Beneath the Surface and Below the Threshold: The Baltic Sea and the framework of Grey Zone Warfare
/By Chiara Infante, edited by Benjamin Turquier
I. Below the Threshold of Armed Conflict
The Baltic Sea has become Europe’s testing ground for a form of competition that is deliberately played out just below the threshold of armed conflict. Attacks on underwater infrastructure aim not only to cause lasting damage but also to test response times, investigation procedures, allied cohesion and legal boundaries.
During the spring of 2026, off the coast of Svalbard, Russian submarines of the GUGI Directorate - Glavnoye upravlenie glubokovodnikh issledovanii, Main Directorate of Deep-Sea Research, which deals with submarine warfare in the Russian Navy, were caught training to use technology designed to disable submarine cables without leaving traces attributable to the author (Reuters, 2026). A joint operation by the United Kingdom, Norway and the United States intercepts and disrupts the exercise before it is concluded (Reuters, 2026). No cable is severed, no ship sinks, and no State declares war on another. Still, in the corridors of NATO, the episode is being read as a deliberate signal: some analysts link it to Russia’s attempt to probe how far it can go before Article 5 is triggered (Reuters, 2026). It is the very dilemma of a grey zone: an aggression built specifically not to look like an aggression. This raises the question that runs through the entire article: how do you respond to a threat that, legally, has not yet occurred? How should we deal with this new framework of hybrid warfare?
II. The Grey Zone Framework: Ambiguity, Coercion, and Accumulation
In the first place, understanding what hybrid warfare and a grey zone are is fundamental to answering this dilemma, where legal boundaries and attribution of responsibilities are blurred.
The American intelligence community defines the grey zone as a space in IR - International Relations between peaceful diplomacy on the one hand and armed conflict on the other. A field of coercive or subversive actions conducted in violation of, or in the absence of, clear international norms (Office of the Director of National Intelligence, 2024a). Hence, it is possible to define the main traits of hybrid warfare, the operational strategy to move in this space. First, coercion is calibrated to remain below the threshold, creating a game of pressures that avoids traditional conflict (Office of the Director of National Intelligence, 2024a). Second, intentional ambiguity within the instigator or the author and the action itself defines the scope of the action. Complicating the assessment of responsibilities raises difficulties and costs in perpetrating a concrete action with certainty: here is where the line blurs, and assessing whether a response is based on self-defence or is a deliberate use of force makes the difference (Office of the Director of National Intelligence, 2024a). Lastly, the accumulation of events. No single event or incident below the threshold could justify the use of force, but the sum of them is what leads targeted States to possibly generate an escalation (Office of the Director of National Intelligence, 2024a).
The Official Director of National Intelligence in the United States, as other intelligence communities has evaluated this kind of action as a growing feature of global power contestation (Office of the Director of National Intelligence, 2024b). In recent years, the Baltic Sea has become an illustrative example of this logic when examining at submarine critical infrastructures.
III. The Pattern of Baltic Sea Incidents
Since 2022, a sequence of events has happened, constituting a structural precedent for today's events. In September 2022, the destruction of three of the four Nord Stream gas pipelines by underwater explosives was the starting point: four years later, the German investigation remains open, with a single Ukrainian suspect identified through the analysis of satellite communications from a sailing vessel, and no formally established state liability, a case that sets the evidentiary standard (and its limits) for everything that follows (Al Jazeera, 2026).
In the Baltic, the scheme was consolidated two years later, when starting from 25 December 2024, the Estlink 2 power cable (laid at a depth of approximately 100 metres) and several fibre optic cables were damaged simultaneously (Europa today, 2026). The Cook Islands-flagged oil tanker Eagle S, part of the Russian shadow fleet, was detected using AIS - Automatic Identification System data with its anchor dragged to the seabed for several kilometres. The Finnish Coast Guard boarded it in international waters and escorted it to port; an unprecedented interdiction operation in the region (Defence News, 2025). This was followed, on January 14, 2025, by the launch of the NATO Baltic Sentry mission, which integrates frigates, fixed-wing maritime patrol, and naval surveillance drones, with the eight coastal states formalising their intention to proceed with public attribution on a case-by-case basis (SHAPE NATO, 2025).
Later, on December 31, 2025, a fault struck the Helsinki-Tallinn cable: the suspected vessel, which had set sail from St. Petersburg under the flag of Saint Vincent and the Grenadines, was held until January 12 without the investigation producing sufficient evidence to indict it (Euronews, 2026). On January 2, 2026, the sixth regional failure in thirteen months was recorded, this time in Latvian waters: the inspection conducted in the port of Liepāja found no direct evidence of tampering, and the file remains open under the sole classification of “probably intentional damage”, with no further action being taken so far (Capacity Media, 2025).
On closer analysis, the five incidents share not only their geographical location but also a common operational strategy, which can be explored in four recurring elements. The first is the choice of the vessel: never a warship, always an ageing merchant vessel linked to the shadow fleet that, since 2022, has been circumventing sanctions on Russian crude oil, an existing logistical infrastructure that makes it impossible to distinguish, a priori, between commercial transit and hostile action (Kyv Schoof of Economics Institute, 2026). The second is the use of a flag of convenience (Cook Islands, Saint Vincent and the Grenadines): this shifts primary jurisdiction to registers with no interest in or capacity for investigation, leaving the coastal state without full authority to proceed beyond a port inspection (Windward, 2026a). The third is the anomalous behavioural pattern: AIS data show regular navigation along the entire route, with a deviation in speed or trajectory concentrated exclusively during the minutes when the damage occurred (Windward, 2026a). The fourth is the evidential threshold missed by a single step: consistent circumstantial evidence (wear and tear on the anchor, no report of a fault, previous suspicions) but never the direct evidence required for criminal prosecution (Windward, 2026b).
There is, however, a fifth element underlying, which explains why the phenomenon does not cease but instead spreads: the phase preceding the hostile act is, in itself, legal. Windward’s data (Windward, 2026b) (one of the main maritime intelligence platforms) show a 52% increase in the North Sea and an 88% increase in the South China Sea in just one year in so-called drifting: the transit at very low speed along routes that coincide with the paths of cables and gas pipelines, typical of those mapping their exact positions. The report describes this increase as systemic rather than episodic (Windward, 2026b). In international waters, this conduct does not breach any regulations: the law of the sea protects freedom of navigation and does not prohibit a vessel from travelling slowly. Reconnaissance preceding a hostile act is, in itself, a lawful act, not because of an accidental regulatory loophole, but because a legal framework designed to guarantee freedom of trade was never intended to anticipate the strategic use of geospatial information gathered whilst navigating.
IV. From Isolated Accidents to Systemic Disruption
The result is an asymmetry that binds both of the plans described above, and this gap between licit preparation and circumstantially strong but legally weak execution makes the Baltic phenomenon not a cluster of episodes in the process of exhaustion, but a method in the process of acceleration. The growth of drifting is not a side fact; it is evidence that the reconnaissance infrastructure required for these operations is expanding faster than the ability of coastal states to trace, even if only circumstantially, who uses it.
Four factors combine to explain the shift from a series of isolated incidents to a systemic threat: a change like operational ambiguity, a quantifiable increase in the scale of the phenomenon, the convergence of multiple domains of action within the same geographical space, and a redefinition of the relationship between state intent and strategic effect.
The first factor concerns the nature of ambiguity. In the initial phase of the phenomenon, ambiguity stemmed from a pre-existing condition: the inability, for tracking purposes, to distinguish between a commercial vessel and a hostile carrier. The Svalbard incident marks a qualitative break, as the technology employed is specifically designed to prevent attribution, rather than to exploit its contingent absence (Reuters, 2026). This shifts ambiguity from an opportunistic variable to a designed one, with direct consequences for the ability of existing countermeasures, calibrated to the forensic analysis of residual clues, to produce results.
The second factor is quantitative. Maritime tracking data recorded nearly 35,000 suspicious vessel activities near submarine cables in the first quarter of 2026 alone, whilst the tracked shadow fleet exceeded 2,100 vessels (Windward, 2026b). These figures indicate a state of operational continuity, rather than isolated incidents, and justify reclassifying the phenomenon from a sequence of events to a persistent systemic capability, a criterion which, in the literature on the grey zone, distinguishes hybrid action from an isolated hostile act.
The third factor is a multi-domain convergence within the same operational theatre: incursions by unidentified drones into military and airport installations, interference with satellite positioning signals, and functional overlap between units deployed to circumvent sanctions and those deployed for infrastructure reconnaissance (Sveriges Radio, 2026). None of these vectors, considered in isolation, crosses the threshold of armed conflict. Their combination, however, produces a cumulative pressure effect greater than the sum of the individual acts, a mechanism that is constitutive, rather than accidental, of hybrid logic.
The fourth factor concerns the relationship between intent and state responsibility. In March 2026, the director of the Finnish intelligence service (Supo), Juha Martelius, stated (Yle News, 2026) that the investigations carried out provided no evidence of deliberate coordination by the Russian state, attributing the damage instead to structural shortcomings in an obsolete and under-regulated shadow fleet, and highlighting the risk of overestimating Russian interference in the absence of direct evidence. This assessment does not diminish the scale of the phenomenon, but reframes its analytical terms: the very existence of an opaque fleet, lacking adequate maintenance and insurance standards, operating regularly on routes overlying critical European infrastructure, constitutes a systemic risk factor regardless of whether direct state intent is established. It follows that the coercive effect typical of the grey area can occur even in the absence of an explicit order, when the relevant state merely tolerates, enables or refrains from regulating the conditions that give rise to the risk (Yle News, 2026).
