Russia's Shadow Fleet and the Undersea Cable Campaign
RAGE Global · Intelligence Analysis · Updated 2026-08-28 · 12 min read
RAGE X ANALYSIS — Expert assessment authored and reviewed by Carlos Kfoury. This is analysis, not reportage. Factual claims carry source attribution; judgements carry confidence labels. Attribution of specific incidents is presented as the assessment of the investigating authority, with denials recorded.
An anchor dragged across a seabed is an accident until someone proves otherwise. That is not a flaw in the technique. It is the technique.
Executive Assessment
Since late 2023, undersea power and communications cables in the Baltic Sea have been damaged repeatedly by vessels dragging anchors along the seabed. Baltic states attribute the pattern to Russia's shadow fleet. The shipowners deny it. Proving intent has been the central problem throughout.
First, the incidents are real and repeated. The Estlink 2 power cable between Estonia and Finland plus four data cables were damaged by the dragging anchor of the Eagle S oil tanker. On 25 December 2024 a Cook Islands-registered vessel was boarded by Finnish authorities over suspected damage to Finland–Estonia and Finland–Germany cables. On 31 December 2025 a cargo ship was detained by Finland over damage in Estonia's EEZ — with a 10 km drag mark on the seabed. On 26 January the Swedish coast guard boarded a vessel on suspicion of anchor dragging; Latvia dispatched a warship. (Confidence: Confirmed as reported incidents; attribution contested)
Second, the shadow fleet is not only a sanctions-evasion instrument. The vessel detained by Finland on 31 December 2025 was found to carry sanctioned Russian steel and had been identified as shipping military goods between Russia and Iran. German authorities have expressed strong suspicions the shadow fleet played a role in deploying drones into Europe, though proof was not established. (Confidence: Confirmed as reported)
Third, NATO's response has measurably worked. Baltic Sentry, launched 14 January 2025, produced a significant reduction in malicious sabotage against critical undersea infrastructure between January 2025 and January 2026, and cut response times to suspicious incidents from 17 hours to one hour. (Confidence: Confirmed as NATO assessment)
Fourth, it imposed a cost on Russia that is arguably larger than the sabotage achieved. Moscow now escorts ageing shadow fleet vessels with warships, which NATO's Allied Maritime Command describes as creating a force flow issue for an already strained Russian surface fleet — pushing Northern Fleet ships into the English Channel and wider Atlantic to cover that shipping. (Confidence: Confirmed as NATO assessment)
Fifth, attribution remains the unsolved problem and it is deliberate. Russia's actions rely on deniability through submarines, UUVs, the shadow fleet and commercial vessels, making sabotage difficult to attribute and harder still to prove. Without clear attribution, Baltic Sentry struggles to respond to attacks without proof of sabotage. (Confidence: Confirmed as published assessment)
The Incident Record
| Date | Incident | Response |
|---|---|---|
| October 2023 | Newnew Polar Bear incident | Individual national protocols existed; no cross-border information-sharing or joint response framework |
| 25 December 2024 | Cook Islands-registered ship suspected of damaging Finland–Estonia and Finland–Germany cables | Boarded by Finnish authorities |
| December 2024 | Eagle S tanker anchor damages Estlink 2 plus four data cables | European Commission identified the vessel as part of Russia's shadow fleet |
| 27 December 2024 | NATO announces enhanced Baltic presence; Estonia begins naval operation guarding an electricity line | Rutte announcement following discussion with Finnish President Stubb |
| 14 January 2025 | Baltic Sentry launched at a Helsinki summit | Multi-domain vigilance activity |
| 26 January 2025 | Swedish coast guard boards vessel on suspicion of anchor dragging; Latvia sends warship | Bulgarian-linked vessel investigated; owner denies involvement |
| 31 December 2025 | Cargo ship suspected of damaging cable in Estonia's EEZ; 10 km anchor drag mark | Detained by Finland; found carrying sanctioned Russian steel and identified as shipping military goods between Russia and Iran; escorted out |
| January 2025 – January 2026 | Significant reduction in sabotage recorded | Response time cut from 17 hours to one |
Handling note. Every incident above is reported with the investigating authority's finding. Where a shipowner denied involvement, that denial is recorded. RAGE INTEL does not assert intent in any individual case; the pattern-level attribution is the assessment of Baltic and NATO governments and is reported as such.
Why Cables
Undersea cables carry gas, electricity and internet traffic between nations. The Baltic states connect to Northern and Central Europe through them. A severed cable is not a symbolic act — it is a measurable loss of national connectivity and, in the case of power interconnectors, of grid resilience.
The strategic message, per academic assessment of the pattern, is that the capability exists to essentially cut off and isolate nations from the outside world. Attacks on undersea cables are comparable to traditional espionage and information operations: activity conducted below the level of warfare, designed to send signals to adversarial nations.
There have also been credible reports that Russia has actively been mapping undersea infrastructure — which is the reconnaissance step that precedes any deliberate campaign and is itself difficult to distinguish from legitimate survey activity.
RAGE INTEL judgement: cable interference is close to an ideal grey-zone instrument. The damage is real and expensive; the attribution is deniable; the cost to the actor is a dragged anchor; and the target's available responses are all either disproportionate or ineffective. It occupies precisely the space Article 5 does not reach — an armed attack is required to trigger collective defence, and an anchor is not obviously an armed attack. (Confidence: Analysis, high)
What Baltic Sentry Actually Did
Launched at a Helsinki summit on 14 January 2025, following a NATO declaration of solidarity on 30 December 2024.
Structure. No fixed end date. A dedicated command chain through Joint Force Command Brunssum and Allied Maritime Command. A new NATO Maritime Centre for Security of Critical Undersea Infrastructure as the knowledge hub. Allied warships and aircraft monitoring critical seabed sectors, with ORP Czernicki as a command platform.
Results, per NATO. Significant reduction in malicious sabotage January 2025 – January 2026. Response time to suspicious incidents cut from 17 hours to one hour.
Second-order effects. The mission became a template — three later enhanced vigilance activities, Eastern Sentry and Arctic Sentry among them, copied its structure. It generated its own procurement line in Task Force X-Baltic, an autonomous-surveillance initiative that eight Baltic allies moved from experiment toward national ownership in early 2026.
The cost imposed on Russia. Escorting shadow fleet vessels ties up warships. Northern Fleet ships have been pushed into the English Channel and wider Atlantic. For a navy already strained, that is a real and continuing tax.
What it has not solved
Baltic Sentry has not stopped undersea sabotage. Reduction is not elimination.
Coverage is a physical problem. Critical undersea infrastructure is vast — thousands of fibre-optic cables and energy pipelines. Operators must prioritise patrol areas, which leaves some infrastructure unmonitored by definition.
Attribution remains the binding constraint. Submarines, UUVs, shadow fleet vessels and ordinary commercial shipping all provide deniability. Without proof of sabotage, the response options narrow to monitoring and escort.
The untested case. The Atlantic Council identifies the real test: what happens when a vessel ignores patrol instructions and coastal state direction to change course. That scenario has not yet occurred and every current protocol assumes compliance.
The Legal and Escalation Problem
This is where the file connects to the broader alliance question.
Article 5 turns on armed attack. Cable damage by anchor dragging is not obviously that, and the ambiguity is the point. NATO has stated that cyber attacks could in principle trigger Article 5, and comparable logic has been extended to hybrid operations — but could in principle is not a threshold, and its deliberate absence cuts both ways.
Allied governments have moved to harden the legal regime protecting the cables themselves, which is the more realistic route: making interference a prosecutable offence with jurisdictional reach rather than a matter of collective defence.
Responses to the shadow fleet have become stronger — French, US and British naval forces boarding, intercepting and tracking. Each of those is a national law-enforcement or maritime-safety action rather than a collective defence one, which is precisely how a state responds to something below the armed-attack threshold.
The unresolved question: at what accumulated volume does deniable sub-threshold activity become something the Alliance must treat differently? There is no published answer, and RAGE INTEL's assessment is that there will not be one — it will be settled by a member invoking Article 4 over a specific incident and the collective response establishing precedent. That is a political act, not a legal one.
The Wider Pattern
Cable interference is one instrument among several operating below the threshold:
| Domain | Activity | Attribution status |
|---|---|---|
| Land border | Instrumentalised migration — Finland closed its 1,340 km eastern border in December 2023 | Finnish government assessment; Kremlin denies |
| Seabed | Cable and pipeline damage | Baltic and NATO assessment; owners deny |
| Electromagnetic | GPS jamming and spoofing affecting civil aviation and maritime navigation across the Baltic | Widely attributed; contested |
| Airborne | Drone incursions into European airspace | German suspicions of shadow fleet involvement; proof not established |
| Information | Continuous | Not applicable |
Each individually sits below the response threshold. Cumulatively they impose substantial cost while giving the Alliance no clean legal moment at which collective defence engages.
Taiwan is the other region most affected by suspicious incidents involving undersea cables and pipelines — a parallel worth noting, because it indicates the technique is not Russia-specific and is being observed by others.
Key Judgements
| # | Judgement | Confidence |
|---|---|---|
| 1 | Repeated Baltic cable damage by anchor dragging is documented across multiple incidents since 2023 | Confirmed |
| 2 | Baltic and NATO governments attribute the pattern to Russia's shadow fleet; owners deny individual incidents | Contested attribution |
| 3 | Shadow fleet vessels have carried sanctioned goods and military cargo alongside oil | Confirmed as reported |
| 4 | Baltic Sentry reduced sabotage and cut response times from 17 hours to one | Confirmed as NATO assessment |
| 5 | Russian warship escort of shadow fleet vessels imposes a force flow cost on a strained surface fleet | Confirmed as NATO assessment |
| 6 | Attribution, not detection, is the binding constraint on response | Confirmed as published assessment |
| 7 | Cable interference sits deliberately below the Article 5 armed-attack threshold | Analysis — high |
| 8 | Coverage of critical undersea infrastructure is physically incomplete and will remain so | Analysis — high |
| 9 | The untested case — a vessel ignoring instructions — is the real test of the current framework | Confirmed as published assessment |
| 10 | Legal hardening of cable protection is a more realistic route than collective defence | Analysis — medium-high |
| 11 | Baltic Sentry's structure has become the template for Eastern and Arctic Sentry | Confirmed |
Indicators to Watch
- Any vessel ignoring patrol instructions. The scenario every current protocol assumes will not happen.
- Task Force X-Baltic autonomous surveillance fielding — the scalable answer to the coverage problem.
- Prosecutions under hardened national cable-protection law, and whether any secure a conviction for deliberate damage.
- Incident rate through 2026 against the January 2025 – January 2026 reduction.
- Any Article 4 invocation over an undersea incident, which would begin establishing precedent.
- Russian Northern Fleet deployment patterns — escort duty is a measurable tax.
- Extension of the technique beyond the Baltic, particularly the North Sea and Atlantic approaches.
- Comparable incidents around Taiwan, indicating diffusion of the method.
Sourcing and Methodology
Tier 1 to Tier 3: NATO Allied Maritime Command statements, national coast guard and government announcements, the Atlantic Council, and established press and academic analysis.
Attribution requires specific care on this subject. Individual incidents are reported with the investigating authority's finding and the shipowner's denial where recorded. Pattern-level attribution to Russia is the stated assessment of Baltic and NATO governments and is reported as such rather than adopted as established fact. Russia denies involvement.
NATO assessments of the effectiveness of NATO operations are treated as interested. Where the underlying metrics are specific — response times, incident counts — they are reported with attribution.
This assessment describes publicly reported incidents and publicly announced alliance activity. It contains no cable route vulnerability analysis, no infrastructure location detail beyond what has been published in incident reporting, and no interference technique description.
Principal references
- NATO Says Baltic Sentry Helped Slash Russian Undersea Infrastructure Sabotage, United24 Media — https://united24media.com/world/nato-says-baltic-sentry-helped-slash-russian-undersea-infrastructure-sabotage-cut-response-time-to-one-hour-19954
- What Russia's Baltic Cable Sabotage Tells Us About Its Shadow Fleet, United24 Media — https://united24media.com/world/what-russias-baltic-cable-sabotage-tells-us-about-its-shadow-fleet-15819
- How the Baltic Sea nations have tackled suspicious cable cuts, Atlantic Council — https://www.atlanticcouncil.org/in-depth-research-reports/issue-brief/how-the-baltic-sea-nations-have-tackled-suspicious-cable-cuts/
- Suspected Baltic Sea cable sabotage by Russia's shadow fleet, The Conversation — https://theconversation.com/suspected-baltic-sea-cable-sabotage-by-russias-shadow-fleet-is-ramping-up-regional-defence-248241
- Securing the Depths: NATO's Need for Regional Cooperation in Baltic Sea Infrastructure Defense, American University — https://www.american.edu/sis/centers/transatlantic-policy/articles/20250424-securing-the-depths.cfm
- Drones and dragging anchors: Inside NATO's secret undersea battle against Russia, BFBS Forces News — https://www.forcesnews.com/nato/drones-and-dragging-anchors-inside-natos-secret-undersea-battle-against-russia
- Baltic Sea Security: Shadow Fleet, Seabed Cables, GPS Spoofing and Interdiction Rules, Grosswald — https://www.grosswald.org/baltic-sea-security-tracker/
- The Baltic Sentry: NATO Effort to Deter Russia's Shadow Fleet, Joint Baltic American National Committee — https://www.jbanc.org/baltic-insights/the-baltic-sentry-nato-effort-to-deter-russias-shadow-fleet-in-the-baltic-sea
Corrections policy — errors are corrected promptly with a notice appended. No silent edits, ever. Corrections to: intel@ragex.co
RAGE INTEL — Intelligence that moves before the news does.
RAGE X Corp · Decode. Dominate. Deliver.