Europe’s sabotage problem is becoming a logistics war
The strongest 2026 cases point to a Russian method built around reconnaissance, proxies and civilian transport networks. But Leipzig, Tallinn and Slovakia also show why attribution must be separated from pattern recognition.
The most important detail in the Leipzig drone case may not be the explosive itself. It is the target. German investigators believe an explosive-laden drone was intended to strike a Ukrainian Antonov cargo aircraft at Leipzig/Halle, a major freight hub used for defence-related transport. More drones and suspected military explosive material have since been found around the airport, suggesting an operation with more preparation than a single improvised device.
Germany has not formally blamed Russia. German security sources see parallels with earlier sabotage cases, while US intelligence assessments reported in the media consider Russian involvement likely. Moscow denies involvement. That leaves Leipzig in a familiar grey zone: strategically plausible, supported by intelligence indicators, but not yet publicly proven through a completed criminal case.
Elsewhere, the chain is more concrete. A Stuttgart court on 18 August convicted a 30-year-old Ukrainian man of acting as an agent for the purposes of sabotage. He arranged shipments containing GPS trackers from Germany to Ukraine. The court found that the operation, initiated by an unnamed Russian state entity, was designed to map transport routes and identify opportunities for future disruption. Two co-defendants were acquitted, and the court did not find that a specific incendiary attack had already been agreed.
That distinction is revealing. Modern sabotage does not always begin with a bomb. It can begin with a package that reports its own location. The attacker learns which depot handles it, which route it takes, where it changes hands and when it is most vulnerable. The intelligence can later be used for an arson attack, an explosive device or simply to force costly security changes.
Eurojust’s investigation into the 2024 self-igniting parcel campaign shows how that method scales. In March 2026, the agency said 22 suspects in Lithuania and Poland were suspected of working on behalf of Russian military intelligence. Parcels caught fire or exploded in Germany, Poland and the United Kingdom. The model reduces exposure for the state sponsor: recruitment can be remote, payments can be fragmented and each low-level operative may know only one task.
The weapons cache near Berlin points to a second layer. German authorities found two handguns and ammunition in a professionally prepared forest hide. Interior Minister Alexander Dobrindt said the weapons were probably intended for attacks. A suspect is being held in Romania. German media, citing security agencies, report that the cache is believed to have been a depot for Russian agents, although prosecutors have not publicly established a final Russian chain of command.
A third layer targets defence industry itself. German security circles suspect Russian intelligence was behind an alleged plan to kill Stefan Thumann, founder of drone maker Donaustahl; reporting has referred to a possible nerve-agent method. In Tallinn, a building used by Milrem Robotics was set on fire. Three Latvian citizens have been detained, and Latvia’s security service is investigating suspected assistance to a foreign state. Estonia’s prime minister says Russian involvement is one line of inquiry, not a finding.
Slovakia adds a useful warning against over-attribution. Police on 25 August thwarted a commissioned arson attack on a factory making unmanned aerial systems. Three foreigners were detained and investigators seized incendiary mixture, phones, a camera and a hand-drawn plan. The commissioning party has not been named and there is no public evidence linking the plot to Russia. It belongs on a map of Europe’s defence-industry threat environment, but not yet on a list of proven Russian operations.
The strategic frame is nevertheless explicit. The Council of the EU in March condemned Russia and its proxies for persistent, coordinated hybrid campaigns, including sabotage and attacks on critical infrastructure designed in part to undermine support for Ukraine. NATO similarly describes Russian hybrid activity as including sabotage, violence, border provocations, cyber operations, electronic interference and economic coercion.
This is why the contest increasingly looks like a logistics war. The objective does not require destroying Europe’s military capacity. It can be enough to make every shipment slower, every factory more expensive to protect and every executive more cautious. The operational advantage lies in ambiguity: cause disruption first, force the target to spend time proving who ordered it later. Europe’s counter-strategy will depend on whether investigators can connect individual operatives to the command structures that sit behind them.
