Three unconnected disruptions this week — an information-operations assessment focused on Rome, an unresolved pattern of cyberattacks, and a first-hand account of Kremlin tactics — share one feature: nobody can say, with evidentiary certainty, who is responsible.

A new assessment from the Robert Lansing Institute examines how Russian, Chinese and Iranian information operations have targeted Italy's democratic institutions — not through one scandal, but through sustained influence activity aimed at shaping domestic political debate. Rome is read not as the target of one hostile state, but as a space where several states' campaigns run in parallel, each exploiting the same institutional openness.

That parallel-actor picture is possible partly because proving any single government's hand in an attack is technically hard. Cybersecurity experts interviewed by RTL Today explain why state involvement in cyberattacks is so difficult to establish in evidentiary terms: infrastructure is routed through third parties, and layers of contractors and intermediaries leave technical indicators pointing toward a sponsor without ever proving one. The result echoes Italy's information-operations case: intelligence services and researchers can reach confidence about who is responsible, but confidence is not proof — and proof is usually what triggers a collective response, whether sanctions, expulsions or a unified diplomatic statement.

Together, these threads support a hypothesis: that the ambiguity surrounding hybrid actions is not an unfortunate byproduct of clandestine tradecraft, but the mechanism through which they achieve their effect. A first-person account in The i Paper, written by someone describing direct exposure to Russian tactics, argues that hybrid warfare functions as an opening phase rather than a self-contained campaign against Vladimir Putin's Kremlin.

Supporting the hypothesis: the Lansing Institute's account of multi-state information operations running inside one EU member state's institutions, and RTL Today's account of why attribution failure is structural rather than incidental. Against it: none of the three sources offers a single confirmed, publicly attributed link between a named incident and a state directive — which is arguably the point. A strategy built on plausible deniability is, by design, hard to falsify from the outside; the absence of proof is what it is engineered to produce.

What to watch: whether Italian authorities or EU institutions formally attribute any of the information operations described by the Lansing Institute to a specific state; whether any European government converts a high-confidence cyberattack assessment into a public, sanctionable accusation in the coming weeks; and whether further first-person accounts like the one in The i Paper emerge from other officials, which would suggest a coordinated public-warning effort rather than an isolated one.