The attempted drone attack on Leipzig/Halle Airport and new Russian acts of sabotage in Germany have radically changed the European debate on Russian hybrid operations on European soil. The German government has officially blamed Russia for the attempted drone sabotage at the airport.

This incident has reignited discussions about whether Russian military personnel who fought against Ukraine should be barred from entering the European Union. However, a more complex question lies elsewhere: Is Europe capable of identifying and neutralizing any individuals, networks, and capabilities that facilitate operations involving drones carrying explosives?

Germany has officially linked the failed August attack on the Leipzig/Halle Airport to Russia. According to the investigation, the operation required professional technical training and serious organizational planning. At the same time, German officials believe that the direct perpetrators may have been low-level agents acting on behalf of Russian state agencies. Russia, as usual, denies any involvement.

Based on an analysis of known facts from the investigation into Russian sabotage operations in Europe, Channel 24 has reached some alarming conclusions – the experience with drone warfare that Russia has accumulated and refined during the war against Ukraine could be passed on to operatives who do not have a typical military background at all. They may also be trained by Russian UAV operators with recent combat experience. Consequently, Europe may soon face a terrifying wave of terrorist attacks and sabotage with catastrophic consequences. Can this threat be prevented? Read about it in Channel 24’s report.

At first, the incident in Leipzig appeared to be a serious but relatively localized breach of airport security. Further investigation points to a significantly more complex and better-organized operation aimed at undermining national security.

On August 4, a drone carrying explosives and a detonator was discovered in the secured area of the Leipzig/Halle Airport near Ukrainian Antonov cargo planes. German media reported that the drone collided with an Antonov aircraft and then fell to the ground without detonating. According to reports, it was carrying about 800 grams of Semtex plastic explosive.

A Russian drone struck the wing of a Ukrainian “Ruslan,” but fortunately did not explode. Next time, it might not be so lucky / Photo: Bild

Airport operations were disrupted. A DHL cargo plane, which aborted its landing, later collided in midair with another unidentified object and was diverted to Hanover. Fortunately, this did not result in a plane crash. After landing, minor damage was discovered on the plane.

Investigators later found a third drone in a field near the airport, as well as approximately 50 grams of a substance preliminarily identified as possibly hexogen, or RDX, a powerful military-grade explosive.

An antenna and electronic equipment, which may have been part of the drone’s control system, were also found near the airport. According to German authorities, the drone’s configuration, the type of explosive, and the detonation technology resemble methods associated with both previous Russian hybrid operations and Russia’s war against Ukraine.

On September 1, 2026, the German government officially held Russia responsible. Interior Minister Alexander Dobrindt stated that the available evidence points to individuals acting in the interests of Russian state structures. Berlin announced the closure of the Russian Consulate General in Bonn, measures against the “Russian House” in Berlin, and tighter controls on the entry of Russian citizens into Germany.

The following day, NDR, WDR, and the Süddeutsche Zeitung reported that German investigators had identified several suspects.

One of them is a Belarusian citizen who also holds a Russian passport and entered the Schengen Area on an Italian tourist visa issued in Minsk. The second suspect, described as a possible logistics specialist and instructor, allegedly arrived via Berlin and left Europe shortly before the attack.

If this information is confirmed, the incident in Leipzig would point to a problem far broader than the issue of Russian military personnel. The main threat lies in the network itself.

The implications for European security become clearer when the incident at Leipzig Airport is viewed in the context of the evolution of Russian drone operations in Ukraine.

Read also: Russia is preparing new terrorist attacks and sabotage in Europe: why the Kremlin will not stop after the attack on Leipzig Airport

Since July 2024, the UN Independent International Commission of Inquiry on Ukraine has been documenting regular Russian short-range drone attacks on civilians along the Ukrainian-controlled bank of the Dnipro River in the Kherson region. In May 2025, the Commission concluded that Russian occupiers committed murder as a crime against humanity through large-scale and systematic drone attacks carried out as part of a coordinated state policy.

