Undersea cables the new front line in hybrid war

Undersea cables: the new front line in hybrid war

Undersea cables carry 99% of global internet traffic, yet face sabotage, chokepoints, and a repair fleet too small to keep pace. Here's why it matters.

The intricate web of undersea infrastructure forms the foundational stratum of modern global connectivity, economic stability, and energy distribution. Beneath the ocean's surface lies a complex array of fiber-optic cables, power conduits, and pipelines that are indispensable for daily life, supporting trillions of dollars in financial transactions, facilitating intercontinental communication, and delivering vital energy resources. This critical network, often termed the "soft underbelly of the world economy," has progressively emerged as a prominent theater for "gray zone" aggression and hybrid warfare.

None of this is new in principle. What has changed is the frequency with which the seabed now makes the news, and the speed with which investigators, insurers, and alliance planners are being forced to develop a working vocabulary for a domain most of them had previously ignored. The vulnerability of these submerged assets presents a formidable challenge to international security, and a calibrated, comprehensive response from state and non-state actors alike is no longer optional.

The indispensable role of undersea infrastructure

The significance of undersea infrastructure transcends mere utility; it is the silent engine driving globalization. The sheer volume of information and resources that traverse these underwater pathways underscores their criticality, and the figures involved are, on reflection, almost difficult to internalize.

Data transmission: the global information arteries

Undersea fiber-optic cables are the literal backbone of the global internet. They are responsible for transmitting over 95% of international data and an estimated 99% of intercontinental internet traffic. This encompasses not only everyday communication but also the rapid, high-volume financial transactions that underpin the global economy, totaling trillions of dollars daily.

Major technology corporations such as Google, Meta, Amazon, and Microsoft have become central to this ecosystem, collectively controlling a substantial share of transcontinental cable capacity and approximately half of all undersea bandwidth worldwide. This concentration of control highlights both an efficiency gain for the so-called hyperscalers and a potential single point of failure within a corporate or geopolitical conflict - a duality that regulators in Brussels and Washington have only recently begun to grapple with in earnest.

Undersea infrastructure is the silent engine driving 99% of internet traffic and global commerce.

Economic impact: the cost of disruption

The economic ramifications of an undersea cable disruption are immediate and substantial. Operators and businesses can face losses in excess of $1.5 million per hour in lost revenue. A stark illustration of this vulnerability occurred when a powerful earthquake off Southern Taiwan severed nine cables in one stroke. The ensuing disruption, which took nearly seven weeks to fully restore, severely impacted internet links, financial markets, banking operations, and communications across multiple Asian countries - underscoring the cascading effects of such incidents long before "gray zone" entered the policy lexicon.

The Red Sea has more recently provided a sobering, recurring case study. The UK-owned vessel Rubymar, struck by an anti-ship missile during a campaign of attacks on commercial shipping in the area, drifted with its anchor deployed and severed three major cable systems - the Asia-Africa-Europe 1 (AAE-1), the Europe India Gateway (EIG), and SEACOM - disrupting an estimated 25% of data traffic between Europe and Asia. A similar pattern repeated roughly a year and a half later, when several further cables in the southern Red Sea were damaged in a single incident; some were restored within a few months, while at least one remained out of service considerably longer. Whatever the precise mechanism of damage in each instance - and independent assessments have tended to favor accidental anchor-drag from a disabled or distressed vessel over deliberate targeting - these episodes demonstrate with unusual clarity the capacity of regional conflict, whether through direct action or as an indirect consequence of disabled vessels, to inflict significant and prolonged damage on global connectivity.

Energy, pipelines, and the renewable build-out

Beyond communication, the undersea domain hosts other vital infrastructure. This includes power lines that connect offshore energy sources, such as increasingly prevalent wind farms, to national grids, facilitating the transition to renewable energy. Furthermore, pipelines are responsible for transporting vast quantities of oil and natural gas, fueling economies and industries across continents. The interconnectedness of these systems means that a disruption to one could potentially cascade and impact others, creating a complex risk matrix that few national security planners had fully mapped until quite recently.

Two forces are now pulling this risk matrix in opposite directions at once. On one side, the offshore wind sector is expanding at a clip that would have seemed ambitious a decade ago - several Asia-Pacific governments have set multi-gigawatt offshore wind targets for the back half of this decade, each requiring its own web of subsea export cables and interconnectors. On the other side, the data-center boom driving today's artificial intelligence buildout is itself creating enormous new demand for transoceanic bandwidth, with hundreds of billions of dollars in planned hyperscaler capital expenditure ultimately depending on a relatively small number of cable systems to actually connect those facilities to the rest of the world. More cable in the water is, in one sense, good news for resilience through redundancy. But it also means more kilometers of vulnerable infrastructure for an already-stretched repair fleet to maintain, a tension this piece will return to.

