A look at the April 2022 attack on the internet in France; perpetrators surgically cut “backbone cables” in three locations around Paris in around two hours
As new details about the scope of the sabotage emerge, the perpetrators—and the reason for their vandalism—remain unknown.Tweets:@tiagodfand@twshilohTweets:Tiago Dias /@tiagodf:At present, there's little information about who may have been behind the attacks. No groups or individuals have claimed responsibility for the damage, and French police have not announced any arrests linked to the cuts. https://www.wired.com/...@twshiloh:In April, there was a sophisticated, coordinated sabotage against i
Context & Ripple Effects
The Wired retrospective fills in the shape of an attack that was reported but never solved: sometime in April 2022, someone with knowledge of where the cables run cut backbone lines at three separate sites around Paris within roughly two hours, and to this day no group has claimed it and French police have announced no arrests. Physical attacks on fiber are not new — the FBI spent years probing eleven fiber-optic cable cuts in the San Francisco Bay Area — but the Paris operation stands out for its coordination and precision rather than opportunistic vandalism.
The timing matters because France's digital infrastructure was already under visible pressure from other directions: Russian-linked Sandworm had spent years inside French entities via Centreon monitoring software (that breach surfaced in early 2021), and the country had previously absorbed waves of low-level disruption like the denial-of-service attacks on thousands of French sites after Charlie Hebdo. The cable cuts added a physical layer to that pattern.
First-order effects
- Operators whose backbone segments were severed had to reroute traffic and dispatch repair crews across three locations, while investigators work a case with no claimed responsibility and no named suspects.
- The two-hour window across three sites confirms the attackers scouted access points in advance — network operators now know their terrestrial cable routes can be degraded faster than incident response can react.
Second-order effects
- Backbone operators face pressure to harden physical access — vaults, manholes, and splice points — and to treat route diversity around major metros like Paris as a security requirement rather than just a redundancy feature.
- With the FBI's unresolved San Francisco investigation showing the same attack class going unpunished for years, the lack of arrests in Paris signals to potential imitators that cable cutting carries little apparent risk.
Third-order effects
- If terrestrial cable sabotage keeps recurring without attribution, physical-layer resilience moves into the same policy conversation as cyber defense — especially in France, where state-linked intrusions like Sandworm's have already made infrastructure security a national issue.
- The longer-term question the unsolved case raises is whether critical internet routes need monitoring and protection regimes closer to what utilities apply to power grids than to what telecom currently applies to buried fiber.
The trend: Physical sabotage of internet backbone infrastructure is emerging as a persistent, hard-to-attribute attack vector that runs parallel to cyber operations against national networks.