The Baltic's invisible front: cables, the shadow fleet and coercion below the threshold of war

How do you defend infrastructure when accident, negligence and sabotage can look almost identical?

📅 Publication date:

Central thesis

Uncertainty can be the most effective weapon

Pressure on Baltic infrastructure does not have to begin with a shot. A severed cable, a vessel with an opaque history and several days of argument over whether the cause was failure, gross negligence, sabotage or a state-directed operation may be enough.

Europe cannot guard every kilometre of seabed. It can, however, deny an attacker the central advantage: the ability to create major disruption through an action that is small, cheap and difficult to attribute.

>99%of intercontinental data traffic is carried by submarine cables
150–200telecommunications cable faults occur globally in a typical year
70air and maritime drones were tested by NATO in the Baltic in 2025
The essential distinction

Damage is not automatically sabotage

Anchors, fishing and other human activity cause most cable faults worldwide, generally without a political intent. The presence of a suspicious vessel near a cable break therefore does not by itself prove a state attack.

Physical mechanismWhich anchor, vessel or physical process damaged the cable?
Legal responsibilityDid the crew act deliberately, with gross negligence, or did equipment fail?
State attributionIs there evidence of instruction, coordination or control by a state?

Each level requires different evidence. Proving the first does not automatically settle the second or the third.

Contents

  1. The internet lies on the seabed
  2. Why the Baltic?
  3. An anchor and three levels of attribution
  4. What does “shadow fleet” really mean?
  5. Can NATO guard every cable?
  6. Europe shifts from protection to resilience
  7. Why does the law of the sea complicate a response?
  8. What does this mean for Poland?
  9. Three escalation scenarios
  10. Conclusion
Infrastructure fact

1. The internet lies on the seabed

Satellites dominate the public image of global connectivity, but fibre-optic cables on the ocean floor remain its real backbone. A joint ITU and International Cable Protection Committee report says that they carry more than 99% of intercontinental data traffic. They support cloud services, payments, government communications, exchanges, logistics and the everyday internet.

Satellites provide valuable backup and reach places without a cable. They cannot replace the aggregate capacity, low latency and transmission economics of fibre. Digital resilience therefore depends on multiple cable routes, diverse landing points and the ability to reroute traffic quickly.

The network is more robust than the image of a single thin line suggests. Operators design in redundancy, and 150–200 global faults a year rarely disconnect a continent. A crisis develops when several routes, a shared node or a landing point fail together — or when a backlog of repairs starts to grow.

Sources: ITU/ICPC — cable resilience report, 2026; ENISA — Subsea cables: what is at stake?.

Strategic assessment

2. Why the Baltic?

The Baltic combines several features that increase both the likelihood of an incident and its political significance. It is shallow, heavily trafficked and densely packed with data and power cables, pipelines, ports, terminals, wind farms and trade routes.

Shallow water makes installation and repair easier, but it also exposes cables to anchors and fishing gear. Dense traffic provides natural cover for error, negligence or deliberate action. A perpetrator needs neither a warship nor explosives. An anchor dragged across the bottom can resemble a familiar shipping accident.

After Finland and Sweden joined NATO, every Baltic coastline except Russia's belongs to an Allied state. That improved defence cooperation but did not remove Russia's military, intelligence or hybrid-pressure capabilities. The sea has become a space where NATO's territorial advantage meets Russia's capacity to manufacture uncertainty.

Incomplete attribution

3. An anchor may identify the ship, not the sponsor

The Eagle S tanker case shows how far technical investigation can go. After the damage of 25 December 2024, Finland's National Bureau of Investigation examined the vessel, the seabed and crew testimony. In June 2025, it referred the case to prosecutors, suspecting the master and two officers of serious offences connected with the cable damage.

That is strong material about the sequence of events and the responsibility of those commanding the vessel. The police's public statement does not, however, say that the crew acted on the Kremlin's orders. That absence does not clear the ship; it marks the boundary between what was established and what was not.

Coercion below the threshold of war exploits precisely this gap. A state can use intermediaries, informal signalling and ships with opaque ownership. It can also exploit a genuine accident for political effect. The defender must respond quickly even though complete evidence may take months to emerge — or never emerge at all.

Source: Finnish Police — conclusion of the Eagle S investigation.

Fact + evidential limit

4. What does “shadow fleet” really mean?

The shadow fleet is not a uniform navy directed from a single headquarters. It is an ecosystem of vessels used to evade restrictions: changing flags, complex ownership, opaque insurance, ageing hulls and practices that make cargoes and responsibility difficult to trace.

The European Union links this fleet primarily to the evasion of restrictions on Russian oil, while also identifying risks to navigation, the environment and undersea infrastructure. Such a vessel could be used as an operational tool, but membership of the shadow fleet is not proof that every incident involving it was planned by a state.

The ecosystem's greatest strategic utility is deniability. An obscure owner, a third-country flag, a multinational crew and a technically plausible “anchor failure” fragment responsibility. The time needed to reconstruct it becomes part of the strategic effect.

Sources: Council of the EU — sanctions on Russia's shadow fleet; EU declaration on the law of the sea, the shadow fleet and undersea infrastructure.

Confirmed action

5. Can NATO guard every cable?

No. Permanently stationing ships over every cable would be expensive, predictable and still could not guarantee protection. NATO therefore launched Baltic Sentry in January 2025, combining frigates, maritime patrol aircraft, national data and uncrewed systems.

The goal is not to observe every metre of seabed but to build a common operating picture: detecting unusual course changes, loss of AIS, prolonged drifting, a dropped anchor and the coincidence between a vessel's track and an operator's alarm. Surveillance should shorten the interval between anomaly, interception and preservation of evidence.

Task Force X-Baltic tested 70 air and maritime drones between March and October 2025. In February 2026, eight Allies — including Poland — agreed to accelerate joint acquisition of surveillance and uncrewed capabilities. This is a move from experimentation to deployment, though not yet an impermeable shield.

Sources: NATO — launch of Baltic Sentry; NATO — Task Force X-Baltic agreement, 2026.

Doctrinal shift

6. Europe shifts from protection to resilience

No government can credibly promise that a cable will never be cut. Better questions are: will one break interrupt a service, how quickly will it be detected, can traffic move to another route and how long will repair take?

PreventDetectRespond and repairDeter

In February 2026, the European Commission presented a Cable Security Toolbox and allocated €347 million to strategic cable projects, smart sensing and repair capacity. In June, it awarded €5.8 million to establish the first two Regional Cable Hubs — for the Baltic and Mediterranean — and launched a €40 million call for emergency repair modules.

The central change is not the militarisation of the entire sea. It is the integration of operators' data with government surveillance, the construction of diverse routes, the pre-positioning of repair equipment, access to specialised ships and rehearsal before a crisis.

Sources: European Commission — toolbox and €347 million; European Commission — Regional Cable Hubs and repair capacity.

Operational constraint

7. Why does the law of the sea complicate a rapid response?

A foreign-flagged ship does not lose legal protection because its course looks suspicious. A coastal state's authority depends on the incident's location, the vessel's status, the grounds for suspicion and the rules of the UN Convention on the Law of the Sea. Different powers apply in territorial waters, the exclusive economic zone and on the high seas.

This creates tension between speed and legality. Acting too late allows evidence to disappear; detaining a ship without sufficient grounds can breach the law and escalate a dispute. The EU is therefore developing a shared understanding of the available tools: flag-state cooperation, hot pursuit, port-state control, sanctions and measures permitted by UNCLOS in specified circumstances.

Deterrence here depends on more than warships. It depends on confidence that a vessel will be identified, its history reconstructed, evidence preserved and legal, financial and operational costs imposed.

Polish perspective

8. What does this mean for Poland?

For Poland, the Baltic is simultaneously a corridor for energy, data, trade and Allied support. Baltic Pipe, the LNG terminal, ports, electricity interconnectors, expanding offshore wind and telecommunications infrastructure form an interdependent system. Failure of one element can be absorbed; coordinated pressure on several would be much more serious.

Poland should not measure security only by the number of patrols. Better indicators include:

Public communication also matters. Premature accusation without evidence erodes credibility. Excessive caution can conceal a recurring pattern. The state should report separately what physically happened, what remains under investigation and what level of attribution has been reached.

Sources: Gaz-System — Baltic Pipe's offshore infrastructure; Polish National Security Bureau — “Maritime Poland”, National Security 46/2025.

Scenarios, not a forecast

9. Three levels of escalation

1. Accident in a tense environment

An anchor cuts a cable without political intent. Panic, false attribution and unnecessary escalation become the main risks.

2. A deniable pressure campaign

A series of hard-to-prove incidents tests responses, raises costs and weakens trust while remaining below the threshold of open attack.

3. Preparation of the battlespace

Route reconnaissance, cyberattacks on operator systems and coordinated physical damage aim to constrain communications and logistics during a crisis.

Without intelligence data, precise probabilities for these scenarios would be false precision. Their value lies in testing resilience, not pretending to offer a certain forecast.

Conclusion

Resilience deprives a small attack of its purpose

A future Baltic crisis could begin without a shot and without anyone admitting that an attack occurred. Watching Russian warships is therefore not enough. Civilian and military data must be combined, merchant vessels tracked, landing points protected, alternative routes created and repair times shortened.

The most effective defence is not a promise that no cable will ever be cut. It is the assurance that an incident will be detected quickly, traffic rerouted, evidence preserved, service restored and responsibility established to the degree the facts allow.

If a small and ambiguous act cannot produce a large crisis, it loses much of its value as an instrument of coercion.

Editorial note

This article separates confirmed facts, strategic assessment and scenarios. “Shadow fleet” describes an operating model and ownership structure; it is not automatic proof of involvement in sabotage. References to specific incidents are limited to findings published by the competent authorities.

Sources and documents

  1. ITU and ICPC — International Advisory Body on Submarine Cable Resilience, 2026 report
  2. ENISA — Subsea cables: what is at stake?, 2023
  3. National Bureau of Investigation Finland — investigation of the damage on 25 December 2024
  4. NATO — Baltic Sentry, 14 January 2025
  5. NATO — Task Force X-Baltic and the rapid-adoption agreement, 2026
  6. European Commission — Cable Security Toolbox and €347 million investment, 2026
  7. European Commission — Regional Cable Hubs and repair-capacity call, 2026
  8. EU — Action Plan on Cable Security: prevent, detect, respond, repair and deter, 2025
  9. Council of the EU — declaration on the law of the sea, the shadow fleet and undersea infrastructure, 2025
  10. Council of the EU — sanctions on Russia and shadow-fleet vessels
  11. Gaz-System — Baltic Pipe offshore pipeline
  12. Polish National Security Bureau — “Maritime Poland”, National Security 46/2025

Back to Geopolitics