Get the weekly SPARTANAT newsletter.
Your bonus: the free E-Book from SPARTANAT.

In Germany, recent incidents have raised concerns about sabotage and espionage targeting critical infrastructure, particularly in the defense sector. With over 165 suspected sabotage cases and 747 drone incidents reported since January, authorities stress the importance of improved security measures and communication among operators to counter these hybrid threats.
Over the course of five days, three facilities were attacked in Germany: two substations in Brandenburg and North Rhine-Westphalia, and on Thursday, a construction site in Munich located in the immediate vicinity of several defense contractors. Then two more substations were targeted. On the same day, a confidential situation report from the Federal Criminal Police Office (BKA) was made public: more than 165 suspected cases of sabotage and 747 suspicious drone incidents since January. The material damage was minor in all three cases; the impact lies in public perception: Each report raises the question of whom to believe and how secure one’s own location is. For operators and suppliers in the security and defense market, this means obligations with deadlines, an unclear division of authority regarding drone defense, and a responsibility to communicate with their own workforce.
Three incidents in five days, plus a string of spying incidents since July
The confidential BKA situation report, compiled by the Joint Hybrid Defense Center—which was inaugurated in June 2026—shows the following as of the end of August 2026:
No specific attribution has been made for Jänschwalde and Bergheim. The public prosecutors’ offices are investigating terrorism or anti-constitutional sabotage; a connection between the two incidents is considered likely, and no letter of claim has been received in either case. North Rhine-Westphalia Interior Minister Reul is investigating foreign-directed sabotage and left-wing extremism. Security circles say the modus operandi is unusually unprofessional for left-wing extremists; so far, there is no evidence to suggest the acts were carried out by disposable agents. The chairman of the Parliamentary Oversight Committee, Marc Henrichmann, warns against jumping to conclusions.
The modus operandi has been disclosed and is described by the relevant authorities. The Federal Office for the Protection of the Constitution (BfV) refers to it as a series of small pinpricks, carried out by recruited opportunistic perpetrators, recruited via messaging apps, and paid in cryptocurrency. BfV President Sinan Selen identifies the target: it is “society itself that must be influenced.” The Federal Office for Civil Protection and Disaster Assistance (BBK) describes the same objective as destabilization and influencing the formation of public opinion and will. Anyone who takes this description seriously will not judge this week’s three attacks solely by the property damage caused.
The cost-benefit ratio favors the attacker. Off-the-shelf materials; according to Brandenburg’s Minister of the Interior, no specialized knowledge required; perpetrators from other European countries using tourist visas or rental cars. On the other hand: hundreds of police officers in cornfields, drones flying over power plants, special checkpoints in Hamburg without concrete leads, and a week of political debate. This asymmetry explains the frequency of the attempts.
The attribution took 28 days and was itself controversial afterward
Attributing an incident takes time, and this time works in the attacker’s favor. There were 28 days between the incident in Leipzig and its attribution. Afterward, the attribution itself became a point of contention: The AfD parliamentary group objects to the insufficient disclosure of evidence; von Notz, deputy chair of the Parliamentary Oversight Committee, points to the investigations by the Federal Prosecutor General and the Federal Criminal Police Office (BKA); security researcher Peter Neumann considers the attribution plausible but the public presentation of evidence too flimsy. Nico Lange of the Munich Security Conference describes the concealment of authorship as an integral part of the method. For Jänschwalde and Bergheim, this phase is ongoing, and it may end differently than it did in Leipzig.
There is no reliable German time series data on desensitization. Mathematically, 165 suspected cases of sabotage in eight months amount to about 20 cases per month, a small fraction of which are publicly prosecuted. Two metrics have been measured: In the Bitkom study “Economic Security 2026” (1,003 companies with ten or more employees, presented on August 26 in collaboration with the BfV), the proportion of companies that were able to definitively confirm a successful attack fell from 87 to 67 percent, while the proportion of companies that merely suspected an attack rose from 10 to 29 percent. In the Bitkom study “Hybrid Attacks” from March 2026 (604 companies, 1,263 individuals aged 16 and older), 83 percent of companies and 82 percent of the population expect a serious crisis as a result of hybrid attacks; 12 percent of companies and 15 percent of the general public consider themselves well-prepared; 22 percent of companies feel sufficiently informed, while 64 percent of the general public report not being informed. Bitkom represents the interests of its members; both surveys are representatively weighted with a specified margin of error. The assumption of waning attention thus remains a working hypothesis; it can be tested internally by measuring participation in exercises and reporting discipline when anomalies are detected on-site.
The responsibility is clear, but the legal basis is not. The Federal Ministry of the Interior classifies critical infrastructure as being at a highly abstract risk and clarifies: “In principle, however, operators are responsible for protecting their respective facilities.” The KRITIS umbrella law has been in effect since March 17, 2026. The regulatory ordinance defining critical services, facility categories, and thresholds has been available as a draft bill since May 28, 2026, but has not yet been enacted; the ministry did not provide a timeline when asked. Consequently, it remains unclear for some facilities whether and when they will be covered. Irene Mihalic (Greens) criticizes that it is unclear “which companies and institutions must take which specific measures”; the German Police Union states that the protection of critical infrastructure is not a primary police task and that there is a lack of consistent investment. Reul calls for expanded operator rights regarding video surveillance and drone defense and believes this can be regulated “relatively quickly.” The German Association of Energy and Water Industries (BDEW) is calling for adjustments to data protection laws regarding the surveillance of adjacent public areas.
Registration triggers deadlines of three, nine, and ten months.
The KRITIS umbrella law (Act on Strengthening the Physical Resilience of Critical Facilities; KRITIS stands for critical infrastructure) requires operators of critical facilities to conduct their own risk analysis at least every four years, implement resilience measures, and develop a resilience plan. Hybrid threats are explicitly named as a risk category. The law’s list of measures includes structural and technical physical security, procedures for monitoring the surroundings, detection devices, access controls, crisis management, emergency power supply, alternative supply chains, and a security management system for employees, including personnel from external service providers. The clock starts ticking upon registration: three months for registration, nine months for the risk analysis, and ten months for resilience measures, reporting requirements, and management obligations. The standard threshold is 500,000 residents served; the Federal Ministry of the Interior may, on a case-by-case basis, classify facilities below this threshold as significant. At the same time, the NIS-2 Implementation Act—which transposed the EU Cybersecurity Directive NIS 2 into German law—has been in effect since December 6, 2025, and applies to approximately 29,500 facilities; operators of critical infrastructure are automatically classified as particularly important facilities under this Act.
The Second Act Amending the Aviation Security Act took effect on March 17, 2026, and allows the armed forces to shoot down drones in support of the federal states if this is the only way to avert a particularly serious accident. According to the Bundestag resolution of February 26, 2026, there is no explicit legal basis for operators to conduct detection and defense; the federal government is called upon to examine a legal basis for such authorization. Anyone offering detection, sensor technology, or facility protection should monitor this review process, as it will determine the permissibility of entire service portfolios. Procuring entities must distinguish between permissible detection measures and countermeasures, the use of which remains the sole responsibility of government agencies.
The documented cases repeatedly involve companies in the defense industry and their management personnel: Espionage against KNDS in July; photos of a Bavarian company premises in June; arrests in March for spying on the drone manufacturer Donaustahl and the private residence of its managing director—which security authorities believe was in preparation for a murder; and two arrests at the Hungarian-Serbian border in July involving explosives and a drone en route to Germany. Selen identifies the security and defense industries as particularly attractive targets for foreign intelligence services. Companies growing in this market factor in personal security, facility security, and information security as part of their growth costs.
If the impact is based on creating uncertainty, the workforce is both a target and a line of defense. The incident in Großenkneten further demonstrates that security personnel are physically affected. Two points are therefore interrelated: the discipline of reporting any anomalies at fences, access roads, and neighboring areas, and providing employees with prompt, direct information so that the interpretation of an incident does not rely on rumors. The recruitment of opportunistic criminals via messaging services affects your staff and the staff of your service providers; the law explicitly addresses this issue.
Stay vigilant!
JAN HESSELBARTH, as co-founder and managing partner of BRAVO SIX ADVISORY GmbH, is responsible for the defense division and brings over 20 years of operational and strategic leadership experience from the German Armed Forces, federal agencies, and the private sector. As a paratrooper officer and Joint Terminal Attack Controller (JTAC), he was responsible for territorial duties and host nation support at the Hamburg Regional Command following a deployment in Kunduz, Afghanistan. His consulting portfolio includes NATO missions, programs involving up to 1,000 participants, training initiatives for more than 5,000 Bundeswehr personnel, and co-authorship of a nationwide study on maritime security for the Federal Ministry of the Interior—a core topic in the context of KRITIS.
BRAVO SIX ADVISORY online
SPARTANAT is the online magazine for Military News, Tactical Life, Gear & Reviews.
Send us your news: [email protected]
Ad
similar
Get the weekly SPARTANAT newsletter.
Your bonus: the free E-Book from SPARTANAT.