Wireva

Russia’s hybrid pressure is turning defence supply chains into a security front

The Leipzig drone case, GPS parcel reconnaissance and attacks on defence companies show how logistics can be targeted below the threshold of open war. Some Russian links are proven; others remain active intelligence hypotheses.

Європою йде хвиля диверсій проти логістики та оборонних компаній

Dguendel / Wikimedia Commons · CC BY 4.0 · rights

This item was produced with AI assistance under the editorial responsibility of Haydamax OÜ.

Europe’s defence-industrial expansion has created a parallel security problem: the supply chain itself is now a target. The attempted attack at Leipzig/Halle airport is the clearest recent example. German investigators believe an explosive-laden drone was intended to strike a Ukrainian Antonov cargo aircraft used for defence transport. More drones and suspected military-grade explosive material have since been recovered near the airport.

For companies and governments, the significance lies in the overlap between commercial and military infrastructure. Leipzig/Halle is a major freight hub. An attack there could disrupt civilian logistics, insurance, airport operations and defence shipments at the same time. It is exactly the sort of target where a relatively cheap operation can impose costs far beyond the physical damage.

Germany has not officially attributed the Leipzig attempt to Russia. Security sources see parallels with earlier suspected Russian operations and media reports cite US intelligence assessments pointing in the same direction. Russia denies involvement. That means the case should be treated as a high-priority Russian hypothesis rather than a completed attribution.

The Stuttgart judgment of 18 August provides a firmer example of how a state-linked operation can work. A 30-year-old Ukrainian man was convicted of acting as an agent for sabotage after arranging packages carrying GPS trackers from Germany to Ukraine. The court said an unnamed Russian state entity initiated the operation to scout transport routes for future disruption. Two co-defendants were acquitted and the court did not find that prosecutors had proved a specific incendiary attack had already been agreed.

From a business-risk perspective, that is a crucial detail. Reconnaissance can be outsourced and disguised as normal commercial activity. A parcel can reveal depots, handover points, timing and routing. A low-level operative does not need access to classified information if the commercial network itself produces the intelligence.

Eurojust’s March 2026 account of the self-igniting parcel attacks reinforces the point. Twenty-two suspects in Lithuania and Poland are suspected of working for Russian military intelligence in a campaign that saw parcels catch fire or explode in Germany, Poland and Britain. The network allegedly used intermediaries and ordinary parcel systems rather than uniformed operatives. That creates plausible deniability and makes prevention dependent on cooperation between companies, police and intelligence agencies.

Physical caches provide another capability. German authorities found two pistols and ammunition hidden near Berlin in a professionally prepared depot. Interior Minister Alexander Dobrindt said the weapons were probably intended for attacks. A suspect is held in Romania. German media report that security services consider the cache potentially linked to Russian agents, although prosecutors have not publicly established a definitive Russian command chain.

The threat also reaches company leadership. German security circles suspect Russian intelligence in an alleged assassination plot against Stefan Thumann, founder of drone maker Donaustahl, with reports of a possible nerve-agent plan. No public court ruling has established Russian responsibility. In Estonia, a building used by defence contractor Milrem Robotics was set on fire; three Latvian citizens have been detained, and Russian involvement is one line of inquiry.

The attempted arson at a Slovak factory producing unmanned aerial systems on 25 August is a useful boundary case. Police detained three foreigners and seized incendiary material, phones, a camera and a hand-drawn plan. The attack was allegedly commissioned, but the commissioning party has not been named. There is no public evidence connecting it to Russia, even if the target resembles those in other cases.

EU and NATO policy now treats the wider challenge as systemic. The EU Council has condemned Russia and its proxies for persistent hybrid campaigns including sabotage and attacks on critical infrastructure, while NATO lists violence, cyber operations, electronic interference and coercion alongside physical sabotage.

For European business, this turns security from a perimeter issue into a governance issue. Supply-chain mapping, insider risk, executive protection and incident attribution increasingly sit alongside cost and capacity decisions. The next stage of the defence boom will therefore be measured not only in factories and contracts, but in whether the infrastructure connecting them can keep operating under sustained covert pressure.

Same event, other desks

Story file →