- ANALIZA
- WIADOMOŚCI
Europe's strategic depth in Russia's crosshairs
The emergence of a threat to air traffic in connection with the incident at Leipzig/Halle Airport was described by the head of the German Federal Ministry of the Interior as a new dimension in the context of hybrid threats. As a reminder, an unmanned aerial vehicle appeared there, „armed with an explosive payload, used for military purposes, and constructed in a manner that allowed it to bypass airport security controls.” However, based on the author’s subjective assessment, we cannot state that there is any surprise in Europe. Such an approach would provide an excuse for certain shortcomings regarding the actions of individual states and their services.
First, on the European continent, not only in the 21st century but also in the 20th, we faced terrorism. Numerous instances of terrorist activity were amplified by the involvement of state actors (ranging from states like the then-Libya and Iraq to, of course, the Eastern Bloc countries led by the USSR). Furthermore, let us recall that as early as the 1970s, civilian aircraft were threatened by plots centred around military-grade MANPADS (SA-7) launchers (Italy). A series of bomb attacks throughout Europe in both recent and more distant history relied on military-grade explosives rather than improvised materials.
Russia is reaching for "tried-and-true" methods
Many terrorist structures received pyrotechnic and sapper training in armed conflict zones, including from the armed forces and intelligence services of specific states. Importantly, during the Cold War, diplomatic channels between Middle Eastern and Eastern Bloc countries were used to smuggle the aforementioned munitions. Therefore, it should come as no surprise if some materials for future terrorist operations were to appear analogously or be obtained via organised crime (as Adam Jawor has repeatedly written about in InfoSecurity24, among others) and third-party entities cooperating with the Russians.
Currently, we are speaking of unmanned aerial systems, which are a novelty, but not a revolution. In the Middle East, during the peak of the so-called Islamic State’s (Daesh) activity, this topic was already being considered. As for counter-terrorism prevention, threats posed by UAVs have been discussed for many years—including single-use systems carrying explosive payloads, OWA-UAVs, or systems designed to drop a payload and attempt a return to the operator. If we can consider anything a shift, it is the dynamic development of tactics and the scale of availability regarding unmanned systems. However, once again, it cannot be said that strikes against critical infrastructure, airports, mass gatherings, etc., using UAVs are something new that requires a revolution in our mindset and approach to technology.
Note that even before the full-scale war, Ukraine struggled with UAVs attempting to target ammunition depots and broader military logistics. Following the outbreak of the war in 2022 and Russia’s aggression, the database relating to these issues became exceedingly vast and, most importantly, accessible. Today, UAV systems are present in every conflict characterised by high force asymmetry, as well as in more symmetrical conditions in terms of adversary capabilities. At the same time, Europe, individual states, and their services understand this problem, particularly concerning critical infrastructure and infrastructure involved in fulfilling critical services, such as military aid. Thus, incursions by unmanned systems into the airspace of NATO/EU nations should not be treated as surprising, but recognised as a fundamental element in the threat catalogue.
See also 
We need to think long-term
Consequently, long-term programmes should be implemented to improve response capabilities (technology, training, inter-agency coordination) and to streamline legal and doctrinal frameworks and regulations. The occurrence of events similar to the German incident throughout Europe is not hypothetical, but borders on certainty. At this point, it should be noted that public opinion, unfortunately, treats the war in Ukraine emotionally, which in many cases hinders discussions on the risks it poses to the security of other states (ranging from veteran crime and the availability of explosives and weapons to the proliferation of tactical solutions).
When speaking of UAV systems, an ideal case study is the Operation Spiderweb (2025) positioning. Ukrainian intelligence services struck selected Russian strategic aviation airbases by infiltrating its territory and launching unmanned systems from camouflaged containers. This was presented in the media as a success for Ukraine’s covert operations and a catastrophe for the Russian side, which was unable to protect its key military bases.
The fact was noted, and discourse quickly moved on to other topics. At the same time, it was forgotten that, for the Russian intelligence services, such an attack represents valuable lessons learned and will most likely be used to formulate their own operational scenarios targeting the West. Consequently, we must expect not only attempts by single aircraft to enter airspace, but entire proverbial containers. The situation at Leipzig/Halle should be treated as a reminder signal of the necessity to undertake broad measures across various sectors, not just within the armed forces. This is particularly true given that there should be no surprise regarding the choice of potential targets. Military aid for Ukraine is in the crosshairs and will remain so long after the active phase of armed conflict concludes. Many nations—led by Germany, Poland, Romania, the United Kingdom, and France—are essential to providing strategic depth for Ukrainians fighting against aggression. This encompasses a catalogue of operational domains that must be grounded in specific infrastructure.
See also 
Many targets and many ways to attack them
In the case of the recent failed attack, we are speaking of transport and logistics, but there is also defence production and training support. Ever since the initial Russian momentum in Ukraine began to wane, we have known that airports, aviation infrastructure, freight centres, warehouses, and railway and road hubs are recognised as primary reference points for Russian intelligence services. We are speaking first of a saturation of traditional espionage, including the technical capability to monitor the movement of military aid (trail cameras, CCTV, etc.) as well as human intelligence (the introduction of assets). Moreover, even before 2022, the Russians demonstrated that they complement this with sabotage and subversion operations—a primary reference point being the 2014 explosion at the Vrbětice ammunition depots in the Czech Republic. Today, the practical scale of such activity is growing alongside the escalating conflict in Ukraine.
