Germany has crossed a new threshold in its confrontation with Russian hybrid activity. Chancellor Friedrich Merz and several members of his cabinet have made clear that while Germany is not at war with Russia, it is nevertheless facing a sustained campaign of hybrid attacks orchestrated from Moscow. These attacks, according to the German government, include drone overflights, sabotage, espionage and disinformation, and they are carried out with what Merz described as a willingness “to act with growing ruthlessness, accepting serious damage to property and even injuries and deaths.” The Chancellor’s remarks came at a press conference held after an attempted drone attack on Leipzig/Halle Airport, a major cargo hub in eastern Germany. It was the first time that the German government had explicitly blamed Russia for an attempted attack on German soil. Investigators discovered an explosive-laden drone in the immediate vicinity of Ukrainian Antonov cargo aircraft that are known to transport military equipment for Ukraine. Since Russia launched its full-scale invasion of Ukraine in February 2022, there has been frequent discussion across Europe about the Kremlin’s use of hybrid warfare against countries supporting Kyiv, and Germany has long been seen as particularly exposed because of its economic weight, its military support for Ukraine, and its central role in European security. Interior Minister Alexander Dobrindt has therefore raised the current threat level from “abstract” to “high,” a significant escalation in official threat assessment. Hybrid attacks are considered especially difficult to detect because it is often unclear who is behind them and whether individual incidents are even connected. The German government has also warned that Moscow is not the only country using such methods. According to the Federal Office of Civil Protection and Disaster Assistance (BBK), China, Iran and North Korea are also targeting Germany with hybrid measures, making the challenge broader than a single bilateral confrontation.
Security experts stress, however, that not every cyberattack, act of sabotage or attempt at disinformation automatically qualifies as part of a hybrid campaign. Ferdinand Gehringer, a security expert who has advised on hybrid threats, told Euronews that the decisive factor is the identifiable link between different measures. This may involve a common actor, coordinated timing, recurring targets or methods, and above all a shared strategic objective. Without such links, isolated incidents may be criminal or opportunistic rather than strategic. The attempted drone strike on Leipzig/Halle Airport is a case in point. A drone fitted with explosives was discovered near Ukrainian Antonov cargo aircraft that also transport military equipment for Ukraine. In his press statement, Interior Minister Dobrindt said that authorities assumed so-called “low-level agents” may have been involved on behalf of a Russian intelligence service. The pattern of the crime, the technology used, and intelligence findings led the federal government to conclude that Russia was behind the attack. Gehringer explained that this is where the so-called overall situation assessment becomes crucial. To judge whether individual incidents are part of the same operation, information from different areas has to be pooled, including from the police, intelligence services, the Bundeswehr, cyber defence authorities and the private sector. “Only by examining technical traces, crime patterns, timelines and disinformation narratives together can links be identified,” he said. This kind of comprehensive analysis is necessary because hybrid campaigns are designed to be ambiguous, allowing the attacker to deny responsibility while still achieving political and strategic effects. The Leipzig case demonstrates how a single event can be read as part of a broader pattern when it is placed alongside other suspicious activities, such as drone flights over military bases, sabotage of undersea cables, and coordinated disinformation narratives in German and other European media.
Hybrid warfare often takes place below the threshold of open armed conflict, which makes it particularly difficult for a state to respond with traditional military means. Its aim is to exploit a country’s vulnerabilities, erode trust in state institutions, and unsettle and destabilise society. It can target critical infrastructure, political processes, economic stability and social cohesion simultaneously. The question of how a country and its society can prepare for and defend against hybrid attacks or even hybrid warfare is therefore urgent. Rearming the Bundeswehr alone is no answer to suspected attacks, spying attempts or disinformation, nor can hybrid attacks in most cases simply be repelled or countered by kinetic means. So how does a state respond to an attack that remains below the threshold of an armed assault? The German federal government has stepped up its precautions against hybrid threats since 2022. These measures include an interdepartmental task force dealing with disinformation and other hybrid threats, as well as procedures that can attribute cyberattacks and foreign information manipulation to a potential originator. Attribution is a key element of deterrence, because it exposes the attacker and creates diplomatic and political costs. At the European Union level, the so-called “Hybrid Toolbox” provides a mechanism for joint responses, allowing member states to coordinate on detection, analysis and countermeasures. Since this year, there has also been the Joint Centre for Countering Hybrid Threats (GAZ Hybrid), which is intended to bring together information on espionage, sabotage, disinformation and other hybrid threats so that such activities can be detected early and tackled more effectively. In the case of the attempted drone attack in Leipzig, the federal government responded, in its own words, “resolutely, calmly and proportionately.” It announced a series of concrete measures, including the closure of the Russian consulate general in Bonn and the Russian House in Berlin, the sanctioning of further Russian individuals over hybrid attacks at EU level, tighter entry controls, and stepped-up pressure on Russia’s shadow fleet, a fleet of aging tankers that Moscow uses to circumvent oil sanctions and that is also suspected of involvement in espionage and sabotage activities.
