Reporting
European Nations Probe Late August Wave of Suspected Russian Sabotage and Cyberattacks

OSLO — European security and cyber defense agencies are investigating a series of suspected Russian-linked sabotage operations, culminating in a massive cyberattack on Norway's public services and the discovery of military-grade explosives near Germany's Leipzig Airport in late August 2026.
On August 24, 2026, Norway's Digitalization Agency (Digdir) suffered its largest-ever distributed denial-of-service (DDoS) attack, which disrupted key public portals including ID-porten, MinID, and Altinn, as reported by The Record. The pro-Russian hacktivist group "Server Killers" claimed responsibility for the disruption, explicitly citing retaliation for Norway's August 23 pledge of €7.8 billion ($9.2 billion USD) in aid to Ukraine, according to the Associated Press. Digdir officials noted that the attack failed to knock most public services offline, and portals remained operational practically all the time, according to BleepingComputer.
Meanwhile, in Germany, investigators discovered a third drone and residues of the military-grade explosive hexogen on August 14 near Leipzig/Halle Airport, a key NATO logistics hub, as reported by The Guardian. U.S. intelligence officials, working with German security services, linked the explosive-laden drone to Russia's military intelligence agency (GRU), citing design and explosive signatures typical of GRU operations, according to the Kyiv Independent. However, German federal prosecutors have not officially commented on the findings or confirmed the state-level link, as noted by Wikipedia's record of the incident.
These incidents follow other high-profile security events across the continent. On August 20, Poland's Internal Security Agency announced the Warsaw arrest of a 63-year-old Ukrainian citizen recruited by the Russian FSB who allegedly planted a car bomb under the vehicle of a Ukrainian defense official before fleeing to Poland, according to Meduza. Additionally, on August 15, an arson attack targeted a Tallinn facility used by military robotics manufacturer Milrem Robotics, as reported by Bloomberg. Three Latvian suspects were detained by Latvian authorities, though Estonian Prime Minister Kristen Michal cautioned that Russian state sabotage remains only "one version being checked," according to Latvian Public Media.
In Slovakia, authorities foiled an arson plot on August 25 targeting the Ukrainian-owned Skyeton drone factory, detaining Latvian and Ukrainian nationals who claimed to belong to an independent "peace movement," according to The New Voice of Ukraine.
Security analysts and European officials warn that Moscow is increasingly relying on low-level, disposable proxy networks—recruiting local criminals, third-country nationals, or hacktivists—to execute hostile acts while maintaining plausible deniability, as reported by Radio Free Europe/Radio Liberty. This strategy allows Russia to conduct hybrid warfare just below the threshold required to trigger NATO's Article 5 collective defense clause, according to Euromaidan Press.
While Western intelligence agencies point to a coordinated campaign, individual European governments are exercising legal restraint, refusing to make formal state-level attributions while active police investigations are ongoing.
Extradition proceedings are currently underway in Poland for the suspected FSB-recruited car bomber, as reported by the Kyiv Independent. Meanwhile, German federal investigators continue their forensic analysis of the Leipzig drone wreckage, according to RANE Worldview.