On 4 August, security staff at Leipzig's airport discovered a drone packed with explosives. The facility is a logistics hub for military shipments to Ukraine. Twenty-six days later, Germany's interior minister stated plainly what many had suspected: Russia was responsible. Vladimir Putin demanded proof; his officials called the accusation absurd. But the Leipzig drone was not an isolated incident. It was the opening move in a month of fires, arson attempts and explosive devices directed at European defence facilities across at least six countries.

A coordinated August campaign

The pattern is striking for its concentration. On 10 August, a major fire broke out at the EMCO defence factory in Bulgaria, with initial reports that a truck had ignited during a fuel delivery. Three days later, an explosion and fire hit KNDS Ammo Italy, a munitions manufacturer outside Rome. The local prosecutor opened a case for negligent disaster against unknown persons, though La Repubblica reported that outside interference was being examined. On 15 August, the Milrem Robotics factory in Tallinn, Estonia, which supplies drones to Ukraine, went up in flames. Two suspects were arrested.

Estonia's prime minister, Kristen Michal, said the possibility of Russian sabotage was being taken seriously. Then, on 25 August, Slovak police announced they had thwarted an arson attack on a Ukrainian-owned drone manufacturer, seizing a large quantity of incendiary mixture. Three suspects were arrested; police said they were following orders. The firm itself blamed Russia. This is the same Slovakia whose government has been one of Moscow's closest allies within the European Union. On 30 August, Poland reported two more incidents: a fire at a Lublin company producing helicopter components, where prime minister Donald Tusk said arson could not be ruled out, and a clearer case at drone producer WB Group, where CCTV caught a masked individual throwing incendiary devices. Tusk called it a continuation of Russia's escalatory activities.

The month ended with two Bulgarians arrested in Munich on 30 August, suspected of throwing incendiary devices from a car at the defence firm Rhode & Schwartz. By early September, what had looked like a series of unconnected industrial fires began to resemble something more deliberate.

Leipzig and the shift to professionals

The Leipzig drone incident stands apart from the other August attacks in one important respect: the suspected perpetrators. German media reported that the individuals who loaded and launched the drones were Russian, and at least one may have entered Germany specifically for the operation. Most sabotage linked to Russia in Europe has been carried out by proxies, often Russian-speakers from former Soviet states recruited online and motivated by cash rather than ideology. The International Institute for Strategic Studies (IISS), which tracks such incidents, has compared these proxies to kamikaze drones: cheap, easy to deploy in large numbers, and entirely disposable. The amateurs can be sloppy. In the 2024 parcel bomb plot, one operative failed to find a pick-up point and the mission had to be aborted.

If Moscow dispatched professionals to Leipzig, it suggests the operation mattered enough to risk exposure. As it happened, the devices appear to have malfunctioned. But the intent was clear: an explosive drone at an airport used to funnel military supplies to Ukraine could have caused catastrophic damage, particularly if a civilian aircraft had been struck. Germany is Ukraine's largest supplier of military aid, a position it adopted after a notably slow start. Targeting the logistics chain that sustains that aid sends a direct message.

The gig economy saboteurs

The broader sabotage campaign relies on a different model. Handlers believed to be in Russia coordinate operations online, recruiting individuals through the same channels used for casual labour or petty crime. In one Polish case reported by the BBC, the hired saboteurs had previously fought for Ukraine as volunteer soldiers. The arrangement gives Moscow a layer of deniability: the people lighting fires or planting devices are not Russian intelligence officers, and in many cases their connection to the Kremlin is circumstantial. This makes attribution harder and political responses more fraught.

Some of the earlier sabotage linked to Russia struck oddly civilian targets, including an Ikea store and a Polish paint shop. The shift towards defence manufacturers changes the character of the campaign. It is no longer about sowing random disruption or fear. It is about degrading Ukraine's ability to fight by attacking the industrial base that supplies it, and about testing whether European governments will respond when the damage is confined to property rather than people.

Coercive signalling and NATO probing

Daniela Richterova of the Department of War Studies at King's College London argues that the current spike is tied directly to developments on the battlefield. Ukraine has taken the war into Russian territory, striking deeper inside Russia than at any previous point. Moscow is under pressure and needs to respond, but in ways that fall below the threshold of direct military confrontation with NATO. Richterova describes the approach as coercive signalling: raising the cost of supporting Kyiv without triggering the alliance's collective defence commitments under NATO's Article 5.

Keir Giles at Chatham House sees something more systematic at work. Russia, he argues, is probing the boundaries of what is acceptable and collecting information on the results. They find out what works and what is vulnerable. He regards the sabotage campaign as preparation for what he calls the next phase of Russian aggression in Europe: assessing the willingness of victim countries to act. The distinction matters. If the goal were simply to disrupt Ukraine's supply lines, there are more effective methods. The pattern of attacks, their variety, and the way some appear designed to test responses rather than maximise damage suggests Moscow is learning as much as it is hurting.

From parcel bombs to factory fires

This is not the first surge. The IISS recorded a similar spike in 2024, when Ukraine's Western allies began permitting Kyiv to use their supplied weapons against targets inside Russia. That year brought the parcel bomb plot: packages containing liquid explosive sent to addresses in Britain and Poland. One ignited at a courier depot shortly before it was due to be loaded onto a DHL cargo aircraft. Investigators concluded this was likely a test run for a larger operation. Keir Giles describes that step as a marked high in terms of Russia's willingness to inflict mass casualties. The White House contacted the Kremlin directly and told it to stop. Russia had found a limit. But the attacks did not end; they shifted.

German federal police have recorded more than 165 suspected sabotage cases nationwide this year, according to a report quoted in German media on Friday. The figure covers all suspected cases, not only those attributed to Russia. Even so, the volume is striking for a country that spent decades treating Russian hybrid threats as something that happened elsewhere.

Cold War echoes and escalation risks

Richterova's research shows that Russia's current methods mirror Soviet sabotage doctrine closely. Targets on Soviet lists were strikingly similar, and agents-saboteurs were used in much the same way. The concept was to conduct small, deniable attacks in peacetime that could be scaled up in the event of war. She believes Europe is still in the grey zone between the two, but the attacks of recent weeks have shrunk that zone considerably. That, she warns, increases the risk of what happens next.

The potential for accidental escalation is real. Had the parcel bomb detonated aboard a cargo aircraft mid-flight, had the Leipzig drone struck a passenger plane, the calculus would change instantly. Richterova says such an incident could result in a big attack, and that NATO, in the current security environment, would not be able to ignore it and would have to react. For now, individual governments are responding in different ways: arrests in Estonia and Slovakia, investigations in Italy and Bulgaria, a direct political attribution in Germany. What NATO has not done is articulate a collective threshold beyond which hybrid attacks amount to an armed attack requiring a joint response.

People mentioned

  • Vladimir Putin

    President of Russia, Russian Federation

  • Kristen Michal

    Prime Minister, Estonia

  • Donald Tusk

    Prime Minister, Poland

  • Daniela Richterova

    Researcher, Department of War Studies, King's College London

  • Keir Giles

    Senior consulting fellow, Chatham House

Organisations

North Atlantic Treaty Organization · International Institute for Strategic Studies · Chatham House · King's College London · Milrem Robotics · WB Group