- Special to The Washington Times - Wednesday, August 26, 2026

KYIV, Ukraine — An explosives-laden drone discovered beside a Ukrainian cargo aircraft at one of Germany’s busiest freight airports has become the latest warning that Russia’s shadow war against the West may be entering a more dangerous phase.

German investigators are examining a suspected attempted attack at Leipzig/Halle Airport, a major logistics hub used by NATO and Ukraine’s Antonov Airlines. On Aug. 4, airport workers discovered a drone carrying what federal prosecutors described as “professional explosives and a detonator.”

Prosecutors said there was sufficient evidence to believe the device was intended to cause an explosion.



The drone was found near Ukrainian Antonov cargo aircraft, one of which was carrying military ammunition, according to German media citing a confidential police report. Investigators also suspect a second drone collided with a DHL cargo aircraft forced to abort a landing during the disruption.

The plane later landed safely in Hanover with minor damage.

German broadcasters NDR and WDR and the Süddeutsche Zeitung reported that investigators found a third drone west of the airport on Aug. 14, along with about 50 grams of suspected RDX, a military explosive. The federal prosecutor’s office in Germany has not publicly confirmed those findings.

Berlin has stopped short of formally blaming Moscow, although German media citing security sources say Russian intelligence is suspected. 

Interior Minister Alexander Dobrindt called the discovery a “hybrid attack” and said it represented “a new threat scenario.” He said the incident vindicated an earlier assessment that Germany faced “a high level of danger.”

Advertisement
Advertisement

Days later, he warned: “We’re not at war, but we are the daily target of hybrid warfare.”

On Tuesday, Chancellor Friedrich Merz said Germany had moved “further into the crosshairs of hybrid attackers” and warned that attackers were increasingly willing to accept severe property damage, injuries and even deaths.

The government, he said, was working with security agencies to determine who was responsible for Leipzig and would disclose its findings shortly.

“They will pay for it,” Mr. Merz said of those responsible for hybrid attacks.

The case comes amid a burst of fires, attempted attacks and cyber incidents involving Europe’s defense industry and countries supporting Ukraine.

Advertisement
Advertisement

On Tuesday, Slovak police announced that they had foiled an arson attack on a factory producing unmanned aerial systems in the country’s east. Three foreign nationals were detained, and police seized a large quantity of incendiary mixture, tools, phones, a camera and a handwritten plan.

Investigators charged the suspects with “public endangerment committed on commission,” but authorities have neither identified the suspected commissioning party nor publicly linked the plot to Russia.

In Estonia, prosecutors are meanwhile investigating an Aug. 14 arson attack against a building used by Milrem Robotics, whose unmanned ground vehicles have been deployed in Ukraine. Prime Minister Kristen Michal said suspects had been identified and that one avenue investigators were pursuing was Russian involvement.

“Attempts to intimidate us or undermine our security will not succeed,” Mr. Michal said.

Advertisement
Advertisement

A Congressional Research Service report released Aug. 11 said Russian-linked hybrid attacks in Europe have been “increasing in number and severity,” encompassing sabotage, assassination, cyberattacks, airspace violations and attacks on critical infrastructure.

One study cited by CRS found that the number of Russian hybrid attacks quadrupled from 2023 to 2024; another investigation counted at least 151 reported Russian operations between the February 2022 invasion and March 2026.

Government Communications Headquarters (GCHQ), Britain’s electronic intelligence agency, has reached a similar conclusion.

Russia is scaling up its daily hybrid activity against the U.K. and Europe,” GCHQ Director Anne Keast-Butler warned in May, saying the campaign stretched “from the seabed to cyberspace” and targeted infrastructure, supply chains, democratic processes and public trust.

Advertisement
Advertisement

A war fought through proxies

The campaign has evolved substantially since Russia’s full-scale invasion of Ukraine.

European governments expelled hundreds of suspected Russian intelligence officers after the invasion and earlier attacks such as the 2018 poisoning of former Russian spy Sergei Skripal in Salisbury, England. 

