Two Cables Down Off Perth: The Seabed Is Maritime’s Newest Attack Surface

Near-simultaneous cable faults inside a federally protected zone, a loitering tanker with a placeholder ETA, and a federal police investigation — undersea infrastructure has officially become a maritime operations problem.

August 17, 2026 | By The CyberSurv Team | CyberSurv

Cable repair vessel at blue hour with glowing subsea fiber optic cable routes beneath the ocean surface near a coastal city skyline

Over the weekend of August 8–9, two of the submarine cables that connect Australia to the rest of the world failed almost back to back — inside a zone that exists specifically to protect them. Indigo West, the direct route between Perth and Singapore, and Indigo Central, which links Perth to Sydney, both suffered shunt faults in close proximity within Australia’s federally declared Perth Submarine Cable Protection Zone. Cable owner SUBCO reported the matter to the Australian Federal Police, which confirmed it has received a report of crime and is assessing the information. Repairs are not expected to be complete before August 26 at the earliest.

We want to be careful here, because the facts demand it: no cause has been established, and no vessel has been publicly named or accused. The International Cable Protection Committee counts well over a hundred cable faults worldwide every year, and the majority are accidents — dragged anchors and fishing gear, not aggression. But the reason this incident matters to every maritime operator is what happened next. Within days, commercial maritime intelligence platforms had reconstructed a remarkably detailed picture of a vessel of interest — and that reconstruction is a preview of how seabed infrastructure protection is going to reshape expectations for everyone who operates ships near critical infrastructure.

The Vessel the Sensors Couldn’t Miss

According to analysis published by Windward, a commercial tanker entered Australia’s Exclusive Economic Zone on July 28, anchored off Perth, and stayed for nearly two weeks. On July 31, its declared ETA changed to January 1, 2027 — a placeholder value typical of vessels with no genuine port call intent. Through August 8–9, the window in which the cables were damaged, its AIS track shows repeated erratic crossings over the cable corridor. Electro-optical satellite imagery captured the vessel roughly 11 kilometers west of Perth on August 3, and synthetic aperture radar placed it directly on the cable route on August 8 at 21:42 UTC.

Three independent sensors — AIS behavior, optical imagery, and radar — stacked into a single, analytically defensible picture. That is the real story. Whether or not this particular tanker did anything wrong, the era in which a ship could loiter over critical infrastructure unobserved is ending. Attribution used to be the hard part of seabed incidents; data fusion is making it tractable. For operators, that cuts both ways: the same tooling that surfaces bad actors will also scrutinize ordinary vessels whose AIS data is degraded, spoofed, or simply sloppy. Broadcast integrity is becoming an operational liability question, not just a navigation one.

A Global Pattern With a Familiar Playbook

The Perth faults did not happen in a vacuum. Since October 2023, at least eleven cables have been damaged in the Baltic Sea alone, in a running series of suspected sabotage incidents that follows a consistent pattern: a commercial vessel drags its anchor across the seabed in international waters, and investigators spend months untangling accident from intent. NATO stood up Operation Baltic Sentry in January 2025 specifically to surveil and protect undersea infrastructure, and incidents have continued into 2026 — including damage to the Sventoji–Liepaja cable on January 2 and a Latvia–Gotland fiber fault under investigation since late January.

Australia saw enough in that pattern to matter. The Perth protection zone — where anchoring and certain fishing activity are prohibited — is exactly the kind of legal shield the Baltic incidents exposed as insufficient on its own. Zones deter the careless; they do not stop the deliberate. Two near-simultaneous faults inside a declared protection zone are precisely the scenario that turns a telecommunications problem into a national security question.

Why Cable Security Is a Maritime Cybersecurity Problem

It is tempting to file subsea cables under “telecom” and move on. We think that is a mistake, for three reasons.

First, the dependency runs through your operations. Roughly 99 percent of intercontinental data traffic moves over submarine cables — including the cloud platforms, remote monitoring, crew connectivity, and shore-side coordination that modern vessel and port operations assume will always be there. When a regional route fails, traffic reroutes and latency spikes; when redundancy is thin, operations degrade. If your fleet management, OT vendor support, or terminal operating system depends on connectivity you have never mapped, you have a single point of failure you have never tested. The North Carolina ports attack earlier this month showed what resilience under degraded conditions looks like when it is planned for — connectivity loss deserves the same treatment.

Second, the threat is hybrid by design. The playbook on display from the Baltic to — potentially — Perth deliberately blurs physical and cyber: a ship as the delivery mechanism, AIS manipulation as the concealment layer, and plausible deniability as the exit strategy. Defending against it requires the same fusion of navigation data integrity, monitoring, and incident response that maritime cyber programs already own. The organizations that treat “anchor drag” and “network intrusion” as separate universes will respond slower than the adversary who treats them as one campaign.

Third, the regulatory trajectory is unmistakable. Governments are converging on the view that undersea infrastructure protection is a shared obligation among coastal states, cable owners, and the vessels that operate near them. Expect tighter reporting expectations, more scrutiny of vessel behavior near protected corridors, and more pressure on operators to demonstrate that their own systems — from GPS and AIS to remote access — can’t be quietly co-opted into someone else’s operation.

What Operators and Port Authorities Should Do Now

A few practical moves we recommend to every maritime organization watching this unfold:

Map your connectivity dependencies. Know which operational functions — OT vendor access, cloud-hosted systems, communications — ride on which routes, and what actually happens when a primary path fails. Tabletop the outage before the ocean runs the exercise for you.

Treat AIS and PNT integrity as security controls. Your vessels’ broadcast behavior is now evidence in other people’s investigations. Anomalous tracks, spoofed positions, and placeholder data create risk exposure even when the underlying cause is a misconfiguration.

Include infrastructure-adjacency in your risk assessments. If your vessels transit or anchor near protected cable corridors, that belongs in your maritime cybersecurity assessment alongside network architecture and access control — because regulators and insurers are starting to look at it that way.

Monitor continuously, not annually. The Perth vessel of interest was surfaced by continuous behavioral monitoring, not a point-in-time audit. Defense needs the same posture. Our RiskGuard 365℠ program exists precisely because threats that unfold over two weeks of loitering cannot be caught by a once-a-year review.

Final Thoughts

The Perth investigation may yet conclude that two cables failing near-simultaneously inside a protection zone was a coincidence. But maritime leaders should notice what this incident has already proven regardless of attribution: the seabed is contested space, ships are the instrument of choice, and the line between physical mishap and cyber-enabled aggression is now thin enough that your organization needs one integrated answer for both. The operators who map their dependencies, harden their data integrity, and monitor continuously will be the ones still moving cargo — and still trusted near critical infrastructure — when the next fault hits.

Let’s Explore What’s Possible

Whether you need a Maritime Cybersecurity Assessment, continuous monitoring through RiskGuard 365℠, or penetration testing that validates your defenses before an adversary does, our team helps maritime organizations turn incidents like Perth into preparedness. Let’s talk about where your dependencies really are.

Schedule a Consultation

Scroll to Top

Discover more from CyberSurv.com

Subscribe now to keep reading and get access to the full archive.

Continue reading