V. The Legal Impasse
Within the esìxisting scenario, current legal instruments offer partial protection. The UN Convention on the Law of the Sea (United Nations, 1982) requires states to penalise anyone who damages an underwater cable, but only if the vessel flies its own flag, while, as seen, the shadow fleet almost always operates under registers of convenience over which the coastal state has no direct jurisdiction. Even further upstream, the activation of NATO collective defence (NATO) requires an armed attack attributable with reasonable certainty to a state: precisely what the method described in this article is designed to prevent. Moreover, the collective defence clause leaves arbitrariness to each State in the measure of the response; at the same time, the interpretation of a hybrid attack can differ by each State because of its nature, adding an element of complexity in the expectation of a NATO response. It is not a random normative vacuum, but the logical consequence of a legal framework designed for clear-cut acts of war (Convention for the Protection of Submarine Cables, 1884), not for a continuum of calculated ambiguity. This is why the real response to the phenomenon has moved elsewhere, not in the courts, but in the capacity for surveillance and deterrence.
VI. Deterrence by Denial
The West’s response to this scenario does not take the form of an act of war, but rather a structural change to the operational environment. The NATO Baltic Sentry mission (NATO, 2025) integrates naval and aerial patrols, maritime surveillance drones and channels for the exchange of information between the coastal states and the private sector managing the infrastructure. This is a model of deterrence by denial, where the aim is not to sanction a hostile act that has already been carried out, but to reduce the likelihood that the action will achieve its desired effect without being detected.
An analytically underestimated factor in this balance is the repair time, which should be treated as an indicator of national security rather than a mere industrial parameter: a cable can be damaged in a few minutes, but restoration depends on variables that go beyond the immediate control of the affected state (International Cable Protection Committee). Precisely because this range affects the actual resilience of the infrastructure, another response logic that goes beyond attribution is that of accumulation: rather than assuming that every accident must be traced back with certainty to a responsible party, the model accepts evidentiary uncertainty and constructs the dissuasive effect on the certainty of operational consequences, in which every anomalous behaviour generates inspection, delay, insurance costs, and commercial risk for the vessel involved, regardless of the outcome of the investigation.
VII. Conclusions
The analysis carried out makes it possible to reframe the issue in more limited terms. The realistically achievable objective is not the militarisation of the entire underwater infrastructure, but rather a shift in the cost-benefit balance that has hitherto made operational ambiguity an effective tool: to increase the economic cost, operational risk and intelligence exposure of any attempt to use the seabed as a lever for political pressure. It is on this level, and not solely on that of military response capability, that the scope for action actually available to coastal states lies. In this sense, there is a judicial compass to which NATO members are attached, the preference over the judicial path rather than militarisation is also what avoids escalation, allowing to still operate within the framework of hybrid warfare below the treshold.
This raises an issue that transcends the specific case and defines its broader analytical relevance: the grey area is, by structural definition, the space in which the existing regulatory framework provides only partial coverage. The issue facing the coming decade is therefore not whether this space will continue to be exploited, for it will be, in proportion to its proven effectiveness, but whether the actors affected by it will succeed in redefining the legal and operational thresholds that delimit it, or whether they will have to accept its persistence as a structural, rather than a transitory, feature of competition between powers. Nevertheless, the issue leaves one question unanswered: how will we learn to navigate the grey area in order to tackle a new system of warfare – hybrid warfare?
Bibliography
Al Jazeera. (2026, 2 luglio). German prosecutors charge Ukrainian suspect over Nord Stream explosions.https://www.aljazeera.com/news/2026/7/2/german-prosecutors-charge-ukrainian-suspect-over-nord-stream-explosions
Atlantic Council. (n.d.). Today's wars are fought in the "gray zone." Here's everything you need to know about it. Accessed 18 September: https://www.atlanticcouncil.org/blogs/new-atlanticist/todays-wars-are-fought-in-the-gray-zone-heres-everything-you-need-to-know-about-it/
Capacity Media. (2026, 5 gennaio). Latvia investigation finds no link between Liepāja vessel and damaged Baltic Sea telecom cable.https://capacityglobal.com/news/latvia-investigation-finds-no-link-between-liepaja-vessel-and-damaged-baltic-sea-telecom-cable
Convention for the Protection of Submarine Cables. (1884).
