're looking to lose weight? And you're not interested in painful weekly injections, especially when you hear about some of those side effects. That's why doctors created a weight loss supplement called lean. That's L-E-A-N. And the results have been remarkable. The study of ingredients in lean have been shown to lower your blood sugar, burn fat by converting it into energy, and curb your appetite and cravings so you're not as hungry. But listen, lean is not for the casual diet or with only a few pounds to lose. The doctors at Brickhouse Nutrition created lean for frustrated dieters with 10 and more pounds to lose. So let's get you started with 20% off and free rush shipping so you can add lean to your healthy diet and exercise plan. Visit TakeLean.com and enter PDB for your discount. That's promo code [email protected]

Podcast Summary

Key Points:

  1. European officials are increasingly attributing sabotage attacks, such as the arson at Milgram Robotics in Tallinn, to Russian security services as part of a broader hybrid warfare strategy.
  2. The incident highlights the ambiguity in defining acts of war under NATO’s Article 5, as non-conventional attacks like fires or cyber operations may not trigger a full military response.
  3. Estonia and other NATO allies are pushing for a unified European response framework to clearly attribute and respond to hybrid attacks, aiming to deter Russia through proportionate consequences.
  4. A key challenge remains in determining what constitutes a "proportionate" response—such as sanctions, expulsions, or retaliation against intelligence networks—without triggering escalation or bureaucratic delays.
  5. A new Senate investigation reveals Iran has heavily relied on USDT stablecoin to circumvent US sanctions, enabling financial transactions and military procurement through its shadow banking network.
  6. Investigators found that Iranian entities, including the central bank, have used USDT for oil sales and drone purchases, with blockchain data showing persistent use despite enforcement pressure.
  7. Iran’s inconsistent response to sanctioned wallets and shifting toward alternative methods suggest adaptation, but USDT remains a significant tool in its financial operations.
  8. The findings have prompted calls for the Justice Department and Treasury to investigate Iran’s compliance with sanctions and anti-money laundering regulations.

Summary:

European governments are intensifying efforts to counter what they describe as Russia’s hybrid warfare tactics, including sabotage and arson attacks on defense facilities like Milgram Robotics in Estonia. Authorities now believe these acts—though not full-scale warfare—are deliberate, coordinated, and linked to Russian intelligence services, prompting calls for a unified EU response framework to attribute and respond to such incidents. The debate centers on defining proportionate retaliation without overstepping NATO’s Article 5 thresholds, especially when attacks fall short of conventional military action.

S. financial sanctions, using it for oil sales, military equipment purchases, and transactions involving its central bank. Evidence suggests the network remains active despite enforcement efforts, with Iran adapting by shifting to alternative methods.

S. Justice and Treasury Departments to examine Iran’s compliance with sanctions. S.

responses underscore growing concerns about digital and asymmetric threats, highlighting the need for clearer policies, faster coordination, and stronger deterrence mechanisms in the face of evolving hybrid and financial warfare.

FAQs

Authorities say a deliberate arson attack on Milgram Robotics' facility in Tallinn on August 15 was a sabotage operation commissioned by Russian security services, targeting a defense company that supplies military equipment to Ukraine.

Russia uses hybrid attacks—like arson, cyber operations, or sabotage—that are disruptive but don't meet the threshold of armed attack. These actions aim to weaken support for Ukraine, intimidate governments, and test Western responses without triggering NATO's Article 5.

The EU is developing an emergency security protocol and a counter-hybrid playbook to enable coordinated, rapid responses to sabotage or cyber attacks, including defining proportional consequences without triggering full NATO Article 5 responses.

No, the Kremlin has denied the accusations of Russian involvement in the attack on Milgram Robotics.

Iran is using USDT, a stablecoin issued by Tether, to move funds, conduct trade, and access digital dollars outside traditional banking systems, including for oil sales and purchasing military equipment.

The report found evidence that Iran’s central bank used USDT to purchase tens of millions of dollars worth of cryptocurrency, with some linked to funds stolen in a North Korean-linked hack of Buybit.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.