A version of this story appeared in the daily Threat Status newsletter from The Washington Times. Click here to receive Threat Status delivered directly to your inbox each weekday.
KYIV, Ukraine — An explosives-laden drone discovered beside a Ukrainian cargo aircraft at one of Germany’s busiest freight airports has become the latest warning that Russia’s shadow war against the West may be entering a more dangerous phase.
German investigators are examining a suspected attempted attack at Leipzig/Halle Airport, a major logistics hub used by NATO and Ukraine’s Antonov Airlines. On Aug. 4, airport workers discovered a drone carrying what federal prosecutors described as “800 grams of PETN explosive and a detonator.”
Prosecutors said findings indicate the device was intended to cause an explosion, but it failed to detonate upon impact.
The drone was found near a Ukrainian Antonov cargo aircraft. One of the planes was carrying military ammunition, according to German media citing a confidential police report. Investigators also suspect that a second drone collided with a DHL cargo aircraft, which was forced to abort its landing during the disruption.
The plane later landed safely in Hanover with minor damage.
German broadcasters NDR and WDR and the Sueddeutsche Zeitung reported that investigators found a third drone west of the airport Aug. 14, along with about 50 grams of suspected hexogen, known in English as RDX, a military explosive. The federal prosecutor’s office in Germany has not publicly confirmed those findings.
Berlin has stopped short of formally blaming Moscow, although German media, citing security sources, say Russian intelligence is suspected.
Interior Minister Alexander Dobrindt called the discovery a “hybrid attack” and said it represented “a new threat scenario.” He said the incident vindicated an earlier assessment that Germany faced “a high level of danger.”
Days later, he warned: “We’re not at war, but we are the daily target of hybrid warfare.”
On Tuesday, Chancellor Friedrich Merz said Germany had moved “further into the crosshairs of hybrid attackers” and warned that attackers were increasingly willing to accept severe property damage, injuries and even deaths.
The government, he said, was working with security agencies to determine who was responsible for the incident in Leipzig and would disclose its findings shortly.
“They will pay for it,” Mr. Merz said of those responsible for hybrid attacks.
The case began amid a burst of fires, attempted attacks and cyber incidents involving Europe’s defense industry and countries supporting Ukraine.
On Tuesday, Slovak police announced that they had foiled an arson attack on a factory producing unmanned aerial systems in the country’s east. Three foreign nationals were detained, and police seized a large quantity of incendiary mixture, tools, phones, a camera and a handwritten plan.
Investigators charged the foreign nationals with “public endangerment committed on commission,” but authorities have neither identified the suspected commissioning party nor publicly linked the plot to Russia.
In Estonia, meanwhile, prosecutors are investigating an arson attack that began overnight Aug. 14-15 against a building used by Milrem Robotics, whose unmanned ground vehicles have been deployed in Ukraine. Prime Minister Kristen Michal said suspects had been identified and that one avenue investigators were pursuing was Russian involvement.
“Attempts to intimidate us or undermine our security will not succeed,” Mr. Michal said.
A Congressional Research Service report released Aug. 11 said Russian-linked hybrid attacks in Europe have been “increasing in number and severity,” encompassing sabotage, assassinations, cyberattacks, airspace violations and attacks on critical infrastructure.
One study cited by the service found that the number of Russian hybrid attacks quadrupled from 2023 to 2024; another investigation counted at least 151 reported Russian operations between the February 2022 invasion and March 2026.
Government Communications Headquarters, Britain’s intelligence, cyber and security agency, has reached a similar conclusion.
“Russia is scaling up its daily hybrid activity against the U.K. and Europe,” Director Anne Keast-Butler warned in May, saying the campaign stretched “from the seabed to cyberspace” and targeted infrastructure, supply chains, democratic processes and public trust.
A war fought through proxies
The campaign has evolved substantially since Russia’s full-scale invasion of Ukraine in February 2022.
