By Jonathan Brown
Shortly after half past seven on the morning of September 1, 2026, something extraordinary happened among the transmission lines near Turnow-Preilack in the German state of Brandenburg. Purpose-built projectiles were launched toward extra-high-voltage conductors serving one of the most important electrical junctions in the region. The projectiles reportedly carried conductive material intended to enter the energized lines and create short circuits. At least two reached their target. Electrical faults erupted, a fireball was observed, transmission circuits were interrupted, and a 500-megawatt generating unit at the nearby Jänschwalde lignite power station shut down automatically.
No city went dark. No hospital lost power. Germany’s interconnected transmission system absorbed the disturbance, protective equipment isolated the faults, and the affected lines were returned to operation. The general electricity supply, according to transmission operator 50Hertz, remained intact.
Judged only by its immediate public effects, the attack was therefore a failure. Judged by what the attackers attempted, understood and partially accomplished, it may be one of the most consequential warnings European infrastructure defenders have received in years.
The attack did not require penetration of a power station, access to an electrical control room or the compromise of an industrial control system. It did not require enough explosive material to demolish a transformer or sever a transmission tower. Instead, the attackers apparently attempted to induce the grid to protect itself by disconnecting its own equipment. Their weapons supplied the conductive bridge; the transmission system supplied the electrical energy. It was a physical attack designed around an understanding of electrical behavior.
That distinction matters. Most public discussion of threats to the electric grid has separated physical sabotage from cyberattack. The first category includes rifles, fire, explosives and mechanical destruction. The second includes stolen credentials, malicious software, compromised supervisory systems and manipulated protection devices. The Preilack attack occupied the space between them. It was kinetic in execution but cyber-physical in its logic: an attempt to produce a controlled operational consequence by deliberately provoking the automated behavior of a complex system.
The protection systems worked. The attackers nevertheless demonstrated that they could reach the system, create real faults and remove a large generating unit from service, at least temporarily. Defenders must now determine whether this was an isolated experiment, a politically motivated attack, an operation conducted on behalf of a foreign power or the first public appearance of a method likely to be copied elsewhere.
What Happened at Turnow-Preilack
The target was the Turnow-Preilack substation, approximately five kilometers from the Jänschwalde power station in Lower Lusatia. Jänschwalde was constructed during the final decades of East Germany and originally consisted of six 500-megawatt generating blocks. As Germany phases out lignite generation, its available capacity has been progressively reduced. LEAG, the plant operator, currently lists three operating blocks with a combined installed capacity of 1,500 megawatts.
Electricity generated at Jänschwalde enters the 50Hertz transmission system through Preilack at the 380-kilovolt level. The site connects different voltage levels, distributes electricity regionally and interregionally, and provides the principal interface between the generating station and the wider transmission network. It is not simply a fenced collection of transformers serving a nearby town. It is part of the architecture through which a major power station becomes useful to the grid.
According to Brandenburg Interior Minister Jan Redmann, the attackers used propellant-powered devices to fire conductive material into extra-high-voltage lines. Investigators discovered a double-digit number of devices, and the total continued to rise as police searched the area. Redmann distinguished them from ordinary consumer fireworks: they had reportedly been manufactured for this purpose and required meaningful preparation. He described the operation as systematic and called it sabotage.
Two devices apparently succeeded in producing short circuits. Witnesses saw a fireball, but authorities had not established that an explosive warhead detonated. Redmann said the visible event was probably the electrical fault itself arcing from the energized line toward the earth. Initial police statements referred to a detonation, while subsequent official comments were more cautious. That discrepancy is important. The devices may have incorporated pyrotechnic or explosive components as propulsion or ignition mechanisms, but the destructive mechanism appears to have been electrical rather than primarily blast-driven.
At approximately the same time, Jänschwalde’s Block B experienced a technical failure and shut down automatically as a safety measure. LEAG initially said the relationship between the transmission faults and the generating-unit shutdown was being examined. Later reporting quoted company leadership describing the shutdown as a direct consequence of the attack. Block B was expected to return to service that evening, suggesting a protective trip rather than catastrophic plant damage.
