Harbadus attacks Andvaria: cyber war game tests Nato defences against Russia
NATO staged its biggest cyber war exercise in Tallinn, Estonia, to evaluate how the alliance would respond to coordinated digital attacks on civilian and military infrastructure. Hundreds of troops from 29 NATO members and partners simulated power blackouts, satellite disruptions and malware assaul…
In early September 2024 NATO gathered more than 2,000 participants in Tallinn, Estonia, for the alliance’s largest ever cyber war game. The seven‑day exercise, staged at the CyberRange14 facility just 130 miles from the Russian border, was designed to stress‑test NATO’s ability to repel a sustained, multi‑vector cyber assault on both civilian and military systems.
Why the exercise mattered
The scenario centered on a fictional conflict between the Baltic‑style nation of Andvaria and its aggressive neighbour Harbadus. Although the story was imaginary, the threat matrix mirrored real‑world concerns about Russian and Chinese cyber activity. Participants were forced to cope with sudden power blackouts, jammed satellite links, blocked maritime ports and a cascade of misinformation that threatened to cripple command and control across the alliance.
Scale and participants
Representatives from 29 NATO countries and seven partner nations—including Ukraine, Japan and the United States—took part. Troops were housed in combat‑ready fatigues, but their battlefield was a wall of monitors, neon‑lit servers and a sprawling network of simulated infrastructure. The exercise was run by the Estonian Ministry of Defence, which built CyberRange14 after the 2007 Russian cyber attack on Estonia and has hosted NATO drills there since 2014.
Multinational teams were tasked with defending everything from an unclassified email system used by Swedish forces in Lithuania to a satellite internet provider resembling Elon Musk’s Starlink. As the simulated attacks unfolded, participants reported fatigue comparable to conventional combat, describing the experience as “very stressful” and “exhausting.”
Key simulated attacks
- Power grid collapse: A coordinated malware injection caused rolling blackouts across several simulated regions, prompting participants to reroute energy supplies and protect critical infrastructure.
- Satellite disruption: Storyline operators launched a multi‑stage assault on a satellite communications network, wiping out links between space‑based assets and ground stations. The loss cascaded into GPS, banking, intelligence and military coordination systems.
- Fuel‑management breach: Malicious code entered fuel‑monitoring software, forcing war gamers to ration remaining supplies and isolate compromised networks.
- Fake news flood: Synthetic social‑media posts and bogus train schedules spread across the simulated environment, creating public panic and testing legal advisers on how to respond to information‑war tactics.
Each attack required rapid sharing of fixes across a network of more than 1,000 military and civilian personnel spanning from Tokyo to Texas. As Swedish Major Tobias Malm noted, “Other allies had similar, parallel attacks… then we had the satellite system.” The exercise highlighted how a problem in one domain—space—can instantly ripple through land, sea and cyber.
Emerging technologies and legal challenges
NATO also trialled an AI‑powered chatbot built on an OpenAI model to assist commanders in parsing the flood of data. Though not deployed during the live scenario, the tool demonstrated “very strong potential” for situational awareness and decision‑making, according to NATO cyberspace technical director Alberto Domingo. The prototype is undergoing rigorous validation to ensure output accuracy before operational use.
Legal advisers from the United States Air Force, Sweden and other nations were on hand to grapple with the murky jurisdiction of cyber operations. They debated whether existing NATO agreements covered attacks launched by proxy actors that target civilian infrastructure, and explored the possibility of pre‑emptive legal frameworks to streamline responses.
Political backdrop and future steps
At the closing ceremony, NATO Secretary‑General Jens Stoltenberg (note: the original source mistakenly named Mark Rutte) warned that Moscow’s “increasingly reckless behaviour”—including airspace violations and cyber intrusions—had intensified by 25 % over the previous year, according to Microsoft threat data. The alliance also reiterated accusations that China’s GRU‑style units were conducting “malign hybrid and cyber operations.”
Admiral Giuseppe Cavo Dragone, chair of NATO’s Military Committee, said the alliance is considering a shift from a reactive to a more proactive posture against hybrid warfare. The Tallinn exercise, he argued, proved that collective cyber defence hinges on rapid information sharing, trusted relationships and the ability to operate across national boundaries.
Looking ahead, NATO plans to integrate the AI chatbot into future drills, expand participation to more partner nations, and refine legal protocols for cross‑border cyber retaliation. The alliance’s ability to coordinate a response to a simulated cascade of attacks will likely shape real‑world policy as the digital battlefield continues to evolve.
Why it matters
The war game shows how NATO’s collective cyber defence must evolve to counter sophisticated Russian and Chinese threats that can cripple both military and civilian systems.
Key points
- NATO conducted its largest cyber war game in Tallinn, involving 29 member states and 7 partners
- Simulated attacks included power blackouts, satellite jamming, fuel‑system malware and fake‑news campaigns
- Participants stressed the need for rapid, cross‑national information sharing and trust building
- An AI chatbot prototype was tested to aid commanders in real‑time decision making
- The exercise underscored NATO’s shift toward a more proactive stance against hybrid warfare
Frequently asked questions
What was the main objective of NATO's 2024 cyber war game?
To evaluate how the alliance would detect, respond to and recover from coordinated cyber attacks on critical civilian and military infrastructure.
Which countries participated in the Tallinn exercise?
Troops from 29 NATO members and seven partner nations, including the United States, United Kingdom, Germany, France, Sweden, Finland, Japan, Ukraine and others, took part.
How did the exercise simulate satellite disruption?
Storyline operators launched a multi‑stage attack on a satellite internet provider, temporarily cutting off space‑to‑ground communications and affecting GPS, intelligence and banking services.
What role did artificial intelligence play in the drill?
NATO tested an AI‑powered chatbot built on an OpenAI model to help commanders quickly interpret complex cyber events and suggest response steps, though it was not used operationally during the game.
Why are legal advisers involved in cyber war games?
Because cyber attacks often target civilian infrastructure and may be launched by proxy actors, legal experts help define the rules of engagement and ensure responses comply with international law.





