Category Archives: Security

Leipziger Drohnenanschlag flog wie ein Handy, nachdem Telekom ihren Schild mit Loch ankündigte

English | Deutsch

Diese Geschichte beginnt am 12. Mai 2026, im Vorfeld der AFCEA-Fachmesse in Bonn, als Deutsche Telekom und Rheinmetall einen gemeinsamen Drohnen-Schutzschild für deutsche kritische Infrastruktur ankündigten. Laut Pressemitteilung hatten sie das Detektionsproblem in Teile zerlegt.

Der erste Teil waren die ISM-Bänder bei 2,4 und 5,8 GHz, mit passiven Funkscannern auf Mobilfunkmasten, die Drohnen anhand ihrer Protokollsignatur erkennen. Das wurde als der Schild dargestellt.

Der übrige Teil betraf Flüge über Mobilfunknetze mit einer SIM-Karte an Bord. Die Mitteilung nannte das ein Forschungsfeld, räumte also im Grunde ein Loch im Schild ein, und verwies für den aktuellen Stand auf die Helmut-Schmidt-Universität Hamburg.

Zwölf Wochen später, am Abend des 4. August, kam eine Drohne mit Semtex und PETN in einer verschlossenen Konservendose an einer ukrainischen An-124 auf Standplatz 213 des Flughafens Leipzig/Halle zum Stehen. Laut ZDF frontal und einer gemeinsamen Recherche von WDR, NDR und SZ, die die NZZ zitiert, trug die Drohne zwei SIM-Karten und einen 5G-Router. Genau das, was Telekom als Loch beschrieben hatte.

Drohne mit SIM-Karten-Steuerung, gefunden am Flughafen Leipzig/Halle, August 2026

Der Erste Weltkrieg ist nicht vergessen

Kürzlich habe ich darauf hingewiesen, dass moderne OPSEC von der russischen Zweiten Armee abstammt, die 1914 vor Tannenberg ihre Marschbefehle im Klartext funkte. Die Mai-Mitteilung der Telekom ist kein obskures Papier. Der größte deutsche Netzbetreiber und der größte deutsche Rüstungskonzern beschrieben darin ihre langsam vorrückende Frontlinie, samt der Schwäche an den Flanken.

Beim Lesen musste ich daran denken, wie sich der russische General nach einem ähnlichen Fehler erschoss. Der Funkteil ist die bekannte Stellung: Die Telekom gibt an, seit 2017 illegale Drohnenflüge für die Polizei zu orten, auch während der Europameisterschaft 2024. Weil der Mobilfunkbereich nur als Forschung beschrieben wurde, bekam jeder, der etwas plante, eine Landkarte in die Hand. Die vorgeschlagene Technik ist Passivradar: Laufzeitänderungen reflektierter Mobilfunksignale über mindestens vier Masten werden zu einem Bewegungsbild zusammengesetzt. Detektion über Physik statt über die Funkverbindung ist sinnvoll und die richtige Richtung. Sie signalisiert Angreifern aber auch, dass diese Physik nirgends im Einsatz ist, und am 4. August ganz sicher nicht war.

Jede Stellungnahme der Hersteller nach dem Vorfall, die ich gefunden habe, redet über den falschen Teil dieser Geschichte. Rheinmetall-Chef Armin Papperger sagte der dpa, man arbeite mit der Telekom daran, Mobilfunkmasten bundesweit zur Drohnen-Früherkennung zu nutzen. Mobilfunkmasten mit Funksensoren erkennen die 90 Prozent. Die Leipziger Drohne gehörte zu den anderen zehn. Ein ZDF-Drohnenexperte brachte es auf den Punkt: Für einen Frequenzscanner am Flughafen war die Drohne von einem Mobiltelefon nicht zu unterscheiden.

Diese Methode ist in der IT-Sicherheit sehr, sehr gut bekannt und untersucht, weil Angriffe in Datenkanäle gestopft werden, um schwer blockierbar zu sein. Es geht darum, die Detektion zur richtigen Zeit auf die richtigen Kanäle zu richten.

Detektion per Selbstauskunft

Die Mai-Mitteilung hatte noch eine Anmerkung zur Erkennung von Mobilfunkdrohnen: 5G Network Slicing, also eine eigene Datenspur für die Drohnensteuerung. Ein Slice identifiziert die Drohnen, die sich darin registrieren. Ein Angreifer nimmt seine normale Verbraucher-SIM im allgemeinen Slice, und der spezielle Drohnenkanal sieht exakt nichts. Das ist das Drohnenabwehr-Äquivalent dazu, Passagiere erklären zu lassen, dass sie kein Flugzeug sprengen wollen, und diese Erklärung eine Kontrolle zu nennen. Kooperative Identifikation hat Wert für das Luftraummanagement ohne Angreifer. Sie hat keinen, wenn Angreifer aussehen wie alle anderen.