The distinction between a generating failure and a grid-connection failure is central to understanding the event. The attackers did not need to damage a boiler, turbine or generator. A power station cannot continue exporting electricity normally when its route into the transmission network suddenly becomes unavailable or electrically unstable. Protective systems are designed to separate equipment from dangerous conditions before those conditions destroy generators, transformers, buswork or other machinery.
The attackers appear to have exploited that principle. By creating faults on the evacuation path, they triggered the defensive behavior of the system. The grid did what it was designed to do: detect the fault, open breakers, isolate the affected circuit and prevent the disturbance from propagating.
That successful defensive response is the reason there was no regional blackout. It should not be confused with proof that the attack was harmless.
Weaponizing the Grid’s Own Energy
A high-voltage transmission line carries an immense amount of electrical energy, but only while carefully maintained insulation distances keep energized conductors separated from each other and from the ground. Air itself serves as insulation. Conductors are suspended with deliberate spacing, and insulators prevent current from flowing through towers and supporting structures.
If a sufficiently conductive path is introduced between phases, or between an energized phase and ground, current can flow where it was never intended to flow. The resulting fault may produce an arc with extreme heat, intense light, molten material and rapidly expanding gases. The available fault current is supplied by the connected power system, not by the attacker’s device.
This is why an electrical attack does not necessarily require a large bomb. An attacker who succeeds in bridging the required electrical distance may cause the system’s own energy to create the visible and operational event. The device initiates the condition; the grid provides the force.
Utilities anticipate accidental faults caused by lightning, vegetation, equipment failures, contamination, animals and wind-driven debris. Protection relays continually measure electrical conditions and identify patterns indicating that current is flowing abnormally. Circuit breakers then open to isolate the faulted component, often in a fraction of a second. Some overhead-line faults are temporary, allowing automatic reclosing systems to test whether the line can be safely re-energized. Persistent faults require the circuit to remain open until operators inspect and repair the affected equipment.
These mechanisms are among the reasons modern interconnected grids are remarkably resilient. They also create a predictable system response. Anyone with enough electrical knowledge can understand that a deliberately induced fault may cause a line to disconnect, a generator to trip or power to be rerouted.
The Preilack devices appear to have been designed around this predictability. Their reported purpose was not merely to strike the conductors but to introduce conductive material into the energized space. The attack therefore depended on three distinct elements: identifying a consequential transmission location, reaching the conductors physically, and understanding how an induced fault could alter system operation.
None of those elements proves state-level sophistication. Electrical arcs caused by conductive objects are not mysterious, and the general operating principles of transmission grids are publicly understood. The projectiles could conceivably have been built by a small extremist cell, technically trained individuals or determined amateurs. But the double-digit number of devices changes the character of the event. It suggests preparation, logistical effort and an attempt to overcome uncertainty through repetition.
A projectile may fail to launch, miss its target, release its payload incorrectly or produce only a momentary disturbance. Deploying many devices increases the probability that at least some will succeed. In this case, at least two apparently did.
The attackers may not have possessed a detailed electrical model of the regional grid. They may not have known the exact loading of each circuit, the protection settings, the available reserve margin or the status of alternative transmission paths. But they understood enough to create genuine faults at a strategically important connection. That is a lower threshold than executing a precisely modeled attack, yet it is considerably higher than indiscriminate vandalism.
A Success Contained by Resilience
The most accurate description of Preilack is that it was a partially successful attack whose larger intended consequence was contained.
It succeeded physically because devices were deployed and at least two reportedly reached the energized lines. It succeeded electrically because two short circuits were produced. It succeeded operationally because transmission circuits were interrupted and a 500-megawatt generating block shut down. It failed strategically because the regional transmission system remained stable, alternative paths carried the load and the public did not lose electricity.
This layered assessment is preferable to both sensationalism and complacency. Calling the incident a failed attempt obscures the fact that the attackers achieved several intended technical effects. Calling it a major blackout or devastating grid attack would exaggerate the outcome. The real significance lies in the distance between the limited equipment consequence and the potentially much larger consequence the operation appears to have sought.
