Завантаження публікації
ОГОЛОШЕННЯ

Russian sabotage in Europe: the explosives-laden Leipzig drone puts Germany and NATO to a new test


Save
Сергій Балацун
Данила Май
Дмитро Швецов
Сергій Балацун; Данила Май; Дмитро Швецов
Газета Дейком | 01.09.2026, 20:05 GMT+3; 13:05 GMT-4
Мова публікації: English

Russian sabotage in Europe is increasingly suspected in incidents involving defence plants and logistics supporting Ukraine. After an explosives-laden drone was found beside a Ukrainian cargo aircraft in Leipzig, Germany is preparing to blame Russia — turning attribution into a test of deterrence.

The warning arrived not as a missile strike but as an object lying inside one of Germany’s most important cargo airports. In early August, an explosives-laden drone was discovered at Leipzig/Halle near a Ukrainian Antonov transport aircraft, raising the possibility that a major aviation disaster had narrowly been avoided.

Investigators subsequently found evidence suggesting that the drone had reached the aircraft, while another suspicious drone was discovered near the airport days later. Leipzig/Halle is a major civilian freight hub but also serves military logistics, making an attack there potentially significant well beyond the loss of a single aircraft.

For weeks, Berlin stopped short of saying publicly who it believed was responsible. Chancellor Friedrich Merz promised that Germany would identify the perpetrator once its security agencies had completed their work, while ministers repeatedly stressed that suspicion alone was not sufficient grounds for accusing another state.

By September 1, however, that caution appeared close to producing a conclusion. Reuters reported that Germany was preparing to formally accuse Russia of involvement in the attempted attack and was considering a coordinated response with allies. The latest reporting still described the attribution as forthcoming rather than completed.

According to Daycom’s analysis of verified public reporting, this gap between attack and attribution is central to understanding Russian sabotage in Europe. An operation does not have to remain permanently anonymous to be useful. It only has to create enough uncertainty to delay the political response and complicate decisions about retaliation.

The Leipzig case is particularly sensitive because of the apparent target. Several Ukrainian Antonov An-124 heavy cargo aircraft operate from the airport, and the site forms part of a logistics network used by civilian operators as well as European and NATO-related military movements.

A successful explosion would therefore have produced effects extending beyond the price of one aircraft. A fire could have disrupted a major freight airport, damaged neighbouring equipment, interrupted commercial operations and affected a transport capability that is difficult to replace quickly.

That is what makes sabotage economically attractive as an instrument of coercion. An attacker does not need to destroy an entire airport. Damaging one rare aircraft or temporarily closing one logistical node can force governments and companies to spend far more on security than the operation itself costs.

German Interior Minister Alexander Dobrindt has described the Leipzig episode as part of a wider hybrid threat rather than an isolated incident. Germany is also leading plans among Baltic Sea NATO countries for faster information-sharing and coordinated responses to drone and sabotage threats.

The concern extends well beyond Germany. European governments have faced fires, suspected arson, interference with infrastructure and other incidents involving companies connected to defence production or assistance for Ukraine, although the evidence linking individual cases to Moscow varies considerably.

Estonia provided one of August’s clearest examples of how authorities are handling that distinction. After an arson attack involving premises used by Milrem Robotics, a manufacturer of unmanned ground vehicles supplied to Ukraine, Prime Minister Kristen Michal said investigators were examining possible sabotage and Russian involvement.

Suspects had been identified, but investigators had not publicly established a definitive chain of responsibility to Moscow. Milrem said the incident did not disrupt its production or deliveries to Ukraine, including its plans to expand the number of robotic military systems operating there.

That evidentiary caution matters. A suspected Russian campaign can be real while a particular fire still turns out to have another cause. Treating every unexplained industrial accident as sabotage would ultimately weaken European credibility when intelligence services do obtain compelling evidence of state involvement.

Italy demonstrates the problem. On August 13, a fire and major explosion struck the KNDS Ammo Italy plant at Colleferro, south of Rome. The facility produces medium- and large-calibre ammunition, but early information pointed toward an incident in the explosives-pressing department, and no one was injured.

Russian involvement quickly became part of the public debate, partly because the factory belongs to the European defence sector and its products include ammunition supplied to Ukraine. Yet Italian Defence Minister Guido Crosetto said authorities had no indication at the time that the explosion was anything other than an internal problem.

Crosetto’s formulation captured the dilemma facing European governments. He has acknowledged that Russia conducts a dangerous hybrid campaign, but argued that acknowledging such a campaign does not justify assigning Moscow responsibility for an incident before investigators establish the evidence.

The alternative approach is visible farther east. Poland and the Baltic states have generally been more willing to describe suspected sabotage, cyber operations, border pressure and airspace incidents as components of a broader Russian strategy rather than as disconnected security problems.

