Russia's Missiles Behind the Swarm
How massed drone and decoy attacks creating openings in Ukraine's air-defence system.
WAR, SECURITY & GEOPOLITICS
Dr Danie Adendorff
7/27/20266 min read


Russia's Missiles Behind the Swarm
How massed drone and decoy attacks may be creating openings in Ukraine's air-defence system
Dr Danie Adendorff DSc (c.h), MSc
————————————————————————
Russia's overnight attacks on Ukraine on 21–22 and 22–23 July deserve closer examination, not because either raid was unique in isolation, but because the same operational structure appeared on consecutive nights. A small missile package was embedded inside a far larger wave of attack drones and decoys. The drones were defeated at a high rate. The missiles were not. That divergence raises a serious question: is Russia using the drone swarm less as the principal weapon than as a mechanism for consuming attention, radar capacity, electronic-warfare effort and engagement opportunities while the more consequential missile threat moves through the same battlespace?
The repeated strike pattern
From 18:00 on 22 July into the early hours of 23 July, Russian forces launched one Iskander-M ballistic missile, five Kh-59/69 air-launched guided missiles and 168 uncrewed aerial vehicles against Ukraine. The drone package combined several systems: Shahed-series attack drones, including some jet-powered variants, Gerbera and Italmas attack drones, and Parodiya-type decoys designed to resemble genuine strike platforms in radar and flight behaviour. The launches came from six locations: Bryansk, Kursk, Oryol and Primorsko-Akhtarsk in Russia, as well as occupied Donetsk and Hvardiiske in Crimea.
The preceding night followed almost the same template. Russia launched one Iskander-M, three Kh-59/69 missiles and 216 drones drawn from the same four categories and dispatched from the same six points. The principal change was not the architecture of the attack, but its scale and missile-to-drone ratio. Repetition matters. A single raid can reflect circumstance. Two closely matched packages on consecutive nights begin to reveal a method.
The operational logic of the decoy layer
The strike package joined weapons that impose very different demands on the defender. The Iskander-M presents a fast, manoeuvring ballistic threat. The Kh-59/69 family adds a small group of guided air-launched missiles. Around them sits a numerically dominant drone layer made up of genuine attack systems and dedicated decoys. The Parodiya is especially important because its operational value does not depend on reaching a target. It is a consumption asset. Its purpose is to be detected, classified, tracked and, in many cases, engaged. Every such contact absorbs part of a finite defensive system.
Ukraine's response draws on an integrated air-defence and early-warning radar network, electronic-warfare units that jam or spoof drone navigation, mobile fire groups that engage low and slow targets at close range, and a limited inventory of advanced surface-to-air systems. Patriot batteries and comparable high-end systems remain among the few assets able to engage the most demanding ballistic and high-speed missile threats with credible reliability. The imbalance is structural. Many drones can be attacked by relatively abundant and comparatively inexpensive means. The missile layer requires scarce sensors, scarce engagement channels and scarce interceptors.
What the interception figures show
The most important change between the two nights was the level of missile leakage. On 21–22 July, Russia fired four missile-type weapons: one Iskander-M and three Kh-59/69 missiles. Three were intercepted, leaving only the Iskander-M to penetrate. That produced a leakage rate of 25 percent. On 22–23 July, six missile-type weapons were launched: one Iskander-M and five Kh-59/69 missiles. Only two were intercepted, allowing four to get through. The leakage rate therefore rose to 67 percent.
The drone picture moved in the opposite direction. Ukrainian defences reportedly defeated 154 of 168 drones on the second night, or roughly 92 percent. On the previous night, 204 of 216 were defeated, close to 94 percent. The system therefore continued to destroy the great majority of the force most visibly associated with the raid, while its performance against the smaller and more consequential missile component deteriorated sharply.
In practical terms, the layer expected to be intercepted was intercepted at a stable and very high rate. The layer intended to penetrate achieved a markedly better result on the second night. That does not prove the drone swarm caused the missile leakage, but it identifies the operational effect that must now be examined.
A qualified Russian success, not a breakthrough
Judged solely as a drone attack, the raid was unsuccessful. Roughly nine in every ten drones and decoys were defeated, consistent with the high interception rates Ukraine has reported across similar attacks. Judged as a combined operation in which the drone mass shielded or burdened the defence while missiles carried the higher-value effect, the result was more favourable to Russia. The missile leakage rate almost tripled from one night to the next, and the Iskander-M penetrated on both occasions.