Vulnerabilities and evolving threats

The physical characteristics of undersea infrastructure, coupled with the vastness and inaccessibility of the marine environment, render it inherently vulnerable to a spectrum of threats, ranging from accidental damage to deliberate sabotage.

Frequency of incidents and primary causes

Globally, the International Cable Protection Committee puts the baseline at somewhere between 150 and 200 faults per year on subsea cable systems - a range that has held remarkably steady even as overall cable route mileage continues to climb. The industry's own analysts at SubTel Forum, who track publicly reported incidents specifically, recorded 46 such incidents in a single recent year, the highest annual figure since they began compiling this data over a decade ago, and a sharp jump from the roughly fifteen reported the year before. Taken in isolation, that kind of jump might suggest an escalating crisis. Looked at over a longer run - SubTel Forum's own decade-long tally counts well over two hundred publicized fault incidents in total, with the Australia-Asia region accounting for more than a third of them, followed by Europe, the Middle East and Africa, then the Americas - the picture is more nuanced: part of the increase almost certainly reflects heightened public attention to a phenomenon that was previously handled quietly by operators, rather than a proportional increase in actual incidents.

The overwhelming majority of these incidents remain accidental, stemming from ordinary human maritime activity rather than malice:

  • Accidental human activity. Fishing and anchoring incidents account for a staggering 86% of subsea cable faults. This includes roughly 44% from suspected fishing or anchoring of unspecified origin, 28% directly attributed to fishing activities, and 14% to anchoring proper. Most accidental damage occurs in depths of less than 200 meters, where human maritime activity is most concentrated.
  • Natural phenomena. Geological events contribute to around 7% of faults, while abrasion accounts for roughly 4%. Underwater rockslides and seismic activity collectively represent approximately 10% of faults, a factor that is beyond human control but can be mitigated through resilient design and route diversification.
  • Malicious actions and sabotage. While statistically less frequent, intentional damage poses the most profound national security risks. Investigators in several Western capitals have increasingly pointed toward state-linked actors, with particular scrutiny falling on vessels connected to Russia and China. Russia is widely assessed to operate specialized submarines and intelligence-gathering vessels theoretically capable of interfering with undersea cables, while China's expanding role in cable construction and repair, coupled with its broader geopolitical posture, has raised questions in some quarters about the potential strategic leverage that comes with helping to build, lay, and maintain infrastructure that others depend on. Both governments have consistently denied any involvement in deliberate sabotage.

Distribution of the ~200 annual subsea cable faults, heavily dominated by human maritime activities.

Methods of attack: from low-tech to high-tech

The methods employed for targeting undersea infrastructure are diverse, ranging from unsophisticated tactics that maintain plausible deniability to highly specialized and covert operations.

  • Anchor dragging. States or proxy actors can utilize anchor dragging as a low-sophistication tactic. This allows for targeting critical infrastructure while preserving plausible deniability, making attribution genuinely difficult even when investigators have a strong working theory. One widely cited case involved a vessel dragging its anchor across the seabed for well over a hundred miles in the Gulf of Finland, damaging a gas pipeline and several telecommunications cables in the same passage - a single anchor track that managed to sever multiple, separately owned assets belonging to different countries. The pipeline dimension of this kind of sabotage is not confined to the Baltic, either; our investigation into the Balkan Stream pipeline saga explores a comparable pattern of energy-infrastructure sabotage entangled with domestic politics further south.
  • Cutting devices. More direct physical attacks involve specialized cutting devices. A patent published by a Chinese university describes a "dragging-type submarine cable cutting device," illustrating the active development of such capabilities, even if the device's stated purpose is framed in benign, dual-use terms. In an earlier real-world incident, the Egyptian coast guard intercepted divers attempting to cut a major Mediterranean cable near Alexandria - a reminder that not every threat originates from a vessel's anchor locker.
  • Deep-sea submersibles. At the higher end of the sophistication spectrum, advanced military capabilities come into play. Russia's "Losharik" submarine is reportedly designed with the specific objective of disrupting global infrastructure systems by targeting submarine cables at depths well beyond the reach of conventional vessels, highlighting a dedicated state-level offensive capability that exists almost entirely outside the realm of plausible deniability.
  • Cyber warfare. Modern seabed warfare has expanded beyond physical intervention to encompass cyber warfare. Attacks on the operational technology systems that monitor and manage undersea infrastructure, or on the landing stations that serve as the critical land-sea interface, could disable or degrade services without any direct physical contact with the cable itself.

Geographical chokepoints and limited redundancy

Certain geographical locations, or chokepoints, concentrate a disproportionate amount of global data traffic, rendering them acutely vulnerable. The Red Sea stands out as a critical internet and telecommunications bottleneck, with an estimated 90% of communications between Europe and Asia and roughly 17% of global internet traffic traversing its cables - a narrow waterway carrying a wildly disproportionate share of the world's data. Readers interested in how this kind of geographic concentration shapes great-power competition more broadly may find our piece on Heartland versus Rimland dynamics a useful companion: the same logic that makes a land corridor strategically vital also applies, almost unchanged, to a seabed corridor a few kilometers wide.

