Germany strengthens its defense against hybrid attack threats

Following a drone incident at Leipzig/Halle Airport, Berlin is seeking new measures against sabotage, espionage, and disinformation.

12punto

Germany is working to reshape its security approach in response to the rise of hybrid threats such as sabotage, espionage, disinformation, and drone attacks. The Berlin administration emphasizes that while the country is not in a direct war with Russia, it is a target of hybrid activities originating from Moscow.

Chancellor Friedrich Merz, in a statement following the attempted drone attack on Leipzig/Halle Airport, said that drone flights, sabotage, and disinformation are being used with increasingly harsh methods. Merz stated that Russia is prepared to act "at the risk of serious material damage, or even injury and death." This statement was one of the first assessments in which Berlin explicitly blamed Russia for the incident in question.

The debate over security and resilience against hybrid threats is deepening in Germany.

Interior Minister Alexander Dobrindt has also raised the current threat level from the "abstract" category to "high." However, detecting hybrid attacks is more complex than traditional security threats: identifying the perpetrators, proving whether different incidents are connected, and demonstrating whether actions serve a common strategic goal often require lengthy investigations.

HOW IS A HYBRID CAMPAIGN UNDERSTOOD?

According to security expert Ferdinand Gehringer, not every cyberattack, act of sabotage, or disinformation attempt is automatically considered part of a hybrid campaign. The determining factor is the ability to establish a link between elements such as a common actor, coordinated timing, similar methods, repeated targets, and a shared strategic objective.

The incident at Leipzig/Halle Airport stands out as one of the notable examples in this regard. A drone with an explosive device was detected near Antonov cargo planes, which also transport military equipment to Ukraine. Dobrindt said that "disposable agents" acting on behalf of a Russian intelligence service may have played a role in the incident.

Cargo airports and critical infrastructure security are at the forefront of hybrid threat discussions.

According to German authorities, to understand such incidents, information from the police, intelligence services, the Bundeswehr, cyber defense units, and the private sector must be evaluated together. Technical traces, crime patterns, timelines, and disinformation narratives can only be read within the same picture in this way.

DEFENSE IS NOT JUST MILITARY

Hybrid warfare is often conducted below the threshold of open armed conflict. The goal is to exploit a country's weak points, undermine trust in state institutions, and destabilize society. For this reason, Berlin's response is not limited to military capacity alone.

The federal government has increased its measures against hybrid threats since 2022. Inter-ministerial task forces and processes for combating disinformation and foreign information manipulation are prominent in this framework. At the EU level, the "Hybrid Toolbox" provides a common response mechanism, while the European Centre of Excellence for Countering Hybrid Threats aims to pool information on cases of espionage, sabotage, and disinformation.

Following the Leipzig/Halle incident, Berlin announced steps such as the closure of the Russian Consulate General in Bonn and the Russian House in Berlin, EU sanctions on Russian citizens linked to hybrid attacks, the tightening of entry controls, and increased pressure on Russia's shadow fleet.

According to experts, the most critical pillar of defense is societal resilience. Emphasizing that a proactive approach is needed rather than just reacting after an attack, Gehringer highlights that citizens evaluating information critically, the work of independent media, and the state communicating quickly and transparently will reduce the impact of hybrid operations.