Power systems are normally planned around credible contingencies. The loss of one transmission element or generating unit should not automatically produce a wider collapse. Operators maintain reserves, monitor line loading and adjust generation so that predictable failures can be absorbed. This is commonly described through the principle of surviving a single significant contingency, although actual reliability planning is more complex than any single formula.
Preilack was a practical demonstration of that resilience. The system isolated the faults and continued supplying consumers. But ordinary contingency planning is principally concerned with component failures that are accidental or otherwise independent. Deliberate attackers are not obliged to respect those assumptions. They can choose targets, coordinate timing, observe maintenance conditions and attempt to create several failures together.
That is the danger concealed by the successful response. The event did not prove that the attackers could destabilize the regional grid. It proved that they could deliberately create a condition the grid had to manage. The next question is whether they were testing a method, attempting a larger effect without adequate knowledge, or participating in a sequence that has not yet ended.
Berlin: Simple Arson, Greater Human Consequences
The contrast with the January 2026 attack on Berlin’s electricity network is instructive. That event was less technically novel but far more damaging to the public.
Early on January 3, attackers set fire to power cables carried on a bridge over the Teltow Canal near the Lichterfelde combined heat and power station. The fire damaged multiple high-voltage and medium-voltage cables concentrated along the same physical route. Approximately 45,000 households and 2,200 businesses initially lost electricity. Around 100,000 people were affected, many during freezing winter weather. Heating, telecommunications, medical services, traffic systems, businesses and public institutions were disrupted.
Because the attack destroyed physical cable infrastructure rather than merely causing a transient fault, restoration required much more than resetting protection systems or inspecting an overhead line. Crews had to replace damaged cable sections, reconstruct connections and re-energize the affected network progressively. Tens of thousands of residents remained without power for days. Full supply was restored on January 7, making the incident Berlin’s longest major outage since the end of the Second World War.
A statement claiming responsibility was issued in the name of the far-left Vulkangruppe, or Volcano Group, a label associated with earlier attacks on infrastructure and industrial targets. German authorities investigated the authenticity of the statement, and the federal prosecutor assumed the case amid suspicion of anti-constitutional sabotage, arson and participation in a terrorist organization. Attribution nevertheless requires care because competing statements and questions concerning the identity and continuity of groups using the name complicated the public record.
The Berlin attackers used a simpler physical method. They identified a location where several important cables crossed a vulnerable structure, applied fire, and allowed the concentration of infrastructure to multiply the effect. There was no need to understand relay behavior, create an airborne conductive bridge or target energized overhead phases. The critical knowledge was geographical and architectural: several circuits depended upon one exposed route.
Berlin produced a far greater humanitarian consequence than Preilack. People lost lighting, refrigeration, communications and, in many cases, heat. Care facilities and medical practices faced immediate difficulties. Mobile communications degraded as base stations exhausted backup power or lost supporting connections. Transportation and traffic control were affected. The outage became not only an electrical emergency but a cascading municipal crisis.
Yet Berlin did not demonstrate the same method of attacking the system’s electrical behavior. It destroyed the infrastructure directly and forced a prolonged repair. Preilack appears to have attempted something subtler: manipulating the physical conditions around energized conductors so that protection systems would remove transmission and generation capacity.
Together, the two incidents expose different weaknesses. Berlin showed the danger of physical concentration and slow-to-replace cable infrastructure. Preilack showed the accessibility of overhead transmission interfaces and the possibility of provoking automatic disconnection without breaching the substation itself.
The fact that both occurred in Germany within eight months should end any assumption that physical grid sabotage is merely an American problem, a wartime problem or a historical curiosity.
Metcalf: The Attack That Changed American Grid Security
The modern reference point for a coordinated physical attack on the power grid remains the assault on Pacific Gas and Electric’s Metcalf transmission substation near San Jose, California, on April 16, 2013.
Before the shooting began, underground telecommunications cables near the site were cut. Attackers then used rifles to fire into the substation from positions outside its perimeter. Seventeen large transformers were damaged. Cooling oil leaked from punctured equipment, causing transformers to overheat and requiring them to be removed from service.