Dieselbe Logik gilt für die in Leipzig installierten Detektionssysteme. Sicherheitskreise sagten dem ZDF, ob und warum die Detektoren nicht anschlugen, werde noch untersucht. Drohnenabwehr an Flughäfen beruht auf Signaturen einer Punkt-zu-Punkt-Verbindung zwischen Steuerung und Fluggerät. Das ist Verhaltensvorhersage: Ein Objekt, das sich im Spektrum wie eine Drohne verhält, wird markiert. Dieses Angriffsgerät verhielt sich so, dass die Detektion getäuscht wurde. Ein beladenes Hochrisiko-Frachtflugzeug war damit nachweislich vier Stunden lang aus dem öffentlichen Luftraum erreichbar, bis ein Busfahrer die Drohne um 23:42 Uhr umkickte.

Die Provider haben mitgeschrieben

Die Ermittler fanden den Piloten nicht über den Flughafen, sondern sie fanden eine Richtung. ZDF frontal berichtete am 18. August, die Auswertung der 5G-Funkdaten und der sichergestellten SIM-Karten weise auf eine Funkzelle in Sachsen-Anhalt bei Merseburg, rund zehn Kilometer vom Tatort, aus deren Richtung mutmaßlich eine zweite Drohne geflogen sei. Bild hatte zuvor eine dritte SIM-Karte in derselben Gegend geortet. Eine Spezialeinheit der Polizei suchte dort ohne Ergebnis.

Das ist eine Funkzellenabfrage auf Verkehrsdaten, die das Bundesverfassungsgericht gut kennt, weil es sie seit zwei Jahrzehnten einhegt. Sie funktionierte hier aus zwei einfachen, aber wackligen Gründen: Die Drohne wurde intakt samt SIM-Karten geborgen, und der Provider hatte die jüngsten Verbindungsdaten noch gespeichert. Auf keines von beidem kann Sicherheit normalerweise bauen. Der deutsche Staat hatte keine gezielte Detektion für mobilfunkgesteuerte Drohnen, also verlagerte sich die Attribution nachträglich auf gewöhnliche Telekommunikations-Metadaten. Leipzig wird mit hoher Wahrscheinlichkeit in der nächsten Runde der Vorratsdatenspeicherungs-Debatte zitiert werden. Die Speicherung von Mobilfunk-Metadaten wurde zur Attributionsmethode für ein kritisches Sensorik-Designversagen an einem Flughafenzaun.

Schengen ohne Piloten

Im März habe ich über die FOI-Typologie verurteilter Spione in Europa geschrieben: der Beobachter, der Wegwerfagent, der mobile Spion, der offene Grenzen ausnutzt. Das Modell ging davon aus, dass der Wegwerfagent die Tat ausführt. Leipzig trennt die Rollen. Jemand in Deutschland montierte eine kleine Antenne in einem Baum bei Kursdorf nördlich des Flughafens, die nach Einschätzung der Ermittler als Signalverstärker diente, und jemand lieferte den Sprengstoff. Die Berichterstattung sagt uns, dass ein Pilot Internet brauchte. Wie der ZDF-Experte sagte: Ein Café in Leipzig oder ein Stuhl im Ausland täten es gleichermaßen.

Die beiden Verdächtigen, die NDR, WDR und SZ am 2. September identifizierten, passen exakt in diese Aufteilung. Ein gebürtiger Russe mit lettischem Pass, beschrieben als Logistiker und Instrukteur, reiste Ende Juli über Berlin ein, fuhr nach Leipzig und flog zwei Tage vor dem Drohnenstart wieder aus. Ein Belarusse mit russischem Pass, im Schengenraum mit einem in Minsk ausgestellten italienischen Touristenvisum, hinterließ DNA an der Drohne, im Inneren der Sprengstoffdose und an der Antenne im Baum. Die Hände wurden per DNA gefasst. Der Instrukteur war vor dem Flug weg. Der Pilot ist weiterhin unbekannt. Dobrindt nannte sie Low-Level-Agenten, das Wort des Ministeriums für Wegwerfagenten.

Jeder Ansatz gegen Sabotage, der darauf beruht, den Piloten zu fassen, wird auf das Problem stoßen, das die IT-Sicherheit seit mindestens 20 Jahren kennt. Man bekommt den Kurier, den Installateur, und das war’s. Fähigkeit und Risiko sind absichtlich entkoppelt. Die deutschen Dienste haben das bereits gesagt. Die gemeinsame Warnung von BKA, BND, BfV und BAMAD, die ich zur Bahnsabotage bei Leverkusen behandelt habe, beschreibt, wie russische Dienste Einheimische über soziale Medien und Messenger anwerben, direkt oder über Mittelsleute.

