The Invisible Battlefield — Infrastructure, Data, and the War Most People Don't See

In this post, I explore the reality of warfare targeting data centers and critical infrastructure, a shift that has been long predicted but is now becoming a harsh reality.

Note: This post reflects exclusively my personal perspective and assessment — as someone who has been working with critical infrastructure for over two decades. It does not represent the official position of any company or organization I work or have worked for. Sources are cited as accurately as possible; interpretations and conclusions are my own.

When I read this article this morning — Iran threatens to destroy OpenAI's $30 billion Stargate data centre in Abu Dhabi — my first reaction was not surprise. It was more of a quiet nod. Welcome to the reality that many of us in the network community have seen coming for years.

But let me start from the beginning.


War Has Changed. Fundamentally.

The goal of modern warfare is no longer primarily to kill people on the battlefield. The goal is to systematically weaken infrastructure — and thereby maximize financial, social, and strategic damage. Those who want to strike a state or economic power today no longer just attack garrisons. They attack data centers. Undersea cables. Power distribution networks. Fiber optic lines running through fields that appear on no official map.

The first state-attributed attack on commercial data centers in an active conflict took place on March 1, 2026: Iranian drones struck AWS data centers in the United Arab Emirates. Not science fiction. Not a drill. Reality. (Source: The Next Web, 06.04.2026)

Today, the IRGC threatens the "complete and utter annihilation" of the Stargate complex — a 19 km² AI campus south of Abu Dhabi, built by OpenAI, SoftBank, Oracle, and MGX, with a planned total capacity of 1 gigawatt and around 500,000 NVIDIA GPUs. Construction cost: over $30 billion. (Source: The Next Web, 06.04.2026)

An Iranian propaganda video summarizes the new logic in one sentence: "Nothing stays hidden to our sight, though hidden by Google."

This is not empty threatening. This is a doctrine.

The Escalation

Timeline · Infrastructure Attacks 2022–2026

Feb 2022

Ukraine
Fiber Strikes

Targeted cable cuts — coordinates from public permit databases.

Sep 2022

Nord Stream
Sabotage

Baltic Sea pipeline — 4 explosions. Energy supply for millions gone overnight.

Mar 1, 2026

AWS UAE
Drone Strike

Iranian drones hit commercial data centers — first state attack on cloud infrastructure.

Apr 6, 2026

Stargate
Threat

IRGC threatens $30bn OpenAI campus. 500K GPUs. "Nothing stays hidden to our sight."

Sources: The Next Web · Reuters · Euronews


What I Heard in 2008 — and What Was Still Dismissed Back Then

Between 2003 and 2014, I was deeply involved in Business Continuity Management, critical infrastructure, and its vulnerabilities. In 2008, 2009, and 2010, my brother and I co-organized a conference series in Berlin with Dr. Nehls under the title "Public Private Security — Protection of Critical Infrastructures". (Documentation: BCM-News, 05.04.2009)

We discussed scenarios back then that are reality today: coordinated malware attacks on industrial facilities, targeted strikes on energy supply infrastructures, hybrid threat scenarios between the state and private sector. The reaction in the room was mostly polite disinterest. The topic felt too abstract, too distant, too theoretical.

It wasn't. It just took longer than expected.


The Glass Network — or: How Transparent Our Infrastructure Really Is

A few weeks ago I was sitting with my friend and cybersecurity expert Warren on a flight from Brisbane to Christchurch. I had just bought Wi-Fi and started putting together a short presentation. No project, no agenda — just an answer to a question that had been on my mind for a while: How much can you find out about a single ASN using exclusively public sources?

I called the result "The Glass Network".

The concept is alarmingly simple:

Step 1 — Base data from the central, publicly accessible database of our industry, which offers a public API: ASN holder, peering locations, IP prefixes, routing information.

Step 2 — Overlay with .kmz files from various fiber operators who publicly document their cable routes — for permitting processes, investor relations, regulatory requirements.

Step 3 — Integration into a GIS system with public power line data from national energy infrastructure registries.

The result: a map where I can see exactly, for any given ASN, which data center is connected to which fiber operator, which energy provider supplies PoP01 and PoP02 �� and precisely where the redundant line runs that is supposed to carry the redundancy concept in an emergency.

The problem: if I can see this, others can too. And not everyone who sees it has constructive intentions.

What many underestimate: the mere combination of three publicly available datasets is sufficient to completely deconstruct an operator's redundancy concept. Anyone who knows that the primary fiber and backup fiber share the same underground conduit — because the permitting situation left no alternative — can take both offline simultaneously with a single targeted strike.

The Glass Network

Three public sources · One complete attack map

① ASN / BGP Data

IP prefixes · Peering locations · Routing tables · IXP presence

PeeringDB · IRR · BGP.tools

② Fiber Infrastructure

ISP .kmz files · Permit databases · PoP locations · Underground routes

ISP filings · Municipal permit registries

③ Power Grid GIS

National energy data · Grid topology · Substation locations · Supply routes

National grid operators · OpenStreetMap energy layer

⚠ Complete Attack Map

Which datacenter uses which fiber path — and which power feed. Including all redundancy routes and single points of failure.

All three layers: freely accessible online


Ukraine: The Moment It Became Real

Through my project "Keep Ukraine Connected" — which I follow with great respect for what Marcin and Daniel have continued to build from it — the true scale of this threat became fully clear to me.

There were missiles hitting fields. In the middle of nowhere. No military target in sight, no apparent strategic significance. Nobody understood at first what was happening.

