Europe Is Running Out of Near Misses From Russian Sabotage

Columna
World Politics Review, 19.08.2026
Candace Rondeaux, profesora (U. Estatal de Arizona) y académica (New America)

Eight hundred grams of Semtex. That was roughly how much of the plastic explosive German investigators say was packed into a tin-can-sized device attached to the drone discovered at Leipzig/Halle airport in Germany on Aug. 4. For perspective, forensic investigators estimated that the bomb that destroyed Pan Am Flight 103 over Lockerbie, Scotland, in 1988, contained roughly 350 to 450 grams of Semtex. All 259 people aboard that flight were killed, along with 11 people on the ground.

No one was killed in Leipzig. The drone’s detonator failed, and an airport bus driver managed to kick the device clear of the Ukrainian cargo plane it was apparently targeting. Part of the heavy-lift pipeline that flies NATO’s strategic airlift missions to Ukraine, the Antonov jet was loaded with ammunition. Aviation authorities halted air traffic and diverted several inbound DHL freighters to Hanover after one such flight arriving from Marseille was struck by an object German authorities suspect was a second drone, though it caused only minor damage.

Twice in two years, Leipzig has come close to disaster. The first time was in 2024, when a parcel containing an incendiary device caught fire shortly before it was loaded onto an aircraft at the airport’s DHL hub. Saboteurs linked to Russia are implicated in both cases. Europe cannot afford to bide its time while it decides what deterrence looks like.

From Leipzig to London, sabotage attacks across NATO territory have taken many forms since Russia’s full-scale invasion of Ukraine: arson, vandalism, bomb plots, drone incursions, assassination attempts and cuts to cable and rail lines. Scattered across a dozen jurisdictions, targets initially seemed as variable as the timing of the incidents, making attribution slow work. Coordinating a response to Moscow’s provocations has been even slower, in part because European capitals are still arguing over what constitutes a hybrid attack on critical infrastructure, and what exactly counts as critical.

The campaign’s goals are clear: disrupt Western support for Ukraine, deepen divisions within NATO and probe how much violence Russia can sponsor below the threshold of open conflict. The trans-Atlantic alliance has held since 2016 that a hybrid attack could trigger an Article 5 mutual defense response, while maintaining that answering one is primarily the job of the state that was hit. The label determines whether an incident lands on a prosecutor’s desk or in a NATO command center.

To turn the tables, Europe needs to do at least four things: go after the networks that regenerate operatives; harden the logistics Russia is probing; open the public record so the press, researchers and lawmakers can see the totality of Moscow’s campaign; and build a credible ladder of consequences for further escalation.

A February 2026 study by GLOBSEC, a Bratislava-based think tank, identified 172 people named in legal proceedings across Europe, tied to 151 incidents of sabotage and subversion since 2022. None of them have triggered NATO’s Article 4, the provision that lets any member call the alliance into consultation when its security is threatened. Poland invoked it in 2014 after Russia’s annexation of Crimea; eight allies invoked it together on the day of the full-scale invasion of Ukraine in 2022; Poland went back to the North Atlantic Council—the alliance’s primary decision-making body—in September 2025 after Russian drones crossed its airspace, some of which were shot down by Polish and Dutch jets.

It would be surprising if Germany did not call for Article 4 consultations in response to the most recent drone incident in Leipzig. It would be even more so if another round of talks in Brussels amounted to much. Intelligence services across NATO territory have learned hard lessons about detecting and disrupting Moscow-directed plots. What they have not learned is how to convert those lessons into deterrence.

Lockerbie underscores the urgency. It took 12 years to convict the only man ever found guilty in the bombing. Now, 38 years later, a new trial is set to open in Washington this month for the man accused of building the bomb for the Libyan intelligence network behind the plot. Documents recovered from the files of Libya’s former spy chief and published last year are also said to tie Libyan intelligence operatives to UTA Flight 772, which was blown apart over Niger nine months after Lockerbie, killing all 170 aboard. Scottish detectives are examining the files now. The lesson is discomfiting: attribution takes years, justice can take decades, but deterrence cannot wait.