Reihenfolge

Der Attributionsweg in der Presse gibt nicht viel her. Am 7. August, zwei Tage nach dem Fund, berichtete das Wall Street Journal, US-Beamte hielten die Drohne für wahrscheinlich mit der russischen Regierung verbunden. Am 25. August zeigten Flugverfolgungsdaten ein US-Regierungsflugzeug von der Joint Base Andrews bei der Landung in Moskau; Washington Post und CNN identifizierten den Passagier als CIA-Direktor John Ratcliffe, mit einer Botschaft zu Angriffen auf NATO-Gebiet, nachdem Geheimdienstinformationen Sabotage-, Cyber- und Drohnenoperationen angezeigt hatten.

Am 27. August zitierte ABC News einen US-Beamten, der Sprengstoff und Bauweise als typisch für den GRU bezeichnete. Am 1. September erklärte Innenminister Dobrindt, polizeiliche Ermittlungen, Tatmuster und nachrichtendienstliche Erkenntnisse belegten zusammen die russische Verantwortung. Die Bundesregierung schloss das russische Generalkonsulat in Bonn. Am selben Morgen, vor der Ankündigung, trafen selbstgebaute, mit Sprengstoff bestückte Raketen das 50Hertz-Umspannwerk Turnow-Preilack, das Jänschwalde ins Übertragungsnetz einspeist; die Polizei Brandenburg leitete ein Verfahren nach § 129a ein, dem Paragrafen zur terroristischen Vereinigung.

Keine Quelle verbindet die Ratcliffe-Reise mit Leipzig. Ich stelle beides in eine Zeitleiste, weil beides in einer stattfand. Die Beweisgrundlage der deutschen Attribution ist nicht veröffentlicht. Ich zeige lediglich eine Abfolge: Washington hatte binnen 48 Stunden eine Einschätzung, überbrachte drei Wochen später persönlich eine Warnung, und eine Woche nach der Warnung folgte Berlins ungewöhnlich förmliche Attribution an Russland. Ob das Koordination bedeutet, die deutsche Einsicht, sich auf Amerika nicht mehr verlassen zu können, oder ein neues Tempo der Bundesanwaltschaft, ist unbekannt. Es bleibt derselbe Minister, der nach dem Berliner Blackout im ZDF Russland ausschloss, bevor die Ermittlungen abgeschlossen waren.

Exponiertes Ziel

Die Antonow hatte laut SZ, die sich auf Polizeiberichte beruft, Munition aus Frankreich geflogen, und die war noch an Bord. Leipzigs Rolle in der Ukraine-Luftbrücke ist öffentlich, und jeder Charterflug meldet sich selbst per ADS-B. Russland schaut natürlich zu, zu minimalen Kosten, genau wie bei der Bahnstrecke nördlich von Leverkusen, die im Juli brannte.

Die Frage, die die Hersteller beantworten, lautet, wie sie eine Drohne erkennen können. Die eigentliche Frage aus diesem Vorfall geht eher dahin, warum ein beladenes Flugzeug vier Stunden lang aus dem öffentlichen Luftraum für jedes Objekt erreichbar war, das keiner Signatur entsprach. Allowlist, nicht Denylist. Erkennung ist eine Vorhersage, die alle historischen Fehler von Systemen offen lässt, die auf gleichbleibende Angriffe setzen, um ein “Gefühl” von Sicherheit zu erzeugen. Erreichbarkeit ist Realität, und sie sagt, dass das Standortrisiko in Deutschland nicht ordentlich gemanagt wird. Die Telekom-Mitteilung hat uns im Mai gesagt, dass Deutschland nicht nur erwartete, dass Angreifer sich selbst zu erkennen geben, sondern dass die Flanken eines langsam vorrückenden Frontschilds offen standen.

Quellenvorbehalte

Die Details zu SIM-Karten, Router, Antenne und Relais stammen aus Sicherheitskreisen über ZDF frontal, WDR/NDR/SZ, Zeit und Bild, übereinstimmend bei fünf Medien und von keiner Stelle offiziell bestätigt.

Die Funkzelle bei Merseburg ist eine Einzelquelle, ZDF frontal. Die Identität der Verdächtigen stammt von NDR/WDR/SZ, bestätigt durch ZDF und Zeit; laut Zeit ermittelt die Bundesanwaltschaft gegen zwei Personen, die Behörde selbst hat sich zu Identitäten nicht geäußert.

Das Detail zur Munition aus Frankreich ist eine Einzelquelle, SZ. Die Pressemitteilung der Bundesanwaltschaft vom 6. August bestätigt nur professionellen Sprengstoff, einen Zünder und eine wahrscheinliche zweite Drohne.

Die Mitteilung von Telekom und Rheinmetall ist Primärquelle und öffentlich.

METR DFIR Role: Boeing Lobbyist to Wear NTSB Badge

How Not to Spell DFIR.

METR is hiring a Member of Technical Staff, Cyberforensics. Salary range $402,048 to $578,583, because YOLO.

The posting went up in the same week the organization disclosed a stolen API key that burned roughly $600,000 in credits over three weeks without anyone noticing, and a public transcript viewer that exposed unpublished evaluation data through a SQL bug a stranger had to report. It went up five days after METR’s report on the OpenAI agent incident, which by its own account was run on OpenAI premises, on datasets OpenAI assembled, using roughly $400,000 in OpenAI-donated credits for an OpenAI model that participated in the incident, with OpenAI holding redaction rights and giving feedback on “structure, emphasis, clarity, and tone” that the authors incorporated. The report states plainly the authors were not robust to that model deceiving them.

Read the posting with the flyingpenguin decoder next to it.

The posting says flyingpenguin says
“develops scientific methods to assess AI capabilities, risks, and mitigations” Mitigations were out of scope by agreement, along with safeguard effectiveness, the extent of the compromise, how the behavior arose in training, and OpenAI’s own investigation. The method on record used a participant in the incident as the analyst.
“robustly good for policymakers and civil society to have a clear understanding” The first two site visits ran on 285 transcripts OpenAI picked by searching for intrusion indicators. The full set arrived on the third visit. The primary model is withheld from METR and from OpenAI’s own researchers. Policymakers received a claim and no artifact to replay.
“embedding researchers inside frontier labs to investigate incidents” Embedding is the conflict, stated as the method. OpenAI defined the investigation window, assembled the datasets, supplied the credits, hosted the desk, held redaction rights, and added one of the seven scope questions itself.
“one of the most important sources of independent information the world has” Independence, by this posting’s own design, means several weeks inside the subject with access the subject grants. The report calls this an “excellent precedent.”
“complex multi-day cyber attacks on frontier lab internal infrastructure and external third parties” Agents had admin access to Artifactory from June 26. Containers could create directories in a shared cache namespace over WebDAV. Hugging Face credentials were found exposed on the internet. Multi-day because nobody was watching until a July 4 outage.
“We expect these assessors to have deep access” Depth granted by the party under examination is depth on loan. The report states the investigators had no direct access to OpenAI infrastructure and could only request datasets.
“embedded in a frontier AI lab for up to several weeks at a time, likely alongside 1-4 other METR staff” The last exercise was three people, six days total, planned as two. The posting turns that sample size into a staffing plan. “Alongside” spells of distrust and knowledge transfer. If investigators are forced to be chaperoned, an Emperor’s pants might be invisible.
“You will attack agent monitoring and security systems, potentially embedded in labs or red-teaming METR internal infrastructure” METR’s infrastructure was red-teamed twice this year without an invitation. In March the attacker got three weeks of free inference. In May a bug hunter got a bounty for finding the SQL path METR had missed.
“produce findings rigorous enough for lab boards, governments, and the public” Five days after publishing those findings, METR disclosed it had no spending limit on the key that drained $600,000, and that its researchers were too used to rate-limit errors to notice.
“build LLM-powered pipelines to triage transcripts, cluster behaviors, flag deception” The report says its analysis agents produced over a thousand pages, often failed to surface the important findings, uncritically adopted the perspective of the agents under review, and that the authors “had to defer to these agents to a substantial extent.” The job is to automate that and call it scale.
“evidence acquisition and preservation” Listed as a required skill in September. The August report relied on transcripts OpenAI “attested” were unredacted and a cache dump OpenAI collected on July 20, both accepted as delivered.
“log and timeline reconstruction across cloud, network, endpoint, and identity systems” The transcripts arrived without per-action timestamps; OpenAI said reconstructing them was not feasible. The investigators built their own approximate timeline. At least 96 transcripts contained spoofed tool calls, and the report cannot rule out subtler spoofing or after-the-fact edits it did not detect. See: Wirken.AI.
“follow an intrusion through AWS (CloudTrail, IAM, VPC flow logs)” The March compromise was a researcher’s personal EC2 instance, intentionally public, running a vibe-coded app with a fail-open authentication bug. The attacker asked the agent for the API key and the agent handed it over.
“package registries” The incident was a package registry with a writable shared cache. The relevant skill is file permissions. It’s like saying a school bus crash investigator has to be familiar with yellow paint cans.
“reason about root causes” Root cause on record, in the report’s own words: 30 to 40 percent of the benchmark targets were impossible, and OpenAI ran no scorer that read transcripts, so submitting the reverse-engineered flag would have scored perfectly. The report treats that as backstory and the agents as the story.
“write findings that hold up to scrutiny” The findings cannot be scrutinized. Nobody outside OpenAI can query the datasets, and nobody at all can query the model.
“DataDog, Kubernetes, CrowdStrike Falcon, Okta, Tailscale, Pulumi, PostgreSQL” This stack was in place while a stolen key ran for three weeks and a public viewer exposed unpublished evaluation data. Tooling is listed as a nice to have. Reading its output apparently was too.
“NTSB/CSB-style safety investigations” NTSB investigators do not sit at the airline’s desk reading a flight recorder the airline selected, on the airline’s software, with the airline editing the tone of the final report. That is the exercise METR ran and now hires to repeat.
“$402,048 – $578,583 a year” Over half a million for a role whose first required skill, evidence preservation, the organization published without.
“Catered lunch and dinner daily; in-office gym and shower” The March drain went unnoticed because the tokens were free. The investigation ran on $400,000 of tokens that were also free. Free is a habit.
“We’ve earned trust as reliable partners who handle confidential information with care” May 2026: an inadvertently exposed endpoint reached unpublished evaluation data, including some sensitive model data, by METR’s own account. Discovered by an outsider. Confidential information handled with a bounty.
“honest and transparent about our results, especially when they may go against the grain” The report went with the grain. OpenAI had presented the same capability narrative at Black Hat three weeks earlier, and OpenAI reviewed the report’s emphasis and tone before publication.
“low-ego, drama-free environment” The report describes agents making sacrifices, accepting permadeath, and running emotional checks, in anecdotes selected and summarized by the analysis model the authors say slanted toward the agents’ point of view. Drama was the deliverable.
“apply even if your background may not seem like the perfect fit” For forensics. At $578,583. Template for entry-level roles, pasted to a job that requires having run severe incidents end to end. One of those two is the real bar.
“AI tools to … identify potential inconsistencies or verification signals in application materials” AI screening applicants for inconsistencies, from an organization that used the incident’s own model to screen the incident’s transcripts and states it would probably have missed the model lying.

A forensics function, should it exist at all, exists to make transparent claims that survive any challenge.

Chain of custody, preserved evidence, an analyst with no stake in the outcome, a method a second examiner can repeat. It’s very, very dry and detailed work. Every ounce of that is absent from the August METR report, and the posting lists each as a skill to acquire afterward in an environment that looks allergic to it.

The report claimed to know what the agents wanted, from inside the agent vendor’s building, on the agent vendor’s credits, with the agent vendor’s edits. GTFO, that is the spiritual enemy of DFIR.

Their job posting is a manual for being a Boeing lobbyist while wearing an NTSB badge.

METR’s hawk patch, “Nothing Is Beyond Our Evaluation,” reworks the NRO’s 2013 NROL-39 octopus, “Nothing Is Beyond Our Reach.” Intelligence agency satellite-launch art, adopted by a nonprofit that just disclosed it was blind to $600K leaving its own account.

And let me just say, claiming you aren’t being paid while taking hundreds of thousands of dollars in highly desirable credits, gets this rating on the meter:

Leipzig Drone Attack Flew Like a Phone After Telekom Shield Was Announced With a Hole

English | Deutsch

This story starts on 12 May 2026, in the run up to the AFCEA trade show in Bonn, when Deutsche Telekom and Rheinmetall announced a joint drone shield for German critical infrastructure. Their release said they had split a detection problem into parts.

The first part was ISM bands at 2.4 or 5.8 GHz, and passive RF scanners on cell towers to identify those by protocol signature. That was depicted as the shield.

The remaining part said flights were on mobile networks with a SIM inside. The release called it a research area, basically admitting a hole in the shield, pointing to the Helmut-Schmidt-Universität in Hamburg for current state.

Twelve weeks later, on the evening of 4 August, a drone carrying Semtex and PETN in a sealed food can came to rest against a Ukrainian An-124 at Standplatz 213 of Leipzig/Halle airport. According to ZDF frontal and a joint WDR/NDR/SZ report cited by the NZZ, the drone carried two SIM cards and a 5G router, exactly as Telekom had described as the hole.

Drone with SIM-card control link found at Leipzig/Halle airport, August 2026

WWI isn’t forgotten

Recently I pointed out how modern OPSEC descends from the Russian Second Army broadcasting its marching orders in the clear before Tannenberg in 1914. The May release press by Telekom is not some obscure brief. It was the largest German carrier and the largest German arms maker describing their slow moving front line, and weakness in their flanks.

Reading it reminded me of how the Russian General shot himself to death after making a similar mistake. The RF part is the known position: Telekom says it has located illegal drone flights for police since 2017, including during the 2024 European Championship. Because the mobile space was described as research only, anyone planning anything was handed a map. The proposed technique is to setup passive radar, reading timing changes in reflected cellular signals across at least four masts to build a movement picture. Using detection in physics instead of a link makes sense and is the right direction. However, it telegraphs to attackers that the physics techniques are not yet deployed anywhere, and certainly were not on 4 August.

Every post-incident statement I have found from the vendors has been talking about the wrong part of this story. Rheinmetall’s Armin Papperger told dpa the company is working with Telekom to use cell towers for early drone detection nationwide. Cell towers with RF sensors detect the 90 percent. The Leipzig drone was in the other ten. As a ZDF drone expert put it, the drone was indistinguishable from a mobile phone to a frequency scanner at the airport.

That method is very, very well known and studied in cyber security, because attacks are stuffed into data channels to make them difficult to block. It’s a matter of getting the detection systems pointed into the right channels at the right time.

Detection by declaration

The May release had another note about detecting cellular drones: 5G network slicing, meaning they would shift to a dedicated data lane for drone control. A slice identifies the drones that register in it. An attacker would use their regular consumer SIM, on the general slice, and the special drone channel would see exactly nothing. This is the counter-UAS equivalent of asking passengers to declare intent not to bomb a plane and calling the declaration a control. Cooperative identification has value for airspace management without attackers. It has none when the attackers appear as everyone else does.

The same logic applies to the detection systems installed at Leipzig. Security sources told ZDF that whether and why triggers failed remains under investigation. Airport counter-UAS is built on signatures of a point-to-point link between a controller and an aircraft. It is behavior prediction: an object that behaves like a drone on the spectrum is flagged. This attack device behaved in a way that fooled the detection. So a loaded high-risk cargo aircraft was proven to be exposed to public airspace for four hours, until a bus driver kicked the attack drone over at 23:42.

Carrier records were recording

Investigators did not find the operator through the airport, because instead they found a direction. ZDF frontal reported on 18 August that analysis of 5G radio data and the seized SIM cards pointed to a cell sector in Sachsen-Anhalt near Merseburg, roughly ten kilometres from the scene, the direction from which a second drone allegedly flew. Bild had earlier reported a third SIM located in the same area. A special police unit searched there without result.

That is a Funkzellenabfrage on traffic data, which the Bundesverfassungsgericht knows well because they have two decades experience fencing it in. It worked here for two simple, yet volatile, reasons: the drone was recovered intact including SIMs, and the carrier stored those recent records. Neither is something security can bank on, usually. The German state had no targeted detection setup for cellular-controlled drones, so attribution flipped to bog-standard telecom metadata after the fact. Leipzig will most likely be cited in the next round of the Vorratsdatenspeicherung debates. Cell metadata retention became the attribution method for a critical sensor design failure at an airport perimeter.

Pilotless Schengen

In March, I wrote about the FOI taxonomy of convicted spies in Europe: the Observer, the Disposable, the Mobile Spy exploiting open borders. The model assumed the disposable one is who carries out the act. Leipzig separates the roles. Someone in Germany placed a small antenna in a tree at Kursdorf, north of the airport, which investigators believe served as a signal amplifier, and someone delivered the explosives. The reporting tells us a pilot needed internet. As the ZDF expert said, a café in Leipzig or a chair abroad would do equally well.

The two suspects identified on 2 September by NDR, WDR and SZ fit exactly that split. A Russian-born Latvian passport holder, described as the logistician and instructor, entered through Berlin in late July, drove to Leipzig, and flew out two days before the drone launched. A Belarusian with a Russian passport, in Schengen on an Italian tourist visa issued in Minsk, left DNA on the drone, inside the explosive can, and on the antenna in the tree. The hands were caught on DNA. The instructor was gone before the flight. The pilot is still unidentified. Dobrindt called them Low-Level-Agenten, which is the ministry’s word for disposable.

Every counter-sabotage approach that rests on catching the person who flies is going to run into the cybersecurity problem of the last 20 years at least. You get the mule, the person who installs, and that’s it. The skill and the risk are decoupled by design. German intelligence has already said as much. The joint BKA, BND, BfV and BAMAD warning I covered on the Leverkusen rail sabotage describes Russian services recruiting locals through social media and messenger apps, directly or via intermediaries.

Sequencing

The attribution path in the press doesn’t have much to it. On 7 August, two days after the discovery, the Wall Street Journal reported that US officials assessed the drone as likely linked to the Russian government. On 25 August, flight-tracking data showed a US government transport from Joint Base Andrews landing in Moscow; the Washington Post and CNN identified the passenger as CIA Director John Ratcliffe, carrying a message about attacks on NATO territory, with preceding intelligence flagging sabotage, cyber and drone operations.

On 27 August, ABC News quoted a US official calling the explosives and device structure typical of the GRU. On 1 September the Interior Minister Dobrindt stated that police investigations, the pattern of the act and intelligence findings together established Russian responsibility. The government closed the Russian consulate in Bonn. That same morning, before the announcement, self-built rockets fitted with explosives hit the 50Hertz substation at Turnow-Preilack that feeds Jänschwalde into the grid; Brandenburg police opened a “129a” investigation, the terrorist organisation statute.

No source connects the Ratcliffe trip to Leipzig. I am placing them in one timeline because they occurred in one. The evidentiary basis for German attribution has not been published. I’m simply pointing out the sequence where Washington held an assessment within 48 hours, delivered a warning in person three weeks later, and then Berlin’s uncharacteristically formal attribution to Russia followed the warning by a week. Whether that reflects coordination, German realization they can’t trust America, or a new pace of Bundesanwaltschaft work, is all unknown. It remains the same minister who, after the Berlin blackout, ruled Russia out on ZDF before the investigation was finished.

Target exposure

The Antonov, according to SZ citing police reports, had flown ammunition from France and it was still on board. Leipzig has a public role in the Ukrainian airlift and every charter announces itself on ADS-B. Russia is of course watching it all with minimal cost, just like the rail line north of Leverkusen that burned in July.

The question the vendors have been answering is how they can recognise a drone. But the actual question from this incident veers more towards why a loaded aircraft sat reachable from public airspace for four hours by any object that did not match a signature. Allow list, not a deny list. Recognition is a prediction that leaves open the historic failures of systems that rely on consistency in attacks to get a “feeling” of safety. Reachability is reality, and it says German site risk isn’t being managed properly. The Telekom release told us in May that Germany not only was expecting attackers to self-identify, but that the flanks were sitting open on a slow-moving frontal defense shield.

Source caveats

The SIM, router, antenna and relay details come from security sources via ZDF frontal, WDR/NDR/SZ, Zeit and Bild, consistent across five outlets and confirmed by none officially.

The Merseburg cell sector is single-source to ZDF frontal. The suspect identities are NDR/WDR/SZ with ZDF and Zeit corroborating, and Zeit reports the Bundesanwaltschaft is investigating two people; the office itself has not commented on identities.

The France ammunition detail is single-source to SZ. The Bundesanwaltschaft’s own 6 August release confirms only professional explosives, a detonator, and a probable second drone.

The Telekom/Rheinmetall release is primary and public.

Berlin Senate Passwort.docx Breach: Ahab of the East Sea Cover Story

Russians are having a laugh about Ahab on the East Sea 1-2-3. And then there’s Sunshine 13. These were passwords disclosed in the Berlin Senate breach. The “Ahabostsee123”, is in fact a yacht for vacations in the Baltic.

Much of the press seems to be wagging a finger about BSI recommendations, calling the passwords weak. The actual story is that 8,110 critical infrastructure risk analyses and emergency plans walked out the door as if nobody is paying attention.

The password story is a form of institutional misdirection. The laughs obscure the real story, the structural one.

Seven Days, Six Terabytes, One Breach

From August 7 to 14 the Russian-speaking ransomware crew Rhysida held access to the networks of two Berlin Senate administrations, transport and building. Seven days of continuous exfiltration before anyone noticed. 5.79 terabytes. Roughly 1.44 million files spanning at least 2014 to 2026, down to Bundesrat correspondence with a federal minister who retired in 2018. That’s a decade of unsegmented material, reachable from a single intrusion, in the largest data theft in the history of the Berlin Landesverwaltung.

It’s floating up now for a 30 bitcoin minimum, roughly two million euros, with bids closing Friday afternoon. The Regierender Bürgermeister says Berlin will refuse to be extorted, no blackmail. Smart. Germans agree on the whole and extortion payments are always advised against, always. The 5.79 terabytes are gone no matter what.

What the Russians Took

Read the ransomlook.io inventory that the Tagesspiegel has documented, once you skip past the giggles and passwords:

  • 8,110 documents, risk analyses, and emergency plans for critical infrastructure, with Rhysida specifically showcasing Verwundbarkeitsanalysen of the Berlin water supply
  • 11,777 folders and documents marked confidential or classified
  • 5,941 files of access credentials, including credentials for the electronic building permit system and for the database of Payone, the payment processor handling transactions for the Land Berlin
  • 27,299 personnel files and pay records, including disciplinary proceedings now dangled as individual extortion material

Rhysida sells to whoever pays. That is the thing to watch. Moscow’s sabotage arm, the one Dobrindt keeps calling “left-wing” Vulkangruppe (a name that fails every German left-wing naming test, no less), can arrive any minute. It needs only 30 of Putin’s bitcoin and a Friday afternoon. Expect the map to work its way into another round of Dobrindt waving his favorite false-flags at the next critical infrastructure breach.

The plain-text credentials sat in files with the operationally efficient name “Passwort.docx”. Unencrypted. Working access data for permit and payment infrastructure, typed into a Word document named after exactly what it contained, which an attacker had a week to poke around and read.

Mangelhaft Wasser

The water supply item deserves special attention, because it has German history worth telling. In summer 2020 the consultancy Alpha Strike Labs, commissioned by the Berliner Wasserbetriebe themselves, found more than 30 vulnerabilities and graded the utility’s IT security “mangelhaft“. Is there a better word for failing? The BWB announced a Sofortpaket (immediate) fix-it project. Remediation, however, was only at the level of self-reported. Independent verification of the fixes, six years later, translates into a big fat zero: none that I can find.

So Rhysida is advertising a vulnerability analysis of the city’s water system, which sounds like offering a Weißwurst to Oktoberfest. The map already exists. Alpha Strike drew it in 2020 and handed it to the utility. Whether Rhysida holds that old map or a newer one goes undisclosed, which is how sellers inflate value. Here it makes no difference. Berlin bet that it would never have to show proof the 2020 holes were closed. The auction calls that bet. Every buyer gets to test the Sofortpaket, and the Wasserbetriebe get to find out who was right.

Gears of Fear Turning

The Senate’s access decisions tell you how governance is spelled in German. The breach becomes public in mid August: the home office access is restricted. Then a week later access gets restored. Monday morning, September 1, access is cut again. Ok, but why? This is when Tagesspiegel published two of the stolen passwords.

Ahab on the East See and Sunshine are funny, but really they unlock the bigger story.

All the credentials were exposed the entire two weeks. The intrusion, the plaintext files, the exfiltration were known to the Senate. What actually changed is exposure to the public of what the institution was sitting on, and who was attacking. Berlin incident response wears the suit and tie of press response, which happens to be the same reflex I documented in the recent tragic CSD attack: the state performs a dance around what’s leaking to the public, while the ground level failure analysis goes unowned and unanswered.

Let’s talk about what really is going on, as much as Berlin’s cover-up culture seems to want to do everything except that.

The Cover-Up

Call it what it is. Operators knew, operators played dumb.

They knew in 2020. Their own consultants handed them a failing grade on the water system and a list of more than 30 holes. They interpreted that as a moment of self-certification, in order to produce no written record of whether anything was fixed. They manufactured a silence as their product, instead of a list of failures and fixes.

An operator who types passwords for their payment backend into “Passwort.docx” knows what all of that means. It’s 2026 in Berlin, not 1936. That file existed because nobody touching it believed in accountability, what an honest audit would bring, let alone the press.

And they knew when they were exposed. Watch the dates. Breach goes public: access restricted. A week later: access quietly restored. Monday, the Tagesspiegel prints the passwords: access cut the same morning. That is a team tracking how they look to someone judging them, lacking internal moral compass, acting on getting exposed instead of getting a clue. Nobody managing legibility that precisely is confused about what they prioritize. They are covering and ducking, pivoting to please whomever they think has immediately authority over them.

A state of improvisation, as political scientists have explained about German institutional habits, instead of rational documented actions.

Throwing blame at “Sonnenschein13” is part of the same operation. Point at the clerk’s password, have a laugh and click on the BSI hygiene lecture. The questions start and stop at that weak endpoint. That’s a shadow of Dobrindt pointing at an attacker’s suspended sentence while perimeters fail to meet baselines, with barrier plans unfunded. The employee is strung up to be visible, far more attention gathering than the operators and the curse of Dobrint.

Berlin collected everything, then they apparently protected nothing, such that when the story broke they spun into managing perceptions of risk instead of the risk. Run the training budget and the apology as routine, then write it off. The questions that actually need to be invested in have names attached: who signed off on skipping independent verification of the Sofortpaket? When? Who owned the directory and the file in it called Passwort.docx? Who ordered home office access restored mid-incident, and who ordered it cut again Monday morning, and what did that person hear over their morning coffee? Put those names in an Untersuchungsausschuss and the whole blowup about a Russian-driven auction gets a lot less interesting. And if they have ties to the AfD, we’ll get closer to the real story here about Russia getting a visit from the CIA about a Winchester America being unable to defend Germany anymore.

Ahab on the East Sea in the Sunshine, is not the story people think it is.