Their assessment is shaped partly by experience. Eastern European intelligence agencies have warned for years about Russian covert activity, while governments geographically closer to Russia have tended to see the distinction between war in Ukraine and pressure on NATO territory as increasingly artificial.

Latvian leaders have argued that the threat is not a hypothetical future stage of confrontation but something already occurring below the threshold of conventional war. NATO itself says Russian hybrid activity has increased, although the alliance said at the end of August that it saw no imminent threat of a direct military attack.

That distinction — between aggression and an imminent conventional assault — is crucial. Sabotage allows an adversary to impose costs while avoiding the unmistakable signature of tanks crossing a border or missiles launched openly by uniformed forces.

Western intelligence officials have previously described a Russian model built partly around proxies: criminals, ideologically sympathetic actors or people recruited online for relatively small payments. Such arrangements can distance a state intelligence service from the person who ultimately plants a device or sets a fire.

The structure offers plausible deniability. An arrested perpetrator may have no formal Russian government position and may never have met an intelligence officer face to face. Instructions, payments and targeting information can pass through intermediaries or disposable online accounts.

It also produces a dangerous lack of control. A professional intelligence operative may understand the consequences of handling explosives around an airport. A cheaply recruited proxy may not. The same deniability that makes an operation politically useful can increase the chance of accidental civilian deaths.

The Leipzig incident represents a more serious technological version of that risk. An explosive drone does not require an operative to enter a secure hangar or remain beside the target. It can potentially be launched from kilometres away, cross barriers that stop people and attack infrastructure from above.

Traditional perimeter security was not designed for that environment. Guards, fences and access badges remain necessary, but they offer limited protection against a small unmanned aircraft approaching an ammunition plant, communications facility, port or cargo airport.

Europe is therefore confronting a security problem familiar from the Ukrainian battlefield: inexpensive drones can create disproportionately expensive defensive requirements. Every strategically important facility cannot simply be surrounded by a full military air-defence system.

Germany’s push for a Baltic Sea drone-defence task force reflects that calculation. The initiative is intended to improve rapid information-sharing among NATO states in a region already concerned about suspected sabotage against cables, pipelines and other critical infrastructure.

The point is not only to intercept individual drones. Shared information can allow investigators to compare aircraft types, routes, communications, explosives, financial transfers and recruitment patterns across borders instead of treating every incident as an entirely separate national case.

Repeated technical details can be decisive in attribution. One suspicious fire may produce little evidence. Similar devices, payments or digital signatures appearing in several countries can reveal a network that no single police investigation would have been able to identify on its own.

This is why Germany’s hesitation over Leipzig has generated such intense debate among security specialists. A high standard of proof protects governments from making reckless accusations. But deterrence also depends on an adversary believing that covert attacks will be detected and carry consequences.

Former German security officials have argued that Moscow watches Western reactions closely. In that interpretation, every ambiguous incident becomes a test: how much disruption can be created before a European government identifies the operation publicly and imposes a meaningful cost?

The difficulty is that the two risks point in opposite directions. Attribute too quickly and a government can be wrong, damaging both its credibility and diplomatic stability. Attribute too slowly and the delay itself can signal that deniable attacks offer an inexpensive way to exert pressure.

The sharper Russian rhetoric surrounding Western military assistance adds context but not proof. Moscow has publicly warned that it will take tougher measures against infrastructure supporting Ukraine. Such statements establish political intent, yet they cannot substitute for evidence in any individual sabotage investigation.

A credible attribution requires more: communications, payments, technical signatures, intelligence reporting, links between suspects and handlers, or a combination of evidence strong enough to reconstruct who ordered an operation rather than merely who executed it.

If Germany formally attributes Leipzig to Russian intelligence, the consequences will therefore reach beyond one criminal investigation. Europe’s largest economy would be declaring that an operation involving explosives and a Ukraine-related aviation target took place on German territory at Moscow’s direction.

That would move the case from policing into foreign and security policy. Reuters reported that Berlin was considering sanctions and consultations with partners, while Foreign Minister Johann Wadephul signalled that Germany would respond if responsibility for the attack were established.

Sanctions, however, present their own limitation. Measures against senior officials may impose political costs on Moscow but do little to stop a person recruited online for a few thousand euros. Countering that model requires disrupting recruitment, money flows, communications and the networks identifying potential targets.

Physical protection must change as well. European arms plants, transport hubs and warehouses built for a peacetime security environment increasingly need detection systems, electronic countermeasures, protected storage and contingency plans for operations under persistent drone threat.

The civilian nature of much of this infrastructure complicates the task. Leipzig/Halle is simultaneously a commercial airport, a major freight centre and a useful node for military logistics. Closing it into a fortress would undermine the economic function that makes the airport strategically valuable in the first place.

Similar tensions exist at ports, railway terminals and industrial plants across Europe. NATO depends heavily on civilian infrastructure to move military equipment, while European support for Ukraine increasingly passes through factories and logistics networks that were never designed as potential front-line targets.

That may also make the familiar term “hybrid warfare” less useful politically. The phrase covers cyberattacks, covert influence, sabotage and proxy violence, but an explosives-laden drone beside an aircraft is physically dangerous in a way that the abstract language of hybridity can obscure.

European Parliament security committee chair Marie-Agnes Strack-Zimmermann has argued that incidents of this kind should be described more plainly as attacks when the evidence supports attribution. Her point reflects a wider concern that cautious terminology can unintentionally minimise what has become a tangible security threat.

Yet changing vocabulary does not solve NATO’s central problem. The alliance needs to discourage a campaign that operates below the obvious threshold of conventional armed attack without creating an automatic escalation mechanism every time a warehouse burns or a suspicious drone appears.

That ambiguity is precisely what makes grey-zone operations valuable. The physical cost may fall on Europe immediately, while the political debate begins with questions: Was it sabotage? Who ordered it? How confident are the investigators? What level of response is justified?

Every unresolved question buys time for the attacker. Every requirement for additional guards, sensors and counter-drone systems transfers costs to the defender. Even a failed operation can therefore succeed partially if it forces Europe to protect thousands of potential targets simultaneously.

Leipzig matters because the scenario came unusually close to becoming something much larger. What might otherwise have entered the record as another suspicious European security incident involved explosives beside a major aircraft at an airport central to international cargo operations.

The fact that disaster did not occur does not make the problem hypothetical. It instead gives Germany the rare opportunity to decide how it will respond before a suspected sabotage operation produces mass casualties rather than after one has already done so.

Berlin’s forthcoming attribution will therefore be only the first test. The harder question is whether Germany and its allies can build a response that makes such operations materially harder, more detectable and more expensive for whoever organises them.

Europe cannot place military air defences around every warehouse, factory and airport. It can, however, share intelligence more quickly, standardise cross-border investigations, protect particularly sensitive logistics nodes and establish predictable consequences when state responsibility is proven.

Without such a system, every new incident risks following the same sequence: an explosion or fire, weeks of uncertainty, competing political interpretations and finally a debate about whether enough evidence exists to act.

That delay is no longer merely an investigative inconvenience. If European assessments of Russia’s sabotage campaign are correct, uncertainty itself has become part of the weapon — allowing pressure to accumulate while governments decide where crime ends and interstate aggression begins.

The explosives-laden drone at Leipzig/Halle has brought that boundary into sharp focus. For NATO, suspected Russian sabotage in Europe is no longer simply an extension of the war against Ukraine happening somewhere in the shadows. It is increasingly a question of how the alliance protects its own territory without waiting for the grey zone to turn unmistakably red.


Сергій Балацун — Міжнародний кореспондент, який пише про всі новини, які надходять з Франції: нову політику уряду, політичні перегони, соціальні протести, гучні судові справи, культурні тенденції, природні та техногенні катастрофи та багато іншого.

Данила Май — Кореспонден, яка спеціалізується на бізнесі, економіці та технологіях. Вона проживає в Європі та висвітлює міжнародні новини.

Дмитро Швецов — Міжнародний кореспондент, який висвітлює війни, зокрема події в Україні, пише про бої на фронті, атаки на цивільні об'єкти та вплив війни на населення України. Він базуєтсья в Лондоні, Великобританія.

Цей матеріал є частиною розгорнутої теми: Загроза Третьої світової війни, яка охоплює численні цікаві аспекти цієї події. Газета «Дейком» ретельно відстежує події, проводячи перевірку джерел та інформації, щоб забезпечити нашим читачам найбільш точне та актуальне інформування.

Повторний випуск публікації 17.09.2026 року о 23:20 GMT+3 Київ; 16:20 GMT-4 Вашингтон.

Цей матеріал опубліковано 01.09.2026 року о 20:05 GMT+3 Київ; 13:05 GMT-4 Вашингтон, розділ: Світові новини, Європа, Війна Росії проти України, Аналітика, із заголовком: "Russian sabotage in Europe: the explosives-laden Leipzig drone puts Germany and NATO to a new test". Якщо в публікації з'являться зміни, про це буде зазначено та описано у кінці публікації.

Читайте щоденну газету та загальну стрічку новин газети Дейком, яка поєднує багато цікавого в понад 40 розділах з усіх куточків світу.


Save
ОГОЛОШЕННЯ

Новини, які можуть Вас зацікавити:

Штатні та позаштатні журналісти газети «Дейком» щодня готують сотні публікацій, щоб читачі отримували найоперативнішу, перевірену й глибоку інформацію. Ми працюємо для тих, хто хоче розуміти суть подій, бачити широку картину та бути на крок попереду.

Останні новини

Вибір редакції

Європейські новини: