Skip to content

II Cyber Warfare & Critical Infrastructure·Analysis·Europe

The invisible front: subsea cables, zero-day vulnerabilities and 153 million identity documents

Three incidents that came to light in a single week show the threat to critical infrastructure growing simultaneously across the physical, software and data layers.

Cyber & Critical Infrastructure Desk · 12 September 2026 · 8 min read · 5 sources

The white cable-laying ship Global Sentinel at sea
Submarine cable-laying ship Global Sentinel (2008) — archive photoPhoto: Nc tech3 / Wikimedia Commons · CC BY-SA 4.0 · resized · Source

Why it matters

A sabotage rehearsal targeting the Svalbard cables, the BlueMoon exploit kit rapidly shared by China-aligned groups and the theft of 153 million driving licence scans show different actors targeting the same weakness: the dependence of critical services on a small number of physical links and suppliers.

Implications

  • Because satellite data infrastructure depends on a few cables on the seabed, a single act of sabotage could disrupt it on a regional scale.
  • Zero-day vulnerabilities being shared among state-linked groups within a few days effectively eliminates the window between patch and exploitation.
  • The concentration of identity verification services in a single supplier means one breach can affect millions of people in two countries.

Physical layer: cables

As reported by Defense News, the United Kingdom, Norway and the United States tracked and intercepted submarines belonging to GUGI, Russia's deep-sea research directorate, in spring 2026. The submarines were reported to have rehearsed a set-up capable of disabling cables without leaving a trace. The two cables in the target area connect Svalbard to the Norwegian mainland; each is about 1,400 kilometres long and descends to a depth of 2,700 metres.

The importance of these cables lies in the data they carry: they transmit data from SvalSat, the world's largest satellite ground station, which is also connected to the NASA network. No cable was damaged. The real message of the incident is that sabotage capability can be rehearsed in peacetime and that detection is possible only through joint allied maritime tracking. Cable security is no longer merely a telecoms matter but a question of the continuity of space and defence data.

Software layer: a shared exploit kit

According to Proofpoint's report of 9 September, the BlueMoon kit, first seen on 28 August, chains two Chrome V8 vulnerabilities with a Windows kernel vulnerability. The company identified four attacker clusters and classified three of them as China-aligned. TA412 targeted US civil society, mining and commodity trading firms; UNK_LateNight targeted US aviation companies; and UNK_QuietRacket targeted government and financial institutions in Indonesia and Singapore.

According to SecurityWeek, the kit circulated among different groups within a few days. This shows that the traditional patch cycle is not sufficient for defence: a vulnerability can be exploited by multiple groups before it is publicly disclosed. The commodity trading and mining firms on the target list indicate that cyber espionage functions as an extension of geo-economic competition.

Data layer: identity documents

As reported by The Record and Help Net Security, 153 million driving licence scans, 10 million identity cards and more than 3 million travel documents belonging to people in the US and Canada were stolen from the identity verification company IDScan. The data were put up for sale on 31 August on a Russia-linked illicit marketplace; the FBI has opened an investigation.

In the same week the US Treasury sanctioned Xinbi Guarantee, a Chinese-language illicit marketplace whose volume has exceeded 24 billion dollars since 2022. Read together, the two incidents reveal a cycle in which stolen identity data supplies raw material to the economy of fake account creation and fraud. The financial leg of this cycle lies in the scam centres of Southeast Asia, and the data leg in suppliers in the West.

Why actors choose these layers

What the three incidents have in common is that the attacker targets points where high impact can be achieved at low cost. The tracking resources needed to protect a cable in the deep sea are far greater than the resources needed to damage it. Exploiting a browser vulnerability is far faster than patching against it in every institution. Data stolen from an identity verification supplier weakens the security of millions of accounts in one stroke.

This asymmetry allows state-linked actors to exert pressure without entering open conflict. The link between identity data sold on Russia-linked illicit marketplaces and fraud networks in Southeast Asia shows that the criminal economy and state interests at times use the same infrastructure. On the defensive side, most of the cost falls on the private sector, infrastructure operators and insurers.

