KEY INSIGHTS
Suspected sabotage and drone activity targeting European critical infrastructure have increased concerns Russia’s hybrid campaign against NATO states is becoming more aggressive. The discovery of an explosive-equipped drone at Germany’s Leipzig/Halle Airport on August 4, followed by drone activity over a German military facility and an alleged Russian assassination plot in Poland, demonstrates the range of threats facing European governments and businesses. While attribution for individual incidents remains difficult, Concentric assesses Russia will likely continue to use sabotage, espionage, cyberattacks, drones, and recruited proxies to disrupt European support for Ukraine while remaining below the threshold of conventional military conflict.
KEY EVENTS
- August 14, 2026: French fighter jets operating under NATO’s Baltic Air Policing mission shot down a foreign drone over eastern Latvia after it entered Latvian airspace. Latvia’s armed forces attributed the incursion to Russian electronic warfare and deployed additional air defense units along the eastern border. Finland restricted air and maritime traffic in the eastern Gulf of Finland the same day.
- August 13, 2026: Polish Prime Minister Tusk announced authorities had disrupted a Russian intelligence operation to assassinate a Ukrainian-American citizen in Warsaw.
- August 6, 2026: Two drones flew over a Bundeswehr base in Mechernich, Germany.
- August 4, 2026: German authorities recovered a drone carrying an explosive device near a runway at Leipzig/Halle Airport, forcing a temporary closure. A bomb-disposal robot removed the detonator near a Ukrainian cargo aircraft. U.S. intelligence officials assessed Russia was likely responsible.
- July 26, 2026: Romanian fighter jets shot down three drones during three days of repeated incursions. Romanian authorities identified at least one as a Shahed-type drone used by Russian forces.
ANALYSIS
Since Russia’s full-scale invasion of Ukraine in February 2022, European governments have recorded an increase in suspected Russian hybrid activity. Hybrid activity combines conventional and unconventional tools, including sabotage, espionage, cyberattacks, information operations, electronic warfare, and covert action, to weaken an adversary without entering conventional conflict. The International Institute for Strategic Studies recorded a 246 percent rise in suspected Russian sabotage operations across Europe between 2023 and 2024, and documented approximately 25 incidents against NATO-linked infrastructure in the first five months of 2025. The Center for Strategic and International Studies reported 34 incidents of arson or serious sabotage in 2024, compared with 12 in 2023 and two in 2022
Russia likely seeks to raise the political, economic, and security costs of European support for Ukraine, erode public willingness to sustain support, and complicate NATO’s ability to respond, while remaining below the threshold of a collective military reaction under Article 5. The design exploits three gaps: between peace and war, between law enforcement and military response, and between public and private responsibility. Attribution is slow and contested, NATO decision-making requires consensus, and much of the exposed infrastructure is civilian or dual use. Each factor works in Moscow’s favor.
Recent events indicate escalation in capability.
- The drone recovered at Leipzig/Halle Airport on August 4 carried an explosive device and a detonator, which German authorities removed near a Ukrainian cargo aircraft. Interior Minister Alexander Dobrindt described the operation as professionally planned rather than the work of amateurs. U.S. intelligence officials assessed Russia was responsible. Leipzig/Halle is one of Europe’s largest freight hubs and supports NATO’s Strategic Airlift International Solution.
- The disrupted plot in Warsaw signals a parallel escalation in who Russia is willing to target. Prime Minister Tusk stated it was the first time an operative acting on Russian orders sought to attack a U.S. citizen on the territory of another NATO country. The plot followed the June 2026 killing of a Russian dissident artist in eastern Poland and a wider pattern of disrupted assassination plots, including operations against a Russian exile in France and against the head of a German arms manufacturer supplying Ukraine.
Russia conducts much of this activity through recruited proxies, including criminals, financially vulnerable individuals, and third-country nationals hired through encrypted messaging and paid in cryptocurrency. The model provides plausible deniability, limits the exposure of Russian intelligence officers, and allows inexpensive operations to impose disproportionate cost.
OUTLOOK
Concentric assesses drone-related and suspected Russian hybrid activity will remain elevated across Europe as the war continues. Germany, Poland, Romania, the Baltic states, and other countries supporting Ukrainian military logistics will remain the most exposed. Deliberate sabotage will almost certainly persist and likely broaden across the transport, logistics, and energy sectors. Russian operations have already targeted rail networks, warehouses, undersea cables, and cargo hubs. Facilities handling defense-related freight, energy assets, and undersea communications and power links face the highest risk, and successful incidents remain capable of causing casualties as well as prolonged operational disruption.targeted violence and assassination will remain elevated, particularly for Russian dissidents, defectors, journalists, and individuals linked to Ukrainian or Western defense efforts. The Warsaw plot indicates Russia has widened its target set to include U.S.-linked persons on NATO territory and has grown more willing to act inside allied states. Reliance on recruited proxies makes these plots harder to detect and predict, because operatives often lack prior intelligence ties and receive tasking at short notice.
For organizations operating across Europe, particularly in aviation, logistics, defense, energy, telecommunications, and critical infrastructure, consider the following measures:
Critical Infrastructure Protection: Review physical security around sensitive facilities and identify areas vulnerable to drone surveillance, sabotage, or unauthorized access.
Operational Resilience: Maintain contingency plans for temporary airspace or facility closures, transport disruption, and restricted access following suspicious incidents.
Personnel Awareness: Brief employees on identifying suspicious surveillance, packages, vehicles, or people seeking information about sensitive operations.
Cybersecurity: Plan for physical sabotage occurring alongside cyber operations, and ensure incident-response plans address simultaneous physical and digital disruption.
Information Security: Limit unnecessary public disclosure of shipment schedules, facility activity, and personnel movements which could assist hostile surveillance, particularly for organizations supporting Ukraine, NATO, or European defense programs.
Authored by: Alex Edwards


