Recent Incidents Renew Concern Over Vulnerability of European Aviation
Recent incidents in Britain, Germany and Moldova have renewed concern over the vulnerability of European aviation and critical infrastructure.
On 8 September 2026, Britain suffered one of its most serious recent air-traffic-control disruptions when a failure in the NATS flight-data processing system affected major airports including Heathrow, Gatwick, Manchester, Glasgow and Stansted. Around 2,000 flights were ultimately cancelled, hundreds more were delayed or diverted, and hundreds of thousands of passengers were affected. However, British authorities and NATS have explicitly said that the evidence so far indicates a technical failure, not a cyberattack. UK Transport Secretary Heidi Alexander ordered NATS to produce an investigation within a week, while the Civil Aviation Authority is conducting an independent review of the system’s resilience.
NATS Holdings, formerly National Air Traffic Services, is the main air navigation service provider in the United Kingdom, providing en-route air traffic control services to flights within the UK Flight Information Regions.
The financial consequences were substantial even though a final industry-wide figure has not yet been published. Reuters reported that the outage cost airlines millions of pounds, while the Financial Times estimated that Ryanair alone cancelled about 260 flights, putting roughly £2.6 million of revenue at risk, before additional expenditure on passenger care, hotels, food, rebooking and repositioning aircraft and crews. The incident also demonstrated how a failure lasting only hours can create disruption lasting several days across Europe's highly interconnected aviation system.
Explosive-Equipped Drone at Leipzig/Halle Airport in Germany
The British failure occurred against a very different but increasingly serious security background elsewhere in Europe. In Germany, an explosive-equipped drone was discovered at Leipzig/Halle Airport on 5 August 2026, forcing restrictions at the airport and triggering a counter-terrorism investigation. On 1 September, the German government formally attributed the operation to Russia, saying intelligence and police investigations indicated Russian state involvement. Chancellor Friedrich Merz subsequently said the operation had been prepared in Russia over several months and that a potentially serious disaster had been narrowly avoided. Moscow denies responsibility.
Germany has already announced concrete diplomatic consequences. Following its attribution of the Leipzig/Halle operation to Russia, Berlin announced the closure of the Russian consulate in Bonn, terminated a cultural agreement involving the Russian House in Berlin and said it would press for further European sanctions and restrictions connected with Russian hybrid activities. NATO publicly expressed solidarity with Germany, and NATO Secretary General Mark Rutte referred to the Leipzig incident as a Russian hybrid attack, placing it within a wider pattern of sabotage, cyber operations, electronic interference and attacks on infrastructure attributed to Russia and its proxies.
Hybrid warfare is a military strategy that blends conventional warfare, irregular warfare and cyberwarfare with other influencing methods, such as fake news, diplomacy, lawfare and foreign electoral intervention.
Zelenskyy’s Departure from Moldova Disrupted by Airspace Closure
Another serious aviation-related incident occurred during President Volodymyr Zelenskyy’s departure from Moldova on 8 September. Contrary to some reports circulating online, he was travelling from Moldova to Norway, not to Poland. Moldovan airspace was temporarily closed after Russian drones entered the country’s airspace; one crashed and caused fires, while another continued towards Romania. Zelenskyy’s departure was delayed, together with other civilian flights. Norwegian Prime Minister Jonas Gahr Støre later said Zelenskyy’s aircraft had come close to being struck during the incident, although the available evidence does not establish that his aircraft was the deliberate target of a Russian attack. Russia denies that there was a threat to the Ukrainian president’s plane.
NATO and EU Respond to Escalating Hybrid Threats
These events are occurring within a much broader pattern documented by NATO and the European Union. NATO says Russia and its proxies have increasingly used cyberattacks, sabotage, electronic interference, disinformation, airspace violations and other hybrid operations against Allied countries and critical infrastructure. In July 2026, the North Atlantic Council formally condemned Russia’s persistent malicious cyber activity and announced further strengthening of NATO’s cyber posture. NATO has also reinforced air and missile defence and intelligence-sharing along its eastern flank as Russian drones and missiles have increasingly crossed or approached Allied airspace.
The European Union is increasingly attempting to impose direct financial costs on those involved. On 13 July 2026, the EU sanctioned nine Russian individuals and four entities associated with cyberattacks and Russia’s wider cyber ecosystem. The broader EU regime addressing Russian hybrid activities currently covers dozens of individuals and organisations and provides for asset freezes, travel bans and prohibitions on providing funds or economic resources. Separate EU cyber sanctions have been extended until May 2027.
The most serious potential consequence is contained in NATO’s collective-defence doctrine. NATO states explicitly that a sufficiently severe cyber or hybrid attack can, on a case-by-case basis, reach the threshold of an “armed attack” and potentially lead to Article 5 consultations and collective defence. No such decision has been taken over the recent aviation incidents, and attribution and proportionality remain essential before any collective response. Nevertheless, the policy is deliberately designed to warn an adversary that hybrid operations do not provide unlimited protection from consequences simply because they remain below the traditional image of conventional warfare.
Article 5 is the cornerstone of the North Atlantic Treaty Organization (NATO) and states that if a NATO Ally is the victim of an armed attack, each and every other member of the Alliance will consider this act of violence as an armed attack against all members and will take the actions it deems necessary to assist the Ally attacked.
The central conclusion is therefore more precise than saying that Russia “hacked British and German aviation on 8 September”. Britain experienced a major technical aviation-system failure that has so far been ruled non-cyber; Germany has separately attributed a potentially lethal airport drone operation to Russia; and Russian drones disrupted Moldovan airspace during Zelenskyy’s departure. Taken together with cyberattacks, sabotage investigations and repeated airspace violations elsewhere in Europe, these incidents explain why NATO now describes Russian hybrid activity as an increasingly serious security threat and why European governments are moving towards stronger sanctions, infrastructure protection, cyber defence and military deterrence.
We think you might also like these articles:Stefaniia Didenko: The "Glocal" Security Nexus
A failure in the NATS flight-data processing system affected major airports
80th UN General Assembly - 100% NEWS