• Close
  • Subscribe
burgermenu
Close

Russia's shadow war in NATO's grey zone

Russia's shadow war in NATO's grey zone

The explosive drone found near Leipzig/Halle Airport highlights how suspected Russian sabotage is testing NATO’s ability to deter attacks below the threshold of Article 5.

By Nami El Khazen | August 27, 2026
Reading time: 6 min
Russia's shadow war in NATO's grey zone

Early this month, an explosive-laden drone reached one of the most strategically important airports in Germany, Leipzig/Halle Airport in Saxony. More than a simple civilian cargo hub, the airport acts as one of the most critical cargo and military logistics hubs used by NATO to move supplies to Ukraine.

German investigators believe the drone was intended to attack a Ukrainian Antonov used to transport military goods, but fortunately for the Ukrainians, the explosive failed to detonate. Two additional drones and an antenna were later found next to the airport. Together, the drones carried roughly 50 grams of suspected military-grade explosive.

The question that immediately arose was obvious: Who was behind it?

 

Tracing the fingerprints

U.S. intelligence now appears to be pointing more directly to Russia. An American intelligence official said on 26 August that the explosive and construction of the first device bore characteristics associated with equipment used by the GRU, Russia’s military intelligence service. The assessment was reportedly reached in conjunction with German intelligence and security agencies. Berlin has not yet publicly blamed Moscow, although Chancellor Friedrich Merz says the government expects to present its findings shortly. Russia, for its part, has denied any responsibility.

Leipzig therefore sits at the centre of a much larger question for NATO. Russia's confrontation with Europe is increasingly taking place in a space that is neither peace in the traditional sense nor conventional war: violent enough to impose costs, but sufficiently deniable and limited to make collective military retaliation difficult.

 

Leipzig and beyond

In July 2024, Leipzig/Halle had already been the scene of a remarkably similar operation. Four explosive-incendiary parcels were dispatched from Vilnius on 19 July, two by DHL toward Britain and two by road toward Poland. The first detonated at Leipzig/Halle the following morning, shortly before it was due to be loaded onto a DHL cargo aircraft. Another ignited inside a truck in Poland, while a third caught fire at a DHL facility in Birmingham. A fourth malfunctioned. Investigators later found that electronic timers had been concealed inside massage cushions and incendiary material inside ordinary consumer products.

Investigators subsequently uncovered additional parcels linked to the United States and Canada, reinforcing suspicions that the attacks were test runs for eventually placing incendiary devices aboard transatlantic cargo aircraft. Lithuanian prosecutors say Russian citizens connected to Russian military intelligence organized and coordinated the network. By March 2026, European investigators had identified 22 people linked to the operation.

Elsewhere, the pattern has included arson, surveillance, plots against military infrastructure and even an alleged plan to assassinate German arms manufacturer Rheinmetall Chief Executive Armin Papperger. NATO has publicly described these incidents as part of an intensifying Russian campaign conducted partly through proxies on Allied territory.

 

The architecture of deniability

Rather than repeatedly inserting identifiable Russian intelligence officers into NATO states, suspected Russian networks have recruited criminals and other intermediaries, sometimes through Telegram and with payments in cryptocurrency. The person setting fire to a warehouse may therefore have no formal relationship with Moscow and may be separated from the Russian intelligence officer directing the operation by several layers of intermediaries.

An overt Russian missile striking a German logistics facility would create a straightforward political crisis, while sabotage produces a far murkier problem. Authorities must identify the perpetrator, trace communications and establish whether a foreign state directed the operation before persuading NATO allies that the evidence is strong enough to justify a response.

Western intelligence officials believe the ambiguity is deliberate. Their assessment is that the latest suspected Russian operations against European defence manufacturers are being calibrated to remain below the level that could trigger NATO’s collective-defence clause, with local criminal networks providing Moscow with an additional layer of plausible deniability.

 

Where article 5 begins

Yet Article 5 is not a tripwire with a clearly marked line painted across Europe. The North Atlantic Treaty refers to an “armed attack,” but NATO deliberately assesses what qualifies as one on a case-by-case basis. The Alliance has also made clear that major cyberattacks and other hybrid attacks could, under certain circumstances, amount to an armed attack and therefore fall under Article 5.

This creates an unusual deterrence problem. Moscow does not need to know precisely where NATO's legal threshold lies. It only has to keep individual operations limited enough that governments hesitate to discover it.

A small fire can be treated as criminal activity. A damaged undersea cable can be blamed on an anchor. A drone can remain unidentified while investigators search for its origin. Even when intelligence agencies strongly suspect Moscow, governments may remain reluctant to make that conclusion public without evidence capable of surviving political and diplomatic scrutiny.

 

Testing NATO’s political threshold

The concern is that Russia may be probing NATO’s political threshold for action, not merely the formal wording of Article 5. European security officials described the process as advancing until resistance is encountered. If Moscow faces little meaningful cost after one operation, there is a risk that future operations could become more ambitious

The Leipzig incident may represent precisely such an escalation. Germany's interior minister had already described the explosive drone as a new threat scenario. France's domestic-intelligence chief, Céline Berthon, subsequently warned that the case illustrated the danger of hybrid operations becoming increasingly direct and violent against European targets.

Unfortunately for Europe, the actions purportedly carried out by Russia are placing European governments in a difficult strategic position. Protecting airports, factories, railways and undersea cables is necessary, but an entirely defensive strategy leaves Russia with the initiative. Moscow can choose from thousands of vulnerable targets while European states attempt to protect all of them. A June report by the Hague Centre for Strategic Studies argued that Russian sub-threshold coercion is selective, concentrating pressure on states supporting Ukraine, while forcing Europe to absorb the costs of defending an ever-expanding number of potential targets.

Yet the answer cannot be to invoke Article 5 every time a suspicious fire breaks out. Doing so would make collective defence less credible . But neither can Article 5 become the only point at which Russia encounters collective consequences.

Washington also appears to be warning Moscow that operations falling short of Article 5 will not necessarily remain consequence-free. CIA Director John Ratcliffe was in Moscow this week for rare talks with Russian intelligence officials, the first known visit by a CIA chief to the Russian capital since 2021. U.S. media reports, citing unnamed sources, say Ratcliffe used the meeting to warn Moscow against attacking NATO members, although neither Washington nor Moscow has publicly confirmed that message.

If that warning was indeed delivered, it points to the dilemma at the heart of NATO’s response. Deterrence cannot begin only once Russia launches an unmistakable armed attack. The Alliance must also convince Moscow that sabotage, proxy operations and carefully calibrated violence below that threshold will carry consequences.

Therefore, the real test for NATO is whether Moscow comes to believe that the space below collective defence is a safe place to act, or whether the Alliance can make clear that the shadows carry a price too.

    • Nami El Khazen
      Journalist
      Focusing on geopolitics and international affairs.