What to watch

Three indicators stand out. First, the frequency of official statements on suspicious maritime activity around cables and pipelines in northern Europe. Second, the speed at which institutions apply patches for the vulnerabilities used in the BlueMoon kit, and any new target regions. Third, reports of fraud waves making use of the IDScan data.

Verifiable quantitative data in this area are limited; most incidents come to light late and only partially. For this reason this report gives no estimate of the economic cost of the cyber incidents.

Probabilities

Scenarios

ScenarioProbabilityTriggerMarket impact
H1Continued grey-zone pressure60%Cable rehearsals, espionage campaigns and data leaks continue without causing outages.Costs accumulate in defence and compliance spending, with no service outages.
H2Physical outage25%A data or energy cable in northern Europe is actually damaged.Regional data traffic and satellite data transmission are disrupted for days.
H3Mass exploitation wave15%BlueMoon-type vulnerabilities are used in a way that causes outages in finance or the power grid.Service outages and data losses occur simultaneously in several countries.

Module A

Constraints Matrix

STRUCTURAL AVG 4.0 · TACTICAL AVG 3.0Structural constraints dominate: the outcome is set more by these limits than by the actors' preferences.

Hard structural constraintspersistent · beyond the actors' will

  • Dependence on a few cables

    4/5

    Data from the satellite ground station on Svalbard reaches the mainland via two subsea cables.

  • Supplier concentration

    4/5

    The concentration of critical services such as identity verification in a few companies turns a single breach into a mass-impact event.

Tactical frictiontemporary · eases over time

  • Patch deployment lag weeks

    4/5

    Zero-day vulnerabilities are shared among groups within a few days, while the corporate patch cycle takes weeks.

  • Maritime tracking capacity months

    3/5

    Detecting deep-sea activity depends on the allies' joint tracking resources.

  • Investigation and disclosure time days

    2/5

    Breaches become public days after they are detected; impact assessment is delayed.

Module B

Signal vs Noise

SIGNAL 67% · NOISE 33%

  • SIGNAL

    Sabotage capability is being rehearsed in peacetime

    Submarines of Russia's deep-sea directorate were reported to have rehearsed, near the Svalbard cables, a set-up to disable cables without leaving a trace.

    Defense News

  • SIGNAL

    Exploit kits spread among groups within days

    Proofpoint reported that the kit first seen on 28 August was used by four separate clusters.

    Proofpoint

  • NOISE

    Expectation that a single sanctions decision will end the fraud economy

    Xinbi is the third major network targeted after Huione and Prince Group; earlier sanctions did not prevent new networks from forming.

    CoinDesk

Module C

Asset-Class and Positioning Implications

Asset classExposureTransmission channelH1H2H3ExpectedConvictionHorizonWhat to watch
EquitiesCyber security services sectorState-linked campaigns and compliance obligations+++++1.15●●3–12 monthsFrequency of critical infrastructure breach notifications
Freight & insuranceCyber and subsea infrastructure insuranceCable sabotage and mass breach risk++++++1.40●●3–12 monthsStatements on suspicious maritime activity in northern Europe
VolatilityEuropean equity market volatilityPhysical infrastructure outage0++++0.55●●0–3 monthsNews of cable and grid outages

How to read: ++ strong structural support · + support · 0 neutral · − pressure · −− strong pressure. “Expected” is the direction weighted by scenario probabilities. H1: Continued grey-zone pressure · H2: Physical outage · H3: Mass exploitation wave.

General, scenario-conditional analysis at asset-class level. It contains no specific security, price target or trade timing and is not personalised investment advice (Turkish Capital Markets Law No. 6362).

Triggers

Thresholds to watch

IndicatorThresholdTodayWhat it means
Brent crude oil> 120130.80The zone where the market impact of infrastructure attacks grows during the energy shock.

Sources

  1. Defense News — NATO allies foil Russian subsea cable sabotage plot
  2. Proofpoint — BlueMoon exploit kit
  3. SecurityWeek — BlueMoon exploit kit chains recent Chrome and Windows zero-days
  4. The Record — IDScan data breach
  5. US Treasury — Xinbi Guarantee sanctions

Sourcing and verification rules: methodology · Report an error: contact

Related reports