European governments expelled hundreds of suspected Russian intelligence officers after the invasion and earlier attacks, such as the 2018 poisoning of former Russian spy Sergei Skripal in Salisbury, England.
MI5 chief Ken McCallum has said that “over 750 Russian diplomats have been expelled from Europe since Putin invaded, the great majority of them spies.”
Russian intelligence has adapted by increasingly outsourcing operations to proxies, sometimes recruited through Telegram and other online platforms, to photograph military facilities, commit vandalism, set fires or plant explosives.
The recruits have included criminals and people motivated primarily by money. This practice puts several layers of plausible deniability between Moscow and those carrying out the attacks, thereby complicating attribution.
Some investigations have now penetrated those layers.
Polish prosecutors this year charged five people in an organized network that they say operated for Russian intelligence and was involved in the 2024 arson attacks against an OBI store in Warsaw, an Ikea in Vilnius, Lithuania, and Warsaw’s vast Marywilska 44 shopping center, as well as preparations to burn another Ikea in Riga, Latvia.
In the Marywilska case, prosecutors say one suspect was told in advance when the fire would begin, ordered to record both the blaze and the emergency response, and instructed to send the footage to a handler for publication on Russian propaganda outlets.
This outsourcing model has provided deniability but initially came at the cost of competence. European intelligence services now warn that Moscow is seeking more capable operatives.
Lithuania’s 2026 national threat assessment says the GRU, Russia’s military intelligence service, is using longer chains of intermediaries while seeking more experienced criminals.
The service is looking to conduct “more dangerous operations” in Western countries, Lithuanian intelligence said, targeting transportation networks and facilities connected with military and humanitarian assistance to Ukraine.
The potential lethality of those operations is also increasing.
German public broadcaster BR reported this month that Stefan Thumann, founder of Bavarian drone manufacturer Donaustahl and an advocate of Ukraine, had been warned of a suspected Russian-linked assassination plot.
German security sources told the broadcaster that plans to kill him may have involved a nerve agent, with Novichok among the methods discussed.
Mr. Thumann is now living under protection.
The case follows a previously uncovered Russian plot against Rheinmetall CEO Armin Papperger, whose company is one of Ukraine’s major suppliers of ammunition, armored vehicles and air defense systems.
U.S. intelligence attributed that plot to Russia, while NATO subsequently confirmed the threat against Mr. Papperger formed part of a wider sabotage campaign against the alliance.
An Associated Press investigation published in May mapped 191 acts of sabotage, arson and other disruptions linked to Russia by Western officials since the invasion. Three Western intelligence officials told AP that Russia’s campaign of targeted killings had also accelerated.
“This campaign is not by accident or chance,” one senior European intelligence official said. “There is political authorization.”
Testing NATO’s threshold
The ongoing campaign increasingly extends into cyberspace.
On Wednesday, the pro-Russian group Server Killers claimed responsibility for what Norway’s Digitalization Agency described as the largest denial-of-service attack it has ever faced. The hackers said the attack was retaliation for Norway’s renewal of security cooperation with Ukraine.
For Western security officials, the common strategic thread is ambiguity and deniability.
Sabotage carried out by paid criminals, unexplained drones and nominally independent hacker groups can impose costs, disrupt weapons production and consume investigative resources without offering NATO the clarity of tanks crossing a border or missiles deliberately striking an alliance member.
That ambiguity complicates retaliation. The Congressional Research Service describes the hybrid approach as exploiting the gap between peace and armed conflict, where uncertainty over attribution can constrain the victim’s response.
Moscow routinely denies directing sabotage in Europe and describes Western accusations as anti-Russian propaganda.
Still, Western intelligence agencies increasingly see the campaign as a means of punishing governments supporting Kyiv, interfering with the flow of weapons to Ukraine, intimidating individuals involved in that support and testing how far Moscow can go without provoking a collective response.
The question facing NATO is therefore becoming less about whether Russia is willing to operate below the threshold of open war than how much violence the alliance will tolerate while continuing to define that threshold as unbroken.

Please read our comment policy before commenting.