The attack lasted less than an hour, and the perpetrators departed shortly before police arrived. No one was killed, and operators rerouted electricity around the damaged station, avoiding the feared blackout in Silicon Valley. Nevertheless, repairs took weeks and cost millions of dollars. The attackers were never publicly identified.
Metcalf was disturbing because it combined reconnaissance, preparation, target selection and disciplined execution. The attackers did not simply fire randomly at a visible facility. They disabled communications, selected vulnerable transformer components and coordinated their activity well enough to damage numerous units without entering the site.
Large power transformers are especially consequential targets. They are expensive, difficult to transport and often manufactured to site-specific requirements. Replacement can require specialized rail or heavy-haul equipment, engineering work and long procurement periods. Utilities maintain spares and mutual-assistance arrangements, but a coordinated attack damaging several uncommon transformers could create a restoration problem far beyond the time required to replace ordinary distribution equipment.
Metcalf helped drive the creation of the North American Electric Reliability Corporation’s physical-security standard, CIP-014. The standard requires applicable transmission owners to identify stations whose loss could lead to instability, uncontrolled separation or cascading conditions; obtain independent verification of those assessments; evaluate threats; and develop physical-security plans. The Federal Energy Regulatory Commission has said that the standard covers the overwhelming majority of 345-kilovolt and all 500-kilovolt substations.
Metcalf and Preilack share several features. Both attacks targeted extra-high-voltage infrastructure. Both occurred at facilities important enough that defenders had to consider wider system consequences. Both produced real equipment or operational effects but failed to cause a public blackout because operators rerouted power or isolated the disturbance. Both also confronted investigators with the problem of distinguishing demonstrated technical knowledge from assumptions about the attackers’ identity.
Their methods, however, were fundamentally different. Metcalf used ballistic damage to degrade large transformers physically. Preilack used projectiles to induce electrical faults in conductors. Metcalf’s intended damage mechanism was penetration and coolant loss; Preilack’s apparent mechanism was an electrical arc followed by protective disconnection.
Metcalf required firearms, stable firing positions and sufficient ammunition. Preilack appears to have required custom projectiles, launch preparation and knowledge of conductor behavior. Neither required access to a control network. Both demonstrate that the most sophisticated software security program in the world cannot stop an attacker who can reach critical electrical equipment from outside the cyber perimeter.
Moore County: When Two Substations Went Dark
On the evening of December 3, 2022, attackers opened fire on two Duke Energy substations approximately ten miles apart in Moore County, North Carolina. The attacks occurred close enough in time to indicate coordination. Equipment suffered extensive damage, and approximately 40,000 to 45,000 customers lost electricity.
The outage lasted for several days. A state of emergency and nighttime curfew were imposed. Traffic signals stopped working. Schools closed. Businesses discarded spoiled food. The local hospital and municipal water and sewer services relied on backup generation. One death was subsequently associated with the loss of power, although the precise legal and medical characterization of outage-related mortality requires caution.
Unlike Metcalf, the Moore County attack succeeded in producing the public consequence that grid operators most fear. The attackers selected two facilities whose simultaneous loss sharply limited the utility’s ability to reroute distribution service. Restoration required repair or replacement of damaged substation equipment rather than a simple switching operation.
The Federal Bureau of Investigation continues to solicit information about the case, describing unknown suspects firing multiple rounds at Duke Energy substations in West End and Carthage. Despite extensive investigation, rewards and public attention, no definitive motive or perpetrator has been established publicly. Early rumors attempted to link the outage to a drag performance in Southern Pines, but law enforcement said it had found no evidence supporting that theory.
Moore County demonstrates how little equipment an attacker may need when target selection is accurate. The incident did not involve military explosives, compromised control systems or specialized cyber capabilities. Firearms, transportation, timing and an understanding of local distribution topology were enough to deprive a substantial community of electricity for days.
This creates an uncomfortable comparison with Preilack. The German attackers employed a more unusual technique against higher-voltage infrastructure but achieved a smaller public effect. The Moore County attackers used a familiar weapon against less nationally consequential facilities but selected locations whose combined loss had an immediate community-wide result.
Sophistication cannot therefore be measured solely by the novelty of the weapon. A technically elaborate operation against a resilient transmission node may accomplish less than a comparatively simple attack against two carefully selected distribution substations. Target knowledge is often more important than firepower.