MI5 chief Ken McCallum has said that “over 750 Russian diplomats have been expelled from Europe since Putin invaded, the great majority of them spies.”

Advertisement
Advertisement

Russian intelligence has adapted by increasingly outsourcing operations to proxies, sometimes recruited through Telegram and other online platforms, to photograph military facilities, commit vandalism, set fires or plant explosives.

The recruits have included criminals and people motivated primarily by money, putting several layers of plausible deniability between Moscow and those carrying out the attacks, thereby complicating attribution.

Some investigations have now penetrated those layers.

Polish prosecutors earlier this year charged five people in an organized network they say operated for Russian intelligence and was involved in the 2024 arson attacks against an OBI store in Warsaw; an IKEA in Vilnius, Lithuania; and Warsaw’s vast Marywilska 44 shopping center, as well as preparations to burn another IKEA in Riga, Latvia.

In the Marywilska case specifically, prosecutors say one suspect was told in advance when the fire would begin, ordered to record both the blaze and the emergency response and instructed to send the footage to a handler for publication on Russian propaganda outlets. 

This outsourcing model has provided deniability but initially came at the cost of competence. European intelligence services now warn that Moscow is seeking more capable operatives.

Lithuania’s 2026 national threat assessment says the GRU, Russia’s military intelligence service, is using longer chains of intermediaries while seeking more experienced criminals.

The service is looking to conduct “more dangerous operations” in Western countries, Lithuanian intelligence said, targeting transportation networks and facilities connected with military and humanitarian assistance to Ukraine.

The potential lethality of those operations is also increasing.

German public broadcaster BR reported this month that Stefan Thumann, founder of Bavarian drone manufacturer Donaustahl and an outspoken supporter of Ukraine, had been warned of a suspected Russian-linked assassination plot.

German security sources told the broadcaster that plans to kill him may have involved a nerve agent, with Novichok among the methods discussed.

Thumann is now living under protection.

The case follows a previously uncovered Russian plot against Rheinmetall CEO Armin Papperger, whose company is one of Ukraine’s major suppliers of ammunition, armored vehicles and air-defense systems.

U.S. intelligence attributed that plot to Russia, while NATO subsequently confirmed the threat against Mr. Papperger formed part of a wider sabotage campaign against the alliance.

An Associated Press investigation published in May mapped 191 acts of sabotage, arson and other disruption linked to Russia by Western officials since the invasion. Three Western intelligence officials told AP that Russia’s campaign of targeted killings had also accelerated.

“This campaign is not by accident or chance,” one senior European intelligence official said. “There is political authorization.”

Testing NATO’s threshold

The ongoing campaign increasingly extends into cyberspace.

On Wednesday, the pro-Russian group Server Killers claimed responsibility for what Norway’s Digitalization Agency described as the largest denial-of-service attack it has ever faced. The hackers said the attack was retaliation for Norway renewing security cooperation with Ukraine.

For Western security officials, the common strategic thread is ambiguity and deniability.

Sabotage carried out by paid criminals, unexplained drones and nominally independent hacker groups can impose costs, disrupt weapons production and consume investigative resources without offering NATO the clarity of tanks crossing a border or missiles deliberately striking an alliance member.

This ambiguity complicates retaliation. CRS describes this hybrid approach as exploiting the gap between peace and armed conflict, where uncertainty over attribution can constrain the victim’s response.

Moscow routinely denies directing sabotage in Europe and describes Western accusations as anti-Russian propaganda.

But Western intelligence agencies increasingly see the campaign as a means of punishing governments supporting Kyiv, interfering with the flow of weapons to Ukraine, intimidating individuals involved in that support and testing how far Moscow can go without provoking a collective response.

The question facing NATO is therefore becoming less whether Russia is willing to operate below the threshold of open war than how much violence the alliance will tolerate while continuing to define that threshold as unbroken.

Copyright © 2026 The Washington Times, LLC. Click here for reprint permission.

Story Topics

Please read our comment policy before commenting.