Latency Games: Cyber Threats Loom for Subsea Networks
By David Strachan
The world of cyber operations is as opaque as the undersea domain itself —dark, poorly understood by outsiders, and shaped by interactions that are largely unseen. Combine the two and you will have one of the most demanding operating environments in modern warfare.
There is a tendency to view cybersecurity in the undersea domain as an add-on that protects individual platforms from malicious interference before they enter the water, or safeguarding them should they fall into the wrong hands. But as subsea operations become increasingly persistent and networked, cybersecurity is becoming inseparable from underwater warfare itself. Future operations will increasingly depend upon underwater wireless sensor networks (UWSNs) held together by streams of data transmitted through the water column using signals that may be detected by anyone within range. These networks will enable everything from scientific research to autonomous undersea conflict. And as they become operationally significant, they will inherit many of the same cybersecurity challenges that have long plagued terrestrial wireless networks.
The undersea domain is a profoundly challenging communication environment. Standard electromagnetic RF transmissions attenuate rapidly in seawater, and as such, two primary modes are used: Optical communication (OCOMMS) provides extremely high bandwidth (megabits or even gigabits per second), but requires short-range line-of-sight between transmitter and receiver, and acoustic communication (ACOMMS), which encodes information onto sound waves that can travel over long distances, often tens of kilometers or more. Although it offers much lower bandwidth (typically kilobits per second), ACOMMS can function across a range of depths and environmental conditions where OCOMMS is impractical, making it the most widely used method for underwater communication in defense, scientific, and commercial applications.
But as with RF, without proper safeguards, ACOMMS transmissions operate “in the clear,” and are therefore vulnerable to detection and interception by eavesdropping adversaries. Not only can these eavesdroppers potentially monitor transmissions, they can also attack the data streams themselves by injecting false messages, interfering with communications, or impersonating legitimate subsea network nodes.
The range of possible underwater cyberattacks is sobering. Wormhole attacks enable an adversary to capture network traffic at one location and tunnel it to another to disrupt routing decisions or enable follow-on attacks. Sinkhole attacks redirect traffic through compromised nodes to intercept, alter, selectively forward, or discard communications. A Sybil attack (named for the 1976 film) involves a single malicious node assuming multiple false identities within the network to undermine trust, distort routing decisions, or manipulate collaborative sensing systems. In a packet forwarding attack, a compromised node intentionally mishandles network traffic by dropping, delaying, modifying, or selectively forwarding packets. Acoustic jamming attacks overwhelm communication channels with noise or false signals, preventing nodes from exchanging information or coordinating operations. All of these attacks can degrade network performance, isolate portions of the network, or subtly corrupt information without completely disrupting communications.
Adversaries can also use the finite endurance of an underwater system against it. A denial-of-sleep attack attempts to exhaust the battery of an underwater node by forcing it to remain active or repeatedly process unnecessary communications. Rather than destroying hardware outright, an attacker can shorten the operational life of a network by rapidly depleting its limited energy reserves.
And an adversary doesn’t need to decrypt communications to exploit them. Traffic analysis enables malicious actors to simply observe when, where, and how frequently nodes transmit, allowing them to infer operational patterns, identify high-value nodes, or locate command elements based solely on communication behavior.
Underwater networks can also be vulnerable to physical tampering, theft, sabotage, or destruction. Because many sensors and communication nodes are deployed in remote, unattended locations, they may be vulnerable to recovery or damage by divers, autonomous vehicles, or specialized subsea equipment. And an entirely new class of underwater infrastructure – submerged data centers – further enlarges the subsea attack surface, but not through the exploitation of acoustic energy, as with ACOMMS, but rather through its weaponization. In an underwater version of a directed energy attack, an acoustic resonance attack can disrupt sensitive hard drive operations even while encased within a protective hull.
While most of these operations are derivatives of well-known wireless network attacks, their effectiveness is amplified by the unique physical constraints of the undersea environment. Jamming is more problematic because there are few alternative communication channels underwater - radio waves don't propagate well, and OCOMMS have their own limitations as noted above, which leaves ACOMMS as the primary option. Denial-of-sleep is especially damaging because recovering or replacing an underwater sensor may require a costly ship deployment, whereas replacing a terrestrial sensor might simply involve a technician driving to the site. Traffic analysis can reveal the locations of critical seabed infrastructure or autonomous vehicles, even if the communications themselves are encrypted, making them vulnerable to kinetic attacks. Physical attacks are harder to detect because the underwater environment is inherently opaque and remote.
The same physical phenomena that degrade communications also make cybersecurity more difficult. Limited bandwidth means techniques such as encryption, authentication handshakes, and key exchanges consume a much larger fraction of available channels than they would on a terrestrial network. Long propagation delays (on the order of seconds rather than milliseconds) complicate protocols that rely on rapid acknowledgements or multiple message exchanges. Network topologies that rely on AUVs make trust management, routing, and authentication more difficult because neighbors are constantly moving and changing. Multipath propagation and ambient noise increase packet loss, making it harder to distinguish between natural communication errors and deliberate jamming or spoofing.
Further complicating matters is that energy itself becomes a cybersecurity constraint. Every authentication exchange, encryption calculation, and routing decision consumes valuable battery life that may be impossible to replenish for extended durations. Finite battery life means every cryptographic calculation and every additional transmitted bit directly reduces mission endurance.
And underwater cybersecurity isn’t confined to static or autonomous systems. Crewed submarines may also be increasingly at risk of cyberattack as they evolve from isolated, “water-gapped” platforms to being fully integrated underwater network nodes. Whereas in the past, the most significant cyber risk to crewed submarines was a compromised supply chain, or perhaps an insider threat, as they become active participants in underwater networks, they are more at risk of cyber intrusion through ongoing exposure to new attack vectors.
The extent to which adversaries will endeavor to exploit the unique cyber vulnerabilities of the undersea domain remains to be seen. Its challenging operating environment may ultimately provide a buffer against cyberattack, as adversaries pursue more accessible targets in other domains. Or it may foster a false sense of security among subsea actors, encouraging complacency while adversaries quietly exploit vulnerabilities in underwater systems that have received comparatively little attention. Perhaps most ominously, the proliferation of undersea systems could open up an entirely new front in so-called gray zone operations, where cyber campaigns increasingly target underwater networks - blinding sensors, manipulating routing, degrading trust, or subtly altering the operational picture without ever firing a shot, and potentially without leaving an attributable trace.
Further Reading:
-
Beaumont, W. Defense Beneath the Waves: A Comparative Cyber Security Analysis of Underwater Systems. Proceedings of IEEE SoutheastCon 2026.
-
Khalid, S., et al. A Comprehensive Analysis of Security-Based Schemes in Underwater Wireless Sensor Networks. Sustainability, Vol. 15, No. 9, 2023.