Moore County also illustrates the asymmetry of attribution. Electricity can be interrupted in seconds, while identifying the responsible people may take years—or never happen. Remote substations offer limited witnesses, sparse nighttime activity and several possible routes of approach and escape. Unless attackers leave useful ballistic, electronic, biological or vehicle evidence, the physical crime scene may say more about what they did than who they were.
The Wider American Pattern
Metcalf and Moore County are not isolated events. In September 2016, a rifle attack on the Buckskin substation in Utah interrupted electricity to approximately 13,000 customers. During late 2022, substations in Washington and Oregon were attacked through gunfire, forced entry or deliberate manipulation of equipment. Four substations near Tacoma were attacked on Christmas Day by men who later admitted that the outages were intended to facilitate a burglary.
These cases reveal the wide range of motives behind attacks that may initially look similar. Some are ideologically motivated. Some may arise from anti-government or accelerationist beliefs. Some are conducted for theft, vandalism or personal grievance. Others remain unexplained. The physical evidence—damaged transformers, cut fences, burned control buildings or opened switches—does not automatically identify the political or strategic purpose.
The scale of reported physical-security activity is also easy to misinterpret. North American grid organizations record thousands of security incidents, but most are intrusions, thefts, vandalism, threats or suspicious activity rather than carefully planned sabotage. Only a small percentage disrupt electricity. Counting every fence breach alongside Metcalf can inflate the apparent prevalence of strategic attacks, while focusing only on successful blackouts can obscure the reconnaissance and failed attempts that precede them.
Preilack belongs in the narrower category of incidents where the apparatus, location and execution strongly indicate an attempt to manipulate grid operation. The double-digit device count and use of conductive payloads are difficult to explain as casual trespass or spontaneous vandalism.
That makes the attack potentially instructive to others. Physical attacks are imitative. Public reporting on one method can cause extremists, criminals or state proxies to reconsider infrastructure they had previously regarded as too difficult to affect. Defenders must explain threats sufficiently to justify protective measures without transforming forensic findings into an instruction manual.
Nord Stream: Infrastructure as Geopolitical Leverage
The September 2022 destruction of the Nord Stream pipelines was not an attack on the electric grid, but it remains essential to understanding the strategic context of European infrastructure sabotage.
Explosions beneath the Baltic Sea severely damaged both strings of Nord Stream 1 and one string of Nord Stream 2. The pipelines had been constructed to carry Russian natural gas directly to Germany. Neither was actively delivering gas when the explosions occurred, but their destruction permanently altered Europe’s energy options and produced one of the largest recorded single releases of methane.
The operation required maritime access, diving or equivalent subsea capability, explosive expertise, navigation and logistical preparation. For years, competing narratives attributed the attack to Russia, Ukraine, the United States or unidentified state actors. The absence of immediate public evidence allowed the incident to become a vessel for propaganda.
The German investigation has since become much more concrete. In July 2026, federal prosecutors charged former Ukrainian military officer Serhii K. with coordinating the operation while allegedly acting on behalf of Ukrainian state entities. Prosecutors say the team used a rented sailing yacht and forged identities to transport personnel and explosives. A second Ukrainian suspect, alleged to have helped place the charges, was arrested in Croatia in August 2026 for extradition to Germany. The defendants remain entitled to the presumption of innocence, and allegations made by prosecutors are not final judicial findings.
Nord Stream demonstrates that strategic infrastructure can be attacked not merely to interrupt a present service but to remove a future political and economic option. The pipelines were not carrying gas, yet their destruction eliminated physical capacity, intensified uncertainty and ensured that any restoration of direct Russian pipeline supply would require major repair and political confrontation.
Preilack was far smaller in scale, but the same strategic principle applies: infrastructure attacks need not produce an immediate catastrophe to alter security calculations. A partially successful attack may force governments and operators to spend heavily, change patrol practices, restrict access, harden facilities and reconsider assumptions about what adversaries are willing to attempt.
