We tell you something.
Sign up for the newsletter now!

Get the weekly SPARTANAT newsletter.

Your bonus: the free E-Book from SPARTANAT.

With your registration, you confirm that you have read the privacy policy.

Conflicts
Critical Infrastructure:

Sabotage Every Day

In Germany, recent incidents have raised concerns about sabotage and espionage targeting critical infrastructure, particularly in the defense sector. With over 165 suspected sabotage cases and 747 drone incidents reported since January, authorities stress the importance of improved security measures and communication among operators to counter these hybrid threats.

09/07/2026 

Over the course of five days, three facilities were attacked in Germany: two substations in Brandenburg and North Rhine-Westphalia, and on Thursday, a construction site in Munich located in the immediate vicinity of several defense contractors. Then two more substations were targeted. On the same day, a confidential situation report from the Federal Criminal Police Office (BKA) was made public: more than 165 suspected cases of sabotage and 747 suspicious drone incidents since January. The material damage was minor in all three cases; the impact lies in public perception: Each report raises the question of whom to believe and how secure one’s own location is. For operators and suppliers in the security and defense market, this means obligations with deadlines, an unclear division of authority regarding drone defense, and a responsibility to communicate with their own workforce.

Three incidents in five days, plus a string of spying incidents since July

  • July 2026: A Moldovan national is arrested in Bavaria on suspicion of using a drone to spy on the defense contractor KNDS. Investigators suspect that Russian government agencies were behind the operation. Source: BKA situation report, as reported by NDR, WDR, and SZ.
  • August 4, 2026: A drone loaded with explosives is discovered at Leipzig/Halle Airport, near several Ukrainian cargo planes. The airport serves as a transshipment hub for military aid shipments. By August 25, three drones—either whole or in pieces—have been found; technical evidence suggests there may be more.
  • Early August 2026: A 33-year-old Ukrainian national is arrested in Thuringia. The Munich Public Prosecutor’s Office accuses him of having delivered photos of the premises of a Bavarian defense contractor to a client in June as part of preparations for a sabotage operation. He is in pretrial detention.
  • August 9, 2026: Drones are spotted at night at a natural gas processing plant in Großenkneten (Oldenburg district). A security guard approaches two individuals dressed in dark clothing. According to the police report, they slam his head against the hood of a car; he falls, and the perpetrators flee wearing balaclavas and gloves. The manhunt proves unsuccessful.
  • September 1, 2026: The German federal government holds Russia responsible for the Leipzig/Halle incident. Federal Interior Minister Dobrindt states that the findings “clearly point to Russian involvement”; the operation, he says, “can be attributed to low-level agents.” Consequences: The ambassador was summoned; the Consulate General in Bonn was closed as of September 18; the lease for the Russian House in Berlin was terminated; and entry controls were tightened. Russia denies any involvement, and President Putin accuses the German government of fabricating evidence.
  • September 1, 2026: At the Turnow-Preilack substation near Jänschwalde, more than a dozen homemade projectiles containing propellant are found; they were fired from tubes and equipped with metal hooks and copper wires to cause a short circuit. One unit at the Jänschwalde power plant shuts down; backup systems kick in. Reports differ on the impact of the attack: rbb reports two short circuits, while ZDF quotes Interior Minister Redmann as saying there was one hit with no consequences.
  • September 2, 2026: In Bergheim near Cologne, a short circuit triggers the failure of several power lines, taking five lignite-fired units offline. Six launch devices are found in a cornfield. Amprion states that the general power supply was not affected. In the evening, the Hamburg police inspect power plants and substations in the greater Hamburg area, reportedly without any concrete leads.
  • September 3, 2026: In Munich, incendiary devices are thrown from a moving car onto a construction site, in the immediate vicinity of which several defense contractors have their headquarters or branches. A witness alerts the police; two Bulgarian nationals (aged 38 and 28) are arrested shortly thereafter at a gas station, and an unexploded incendiary device is defused. According to information from the ARD’s Berlin bureau, there are strong indications that this was a mission commissioned by a Russian intelligence service and carried out by hired disposable agents. No official attribution has been made.

The total number of cases

The confidential BKA situation report, compiled by the Joint Hybrid Defense Center—which was inaugurated in June 2026—shows the following as of the end of August 2026:

  • more than 165 suspected cases of sabotage nationwide in the current year, including espionage incidents not involving drones,
  • 747 suspicious drone incidents from January through the end of August, involving 1,068 drones flying over critical infrastructure, military facilities, and defense contractors—compared to approximately 1,300 reported drone incidents in all of 2025,
  • 24 new investigations into espionage, 12 of which involve cyberespionage, plus 40 preliminary inquiries,
  • 112 confirmed espionage-related crimes, including more than 60 cases of imaging that endangered security and 26 cases involving suspected espionage activities for the purpose of sabotage,
  • regional breakdown: Brandenburg 23, North Rhine-Westphalia and Schleswig-Holstein 21 each, Lower Saxony 15 crimes.

What remains unclear regarding the substations

No specific attribution has been made for Jänschwalde and Bergheim. The public prosecutors’ offices are investigating terrorism or anti-constitutional sabotage; a connection between the two incidents is considered likely, and no letter of claim has been received in either case. North Rhine-Westphalia Interior Minister Reul is investigating foreign-directed sabotage and left-wing extremism. Security circles say the modus operandi is unusually unprofessional for left-wing extremists; so far, there is no evidence to suggest the acts were carried out by disposable agents. The chairman of the Parliamentary Oversight Committee, Marc Henrichmann, warns against jumping to conclusions.

The authorities identify society itself as the target

The modus operandi has been disclosed and is described by the relevant authorities. The Federal Office for the Protection of the Constitution (BfV) refers to it as a series of small pinpricks, carried out by recruited opportunistic perpetrators, recruited via messaging apps, and paid in cryptocurrency. BfV President Sinan Selen identifies the target: it is “society itself that must be influenced.” The Federal Office for Civil Protection and Disaster Assistance (BBK) describes the same objective as destabilization and influencing the formation of public opinion and will. Anyone who takes this description seriously will not judge this week’s three attacks solely by the property damage caused.

The burden falls on the side under attack

The cost-benefit ratio favors the attacker. Off-the-shelf materials; according to Brandenburg’s Minister of the Interior, no specialized knowledge required; perpetrators from other European countries using tourist visas or rental cars. On the other hand: hundreds of police officers in cornfields, drones flying over power plants, special checkpoints in Hamburg without concrete leads, and a week of political debate. This asymmetry explains the frequency of the attempts.

The attribution took 28 days and was itself controversial afterward

Attributing an incident takes time, and this time works in the attacker’s favor. There were 28 days between the incident in Leipzig and its attribution. Afterward, the attribution itself became a point of contention: The AfD parliamentary group objects to the insufficient disclosure of evidence; von Notz, deputy chair of the Parliamentary Oversight Committee, points to the investigations by the Federal Prosecutor General and the Federal Criminal Police Office (BKA); security researcher Peter Neumann considers the attribution plausible but the public presentation of evidence too flimsy. Nico Lange of the Munich Security Conference describes the concealment of authorship as an integral part of the method. For Jänschwalde and Bergheim, this phase is ongoing, and it may end differently than it did in Leipzig.

Data is lacking to gauge desensitization, but data is available on the growing number of unreported cases

There is no reliable German time series data on desensitization. Mathematically, 165 suspected cases of sabotage in eight months amount to about 20 cases per month, a small fraction of which are publicly prosecuted. Two metrics have been measured: In the Bitkom study “Economic Security 2026” (1,003 companies with ten or more employees, presented on August 26 in collaboration with the BfV), the proportion of companies that were able to definitively confirm a successful attack fell from 87 to 67 percent, while the proportion of companies that merely suspected an attack rose from 10 to 29 percent. In the Bitkom study “Hybrid Attacks” from March 2026 (604 companies, 1,263 individuals aged 16 and older), 83 percent of companies and 82 percent of the population expect a serious crisis as a result of hybrid attacks; 12 percent of companies and 15 percent of the general public consider themselves well-prepared; 22 percent of companies feel sufficiently informed, while 64 percent of the general public report not being informed. Bitkom represents the interests of its members; both surveys are representatively weighted with a specified margin of error. The assumption of waning attention thus remains a working hypothesis; it can be tested internally by measuring participation in exercises and reporting discipline when anomalies are detected on-site.

Responsibility lies with the operator; a clear regulation on this matter is lacking

The responsibility is clear, but the legal basis is not. The Federal Ministry of the Interior classifies critical infrastructure as being at a highly abstract risk and clarifies: “In principle, however, operators are responsible for protecting their respective facilities.” The KRITIS umbrella law has been in effect since March 17, 2026. The regulatory ordinance defining critical services, facility categories, and thresholds has been available as a draft bill since May 28, 2026, but has not yet been enacted; the ministry did not provide a timeline when asked. Consequently, it remains unclear for some facilities whether and when they will be covered. Irene Mihalic (Greens) criticizes that it is unclear “which companies and institutions must take which specific measures”; the German Police Union states that the protection of critical infrastructure is not a primary police task and that there is a lack of consistent investment. Reul calls for expanded operator rights regarding video surveillance and drone defense and believes this can be regulated “relatively quickly.” The German Association of Energy and Water Industries (BDEW) is calling for adjustments to data protection laws regarding the surveillance of adjacent public areas.

Four Consequences for Operators and Suppliers

Registration triggers deadlines of three, nine, and ten months.