While the Lockerbie case crawled toward a verdict, another generation of extremists was preparing a different kind of attack on civilian aviation: the one that brought down the World Trade Center and tore open the Pentagon on Sept. 11, 2001. Fear and uncertainty then produced rash American decisions, the consequences of which are still reverberating. Europe can still avoid both mistakes: waiting for catastrophe to recognize a campaign, then letting catastrophe dictate the response.

Coverage of the prosecutions of low-level saboteurs on the continent has produced a tidy narrative: a gig economy of covert action, disposable labor hired for a discrete task and discarded upon arrest. This explanation is not wrong so much as it is incomplete.

Consider the case of Roman Lavrynovych, a 22-year-old Ukrainian builder convicted in June of conspiring to burn a house and a car in London linked to then-Prime Minister Keir Starmer. The BBC reported that Russia was behind the attack, but also that Lavrynovych did not seem to know whose property he was setting alight, and the thousands of pounds he was promised never arrived. His handler’s contact information was saved in his phone as EL Money.

The BBC found evidence suggesting EL is Evgeny Lyukshin, 23, trained in information warfare and the son of a senior Russian Foreign Ministry official, though the network could not confirm it and Lyukshin did not respond to questions. The Insider traced father and son to a Moscow address used to house staff from Russia’s SVR intelligence service. Lavrynovych is headed to prison. As of this writing, Lyukshin’s status is unknown.

This points to a discomfiting fact: We are four years into a covert campaign where the only point of consensus is that the people getting caught are disposable while their handlers abscond. This should itself be a warning.

European governments know far more about the shape of the Kremlin’s shadow war than the public can see. Much of it sits in national court files across multiple jurisdictions, where indictments arrive as one-paragraph statements with the names redacted, judgments as unwieldy PDFs when they are posted at all, and the whole is governed by privacy rules written for ordinary criminal defendants rather than for state-directed operations.

Sunlight would help. Access to court records, indictments, evidence summaries and declassified attribution would let journalists and researchers connect cases across borders, and would let lawmakers grasp the cumulative threat before a mass-casualty attack forces the argument under crisis conditions.

The Leipzig case is illustrative. German investigators recently recovered a DNA trace from the drone that matches biological evidence found on the incendiary device that ignited at the airport’s DHL logistics center in July 2024. Germany’s weekly newspaper Die Zeit reported last week that the same DNA profile had already been registered in Lithuania. German authorities have not confirmed the match, but a separate news investigation found that the man who transported and armed the 2024 parcels also brought drone components and SIM cards into Germany that summer, the same type of equipment needed to fly a device like the one discovered at Leipzig in early August.

Lower-level players are already in custody. The clues point past them, indicating that European authorities urgently need to focus on coordinated identification and disruption of the persistent middle layer: the coordinators, recruiters, logisticians, financiers and technical specialists who survive individual arrests and keep supplying new operatives.

Germany is beginning to move in that direction. Earlier this month, its Cabinet approved legislation that would give intelligence services much broader powers to hack hostile systems, disrupt foreign operations and intervene against sabotage rather than simply watch it unfold. The measures still require parliamentary approval, but the shift from intelligence collection to active disruption is overdue.

Germany also opened a counter-drone research center this week, which is a reasonable response to the spate of mysterious drone overflights and a welcome step after the most recent drone incident. It is not, however, an answer to the reconnaissance behind it. Whoever sent the drone toward the cargo apron in Leipzig understands how freight moves along the seam between Europe’s commercial networks and the strategic airlift that delivers military gear to the Ukrainian frontline.

Freight networks are not only targets to be defended with sensors and jammers. Their daily rhythms give visibility into routes, dwell times, handoffs and vulnerabilities to anyone patient enough to watch. Logistical corridors have to be treated as counterintelligence terrain, which means investing in anomaly detection, access control and more information-sharing between commercial operators and security services. Twice now, Leipzig has been saved by a faulty detonator. No one should count on getting that lucky again.

No hay comentarios

Agregar comentario