Nord Stream also warns against attribution by intuition. For years, political actors promoted confident theories unsupported by public evidence. The investigation ultimately moved through vessel records, explosive evidence, identity documents, travel patterns, arrests and judicial proceedings. Preilack requires the same discipline. The fact that Germany faces Russian hybrid operations does not prove Russian responsibility. The history of German far-left infrastructure sabotage does not prove domestic extremist responsibility. The technique must not be mistaken for a signature until investigators establish that it is one.
Ukraine: The Grid as a Battlefield
No comparison can place the Preilack incident in proper perspective without examining Ukraine, where attacks on electrical infrastructure have progressed from limited cyber disruption to a sustained campaign combining missiles, drones, bombs, artillery, occupation, cyber operations and repeated attacks on repair efforts.
In December 2015, attackers compromised Ukrainian electricity-distribution companies, remotely opened breakers and interrupted power to approximately 225,000 customers. The operation combined credential theft, remote access, manipulation of operator workstations, interference with customer communications and destructive malware. A second attack in 2016 used malware engineered to interact with electric-grid protocols.
Those incidents became foundational examples of cyber operations causing physical-world disruption. Yet the full-scale Russian invasion transformed the threat. Beginning in 2022, and with renewed intensity from March 2024 onward, Russian forces repeatedly struck generation, transmission and distribution infrastructure using missiles and unmanned aircraft.
The United Nations documented nine waves of coordinated long-range attacks between March 22 and August 31, 2024, damaging or destroying numerous generating, transmission and distribution facilities. The consequences propagated beyond electricity into water supply, sewage, sanitation, heating, health care, education and economic activity. Later campaigns expanded the damage. During January 2026 alone, the United Nations reported near-daily attacks affecting energy infrastructure in at least seventeen Ukrainian regions and Kyiv.
By the winter of 2025–2026, Russian forces were increasingly striking smaller distribution substations with drones in addition to attacking large generating and transmission targets. This imposed a different form of pressure. Destroying one small substation may not destabilize the national grid, but attacking many of them repeatedly can produce local outages, exhaust repair inventories, stretch air defenses and force utilities to disperse crews and replacement equipment.
Ukraine reveals the mature form of a campaign that Preilack only hints at: adversaries study the system, identify bottlenecks, observe repairs, change target classes, overwhelm defenses and attack again. They do not judge success by whether one strike causes national collapse. They measure cumulative degradation, repair burden, public exhaustion and the diversion of defensive resources.
It also demonstrates that physical and cyber attacks need not be alternatives. Cyber access can provide operational awareness, disrupt communications, alter protective systems or complicate restoration while physical weapons damage equipment. Physical reconnaissance can support cyber targeting, while stolen network data can improve kinetic target selection. The most dangerous scenario is not a more powerful version of the Preilack projectile. It is a coordinated operation in which physical faults, cyber interference, communications disruption and disinformation reinforce one another.
Germany is not Ukraine, and the Preilack incident was not an act of open warfare. The German grid benefits from extensive European interconnection, reserve capacity, mature protection systems and the absence of sustained missile attack. Comparisons must not collapse those differences. Ukraine nevertheless shows what electrical infrastructure becomes when an adversary treats it as a system to be studied and progressively degraded rather than a collection of isolated targets.
The Geography of Vulnerability
Electric grids are difficult to defend physically because their essential components must be geographically distributed. Power plants, substations, overhead lines, underground cables, communications systems and control centers form a network spanning cities, farmland, forests, mountains and waterways. Many assets are unattended for long periods. Transmission corridors must cross public or lightly controlled land. Complete physical enclosure is impossible.
Traditional security measures concentrate on the substation perimeter: fences, lighting, cameras, intrusion detection, locks, patrols and ballistic barriers. These measures remain important, particularly for transformers, control buildings and exposed switchgear. But the Preilack attack appears to have engaged the conductors outside—or at least without requiring conventional penetration of—the protected operational core.
A fence protects the ground on one side of it. It does not necessarily protect the electrical space above or beyond it. Overhead conductors cannot be wrapped in concrete walls along their entire route. Increasing the cleared perimeter around every consequential span would require vast areas of land, create environmental and property conflicts, and still not eliminate attack options.
The challenge is therefore not to make all contact impossible. It is to detect preparation earlier, reduce the probability of successful engagement, limit the operational effect and restore service rapidly.
That requires utilities to think in terms of attack paths rather than property boundaries. Where can an adversary obtain an unobstructed approach to consequential conductors? Which circuits share towers, bridges, trenches or rights of way? Which generating sites depend on a narrow set of evacuation paths? Where do public roads, forest tracks or abandoned structures provide concealment? Which failures can be rerouted quickly, and which require specialized repairs?
Publishing exact answers would create obvious security problems. Failing to ask the questions internally is worse.
Protection Worked—But Protection Is Not Prevention
The Preilack event validates the engineering of electrical protection. Relays detected abnormal conditions, breakers isolated affected circuits, the generating unit entered a safe state, and the wider system remained stable. That is a significant defensive success.
Protection systems, however, are designed primarily to prevent equipment damage and cascading failure after a fault has begun. They do not prevent the adversary from creating the fault. Their successful operation may also impose exactly the immediate consequence the attacker seeks: disconnection of a line, transformer or generator.
This does not make protection defective. Allowing a generator to remain connected through an unsafe transmission condition could produce severe damage and widen the disturbance. The system must choose controlled separation over uncontrolled destruction.
The strategic problem is that attackers may exploit this conservative behavior. A safety system necessarily responds to dangerous electrical conditions regardless of whether they arise from lightning, equipment failure or sabotage. It cannot simply ignore an intentional fault.
Defenders must therefore build resilience around the expected protective response. If one circuit opens, alternative circuits must remain available. If a generating unit trips, reserve generation or imported power must compensate. If automatic reclosing is unsuccessful, operators need accurate situational awareness and safe access for inspection. If suspicious devices remain in the area, repair crews cannot be sent into danger blindly.
Preilack combined an electrical incident with an explosive-ordnance scene. Police had to search for additional devices while utility personnel assessed transmission equipment. That interaction can delay restoration even when the electrical damage is limited. A device that fails to reach a conductor may still threaten workers, investigators or nearby infrastructure.
The double-digit device count also raises the possibility that some were intended to complicate response rather than merely produce faults. There is no public evidence yet supporting that interpretation, but investigators must determine whether the devices shared one purpose, were arranged in waves or included secondary hazards.
Attribution and the Hybrid-Warfare Trap
The attack occurred on a day of exceptional political tension. Germany publicly accused Russia of responsibility for a separate attempted explosive-drone attack at Leipzig/Halle Airport and announced diplomatic and punitive measures. German officials have repeatedly warned that Russia uses sabotage, recruited proxies, cyber operations, incendiary devices and deniable criminal intermediaries against European states supporting Ukraine.
Brandenburg has also experienced a history of infrastructure attacks associated or claimed by far-left militants, including attacks on railways, communications infrastructure and the Tesla factory in Grünheide. The January Berlin blackout intensified concern about the Volcano Group milieu.
Either context may ultimately matter. Neither currently constitutes attribution.
Foreign services sometimes recruit local criminals or ideological actors, blurring the distinction between state and non-state operations. Domestic extremists can imitate methods associated with state sabotage. Opportunists can exploit geopolitical tension to misdirect investigators. Claims of responsibility can be authentic, exaggerated, fabricated or issued by groups attempting to appropriate an operation they did not conduct.
The Preilack devices may yield fingerprints, DNA, tool marks, chemical residues, electronic components, manufacturing patterns or purchase histories. Surveillance footage, mobile-device records, vehicle movements and prior reconnaissance may prove more important than the visible remains. If the attackers used timers, remote triggers or commercially sourced components, those systems may create additional evidentiary trails.
Until such evidence emerges, responsible analysis must preserve several possibilities. This may have been a domestic extremist attack. It may have been a foreign-directed operation. It may have involved individuals with mixed ideological and financial motives. It may have been designed as a test rather than a maximum-effect strike. It may also have been less sophisticated in planning than the visible method makes it appear.
Technical ingenuity is not identity.
Potential Consequences
The immediate consequence of the Preilack attack was limited: two deliberate electrical faults, interrupted transmission circuits and the temporary loss of a 500-megawatt generating unit. The potential consequences of the method are much larger.
The first is imitation. Once a workable attack concept becomes publicly visible, it may be copied by actors who lack the imagination to develop it independently. The equipment used at Preilack may have been crude, unreliable or highly specialized; the public does not yet know. What matters strategically is that attackers elsewhere may now begin thinking of exposed conductors not merely as lines to be cut but as electrical systems whose protective behavior can be deliberately invoked.
The second is coordination. A single induced fault is normally manageable. Several faults at carefully selected locations, particularly during maintenance, extreme weather or heavy loading, could be far more consequential. An attacker would not necessarily need to collapse an entire synchronous grid. Removing several transmission paths could isolate generation, overload remaining corridors, force emergency redispatch or create regional supply problems.
The third is repetition. The most damaging campaign may not be one spectacular attack but a succession of limited incidents. Repeated faults would require inspections, police deployments, line patrols, explosive-ordnance responses and possibly temporary operating restrictions. Even unsuccessful devices could force utilities to treat large areas as crime scenes. The resulting security and maintenance burden could become an objective in itself.
The fourth is attacks on restoration. Grid recovery depends on personnel entering damaged areas, examining equipment, replacing components and re-energizing circuits in a controlled sequence. Secondary devices, repeated launches or false reports could delay this process and expose workers. Ukraine has demonstrated the strategic value adversaries place on exhausting repair capacity and attacking infrastructure faster than it can be restored.
The fifth is cyber-physical combination. A physical fault becomes more dangerous if operators simultaneously lose communications, telemetry or confidence in protection settings. Cyber interference could obscure which line has faulted, delay remote switching, manipulate alarms or complicate restoration. Conversely, compromised operational information could tell attackers when circuits are heavily loaded or when redundant equipment is unavailable. No such cyber component has been reported at Preilack, but the incident provides an obvious foundation upon which one could be added.
The sixth is transformer and bus damage. The Preilack faults appear to have been cleared before catastrophic equipment failure. A different fault location, longer arc duration or failure of protection could expose expensive transformers, breakers, buswork and generators to severe thermal and mechanical stress. Replacement times would then be measured not in hours but potentially in months.
The seventh is cascading societal disruption. Electricity is the enabling infrastructure beneath telecommunications, water, fuel distribution, health care, transportation, finance and public safety. Berlin and Moore County showed that even geographically limited outages quickly become communications, heating, medical and municipal emergencies. A prolonged outage at a more consequential node could produce cascading effects well beyond the number of customers initially disconnected.
The eighth is strategic coercion. Infrastructure sabotage can be used to create uncertainty without producing mass casualties. An adversary may seek to demonstrate access, impose protection costs, influence political decisions or convince the public that the government cannot secure essential systems. The psychological effect can exceed the physical damage, particularly when attribution remains unresolved.
Finally, Preilack may alter the relationship between infrastructure secrecy and public accountability. Communities deserve to know whether essential systems are secure, yet detailed descriptions of bottlenecks and vulnerabilities can aid attackers. Governments and operators will face pressure to demonstrate that they have acted without disclosing exactly which sites, circuits and operating conditions concern them most.
The most dangerous conclusion would be that nothing serious happened because the lights remained on. The grid’s protection systems and operational redundancy won this encounter. They prevented a limited but real attack from becoming a regional emergency.
But the attackers reached the conductors. Their devices produced the intended electrical faults. A major generating unit disconnected. And investigators found enough additional apparatus to indicate that this was not a momentary act of vandalism.
Preilack therefore belongs beside Berlin, Metcalf, Moore County, Nord Stream and the continuing destruction of Ukraine’s energy system—not because its immediate damage equaled those events, but because it adds a new warning to their collective lesson. Modern energy systems are enormous, distributed and resilient, yet they depend on exposed physical interfaces whose behavior is predictable to anyone willing to study them.
The attack did not reveal that Germany’s grid is fragile. It revealed something more complicated: a resilient grid can survive a serious attack while simultaneously teaching an adversary what worked, what failed and what might be attempted next.
Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
© 2026 Border Cyber Group. All rights reserved.
Member discussion: