Summary
- DGSI director Céline Berthon says France must consider more direct attacks against strategic companies and infrastructure after the Leipzig/Halle drone incident.
- Defence, technology, energy, communications, and other strategic sectors fall within the warning.
- Hybrid operations can combine cyber intrusion, economic interference, physical sabotage, and locally recruited proxies, widening the scope of corporate resilience planning.
France is reassessing the prospect of more direct attacks against strategic companies and critical infrastructure after an explosives-laden drone was found near a Ukrainian military-support aircraft at Leipzig/Halle airport, widening the security discussion around European businesses beyond cyber intrusion and conventional espionage.
Céline Berthon, director of France’s DGSI, told an annual gathering organised by employers’ association Medef that the incident should prompt organisations to consider the possibility of more violent action on French territory. Defence and technology businesses are among the immediate concerns, alongside energy, communications, and other strategically important sectors.
The warning followed the discovery on 4 August of a drone carrying explosives near a Ukrainian Antonov cargo aircraft at Leipzig/Halle, an important German logistics airport also used to support military shipments. German investigators had not publicly assigned responsibility for the attempted attack when Berthon spoke, while Russia denied involvement.
French intelligence is therefore treating the episode as evidence of how available methods are changing rather than as proof of responsibility by a particular state. Berthon described a steep rise in hybrid threats since Russia’s full-scale invasion of Ukraine, spanning cyber penetration, economic and scientific interference, and violence carried out through locally recruited intermediaries.
Corporate security extends into physical infrastructure
European businesses are accustomed to warnings about ransomware, espionage, phishing, and supply chain compromise, but hybrid operations blur the boundary between digital and physical security. A hostile campaign can begin with reconnaissance or a network intrusion and progress towards stolen information, employee targeting, sabotage, or disruption of infrastructure.
That creates particular exposure for sectors whose assets cannot simply be moved elsewhere. Energy networks, telecommunications infrastructure, aerospace facilities, research centres, logistics hubs, datacentres, and advanced manufacturing plants combine valuable information with physical systems whose interruption can affect customers and suppliers far beyond the original site.
Leipzig/Halle illustrates that overlap because the airport is both commercial infrastructure and part of the logistics network supporting Ukraine. Similar dual-use characteristics exist across ports, communications systems, industrial plants, and technology supply chains.
Intelligence warnings about hybrid threats consequently land inside continuity planning rather than remaining solely a matter for government security services. Companies may need to examine site access, contractor vetting, reporting of unusual reconnaissance, operational-technology segmentation, and the ability to keep services running when cyber and physical incidents occur together.
The DGSI already advises French organisations on economic interference and foreign attempts to obtain strategically valuable knowledge. Its guidance has covered overseas audits, transfer of research expertise, and risks connected with foreign technologies used in professional environments, reflecting a security mandate that extends well beyond conventional counter-terrorism.
Attribution can move slower than disruption
Businesses may have to respond before governments can establish who is responsible for an incident. Attribution frequently involves intelligence, forensic, diplomatic, and legal work that takes longer than an organisation can wait before restoring services, protecting staff, or isolating systems.
Hybrid methods make that task harder by using intermediaries, commodity cyber tools, disposable infrastructure, and criminal techniques that create distance between an operation and whoever directed it. Something that first resembles ordinary vandalism, cybercrime, or industrial espionage may later prove to have a strategic purpose.
Berthon also linked the threat environment to attempted interference with economic, scientific, and institutional targets, while France’s approaching presidential election adds political sensitivity to attempts that could affect public confidence or essential services.
France’s armed forces are separately examining the economics of drone defence, because low-cost unmanned systems can be manufactured in volumes that do not match the cost profile of conventional defensive technologies. Civilian critical infrastructure faces a similar problem, with airports, energy assets, and communications networks covering large physical areas that cannot be protected through expensive point defences alone.
The warning therefore does not point towards a single product or security control. It suggests that the separation between cybersecurity, corporate intelligence, physical protection, supply chain resilience, and business continuity is becoming less useful for organisations whose assets have strategic value.
The Leipzig investigation may eventually produce a clear attribution, but French industry has already been given a broader planning assumption: digital intrusion and physical interference may form different stages of the same operation, and companies may need to manage the consequences before governments can say with confidence who is behind it.












