Germany’s Chancellor Friedrich Merz and several ministers have already stressed that while Germany is not at war with Russia, it is nonetheless under hybrid attack from Moscow.

ADVERTISEMENT


ADVERTISEMENT

This includes drone overflights, sabotage and disinformation, as well as a willingness “to act with growing ruthlessness, accepting serious damage to property and even injuries and deaths,” as Merz said at a press conference after the attempted drone attack on Leipzig/Halle airport.

It was the first time the government explicitly blamed Russia for the attempted attack.

Since Russia launched its full-scale invasion of Ukraine, there has been frequent talk of hybrid warfare against Kyiv’s partner countries, with Germany seen as particularly exposed.

Interior Minister Alexander Dobrindt has therefore raised the current threat level from “abstract” to “high”. Hybrid attacks are considered hard to detect because it is often unclear who is behind them and whether individual incidents are even connected.

There is growing concern about Russian hybrid actions against Germany, but Moscow is not the only state resorting to such methods. According to the Federal Office of Civil Protection and Disaster Assistance (BBK), China, Iran and North Korea are also targeting Germany with hybrid measures.

How to detect a hybrid campaign

However, “not every cyberattack, act of sabotage or attempt at disinformation is automatically part of a hybrid campaign,” security expert Ferdinand Gehringer told Euronews.

What matters, he says, is the identifiable link between different measures. This may involve “a common actor, coordinated timing, recurring targets or methods and, above all, a shared strategic objective.”

One example is the attempted drone strike on Leipzig/Halle airport. A drone fitted with explosives was discovered there in the immediate vicinity of Ukrainian Antonov cargo aircraft that also transport military equipment for Ukraine.

In his press statement, Dobrindt said they assumed that so-called “disposable agents” may have been involved on behalf of a Russian intelligence service. The pattern of the crime, the technology used and intelligence findings also led the federal government to conclude that Russia was behind the attack.

This, Gehringer says, is where the so-called overall situation assessment comes in. To judge whether individual incidents are part of the same operation, information from different areas has to be pooled, from the police, intelligence services, the Bundeswehr, cyber defence and the private sector, for example.

“Only by examining technical traces, crime patterns, timelines and disinformation narratives together can links be identified,” explains Gehringer.

How Germany is defending itself

Hybrid warfare often takes place below the threshold of open armed conflict. Its aim is to exploit a country’s vulnerabilities, erode trust in state institutions and unsettle and destabilise society.

But how can a country and its society prepare for and defend themselves against hybrid attacks or even hybrid warfare?

Rearming the Bundeswehr alone is no answer to suspected attacks, spying attempts or disinformation. Nor can hybrid attacks in most cases simply be repelled or countered by kinetic means. So how does a state respond to an attack that remains below the threshold of an armed assault?

The federal government has stepped up its precautions against hybrid threats since 2022. These include an interdepartmental task force dealing with disinformation and other hybrid threats. There are also procedures that can attribute cyberattacks and foreign information manipulation to a potential originator.

At EU level, the so-called “Hybrid Toolbox” provides a mechanism for joint responses.

Since this year, there has also been the Joint Centre for Countering Hybrid Threats (GAZ Hybrid). It is intended to bring together information on espionage, sabotage, disinformation and other hybrid threats, so that such activities can be detected early and tackled more effectively.

In the case of the attempted drone attack in Leipzig, the federal government responded “resolutely, calmly and proportionately”.

It announced measures such as the closure of the Russian consulate general in Bonn and the Russian House in Berlin, sanctioning further Russian individuals over hybrid attacks at EU level, tightening entry controls and stepping up pressure on Russia’s shadow fleet.

Public as part of defence

According to Gehringer, however, defence starts even before a campaign begins: “More generally, we need to move away from merely reacting and towards a more anticipatory approach. The goal must be to raise the costs for attackers, disrupt their planning paths, uncover networks as early as possible and also blunt the impact of attacks.”

If, for example, an attack on a substation caused a power cut, households and businesses could bridge the gap with emergency power until the grid operator repaired the damage.

In the best case, he says, preparation would eventually be so good that hybrid attacks could be headed off by identifying relevant activities at the planning stage and nipping them in the bud.

At the same time, the state and society need to be ready, in terms of communication, for possible attacks. That would not only limit damage but also rob hybrid operations of their intimidatory effect.

This can only be achieved through a combination of deterrence, defence and resilience, the security expert told Euronews.

According to Gehringer, the public “plays a very important role” here, but is “still being needlessly wrapped in cotton wool.”

“Yet it is part of the solution,” he adds, explaining that disinformation, for example, can never be fully prevented, nor should that be the aim, since an open society must always contend with manipulative information, in his view.

“Our goal must therefore be resilience rather than isolation”, says Gehringer. Citizens need to be able to assess information critically, the media must operate independently, and the state must communicate “quickly, credibly and transparently”, Gehringer explains.

Share.
Leave A Reply