The significance of these findings extends far beyond the mere number of drone attacks against Ukrainian civilians.

Such drones transmit real-time video to their operators. The Commission established that civilians were attacked while walking, driving, or going about their daily lives. This means that in many cases, Russian drone operators were likely aware of the civilian nature of the target even before the explosives were deployed. Hundreds of video recordings of such attacks were subsequently circulated via Russian Telegram channels.

By September 2025, the Commission had documented similar methods across a stretch of more than 300 kilometers, covering the Kherson, Mykolaiv, and Dnipropetrovsk regions. It concluded that occupying forces, operating under centralized command, employed the same modus operandi for attacks on civilians and civilian objects.

On August 19, 2026, a Russian drone attacked a passenger minibus in the Korabelny district of Kherson. Four civilians were killed, and five others were wounded. On September 1, another drone attacked a taxi in the same district, wounding three adults and two girls aged two and eleven.

18+ Aftermath of the Russian attack on a minibus in Kherson on August 19, 2026; photo courtesy of the National Police:

On August 25, in the Kharkiv region, an FPV drone killed two men who were clearing debris near a house in Slatyn. The threat of a follow-up strike prevented rescue workers from immediately responding to a fire that broke out later. Six days later, a Russian FPV drone attacked a civilian vehicle carrying a family in Zolochiv, Kharkiv Oblast, while another drone struck a municipal hearse transporting a body to a cemetery.

It is precisely in this environment that Russia has accumulated significant practical experience in drone-based reconnaissance, targeting, navigation, delivering payloads, and circumventing electronic countermeasures.

A drone systems specialist with such experience could pose an increased risk to European security. More precisely, it already does. It’s just that not everyone wants to admit it.

This is precisely where the Leipzig case changes the logic of the analysis. It is not a matter of the same Russian operator who attacked civilians in Kherson or Zaporizhzhia later piloting a drone in Germany. The point is different: the experience and capabilities developed during the war can be transferred without the most experienced UAV operators physically coming to Europe.

An intelligence service can recruit local or “mobile agents.” An experienced specialist can train another operator. Components can be purchased on the open market. Explosives, communications equipment, and control systems can be prepared separately. A logistics specialist can legally enter Europe on a tourist visa–which is still valid for Russians in the EU–ahead of the main group. Those coordinating the operation remotely may never cross the EU border at all.

The Russian sabotage operations at Leipzig Airport increasingly resemble precisely this distributed model.

According to German media reports, one of the suspects may have served as a logistics coordinator and instructor, while the German government described the direct perpetrators as “low-level agents.” It was reported that DNA traces were found on a drone, a container of explosives, and equipment installed near the airport.

This has important implications for security policy. Screening only those individuals whose service in the Russian army can be proven (more than 1 million people) addresses only one aspect of the threat. Such an approach will not necessarily identify recruiters, intelligence intermediaries, trained civilian specialists, dual citizens, logistical personnel, or newly recruited agents.

Former Russian President Openly Threatens Germany / Screenshot

Therefore, an entry ban on Russian military personnel and veterans and a strategy to counter sabotage are not one and the same tool. At the same time, restricting entry for individuals who pose the highest risk of being involved in drone sabotage on European territory would be a fully justified step toward strengthening European security.

The European Union has already recognized the potential security risk posed by individuals who participated in Russia’s war against Ukraine.

The 21st EU sanctions package, adopted on July 23, 2026, laid the groundwork for a comprehensive visa ban on current and former combatants of the Russian armed forces and affiliated groups who participated in the aggression against Ukraine. The Council of the EU has not yet activated this ban and must separately determine the date on which it will take effect.

The Russian Foreign Ministry, defying logic, claims Germany’s accusations are baseless / Screenshot

But there are problems with this. The proposal has faced resistance, particularly from France and Italy. Their objections mainly concern implementation mechanisms and legal precision, rather than the very existence of real security risks.

Key questions include: how can authorities reliably establish that an applicant directly participated in hostilities; how to evaluate Russian military documents; which visa instruments provide the most reliable legal basis; and how to avoid equating the mere fact of military service with personal responsibility for hostile activities. Subsequently, the EU considered limiting the scope of such a measure to individuals who directly participated in combat operations, as well as to short-term visas.

These reservations are well-founded. An overly broad rule is difficult to apply consistently and is also more vulnerable to legal challenges. However, the Russian sabotage operations in Leipzig suggest that the discussion itself may be focused on the wrong distinction.

The key distinction lies not simply between Russian combatants and civilians. It lies between people whose documented military or technical experience, or established participation in Russian military operations, indicates a heightened risk of involvement in sabotage, and people for whom no such evidence exists.

A more targeted approach is possible, as there is already a significant body of documented information on Russian drone operations.

The UN Commission has established the systematic nature of attacks against civilians. Ukrainian investigative authorities have gone further in establishing individual accountability. In June 2026, Ukrainian authorities announced that they had named ten servicemen from Russia’s 404th Motorized Rifle Regiment as suspects in FPV drone attacks on the civilian population and civilian infrastructure in the Kherson region.

Civil society organizations are also gathering evidence. Truth Hounds reported that during 2025, it identified more than 120 suspected perpetrators of war crimes, documented more than 43,900 suspected incidents, and filed seven submissions under universal jurisdiction procedures. These figures pertain to suspected war crimes in general and are not limited to drone operators.

Separately, the OSINT project ruskimviz.net maintains an open database of identified Russian UAV operators. This creates another layer of publicly available information that can be used for further verification and investigations.

Therefore, the key political task is to create a reliable mechanism that will allow for the transformation of various categories of evidence into legally sound security decisions.

The ruskimviz.net project maintains a database of exposed Russian war criminals / Screenshot

The EU should adopt an evidence-based approach and focus on identified UAV operators, commanders, instructors, intelligence officers, and intermediaries whose involvement in hostile activities is confirmed by a combination of data from official investigations, intelligence, and reliable civil society sources.

Such an approach would also more accurately reflect the current model of Russian hybrid operations: small groups, commercial technologies, intelligence coordination, one-time operatives, and highly specialized expertise, all brought together only for the duration of a specific operation.

A substantial body of international evidence has long been gathered in Ukraine showing that Russian military units have systematically used drones not only on the battlefield but also against civilians. The international press has also drawn attention to this. In particular, journalists from The New York Times conducted an investigation and found that a Russian drone, fully controlled by AI, systematically killed civilians in the Zaporizhzhia region. In other words, we’re talking about parameters predetermined by the occupiers. And the Russians could export all this experience to Europe.

Currently in Leipzig, German investigators believe that Russia organized a sabotage operation against critical logistics infrastructure involving agents operating within Europe. The key link between these cases lies not in the proven movement of specific drone operators from one theater of operations to another, but in the transfer of experience, methods, and operational capabilities.

This distinction is of fundamental importance for European security policy. The discussion cannot be limited solely to the question of whether Russian veterans should be granted tourist visas. Europe also needs a system capable of identifying individuals who can operate drones, train others, or organize or facilitate the use of drone warfare tactics developed over more than four years of full-scale war against Ukraine.

The investigation in Leipzig clearly illustrates the complexity of this threat. One of the suspects entered the Schengen Area on a standard tourist visa, while another presumably arrived separately as a logistics specialist and instructor. Those who direct such operations may never enter the EU at all.

Therefore, a more effective approach is based on individual risk assessment, supported by data on involvement in the war in Ukraine. European authorities should focus on identified operators, instructors, intermediaries, and individuals linked to intelligence structures, while integrating visa and border controls with an ever-growing body of evidence regarding Russian military and sabotage networks.

Leipzig has shown that Russian terrorist tactics involving drones–honed in Ukraine–can be transferred beyond the battlefield and adapted for operations against civilian infrastructure within Europe itself. European security policy must take this reality into account.