The KRITIS umbrella law (Act on Strengthening the Physical Resilience of Critical Facilities; KRITIS stands for critical infrastructure) requires operators of critical facilities to conduct their own risk analysis at least every four years, implement resilience measures, and develop a resilience plan. Hybrid threats are explicitly named as a risk category. The law’s list of measures includes structural and technical physical security, procedures for monitoring the surroundings, detection devices, access controls, crisis management, emergency power supply, alternative supply chains, and a security management system for employees, including personnel from external service providers. The clock starts ticking upon registration: three months for registration, nine months for the risk analysis, and ten months for resilience measures, reporting requirements, and management obligations. The standard threshold is 500,000 residents served; the Federal Ministry of the Interior may, on a case-by-case basis, classify facilities below this threshold as significant. At the same time, the NIS-2 Implementation Act—which transposed the EU Cybersecurity Directive NIS 2 into German law—has been in effect since December 6, 2025, and applies to approximately 29,500 facilities; operators of critical infrastructure are automatically classified as particularly important facilities under this Act.

Detection is permitted; defense by operators is unregulated

The Second Act Amending the Aviation Security Act took effect on March 17, 2026, and allows the armed forces to shoot down drones in support of the federal states if this is the only way to avert a particularly serious accident. According to the Bundestag resolution of February 26, 2026, there is no explicit legal basis for operators to conduct detection and defense; the federal government is called upon to examine a legal basis for such authorization. Anyone offering detection, sensor technology, or facility protection should monitor this review process, as it will determine the permissibility of entire service portfolios. Procuring entities must distinguish between permissible detection measures and countermeasures, the use of which remains the sole responsibility of government agencies.

Suppliers and their managing directors are among the targets

The documented cases repeatedly involve companies in the defense industry and their management personnel: Espionage against KNDS in July; photos of a Bavarian company premises in June; arrests in March for spying on the drone manufacturer Donaustahl and the private residence of its managing director—which security authorities believe was in preparation for a murder; and two arrests at the Hungarian-Serbian border in July involving explosives and a drone en route to Germany. Selen identifies the security and defense industries as particularly attractive targets for foreign intelligence services. Companies growing in this market factor in personal security, facility security, and information security as part of their growth costs.

The workforce determines how an incident is reported and interpreted

If the impact is based on creating uncertainty, the workforce is both a target and a line of defense. The incident in Großenkneten further demonstrates that security personnel are physically affected. Two points are therefore interrelated: the discipline of reporting any anomalies at fences, access roads, and neighboring areas, and providing employees with prompt, direct information so that the interpretation of an incident does not rely on rumors. The recruitment of opportunistic criminals via messaging services affects your staff and the staff of your service providers; the law explicitly addresses this issue.

Recommendation for Action

  1. Obtain a written determination specifying whether your company falls under the KRITIS Framework Act, the BSI Act as amended by the NIS 2 Implementation Act, or both, including the rationale and date. Establish a monitoring process for the KRITIS Regulation to ensure the three-month registration deadline is not missed due to jurisdictional issues. A case-by-case legal review remains necessary.
  2. Check your sites against the now-documented procedures: preparatory activities in the surrounding area over several days, storage in adjacent fields, sightlines to overhead power lines and access roads, and drone approaches at night. Conduct a drill with a nighttime scenario in which the entire reporting chain to the police, grid operators, and—where applicable—the State Office for Civil Protection (BBK) and the Federal Office for Information Security (BSI) is fully tested. Include personnel from external service providers in your security management system and establish guidelines for security guards’ conduct when encountering unknown individuals.
  3. Establish an information protocol for incidents in the vicinity of your sites, with a designated sender, a fixed communication channel, and a rule requiring the first report to be made within a few hours. Include recruitment via messaging services in your security training, with a clear reporting address within the company.

Three questions for you:

  1. Do your employees know where to report any suspicious activity on-site, and have you reviewed this procedure in the past twelve months?
  2. How do your employees learn about an incident in your vicinity: from your company or from social media?
  3. What statement do you make to your workforce while the cause of an incident remains undetermined, and who within the company is authorized to make it?

Stay vigilant!

JAN HESSELBARTH, as co-founder and managing partner of BRAVO SIX ADVISORY GmbH, is responsible for the defense division and brings over 20 years of operational and strategic leadership experience from the German Armed Forces, federal agencies, and the private sector. As a paratrooper officer and Joint Terminal Attack Controller (JTAC), he was responsible for territorial duties and host nation support at the Hamburg Regional Command following a deployment in Kunduz, Afghanistan. His consulting portfolio includes NATO missions, programs involving up to 1,000 participants, training initiatives for more than 5,000 Bundeswehr personnel, and co-authorship of a nationwide study on maritime security for the Federal Ministry of the Interior—a core topic in the context of KRITIS.

BRAVO SIX ADVISORY online

SPARTANAT is the online magazine for Military News, Tactical Life, Gear & Reviews.
Send us your news: [email protected]

similar

We tell you something.
Sign up for the newsletter now!

Get the weekly SPARTANAT newsletter.

Your bonus: the free E-Book from SPARTANAT.

With your registration, you confirm that you have read the privacy policy.