German authorities are expanding counter-drone defenses after investigators thwarted an apparent attack near Leipzig Airport involving a mobile-phone-controlled drone carrying Semtex. The device was found in a secure airport area near a Ukrainian Antonov cargo aircraft, and investigators said a faulty detonator likely prevented an explosion. Prosecutors are treating the case as attempted causing of an explosive detonation and dangerous interference with air traffic, while Germany’s Federal Prosecutor has taken over the investigation. Authorities are also examining a second suspected drone-related incident involving a DHL cargo plane that landed safely with nose damage.
U.S. intelligence linked the Leipzig incident to the Russian government, placing it within a broader sabotage and hybrid-threat campaign against European civilian and critical infrastructure. In response, Interior Minister Alexander Dobrindt ordered the Federal Police to expand counter-drone units from four to eight locations nationwide, while the Interior Ministry issued an urgent tender for airport drone-detection systems and moved to enlarge the drone-defense test center in Cochstedt near Magdeburg. Investigators are also reviewing a possible connection to the 2024 package explosion at DHL’s Leipzig logistics hub after reports of a DNA match with evidence from that earlier case.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
The International Institute for Strategic Studies said suspicious drones were spotted at least 144 times in 13 European countries during this period. It assessed that Russia likely used a sustained drone campaign to probe air-defense gaps and surveil airports, ports, and other critical infrastructure.
Unknown individuals attempted to contaminate the drinking water system on a German naval ship while it was docked in port. Dozens of liters of used oil were introduced, but the crew detected the contamination early and authorities ruled out an accident.
A package arriving from Lithuania exploded at DHL’s Leipzig logistics center. Investigators later examined whether DNA evidence from this July 2024 case matched traces from the later Leipzig airport drone incident.
U.S. intelligence linked the thwarted Leipzig airport drone attack to the Russian government and assessed that the drone was almost certainly intended to target civilian cargo aircraft. The attribution framed the incident as part of Russia’s broader sabotage campaign in Europe.
Federal Interior Minister Alexander Dobrindt ordered a major strengthening of Federal Police counter-drone capabilities, expanding permanent units from four to eight locations nationwide. The move followed the Leipzig incident and was paired with plans to further expand the drone-defense test center in Cochstedt near Magdeburg.
The day after the Leipzig airport events, Germany’s Interior Ministry published an urgent tender for airport drone-detection systems. The procurement called for passive detection with at least a four-kilometer radius plus command-and-control functions.
Germany’s Federal Prosecutor assumed control of the Leipzig airport case, which prosecutors were treating as attempted causing of an explosive detonation and dangerous interference with air traffic. With the takeover, the Bundeskriminalamt became responsible for leading the police work.
An airport worker found a mobile-phone-controlled drone carrying about 600 grams of Semtex in a secure area near a Ukrainian Antonov cargo plane at Leipzig Airport. Investigators said the detonator was defective and the device did not explode; authorities also examined a second suspected drone-related incident involving a DHL cargo aircraft that landed with nose damage after striking an unknown object.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.