According to Gehringer, however, defence starts even before a campaign begins. He argues that Germany and its allies need to move away from merely reacting and towards a more anticipatory approach. “The goal must be to raise the costs for attackers, disrupt their planning paths, uncover networks as early as possible and also blunt the impact of attacks,” he said. This means that resilience must be built into critical infrastructure, public institutions and society itself before an attack occurs. If, for example, an attack on a substation caused a power cut, households and businesses could bridge the gap with emergency power until the grid operator repaired the damage. In the best case, preparation would eventually be so good that hybrid attacks could be headed off by identifying relevant activities at the planning stage and nipping them in the bud. This requires robust intelligence-sharing, public-private partnerships, and a level of societal preparedness that Germany has not yet fully achieved. At the same time, the state and society need to be ready, in terms of communication, for possible attacks. A government that communicates clearly and honestly during a crisis can limit panic and prevent the spread of disinformation. That would not only limit damage but also rob hybrid operations of their intimidatory effect. Hybrid attacks are designed to create fear, confusion and distrust; a well-prepared public that understands what is happening is far less vulnerable to those effects. Gehringer stressed that communication must be part of the overall defence strategy, not an afterthought. This includes explaining what is known and what is not known, avoiding exaggeration, and providing practical guidance to citizens. The state must also be careful not to feed the narrative of helplessness that hybrid attackers seek to create.
This can only be achieved through a combination of deterrence, defence and resilience, the security expert told Euronews. Deterrence means making clear that attacks will have consequences, through sanctions, diplomatic expulsions, criminal prosecution and other measures. Defence means active measures to detect, attribute and disrupt hostile activities. Resilience means the ability of society to withstand and recover from attacks. According to Gehringer, the public “plays a very important role” here, but is “still being needlessly wrapped in cotton wool.” He argued that citizens are capable of understanding the threat and contributing to national resilience, and that treating them as passive victims is a mistake. “Yet it is part of the solution,” he added, explaining that disinformation, for example, can never be fully prevented, nor should that be the aim, since an open society must always contend with manipulative information. The goal, in his view, is not to create a closed or heavily censored society, but to build a population that is informed, critical and resilient. “Our goal must therefore be resilience rather than isolation,” Gehringer said. Citizens need to be able to assess information critically, the media must operate independently, and the state must communicate “quickly, credibly and transparently.” This is a demanding standard, especially in an era of social media, deepfakes and foreign interference, but it is essential for preserving democratic resilience. The German government’s recent actions, including the closure of Russian diplomatic facilities and the imposition of sanctions, show that Berlin is willing to respond forcefully to specific incidents. But the longer-term challenge is to embed hybrid defence into the daily functioning of the state and society, so that Germany is not caught off guard by the next attack.
In sum, Germany is navigating a new and dangerous landscape in which hostile states use ambiguity, technology and social division as weapons. The attempted drone attack on Leipzig/Halle Airport marks a turning point because it forced the German government to name Russia publicly as the culprit and to move from abstract warnings to concrete countermeasures. Yet the broader lesson of hybrid warfare is that no single response is sufficient. Military rearmament, police investigations, intelligence cooperation, cyber defence, diplomatic sanctions and public communication must all work together. The threat is not limited to Russia; China, Iran and North Korea are also mentioned by German authorities as potential actors using hybrid methods. This means that Germany and its European partners need a permanent, coordinated and well-resourced system for detecting and countering hybrid threats. The creation of the Joint Centre for Countering Hybrid Threats and the EU Hybrid Toolbox are steps in the right direction, but they must be backed by political will and practical implementation. Above all, the public must be brought into the defence effort. As Gehringer argues, citizens are not just potential victims; they are part of the solution. A resilient society, with independent media, critical thinking and transparent government communication, is the best defence against the kind of hybrid attacks that are designed to destabilise and divide. Germany has begun to recognise this, but the work is only beginning. The coming months and years will test whether the country can maintain its openness while hardening itself against those who seek to exploit it.
Word count: approximately 2,000.