Then it became clear: these were targeted strikes against fiber optic installations. The coordinates didn't come from intelligence reports. They came from public permitting documents, underground construction maps, the databases we had filled ourselves.

Nothing more, nothing less.


The Economic Damage: Numbers Already Affecting PoP Budgets

The war in the Middle East is also an economic war — and its effects have long since arrived in the operating costs of data centers and network infrastructure.

Energy prices (as of March 2026):

For comparison: during the Ukraine war in 2022, gas reached €220/MWh and electricity €488/MWh. We're not there yet — but the direction is clear.

Global supply chains:

  • Around 500 oil and gas tankers are currently stranded in the area of the Strait of Hormuz — previously 19.5 million barrels per day passed through there (Source: ZDF Heute, 21.03.2026)
  • Fertilizer: supply shortfalls are driving food production costs worldwide (Source: ZDF Heute, 21.03.2026)
  • Germany's projected economic damage through end of 2027: €40 billion (Institute of German Economy) (Source: ZDF Heute, 21.03.2026)
"The actual bill is paid by companies and consumers facing significantly higher raw material costs." — Martin Lück, Franklin Templeton (Source: ZDF Heute, 21.03.2026)

For network operators this means concretely: PoP OPEX increases without a single screw being touched. Power, cooling, diesel generators, maintenance contracts — everything gets more expensive because missiles hit a tanker in the Strait of Hormuz.

The Cost of Infrastructure War

Energy price comparison · Baseline vs. conflict escalation

Natural Gas

€ / MWh

Jan '26 € 36
Mar '26
€ 74
+106 %
UA '22 peak
€ 220
+511 %

Electricity

€ / MWh

Jan '26 € 103
Mar '26
€ 149
+45 %
UA '22 peak
€ 488
+374 %

Oil

$ / Barrel

Jan '26 $ 65
Mar '26
$ 119
+83 %

No historical UA crisis peak available for direct comparison.

Sources: Strom-Report 06.03.2026 · ZDF Heute 21.03.2026


The Digital Battlefield

Parallel to the physical dimension, digital warfare is running. Iranian APT groups APT42 and APT33 are actively mobilized for offensive cyber operations against Israeli and US defense and government networks. (Source: Euronews Next, 03.03.2026)

One example that illustrates the scale: the app BadeSaba Calendar — with over 5 million downloads on Google Play — was compromised. Push notifications reading "Help is on the way" and "Time for reckoning" were sent to all users. (Source: Euronews Next, 03.03.2026)

This is not a military hack in the classical sense. This is infrastructure as an information weapon. Psychological warfare through civilian channels.

ShieldX — my open-source project for detecting prompt injection and LLM attacks — was born precisely in this context: because the attack surface of AI systems is barely understood, while state actors are already systematically targeting them. I say this not to promote myself, but because it's relevant: anyone operating AI infrastructure needs to understand AI attacks.


What This Means for Us as a Network Community

I say this without drama, but clearly — and it is my personal assessment:

We are part of the problem.

Not because we act with malicious intent — but because we have grown accustomed over years to a culture of open exchange that emerged in a different threat landscape. The central databases of our industry are a blessing for interoperability, troubleshooting, and operations. And they are simultaneously a detailed situational picture for anyone who wants to attack infrastructure.

What we make public — combined with freely available fiber maps, GIS data, and energy infrastructure registries — is sufficient to fully map the redundancy concept of a mid-sized operator.

This does not mean: shut everything down, withhold all data. That would be counterproductive and unworkable.

It means: raise awareness. Understand what we publish. Verify whether primary and backup fiber are actually diversified — or only on paper. Energy redundancy means two suppliers, not two cables from the same supplier through the same conduit.

And it means: the conversation we started in Berlin in 2008 must be continued today — with genuine urgency.

What Your Network Reveals

Public data layers · Risk classification by combination depth

01

Publicly Available — Single Source

ASN ownership, IP prefix ranges, BGP routing tables, IXP peering locations, network topology, provider relationships

↗ PeeringDB · IRR · BGP.tools · RIPE NCC

02

Combinable — Two Sources

Physical fiber routes, exact PoP locations, datacenter identities, underground cable paths, route diversity gaps, shared conduit risks

↗ + ISP .kmz filings · Municipal permit databases

03

⚠ Critical — Three Sources Combined

Power supplier per PoP, redundancy path layout, single points of failure, backup fiber exposure, complete physical infrastructure map

↗ + National GIS power grid data · Grid operator filings

Each additional source multiplies the attack surface — their combination is what creates the critical risk


Conclusion

What is happening today with Stargate in Abu Dhabi, what happened in Ukrainian fields in 2022, what happened to AWS data centers in the UAE on March 1, 2026 — these are not isolated events. This is the consistent evolution of a war doctrine that treats infrastructure as the primary target.

"Who's going to insure a $20bn facility in the Middle East that can be taken out by a $5,000 drone?" (Source: The Next Web, 06.04.2026)

This question is not rhetorical. It is the definition of the new war.

From my personal perspective: we build glass networks and make them transparent. We map our redundancy paths in public databases. We document our power suppliers in permitting documents. And then we wonder when someone strikes exactly there.

Today's example is not the end. It is the beginning of a conversation our community should have had long ago.


René Fichtmüller has been working with Business Continuity Management and critical infrastructure resilience since 2003. He was co-founder of the conference series "Public Private Security — Protection of Critical Infrastructures" (2008–2010) and works on projects in network security and AI infrastructure resilience.


Sources: