Berlin, September 3rd, 2026 (The Berlin Spectator) – Germany’s power infrastructure came under attack twice within a short span this week, prompting investigators to open sabotage inquiries in two states. In Brandenburg, unknown perpetrators used homemade projectiles resembling New Year’s Eve rockets to send conductive material toward high-voltage lines at the Turnow-Preilack substation near the Jänschwalde power plant. Hours later, a substation in Bergheim near Cologne suffered a deliberately triggered short circuit that knocked five lignite power plant units offline.
Neither incident affected the general power supply. That sets both apart from a fire attack on a cable bridge in southwestern Berlin earlier this year, which caused a large-scale blackout affecting tens of thousands of people. Authorities attributed that earlier attack to left-wing extremists.
“Damn Lucky”
Brandenburg’s Interior Minister Jan Redmann (CDU) told the state parliament’s interior committee that his region had been “damn lucky”. Of more than a dozen rocket-like devices equipped with propellant charges, only one reached its target, successfully creating a conductive link between a high-voltage line and the ground. A second device also ignited but appears to have missed the line. Had the attack succeeded as planned, Redmann said, it could have destabilized the grid. Police are now investigating the case. They are treating this as potential terrorism.
Redmann said the attackers appear to have scouted the site and installed their equipment days in advance, a process he described as requiring real technical know-how. He called for faster upgrades to infrastructure security, noting that many facilities were built for a different threat environment and that intelligent video surveillance could help detect movement near transmission towers. Still, he acknowledged, no country can station a guard at every pylon.
In North Rhine-Westphalia, Interior Minister Herbert Reul (CDU) was more blunt about the Bergheim incident. Investigators there believe cables were deliberately draped over overhead lines to trigger the short circuit. “That was intentional,” Reul said. “Whoever does that is attacking our country.” Grid operator Amprion confirmed that the general power supply was never at risk and that system stability held throughout.
Who Is Behind It?
Redmann pointed to parallels between the two cases, including their timing and photographs showing a similar electrical arc pattern at both sites, as reason to suspect a connection. Investigators in North Rhine-Westphalia say they are pursuing two lines of inquiry in parallel: sabotage directed by a foreign state, and left-wing extremism.
No confirmed information has emerged yet on who carried out either attack. In several sabotage cases over the past two years, however, security agencies have pointed to left-wing extremists, partly because letters of responsibility believed to be authentic surfaced afterward. That includes January’s blackout in southwestern Berlin, claimed by a self-described left-wing extremist network calling itself the “Vulkangruppe”, which cited opposition to capitalism as its motive.
Germany’s domestic intelligence agency, the Bundesamt für Verfassungsschutz, has said that violence-oriented left-wing extremists view attacks on critical infrastructure as strikes against a “repressive state” focused on protecting capitalist profit interests and consolidating its own power. The agency has identified energy, information technology and telecommunications, transport, and government administration as the sectors most likely to be targeted by vandalism and arson.
A Pattern Of Incidents
Investigators say they have found no evidence so far linking either recent attack to Russian hybrid warfare, though that possibility remains one of three scenarios under consideration, alongside left-extremist sabotage and a Russian-directed operation designed to look like left-extremist action. Federal Interior Minister Alexander Dobrindt (CSU) described the broader climate after recent measures against Russia, taken in response to an explosive-laden drone incident at Leipzig/Halle Airport: “We are not at war, but we are a daily target of hybrid warfare.” Hybrid warfare typically combines military, economic, intelligence, and propaganda tools, including cyberattacks and efforts to sway public opinion, often around elections, while obscuring who is actually responsible.
Investigators are also taking a fresh look at a June fire at a substation in Reutlingen, believed to have been arson, which left roughly 7,600 buildings and 40,000 people without power temporarily. Affected states say they now plan to coordinate more closely on these cases.
Other recent incidents include the March 2024 arson attack on a transmission tower that halted production for days at Tesla’s Grünheide plant near Berlin, and January’s attack on the Berlin cable bridge, which left around 45,000 households and more than 2,200 businesses, along with hospitals and care homes, without electricity for days.
Calls For Better Protection
Germany’s Interior Ministry maintains that critical infrastructure is generally well protected, relying mainly on technical safeguards along with emergency and recovery planning. But operators argue that absolute security is impossible. Ingbert Liebing, head of the German Association of Local Utilities (VKU), said incidents could strike anywhere despite ongoing efforts by companies to intensify their precautions, and pressed for the culprits behind the string of recent sabotage cases to finally be caught. He also called on federal and state governments to help fund effective protection concepts, arguing that the state cannot shift responsibility for public security onto private companies alone.
Legal obligations for infrastructure operators have tightened over the past three years, covering both cyber defense and physical security, including mandatory risk assessments and incident reporting. Germany’s Federal Network Agency (Bundesnetzagentur) said it is treating the two latest incidents “very seriously” and is working with grid operators to identify and close vulnerabilities while improving joint response capacity in the event of outages.