The Baltic Sea presents a different but equally instructive case of geographical concentration. Spanning roughly 149,000 square miles, it is characterized by shallow waters, narrow basins, and access limited to three constrained passages through the Danish straits - the Great Belt, the Little Belt, and the Øresund. In the few years since the war in Ukraine escalated, around ten subsea cables connecting the region have been cut or damaged, with a notable cluster of incidents occurring over a single winter. The repeated nature of these incidents, several of which involved vessels with opaque ownership structures or unusual maneuvering patterns over the cable routes, has propelled the region to the forefront of international discussions on subsea cable security - a discussion that, as we shall see, has continued well into the most recent winter as well.

Furthermore, the greatest threat arises when damage occurs in areas with limited redundancy and repair capacity. Repairing a subsea fiber-optic cable is a complex and expensive endeavor, costing approximately $500,000 to $1 million per incident. For subsea power cables, the cost can escalate dramatically to $10 million to $100 million per incident - and, as the Baltic cases below illustrate, real-world repairs to a major interconnector have landed squarely at the upper end of that range. These repairs necessitate specialized ships and crews, which are few in number and often globally dispersed, leading to potential delays that can span several months and exacerbate the impact of any disruption.

A century of undersea warfare: historical context

The strategic importance of undersea cables is not a contemporary discovery; states have recognized and exploited their vulnerabilities for well over a century, and a brief excursion into this history illuminates just how enduring the pattern has been.

Early precedents: the age of telegraphy

The Spanish-American War provided one of the earliest demonstrations of undersea cable warfare. The U.S. Navy notably cut British-owned cables connecting Cuba, despite Britain's declared neutrality in the conflict. Captain George Squier of the U.S. Army Signal Corps, recognizing the profound strategic implications of this episode, famously asserted that undersea cables constituted "a powerful instrument of war, more important than battleships and cruisers." This early recognition set a precedent that would echo through every major conflict of the following century.

The World Wars: severing the enemy's voice

During both World War I and World War II, belligerent powers fully grasped the strategic value of undersea cables. Britain, leveraging its naval supremacy, effectively targeted German cables, forcing Germany to rely on less secure - and thus more easily interceptable - radio communications for much of its wartime signaling. Similarly, the Imperial Japanese Navy attacked British cables and relay stations in the Pacific theater, while the Royal Navy developed midget submarines specifically for cable-cutting operations, underscoring the tactical importance these assets held in maritime strategy on both sides of the conflict.

The Cold War: espionage beneath the waves

The Cold War era saw a significant escalation in clandestine undersea activities. The Soviet Union reportedly outfitted elements of its vast fishing and merchant fleets with intelligence-gathering and marine sabotage equipment, blurring the line between civilian and military maritime presence in a manner that anticipates much of today's "dual-use" debate. In parallel, the United States conducted covert operations to interfere with Soviet undersea cables. One of the most famous examples, the U.S. Operation Ivy Bells, involved successfully tapping a Soviet cable linking a naval base for nearly a decade, providing invaluable intelligence before its eventual compromise. These incidents underscore the enduring nature of undersea infrastructure as a domain for espionage and strategic disruption, even during periods of ostensible peace - a lesson policymakers are now relearning in real time.

Timeline of subsea warfare, illustrating a century-long precedent of targeting strategic communications.

The contemporary surge: Baltic Sea and Taiwan Strait incidents

If the historical record establishes that undersea cables have always been a target in times of conflict, the period since the war in Ukraine escalated has brought the issue back into sharp, almost daily focus - particularly in two theaters that, on the surface, could not be more different.

The Baltic Sea: a pattern that keeps repeating

In the Baltic Sea, a string of incidents involving power cables, telecommunications links, and gas pipelines has prompted NATO to substantially boost its presence in the region with frigates, maritime patrol aircraft, and naval drones. Investigations have produced a genuinely mixed record. One early case, involving a vessel that dragged its anchor for more than a hundred miles across a pipeline and several telecommunications cables linking Finland, Estonia, and Sweden, did result in formal scrutiny of the ship and its anchor. A second case, in late 2024, saw two cables - one connecting Lithuania and Sweden's Gotland Island, the other running between Finland and Germany - severed within hours of each other, prompting accusations of hybrid warfare from European officials even as the damage was never conclusively attributed to a specific party; a Chinese-flagged cargo vessel that had been in the area, and that had recently departed a Russian port, came under sustained scrutiny from Swedish, Finnish, German, and Danish investigators, who were eventually permitted to board it.

