Between peace and war: Germany’s battle against hybrid threats

Business Entertainment Genel News Politics Sports Uncategorized

Germany’s Chancellor Friedrich Merz and several ministers have already stressed that, while Germany is not at war with Russia, it is nevertheless facing hybrid attacks from Moscow.

These include drone overflights, sabotage and disinformation, as well as a willingness “to act with growing ruthlessness, accepting serious damage to property and even injuries and deaths,” as Merz said at a press conference following the attempted drone attack on Leipzig/Halle Airport.

It was the first time the German government had explicitly blamed Russia for an attempted attack. Since Russia launched its full-scale invasion of Ukraine, there has been frequent discussion of hybrid warfare against countries supporting Kyiv, with Germany seen as particularly exposed.

German Interior Minister Alexander Dobrindt has therefore raised the current threat level from “abstract” to “high”. Hybrid attacks are considered difficult to detect because it is often unclear who is behind them and whether individual incidents are even connected.

There is growing concern about Russian hybrid activities targeting Germany, but Moscow is not the only country using such methods. According to the Federal Office of Civil Protection and Disaster Assistance (BBK), China, Iran and North Korea are also targeting Germany with hybrid measures.

German Chancellor Friedrich Merz attenda a meeting of the German federal parliament in Berlin, 8 September, 2026

How to spot a hybrid campaign

However, “not every cyberattack, act of sabotage or attempt at disinformation is automatically part of a hybrid campaign,” security expert Ferdinand Gehringer told Euronews.

What matters, he said, is the identifiable link between different measures. This may involve “a common actor, coordinated timing, recurring targets or methods and, above all, a shared strategic objective.”

One example is the attempted drone strike on Leipzig/Halle airport. A drone fitted with explosives was discovered there in the immediate vicinity of Ukrainian Antonov cargo aircraft that also transport military equipment for Ukraine.

In his press statement, Dobrindt said they assumed that so-called “low level-agents” may have been involved on behalf of a Russian intelligence service. The pattern of the crime, the technology used and intelligence findings also led the federal government to conclude that Russia was behind the attack.

This, Gehringer said, is where the so-called overall situation assessment comes in. To judge whether individual incidents are part of the same operation, information from different areas has to be pooled, from the police, intelligence services, the Bundeswehr, cyber defence and the private sector, for example.

“Only by examining technical traces, crime patterns, timelines and disinformation narratives together can links be identified,” explained Gehringer.

Ukrainian Antonov transport aircraft is parked behind a fence on the grounds of Leipzig/Halle Airport, 6 August, 2026

How can Germany defend itself

Hybrid warfare often takes place below the threshold of open armed conflict. Its aim is to exploit a country’s vulnerabilities, erode trust in state institutions and unsettle and destabilise society.

But how can a country and its society prepare for and defend themselves against hybrid attacks or even hybrid warfare?

Rearming the Bundeswehr alone is no answer to suspected attacks, spying attempts or disinformation. Nor can hybrid attacks in most cases simply be repelled or countered by kinetic means. So how does a state respond to an attack that remains below the threshold of an armed assault?

The federal government has stepped up its precautions against hybrid threats since 2022. These include an interdepartmental task force dealing with disinformation and other hybrid threats. There are also procedures that can attribute cyberattacks and foreign information manipulation to a potential originator.

Interior Minister Dobrindt and Foreign Minister Wadephul at a press conference on the drone attack on Leipzig/Halle airport, Berlin, 1 September 2026

At EU level, the so-called “Hybrid Toolbox” provides a mechanism for joint responses.

Since this year, there has also been the Joint Centre for Countering Hybrid Threats (GAZ Hybrid). It is intended to bring together information on espionage, sabotage, disinformation and other hybrid threats, so that such activities can be detected early and tackled more effectively.

In the case of the attempted drone attack in Leipzig, the federal government responded “resolutely, calmly and proportionately”.

It announced measures such as the closure of the Russian consulate general in Bonn and the Russian House in Berlin, sanctioning further Russian individuals over hybrid attacks at EU level, tightening entry controls and stepping up pressure on Russia’s shadow fleet.

The public as part of the defence

According to Gehringer, however, defence starts even before a campaign begins: “More generally, we need to move away from merely reacting and towards a more anticipatory approach. The goal must be to raise the costs for attackers, disrupt their planning paths, uncover networks as early as possible and also blunt the impact of attacks.”

If, for example, an attack on a substation caused a power cut, households and businesses could bridge the gap with emergency power until the grid operator repaired the damage.

In the best case, he says, preparation would eventually be so good that hybrid attacks could be headed off by identifying relevant activities at the planning stage and nipping them in the bud.

At the same time, the state and society need to be ready, in terms of communication, for possible attacks. That would not only limit damage but also rob hybrid operations of their intimidatory effect.

Police search the area around the extra-high-voltage power lines near the Turnow-Preilack substation and the Jänschwalde power plant in Preilack, 3 September, 2026

This can only be achieved through a combination of deterrence, defence and resilience, the security expert told Euronews. According to Gehringer, the public “plays a very important role” here, but is “still being needlessly wrapped in cotton wool.”

“Yet it is part of the solution,” he added, explaining that disinformation, for example, can never be fully prevented, nor should that be the aim, since an open society must always contend with manipulative information, in his view.

“Our goal must therefore be resilience rather than isolation”, said Gehringer. Citizens need to be able to assess information critically, the media must operate independently, and the state must communicate “quickly, credibly and transparently”, Gehringer explained.

What do you feel about this post?

0%
like

Like

0%
love

Love

0%
happy

Happy

0%
haha

Haha

0%
sad

Sad

0%
angry

Angry

Leave a Reply

Your email address will not be published. Required fields are marked *