This should not be exaggerated into evidence of a decisive breakthrough. Two nights do not establish a trend, and the available open-source data cannot prove the mechanism. The higher leakage rate may have resulted simply from the larger missile package: five Kh-59/69 missiles rather than three competing for a fixed number of engagement channels. It may also have reflected a diversion or saturation effect generated by the drone and decoy layer. Both explanations fit the limited evidence, and Ukrainian officials have not publicly identified which mechanism was decisive.
The defensible conclusion is narrower. Russia repeated a recognisable structure: a small, high-value missile strike enclosed within a much larger multi-type drone and decoy package. On the second use of that structure, the missile component became measurably harder to stop. That is sufficient to treat the pattern as a developing tactic requiring systematic analysis. It is not sufficient to claim that causation has been established.
The ISR and command burden
The central vulnerability may lie less in the number of drones destroyed than in the work required to destroy them. Each of the 168 contacts had to be detected, classified and managed before it could be dismissed as a decoy or assigned for engagement. That workload is absorbed by radar operators, electronic-warfare teams, mobile fire groups and command personnel whose capacity is finite. Faster and more reliable discrimination between Parodiya decoys and Shahed, Gerbera or Italmas attack drones would release defensive attention for the missile picture earlier in the engagement cycle.
The use of the same six launch areas on both nights also points to a left-of-launch warning problem. Repeated force-generation patterns around known sites should be exploitable through standoff intelligence, surveillance and reconnaissance, satellite imagery, signals intelligence and pattern-of-life analysis. Earlier warning would reduce the volume of discrimination and prioritisation that must be compressed into the final minutes after launch.
The missile engagement chain must also be protected from drone triage. Both the Iskander-M and Kh-59/69 present short decision windows. If their tracks compete with scores or hundreds of drone contacts for command attention, radar bandwidth, classification effort or cueing capacity, an already narrow engagement margin becomes thinner. Missile fire-control pathways therefore need functional separation and protected priority, not merely doctrinal statements that missiles are more important.
The decoy problem further implies a gap in signature libraries and automated classification. If Parodiya tracks continue to consume substantial engagement resources, radar cross-section libraries, flight-profile models or machine-assisted classifiers may not yet identify them with sufficient speed and confidence. This is not an insoluble feature of the threat. It is a technical and analytic problem that can be reduced through better data, improved sensor fusion and continual updating of threat signatures.
What must be measured next
The immediate analytical weakness is the absence of a standing, publicly available dataset linking drone-package composition to missile leakage across multiple nights. At present, assessments must be reconstructed from individual strike summaries. A dedicated cross-night analysis should record launch locations, drone and decoy composition, missile types, engagement rates, regional targeting patterns and observed penetrations. Only then will it be possible to distinguish a genuine saturation tactic from the statistical noise of an unusually difficult night.
Human performance must be included in that analysis. The difference between 168 and 216 simultaneous drone contacts is not merely numerical. It represents a substantial increase in cognitive and procedural load for radar, command-and-control and fire-control teams. A swarm attack can therefore probe a human bottleneck even when the technical systems remain operational. The defender may continue to shoot down most incoming drones while suffering reduced decision quality against the smaller number of weapons that matter most.
Conclusion
Russia's recent attack pattern does not show that Ukraine's air defences have collapsed. It shows something more subtle and potentially more durable: a method of forcing the defender to spend large amounts of effort on a threat layer that is mostly defeated while creating uncertainty around the performance of the missile-intercept layer. The decisive metric is therefore not the percentage of drones destroyed in isolation. It is whether the combined raid degrades the defender's ability to detect, classify, prioritise and engage the weapons with the greatest destructive potential.
For Ukraine, the operational priority is clear. Improve early warning at known launch sites, accelerate decoy discrimination, protect the missile sensor-to-shooter chain from drone workload, and build a cross-night evidence base capable of testing whether missile leakage rises with swarm complexity. Until that analysis is available, the tactic should be treated neither as a Russian breakthrough nor as a statistical curiosity. It is a repeatable pressure mechanism, and it warrants sustained attention.
Source and analytical note
This article is based on published Ukrainian Air Force overnight attack summaries for 21–22 and 22–23 July 2026 and Ministry of Defence reporting covering the same period. It is an open-source analytical assessment and not an actual Ukrainian military debrief or internal command document.
Author workflow disclosure.
This article was produced through an AI-assisted but human-directed workflow. AI support was used for accessibility assistance, structuring, language refinement, source-discovery prompts, revision planning, and conversion of editorial comments into amendments. Dr Danie Adendorff retained responsibility for the argument, accepted or rejected changes, checked the logic of claims, assessed source credibility, and remained accountable for the final text. AI-generated material was not treated as empirical evidence. Synthetic or illustrative examples were not presented as observed data.
© 2026 WDA Publishing. All rights reserved.