It is worth noting that, as reported by InfoSecurity24, the Polish side—using documentary material broadcast on public television—demonstrated the modus operandi of sabotage and subversion targeting air freight and transport. Incendiary devices capable of threatening aircraft, airport infrastructure, or shipping facilities were dispatched. Yet, as mentioned, the catalogue of targets is far broader, encompassing the infrastructure of bases training Ukrainian soldiers, as well as the support infrastructure for these military facilities. Germany cannot be surprised, nor can other European nations, that the rules of the game regarding the defence industry have changed. As early as 2024, a comprehensive analysis titled „Zbrojeniówka na celowniku dywersantów i sabotażystów OPINIA” appeared on Defence24, highlighting the immense scale of security challenges in this area. It includes counterintelligence operations, combating sabotage and subversion, and physical protection of key defence sector figures (e.g., the assassination plot against Armin Papperger, CEO of the German defence concern Rheinmetall, reported in 2024), as well as key engineering and design personnel.
Beyond primary defence contractors, who must inherently be aware of their industry’s realities, the space of small and medium-sized dual-use enterprises is expanding dynamically year by year. They seek rapid market entry, ideally leveraging a „combat-proven” brand and gaining advantages from operations in locations such as Ukraine. However, their security standards are naturally derived from the civilian market. This is to say nothing of subcontractor networks, raw material supply chains, and similar links. Targets are multiplying, and every month of industrial warfare under conditions of Russian aggression against Ukraine increases the probability of strikes, sabotage operations, and even the stimulation of terrorism across various European states.
Russia accepts the risk
There is one more aspect that must be emphasised, as it is critical to understanding the magnitude of the challenges we face here and now; namely, the Russians possess a high tolerance for risk in secret operations. Since Vladimir Putin was placed in the presidency by Boris Yeltsin, Russian intelligence services have been freed from many of the constraints that are typical of European states. Therefore, if the Leipzig/Halle incident turns out to be linked to the Russian side, it would fit into a long line of previously breached boundaries. As a reminder: operations involving military-grade nerve agents and poisons, radioactive substances, and execution-style assassinations using firearms (including in prominent locations virtually in the centre of Berlin).
Let us also remember the downing of Flight MH17 using a Russian air defence system. Currently, grey-zone actions below the threshold of war are a standard instrument of Russian operations, and generating sensation around this misses the point—especially when the research perspective is narrowed solely to the post-2022 period. The visible shift lies in quantitative scaling, less sophisticated methods of procuring mass assets, and an acceptance of losses and compromise.
Conclusions... for Poland as well
In conclusion, we must identify a natural set of tools resulting from an understanding of the complexity of these threats and their long-term nature (rather than treating them as novel or revolutionary). The first element is indisputably the continuous staffing and technical reinforcement of our counterintelligence services across Europe. We cannot afford to shift resources back and forth between counterintelligence and counter-terrorism, as the adversary understands this dynamic perfectly and will exploit it. Regrettably, the picture in Europe—at least in the media—suggests that states are forced to redeploy resources from one vector to another, publicly exposing their vulnerabilities. In the case of Poland, this should be viewed as a lesson learned, driving efforts to strengthen the synergy between traditional counterintelligence and counter-terrorism competencies, recognising that the Russian side operates on the fluid boundary between espionage, sabotage, subversion, and terrorist-type threats.
When discussing counterintelligence, it is crucial to understand that the greatest asset is knowing the adversary’s plans before execution—which also mandates investment in intelligence. This must be specifically directed at state entities that may be behind attacks, sabotage, subversion, or the sponsorship of terrorism. Therefore, it is important to reiterate that under current conditions, Poland must not only invest in its armed forces, but also drastically increase the resources allocated to its counterintelligence and intelligence services, knowing that we rank high in Europe—and will remain so—among Russia’s target priorities.
Furthermore, we cannot avoid emphasising that terrorist prevention and education aimed at building awareness of both terrorist and espionage threats represent a highly complex challenge for European states and societies today. We cannot merely teach and warn against classic recruitment and espionage; we must also continuously build awareness regarding sabotage, subversion, and terrorist threats. Both issues, under current conditions, affect an increasingly broad group of people—whether due to their professional activity, place of residence, or accidental presence in situations connected to these threats. The capstone of our efforts must be strategic communication that preempts potential adversary narratives in the event of successful attacks or attempts to exploit incidents to sow fear.
Finally, we must also recognise that internal security demands technological transformations on a scale equal to those that took place following the 9/11 terrorist attacks. This entails acknowledging that the military, law enforcement, security services, and industry, together with the research and development sector, stand on the same figurative frontline. Today, there is no room to segregate threats strictly between the military domain and non-military security. Cyber threats, alongside the proliferation of electronic warfare solutions and various unmanned systems, provide a clear answer: efficiency can only be achieved through a systemic approach. This is particularly true when an adversary intentionally operates below the threshold of war while employing hybrid methods—drawing on their own military experience and leveraging the professional resources of their intelligence services. Therefore, when discussing the technical modernisation of the armed forces, we must simultaneously recognise the technical modernisation needs of areas such as critical infrastructure protection.