https://iscpc.org/information/Convention_on_Protection%20_of_Cables_1884.pdf
Defense News. (2025, 14 January). NATO launches Baltic patrol mission, eyes standard for detaining ships. https://www.defensenews.com/global/europe/2025/01/14/nato-launches-baltic-patrol-mission-eyes-standard-for-detaining-ships/
Euronews. (2026, 12 gennaio). Cargo vessel suspected of damaging undersea cable allowed to leave Finland.https://www.euronews.com/2026/01/12/cargo-vessel-suspected-of-damaging-undersea-cable-allowed-to-leave-finland
EuropaToday. Cavi sottomarini Mar Baltico tagliati, sabotaggio: la mappa. Accesed 20 september 2026, https://europa.today.it/attualita/cavi-sottomarini-mar-baltico-tagliati-sabotaggio-mappa.html
European Commission. (2026, 5 february). Commission increases submarine cable security with €347 million investment and new toolbox. https://digital-strategy.ec.europa.eu/en/news/commission-increases-submarine-cable-security-eu347-million-investment-and-new-toolbox
European Union. (2024). Commission Recommendation (EU) 2024/779 of 26 February 2024 on secure and resilient submarine cable infrastructures. EUR-Lex. https://eur-lex.europa.eu/legal-content/IT/ALL/?uri=CELEX:32024H0779
International Cable Protection Committee. Government best practices. Accessed il 20 september 2026, https://www.iscpc.org/publications/icpc-best-practices/
International Institute for Strategic Studies. (2026, may). The Nordic-Baltic states in the Indo-Pacific: Similarities and challenges. https://www.iiss.org/research-paper/2026/05/the-nordic-baltic-states-in-the-indo-pacific-similarities-and-challenges/
Kyiv School of Economics Institute. (2026, agosto). Russian shadow fleet tracker: July 2026. https://institute.kse.ua/wp-content/uploads/2026/08/russian_shadow_fleet_tracker_july_2026_eng_august_2026.pdf
Lieber Institute for Law and Land Warfare. Hybrid threats & grey zone conflict symposium: The challenge to liberal democracies. West Point. Accessed 17 september 2026, https://lieber.westpoint.edu/hybrid-threats-grey-zone-conflict-symposium-challenge-liberal-democracies/
NATO. (2025, 14 january). NATO launches Baltic Sentry to increase critical infrastructure security. https://www.nato.int/en/news-and-events/articles/news/2025/01/14/nato-launches-baltic-sentry-to-increase-critical-infrastructure-security
NATO Allied Maritime Command. (2025). NATO Baltic Sentry steps up patrols in the Baltic Sea to safeguard critical undersea infrastructure. https://mc.nato.int/media-centre/news/2025/nato-baltic-sentry-steps-up-patrols-in-the-baltic-sea-to-safeguard-critical-undersea-infrastructure.aspx
Centre for Eastern Studies (OSW). (2025, 15 january). Baltic Sentry: NATO's enhanced activity in the Baltic Sea. https://www.osw.waw.pl/en/publikacje/analyses/2025-01-15/baltic-sentry-natos-enhanced-activity-baltic-sea
Office of the Director of National Intelligence, National Intelligence Council. (2024, july). Conflict in the gray zone: A prevailing geopolitical dynamic through 2030 https://archive.dni.gov/files/ODNI/documents/assessments/NIC-Unclassified-Conflict-In-The-Gray-Zone-July2024.pdf
Office of the Director of National Intelligence, National Intelligence Council. (2024, july). Updated IC gray zone lexicon. https://archive.dni.gov/files/ODNI/documents/assessments/NIC-Unclassified-Updated-IC-Gray-Zone-Lexicon-July2024.pdf
Reuters. (2026, 10 settembre). NATO allies foil Russian subsea cable sabotage plot. https://www.reuters.com/world/europe/nato-allies-foil-russian-subsea-cable-sabotage-plot-2026-09-10/
SHAPE (Supreme Headquarters Allied Powers Europe). (2025). Baltic Sentry to enhance NATO's presence in the Baltic Sea. https://shape.nato.int/news-releases/baltic-sentry-to-enhance-natos-presence-in-the-baltic-sea
Sveriges Radio. (2026). Sharp rise in GPS jamming over Baltic Sea. https://www.sverigesradio.se/artikel/sharp-rise-in-gps-jamming-over-baltic-sea
Ocean Development & International Law.
https://doi.org/10.1080/00908320.2025.2534621
ukranews.com (2026). Poland and Germany identified source of GPS interference recorded over Baltic Sea since February 2022. https://ukranews.com/en/amp/news/1091735
United Nations. (1982). United Nations Convention on the Law of the Sea. https://www.un.org/depts/los/convention_agreements/texts/unclos/unclos_e.pdf
Windward. (2026). Underwater cable sabotage in the Baltic Sea. https://windward.ai/knowledge-base/underwater-cable-sabotage-in-the-baltic-sea/
Windward. (2026). Undersea cables risk report: Q1 2026. https://windward.ai/knowledge-base/undersea-cables-risk-report-q1-2026/
Yle news, Supo: Russia remains tops of Finland’s security threat concerns.