In response to this accumulating pattern, NATO launched Baltic Sentry, a multinational activity intended to increase patrols, enhance situational awareness, and signal that the alliance reserves the right to act against vessels suspected of posing a security threat to critical infrastructure.

The pattern has not stopped since. On the last day of one recent year, a Finnish telecommunications operator detected a serious disruption on a fiber-optic line running along the Baltic seabed between two capitals; Finnish authorities subsequently took control of a vessel and escorted it into port for inspection. A few days into the new year, an undersea telecoms cable linking two coastal towns roughly 65 kilometers apart - one in Lithuania, one in Latvia - was found damaged. Latvian police boarded a docked vessel and opened criminal proceedings, though within days they reported finding no evidence directly linking that ship to the cable damage and said the investigation would continue. Taken together, these incidents - alongside several others affecting Finland-Estonia and Sweden-Estonia links over the same winter - illustrate something important: even with heightened NATO patrols, a heavily monitored sea, and a standing alliance task force watching for exactly this kind of activity, the basic problem of catching a vessel in the act, and then proving intent, has not gone away.

The Eagle S case: why prosecutions keep collapsing

No single incident illustrates the legal dimension of this problem better than the case of the Eagle S, an oil tanker flagged in the Cook Islands and widely described by Finnish and Estonian officials as part of Russia's sanctions-evading "shadow fleet."

On Christmas Day of one recent year, the Estlink 2 power cable connecting Finland and Estonia - along with four separate telecommunications cables - was severed in the Gulf of Finland. Finnish authorities contacted the Eagle S to ask about the status of its anchors; the crew reported, incorrectly, that the anchors were secured. The vessel continued on its route, ultimately dragging its anchor for somewhere in the region of 90 kilometers across the seabed, before Finnish authorities invited it into territorial waters and boarded it.

What followed was, by most accounts, the first serious judicial attempt anywhere to prosecute the crew of a vessel for this kind of infrastructure damage. The captain and two senior officers - a Georgian national and crew members of other nationalities - were charged with aggravated criminal damage and aggravated interference with communications. The trial established, without much dispute, that the damage had caused tens of millions of euros in losses within Finland, easily clearing the threshold for "aggravated" offenses under Finnish law.

And then the case collapsed - not on the facts, but on jurisdiction. The Helsinki District Court ruled that, because the anchor-dragging occurred in Finland's exclusive economic zone rather than its territorial waters, the incident had to be treated under the UN Convention on the Law of the Sea as an "incident of navigation." Under UNCLOS, criminal jurisdiction over such incidents belongs to the vessel's flag state - in this case, the Cook Islands - or to the home countries of the crew. The court dismissed all charges, and the Finnish state was left to cover the defendants' legal costs, reportedly close to €195,000. Prosecutors have appealed the ruling, but the practical lesson is already clear, and it is one that any operational planner would recognize immediately: a flag of convenience and a foreign crew can function as a genuinely effective legal shield, almost regardless of how clear the physical evidence of anchor-dragging turns out to be.

The cable itself took roughly seven months to fully repair, at a cost reported to run as high as €60 million - figures that sit comfortably within, if not above, the $10-100 million range typically cited for major subsea power cable repairs, and which give some sense of why operators and insurers are watching this jurisdictional question so closely.

Taiwan and the question of coordination

The waters around Taiwan have witnessed a parallel - though geographically distinct - pattern. Taiwanese and European authorities have together logged more than twenty separate cases of undersea cable damage around Taiwan and in the Baltic Sea combined in the past few years, a figure that, on its own, says a great deal about how routine this category of incident has become.

On several occasions, cables connecting Taiwan's main island to its outlying territories, including the Matsu and Penghu island groups, have been severed by vessels that Taiwanese authorities have linked, with varying degrees of confidence, to Chinese ownership or crewing. One incident near Yehliu, a peninsula on Taiwan's northern coast, involved a Hong Kong-registered freighter that Taiwan's coast guard placed under investigation after cables in the area were found damaged. Notably, the damage in that case did not disrupt communications, since operators were able to reroute traffic to backup cables - a small but telling demonstration that redundancy, where it exists, does its job.

What has drawn more attention from regional analysts, however, is a more recent pattern in which the same freighter's movements appeared to coincide, in time and space, with those of a separate vessel registered in Russia. Specialist publications focused on the region have suggested this kind of overlap - a Chinese-linked merchant ship and a Russian-linked merchant ship operating in apparent proximity near sensitive cable routes - may point toward a degree of coordination between Moscow and Beijing on maritime sabotage activity, building on earlier indications of Chinese vessels receiving what was described as Russian assistance during the 2023-2024 wave of Baltic incidents. Both Chinese and Russian officials have generally declined to comment substantively on these allegations, or have denied involvement outright.

As one regional security researcher put it when discussing the broader pattern of suspicious cable incidents, the entire point of operating in this "gray zone" is about being deniable - just deniable enough so that even though everybody knows it's you, they can't prove it's you. That single observation arguably does more to explain the last several years of subsea incidents, from the Baltic to the Taiwan Strait, than any individual case file.

In each Taiwan case to date, telecommunications operators have managed to reroute traffic to backup cables, avoiding service disruption even as the incidents themselves have fueled concerns about so-called "gray zone" activity - hostile actions calibrated to fall short of an act of war while still degrading an adversary's resilience. Taiwan's coast guard has explicitly framed several of these episodes in precisely those terms, while officials in Beijing have, for their part, generally declined to comment substantively on the allegations. European officials have separately stated that they consider any deliberate destruction of critical undersea infrastructure unacceptable, drawing an explicit line connecting incidents from the Baltic Sea to the Taiwan Strait as part of the same broader trend.

What both theaters share, beyond the obvious geopolitical backdrop, is the now-familiar combination of opaque ship ownership, flags of convenience, and damage that is - on its face - indistinguishable from an ordinary maritime accident.

Technical aspects of submarine cables

Understanding the physical and technical characteristics of submarine cables is crucial for comprehending their vulnerabilities and the challenges associated with their protection and repair - and, frankly, for appreciating just how much engineering effort goes into something most people will never see.

Structure and composition

Submarine optical fiber cables are engineered for extreme environments. A typical structure consists of fibers encased in a water-blocking gel, a protective steel tube, an inner sheath of high-density polyethylene, double steel wire armor for mechanical protection, and an outer layer of polypropylene yarn. This layered construction provides resilience against pressure, abrasion, and intrusion, though, as the methods of attack discussed above make clear, no amount of armoring can fully neutralize a determined anchor.

Cross-section of an ultra-low-loss submarine cable designed to withstand extreme deep-sea pressures.

Dimensions, depth, and strength

These cables exhibit varying dimensions and strengths depending on their intended application and deployment depth. Outer diameters can range from roughly 15mm to 45mm, with weights in air typically between 0.5 and 6.0 tonnes per kilometer. A specific unrepeated cable design might have an outer diameter of around 34mm and weigh roughly 55 kilograms per kilometer in air. They are designed for seabed environments at depths up to 8,000 meters, though the maximum laying depth for certain armored types intended for shallower, higher-traffic areas may be limited to around 500 meters. Breaking loads vary significantly, with minimum breaking loads around 400 kilonewtons for some configurations, rising to roughly 550-800 kilonewtons for double-armored cables - figures that speak to the genuinely punishing environment these systems are built to survive.

Fiber type and lifespan

Submarine cables primarily utilize ultra-low-loss single-mode fiber, of the type standardized under ITU-T G.654. This fiber type is optimized for C-band and L-band dense wavelength division multiplexing transmission at 1550 nanometers, exhibiting very low attenuation in the region of 0.17 to 0.18 dB per kilometer. This low loss is critical for transmitting signals over thousands of kilometers without significant degradation. Due to their high cost and the difficulty of maintenance, these cables are designed for a long operational lifetime, typically in the order of 25 years - a planning horizon that, in light of the threats discussed throughout this piece, now looks rather optimistic in certain regions.

Legal frameworks and the international response

The complex nature of undersea infrastructure, spanning international waters and national jurisdictions, necessitates a robust - albeit often insufficient - legal and collaborative framework for protection.

Early international law: the 1884 Paris Convention

One of the earliest attempts to address the protection of undersea cables was the International Convention for the Protection of Submarine Telegraph Cables, signed in Paris in 1884. Still in force for a few dozen states, this convention makes it a punishable offense to willfully or negligently break a submarine cable outside territorial waters. However, its effectiveness is constrained by limited enforcement tools and the fact that it does not explicitly extend protection to pipelines, reflecting its pre-modern origins - it was drafted, after all, for an age of telegraphy, not fiber optics.

UNCLOS and its limitations

The United Nations Convention on the Law of the Sea, adopted in 1982, represents a more comprehensive legal framework. UNCLOS incorporates protections for submarine cables and clarifies other matters related to maritime zones and freedoms. Nevertheless, it was negotiated before the widespread advent of the internet and consequently suffers from what specialists have termed "enforcement gaps," particularly concerning modern threats and the evolving nature of maritime activity.

Jurisdiction for criminalizing the willful or negligent breaking of cables on the high seas - and, as the Eagle S case demonstrated, even within a coastal state's own exclusive economic zone - is primarily limited to flag states, creating real challenges for effective prosecution. Furthermore, UNCLOS can lead to tensions with coastal states' national security interests, especially within their exclusive economic zones. It is also worth noting that the United States remains outside the convention, which can complicate certain multilateral efforts.

NATO's coordinated deterrence

Recognizing the escalating threat, NATO has significantly ramped up its focus on critical undersea infrastructure protection through a number of initiatives:

  • Critical Undersea Infrastructure Coordination Cell. Established at NATO headquarters, this cell aims to improve monitoring, information sharing, and overall protection of these vital assets across the alliance.
  • Maritime Centre for the Security of Critical Undersea Infrastructure. Launched at the Vilnius summit, this center is dedicated to developing strategies for preparing for, deterring, and defending against hybrid threats targeting undersea infrastructure.
  • Critical Undersea Infrastructure Network. This network convenes civilian and military authorities, industry representatives, and experts to deepen cooperation and synchronize efforts across various stakeholders, who do not always, it must be said, speak the same institutional language. The network has now held its first formal meeting, a modest but real step toward turning what had been an ad hoc set of national responses into something resembling a coordinated alliance posture.
  • Baltic Sentry. Launched in response to the spate of disruptions in the Baltic Sea, this multi-domain activity seeks to strengthen military presence, enhance situational awareness through consistent patrols involving frigates, patrol aircraft, and naval drones, and improve rapid response capabilities. It draws on NATO's "Digital Ocean Vision" for a comprehensive "seabed to space" surveillance approach, integrating multiple intelligence streams into a single operational picture.

The EU's Action Plan on Cable Security

Where NATO has focused primarily on deterrence and presence, the European Commission has pursued a more structural, funding-driven approach. Announced at a summit in Vilnius and built around four priorities - prevention, detection, response and repair, and deterrence - the EU's Action Plan on Cable Security represents the bloc's most comprehensive attempt yet to treat submarine cables as critical infrastructure in their own right, on a par with power grids or telecommunications networks more broadly.

In practical terms, this has translated into a series of concrete funding instruments. The European Cybersecurity Competence Centre has opened a call worth around €10 million, the first of several over the next few years totaling roughly €21 million, dedicated to establishing Regional Cable Hubs - one per sea basin - that would aggregate monitoring data, apply AI-based threat analysis, and allow for a faster response to incidents. The EU has committed to co-financing up to 70% of the cost of establishing these hubs. Separately, several hundred million euros are earmarked for the following two years to fund digital backbone infrastructure projects, including so-called "smart" subsea cables equipped with built-in sensing capabilities, improvements to the EU's own cable repair capacity, and a prioritized list of "Cable Projects of European Interest."

This sits alongside existing instruments such as the Critical Entities Resilience Directive and the NIS2 cybersecurity directive, both of which now apply more directly to cable operators than they did just a few years ago. Taken together, the EU's approach amounts to a recognition - somewhat overdue, by the Commission's own admission - that submarine cables had been treated for decades as a purely commercial matter, governed by consortium agreements and insurance contracts, when in fact they had quietly become as strategically significant as any pipeline or power line crossing a land border.

National efforts: Japan, Australia, and beyond

Beyond NATO and the EU, individual nations are also implementing measures of their own:

  • Japan has proactively invested in new cable lines and landing stations to diversify its connectivity routes and reduce reliance on single chokepoints. Japan's economy ministry has moved to bring subsea cables formally within the scope of its economic security framework, a designation that would unlock additional subsidy and protection mechanisms for the country's domestic cable-laying fleet.
  • Australia has financed projects such as the Coral Sea Cable System to bolster regional connectivity and mitigate vulnerabilities in a part of the world where alternative routes are not always readily available.
  • The EU's own Secure Connectivity Programme represents a strategic initiative aimed at upgrading and securing the bloc's digital infrastructure against a range of threats, both physical and cyber.
  • The United States established a dedicated Cable Security Fleet some years ago, comprising US-flagged repair vessels intended to reduce reliance on foreign-operated ships - an early recognition, in hindsight, of a problem that has only grown more acute since.

The repair fleet bottleneck: an underappreciated vulnerability

If there is one structural weakness that ties together every theater discussed so far, it is the global shortage of vessels capable of actually repairing damaged cables once they have been cut. In a sense, this is the seabed equivalent of a point our analysis of strategic reserves and long wars makes about munitions and fuel stockpiles: it is rarely the first incident that breaks a system, but the second, third, or tenth, once the available reserve of capacity to respond has already been committed elsewhere.

The global fleet of cable-laying and repair ships numbers somewhere in the region of 60 to 62 vessels worldwide - a remarkably small figure given that these ships are responsible for maintaining a network spanning well over a million kilometers of seabed. Of that total, industry analysts estimate that only around 19 vessels are dedicated specifically to maintenance work, with roughly 26 focused on new installation and the remainder switching between both roles as contracts demand. Many of these vessels date back to a construction boom around the turn of the millennium, and the fleet is aging accordingly: projections suggest that by 2040, roughly two-thirds of the dedicated maintenance fleet - and close to half of the global cable fleet overall - will have reached the end of its service life, even as total cable mileage is expected to grow by close to half over the same period, with annual repair demand rising at a broadly similar pace.

Addressing this gap, according to industry estimates, would require an investment in the region of $3 billion and the construction of around fifteen replacement vessels plus several additional ships - the bulk of which industry analysts suggest would need to enter service within the next decade. The economics, however, remain stubbornly unfavorable: maintenance contracts tend to be too short to justify the kind of long-term investment a new-build cable ship requires, and at least one major industry player has reportedly exited the maintenance market altogether in order to dedicate its entire fleet to new cable-laying instead - a decision that, however rational for that company, leaves even fewer ships available for repairs at precisely the moment the in-service cable count keeps climbing.

There are signs of movement, even so. One major operator has ordered two new advanced maintenance vessels, each equipped with its own remotely operated underwater vehicle for cutting, inspection, and burial work, specifically to replace two aging ships - one in service since the early 1980s and based in Cape Town, the other dating to the late 1980s and responsible for the Mediterranean, Black Sea, and Red Sea - that between them have covered an extraordinary geographic span for far too long on far too little support.

The consequences of this scarcity are not theoretical. When a cluster of cable faults struck parts of Africa in recent years, the single repair vessel dedicated to serving the entire continent found itself the only resource available, extending repair timelines considerably. In a separate incident affecting Vietnam, all of the country's operational undersea cables suffered partial or total damage in roughly the same period, costing the country a substantial share of its international data capacity; with nearby repair vessels already committed elsewhere, full restoration was not achieved until many months later, forcing telecommunications firms to lease emergency terrestrial capacity in the interim.

Some governments have begun to respond. The United States, as noted above, established its Cable Security Fleet some years ago. Japan has moved toward subsidizing its domestic cable-ship operator. And a small but growing number of specialist firms have begun marketing autonomous underwater vehicles designed to sit on the seabed for extended periods, inspecting cables and pipelines for signs of interference at a fraction of the cost of deploying a crewed vessel on standby. Whether these efforts can close the gap before the existing fleet's age catches up with it remains, at the time of writing, an open question.

The critical imbalance between 1.4 million km of cable and the scarce global fleet of repair vessels.

Detection and monitoring: the technological frontier

Where physical deterrence and legal frameworks have struggled to keep pace with the threat, technology has begun to offer at least a partial answer - and the pace of development in this area over the past two years has been genuinely striking.

A growing emphasis is being placed on autonomous and uncrewed platforms. Autonomous underwater vehicles, uncrewed surface vessels, and portable remotely operated vehicles are now being deployed alongside traditional aircraft and satellites to form a layered sensor network capable of monitoring critical undersea infrastructure far more continuously than periodic ship patrols ever could. Several Northern European navies have established joint experimentation centers specifically to test these technologies against realistic seabed threat scenarios, working alongside private robotics firms that have, in some cases, scaled remarkably quickly from small startups to suppliers of national defense ministries - a dynamic not unlike the one our piece on AI and drone warfare describes in the context of compressed targeting cycles and autonomous platforms more broadly, albeit applied here to the considerably slower-paced business of seabed surveillance.

Perhaps the most conceptually elegant development, however, involves repurposing the cables themselves as sensors. A technique known as distributed acoustic sensing, or DAS, measures subtle changes in strain within a cable's optical fibers, effectively transforming an ordinary data cable into an enormous underwater microphone capable of detecting vibrations - including, in principle, those generated by a passing vessel or submarine. Recent multi-span demonstrations have extended the effective sensing range of this technique well beyond what was achievable only a couple of years ago, with research teams reporting continuous monitoring across cable spans of more than 200 kilometers using enhanced-scattering fiber alongside standard high-capacity data transmission, with the sensing and the data traffic coexisting on the same strands without meaningfully degrading either.

The implications extend well beyond cable protection into the realm of anti-submarine warfare, eroding what has historically been the ocean's greatest gift to those wishing to operate undetected. A cable that can hear a ship's engine noise, or the characteristic acoustic signature of an anchor being lowered, from tens of kilometers away is a fundamentally different proposition for anyone planning a covert operation than a cable that simply carries data until the moment it is cut.

This shift - from a posture of presence to one of pattern recognition - reflects a broader recognition among defense planners that physically guarding over a million kilometers of seabed is simply not feasible, and that the more realistic goal is identifying anomalous behavior early enough to investigate, and ideally intervene, before damage occurs.

Challenges to comprehensive protection

Despite increasing awareness and concerted efforts, significant challenges persist in ensuring the comprehensive protection of undersea infrastructure - and it would be a disservice to readers to pretend otherwise.

  • Attribution difficulties. The inherent nature of many incidents, often presenting as accidental damage such as a snagged anchor or entangled fishing gear, makes it exceedingly difficult to reliably distinguish between genuine accidents and deliberate attacks. The Eagle S case shows that even when the physical evidence of an anchor drag is essentially undisputed, establishing intent - and then successfully prosecuting it - is an entirely different challenge. This ambiguity provides potential saboteurs with plausible deniability, complicating diplomatic and military responses in ways that can drag on for months or, in some cases, years without resolution.
  • Jurisdictional complexities. International law offers minimal protection beyond territorial waters, and existing enforcement mechanisms are weak, particularly when vessels flying flags of convenience are involved. The concept of "digital un-sovereignty" arises from the fact that a significant portion of undersea cables is privately and multinationally owned, creating a complex web of ownership and accountability that can diverge sharply from traditional state-centric security paradigms.
  • The vastness of the infrastructure. The sheer scale of global undersea infrastructure, comprising well over a million kilometers of cables, makes comprehensive, real-time protection an immense logistical and financial undertaking. Monitoring every kilometer effectively is, with current resources, simply not realistic.
  • Dual-use ambiguity. Many civilian vessels and equipment - fishing boats, research vessels, merchant ships - have a dual-use nature. This complicates monitoring efforts considerably, making it difficult to discern malicious intent from entirely legitimate maritime activity. Distinguishing between a routine survey and a reconnaissance mission for potential sabotage requires sophisticated intelligence and persistent surveillance, neither of which is cheap.

The dual-use dilemma: distinguishing routine maritime activity from covert hybrid warfare on the seabed.

Looking ahead

The increasing recognition of undersea infrastructure as a critical theater of competition and potential conflict necessitates sustained international cooperation, technological innovation, and a clear-eyed assessment of geopolitical realities. None of the structural vulnerabilities outlined here - the chokepoints, the aging repair fleet, the jurisdictional gaps exposed so starkly by the Eagle S ruling, the dual-use ambiguity - lend themselves to a quick fix, and it would be naive to pretend that any single initiative, however well-funded, will resolve them in the near term.

What does seem clear, on balance, is that the era of treating the seabed as a neutral, largely unregulated commons is drawing to a close. Whether this shift produces a more resilient and better-governed network, or simply a more heavily militarized one, will likely depend as much on the broader trajectory of great-power relations as on any technical or legal innovation discussed in this piece. The invisible front beneath the waves will, in either case, continue to demand strategic attention as the world's reliance on these vital conduits only grows.

The intricate web of undersea infrastructure forms the vulnerable soft underbelly of the global economy.

Key takeaways

  • Over 95% of international data and an estimated 99% of intercontinental internet traffic travel through undersea fiber-optic cables.
  • A handful of major tech companies - Google, Meta, Amazon, and Microsoft - collectively control roughly half of all undersea bandwidth worldwide.
  • Cable disruptions can cost operators in excess of $1.5 million per hour in lost revenue, and a single earthquake-driven incident off Taiwan once severed nine cables at once, taking nearly seven weeks to fully restore.
  • The ICPC estimates 150-200 faults occur on subsea cable systems globally each year; SubTel Forum separately logged 46 publicized incidents in one recent year - its highest figure since tracking began, up from roughly fifteen the year before.
  • Fishing and anchoring account for roughly 86% of all subsea cable faults, making accidental damage by far the most common cause; natural events such as seismic activity add a further 10%.
  • The Red Sea carries an estimated 90% of communications between Europe and Asia and around 17% of global internet traffic, making it one of the world's most consequential chokepoints.
  • Repairing a subsea fiber-optic cable typically costs $500,000 to $1 million, while a subsea power cable repair can run from $10 million to $100 million - the Estlink 2 interconnector's roughly seven-month repair reportedly approached €60 million.
  • The global cable repair fleet numbers only around 60-62 specialized ships - just 19 of them dedicated maintenance vessels - and by 2040 roughly two-thirds of that maintenance fleet, and close to half of the overall fleet, are projected to reach the end of their service life.
  • Since the war in Ukraine escalated, around ten subsea cables connecting the Baltic Sea region have been cut or damaged, with new incidents continuing into the most recent winter despite NATO's Baltic Sentry patrols.
  • In the Eagle S case, a Helsinki court found it lacked jurisdiction over a Cook Islands-flagged tanker that severed Finland's Estlink 2 power cable and four telecom cables, ordering Finland to pay roughly €195,000 in the crew's legal costs - a stark illustration of UNCLOS's enforcement gaps.
 avatar
@andre
  • Redaction badge
    Redaction
Andre Dees
Senior Military Affairs Analyst
Andre Dees is a retired army colonel with over two decades of distinguished service, having commanded infantry units and held senior positions in joint operational planning and logistics across multiple theaters. Drawing on that depth of field and staff experience, he provides clear, realistic analysis of modern warfare, hybrid threats, territorial defense, and the practical challenges facing European armed forces. His analytical focus is always on logistics, operational feasibility, and the hard realities of force projection - the unglamorous fundamentals that ultimately determine whether military strategies succeed or fail.
No posts yet