top of page

Legal and Ethical Challenges of Offensive Cyber Operations

  • sonalimukhia2002
  • Jul 12
  • 15 min read

Author: Tarun Sharma, Jaipur National University


ABSTRACT

The application of offensive cyber operations to modern-day geopolitical strategies is evident, but the legal framework is still blurry. What legal regulations should govern cases of states launching cyber attacks against each other, such as destroying critical infrastructure, leaking confidential information, or disrupting services? This paper addresses the legal and ethical aspects of cyber operation and demonstrates that although relevant principles can be found in international humanitarian law and the United Nations Charter, their applicability is undermined by ambiguities, difficulties with attributions, and differing interpretations of crucial terms among states. Three shortcomings of using the existing legal framework for addressing cyber offensives emerge through the analysis of doctrine, practice, and scholarship. First, there is uncertainty surrounding what defines cyber operations rather than an armed attack. Seconframeworkd, there are challenges with attributing cyber operations to a specific actor. Third, there is no common ethic.

Keywords: cyber operations, cyber warfare laws, International Cyber Law.


INTRODUCTION

In 2015, a power grid went offline in Ukraine due to an attack by hackers hired by Russia. People in three regions lost access to electricity and were left in darkness and freezing temperatures in the midst of the cold season. Unlike many hacking attacks aimed at espionage or extorting ransoms, this one did not involve any stealing of data or blackmailing of businesses – the perpetrators deliberately disabled the critical infrastructure vital for ordinary citizens' wellbeing. In a few years, the NotPetya virus paralyzed computer networks across the globe, affecting numerous shipping enterprises, medical organizations, governmental institutions, and causing massive losses worth billions of dollars. However, despite mounting evidence that Russian state agents orchestrated the attack, there were no legal repercussions from the international community since there was neither any specific international treaty regulating the matter nor an enforcement mechanism to deter potential offenders.

This situation is rather telling of the current inadequacy of the international legal system in dealing with cyberwarfare. There is no doubt that relations between states are regulated by numerous international treaties which prohibit such actions as bombing of hospitals or using certain types of weapons. In other words, traditional armed conflicts have a rather complex body of regulations. On the other hand, when a state undertakes a cyber operation that results in destruction of infrastructure and civilian casualties, there seems to be confusion concerning what sort of actions may be applicable here. Are they to be considered military conflicts, crimes, or something altogether?

There is no definite answer to that question because legal experts still disagree about how the issue should be regulated. Some believe that the existing laws are sufficient in addressing the matter whereas others insist that cyber operations require special legislation. At the moment, most states launch cyber operations without considering international legal regulations since they only have internal guidelines which dictate their course of action, often leaving the international community in fear of escalating tensions.

In this paper, the problems related to the regulation of offensive cyber operations legally and ethically are analysed. While there are particular instruments that can deal with cyber threats on a legislative level, they cannot do so because of the very peculiarities of such an attack and the fact that no terminology standards have been agreed on internationally. Thus, the research presented here will be conducted in several consecutive steps. The first one will focus on determining the definition of an offensive cyber operation and its peculiarities. Then, the question of applicability of the current laws. Later, special attention will be paid to the conditions under which such actions could be recognized as warlike activities according to the international regulations. After that, the discussion of possible ethical issues arising in the process of cyber attacks on civilians. Finally, recommendations for state organizations and businesses.

This line of thought seems to be the only way to solve the issue, as the problem of cyber wars could escalate dramatically if there would not be any guidelines regulating it.


LITERATURE REVIEW

The issue of legal status of cyber operations became one of the hot questions of international law research. After the events of 2007 in Estonia, researchers started to explore ways of applying traditional legal norms to cyber warfare. There are at least two opposite opinions on the matter. First of all, Duncan Hollis is of the opinion that the prohibition of force stipulated by the UN Charter is general enough to include cyber operations without adopting new treaties. Second of all, Scott Shackelford thinks that due to some special characteristics of cyber space such as its speed, problems with attribution, inability to control dissemination of malicious codes and blurred border between military and civilian cyber infrastructure new treaty instruments are needed.

International humanitarian law specialists are trying to figure out ways of application of the Geneva conventions to the situation. The International Committee of the Red Cross has produced lots of research on such principles of the laws of war as distinction, proportionality and necessity in terms of cyber warfare. Implementation of these principles becomes very difficult in the case of cyberspace due to the fact that military and civilian infrastructures are entangled and it is almost impossible to make any predictions about potential harm from malware.

In the question of an armed attack under the UN Charter Michael Schmitt suggests to consider cyber operations as armed attacks on the basis of the degree of harm rather than the methods of conducting them. Threshold approach was severely criticized for its ambiguity and potential incapability to address serious cases of cyber operations according to international law.

Now attribution becomes the central point of implementation of international law in cyberspace. As Kubo Macák et al. say that the need of proving the state responsibility fails in the case of uncertain technical and/or politically disputed attribution. In the case of cyber operations intelligence agencies can be sure about responsibility but there is no way to prove it publicly.

In addition to the above-mentioned difficulties, involvement of corporations in cyber operations is another important issue that requires scholars' attention. The issue of responsibility of technology corporations in case the technologies are used by the government for offensive operations which lead to civilian injuries is discussed by researchers such as Anja Damanik. Thus, the question of complicity and corporate due diligence is developed further.

The international community has used soft law measures including the Tallinn Manual rather than adopting binding treaty law. It is discussed whether it is a flexible approach or a way for states to neglect their commitment. State practice demonstrates that there is significant difference between countries in terms of what kind of cyber operations can be conducted, therefore international cyber law is still being shaped.

In addition, recent research discusses ethical aspects which are not necessarily regulated by international law. Scholars argue that Just War Theory principles must be applied to regulate cyber operations even if there is no prohibition of them in international law. International law permissibility does not necessarily mean permissibility from an ethical perspective.

The academic discussion recognizes that the international law regulates cyber operations, however there is a fundamental dispute regarding the interpretation of this regulation. There are three main gaps left to discuss: enforcement mechanisms of cyber law, evolution of international institutions in order to deal with cyber disputes and asymmetry of cyber power of the countries.


METHODOLOGY

The present work employs doctrinal research. That is, the interpretation of existing legal treaties, doctrines, and jurisprudence to determine both the meaning and application of international law in novel situations. No experiment is performed nor surveys conducted in this case. Rather, the research centers on a careful analysis of legal documents, treaties, doctrines, rulings, and opinions from relevant authorities on the matters under scrutiny.

The sources used include international treaties and agreements. In particular, it involves the examination of the UN Charter since this international agreement is regarded as the fundamental legal framework regulating international relations. Moreover, there are treaties specifically aimed at regulating various aspects of warfare such as the Geneva Conventions, the Fourth Geneva Convention, and the Tallinn Manual. Although it is not an international treaty, it represents a detailed expert evaluation of how international laws apply to cyberspace and is cited as an informative source, but not as law.

State practice in responding to cyberattacks will be analysed as well. State practice is one of the key elements of international law, and once state actions have occurred repeatedly and are considered by states as being consistent with international law, such acts acquire a legal character. Thus, once a state responds to cyberattacks in the same manner as it would respond to acts of military aggression, this state practice may result in establishing new international legal norms. In this context, state practice regarding the US, the Russian Federation, China, Ukraine, Europe, etc. will be analysed.

Apart from legal sources, there is also a review of scholarly articles published in reputable peer-reviewed academic journals. Moreover, reports released by expert organisations such as the International Committee of the Red Cross have been studied as well.

Recognize the limitations inherent to this method. The majority of cyber actions are confidential, and the government rarely explains its legal reasoning when conducting cyber attacks. The discipline develops quickly, therefore, sources of information become obsolete very soon. There is no international law since there is no consensus about the norms regarding cyberspace, which makes it impossible to give certain legal conclusions. However, we can specify areas of debate and find possible solutions but can hardly state any definite conclusions.

The fourth limitation is associated with the high degree of difficulty in attribution. In case we deal with a cyber attack, there is no way for us to identify who carried it out. When referring to intelligence services and cybersecurity firms, we make assumptions that prove to be incorrect sometimes, as in some cases attribution changes.


WHAT IS AN OFFENSIVE CYBER OPERATION?

Before discussing the law regulating cyber operations, it is important to define our topic of discussion. "Offensive cyber operation" is self-explanatory, yet includes a large variety of activities which include the theft of classified information by one government from another, disruption of communications between troops during a war, damaging vital infrastructure such as power plants or water treatment facilities, spreading misinformation to change public opinion in the other nation and others. Are all of these offensive cyber operations? Do they fall within one category from the standpoint of laws?

Firstly, the problem is related to the definition itself. In case of conventional warfare, one could easily differentiate an offensive act – missiles, bombs and similar weapons leave absolutely no doubt as to their use in hostilities. However, a cyber attack may vary, from stealing classified information to disrupting some websites, causing no actual damage, and even damaging critical infrastructures through the manipulation of computer-controlled industrial control systems (ICS). Moreover, each state tends to have its own classification of such attacks.

From the technical point of view, the definition of cyber operation is as follows: an offensive cyber operation implies the use of digital and computer networks to penetrate the computer network of another state without permission and perform any actions resulting in harming the state. Such harm may include information theft, interference with normal functioning of websites, destruction of data or computer control of physical objects. However, there are some questions that remain open.

This question presents several difficulties. According to international law, espionage differs from armed attack. Espionage is always conducted, it is not illegal, while an armed attack is grave and can justify a military counteraction. When does a cyber attack become an armed attack? Physical damage or death qualifies as an armed attack. Can attacks causing economic damage or attacks on civilian infrastructure qualify as armed attacks?

There are cyber goals that are blurring the line between military and civil targets. For example, a power generation facility is used by military bases as well as by civilians, and a telecommunication system transports military information alongside civilian data. Such dual-purpose targets may be subjected to different treatment, but there is no consensus about this question.

Another problem in defining and applying international law is attribution. It is hard to establish attribution even with proper definitions of offensive operations in cyberspace. While an attacker can be seen easily in a conventional attack, cyberspace attackers obfuscate their identities by routing the attack through other countries' territory, by hiring proxies.


DOES INTERNATIONAL WAR LAW APPLY TO HACKING?

The law of war is international humanitarian law that is applicable during wartime to protect the civilians. The principles include separation of civilians and soldiers, avoidance of targeted bombing of hospitals and educational institutions, and prohibiting torture equipment.

How does one then apply these laws to cyberwarfare? War law assumes soldiers on the field with visible weapons, while cyberattacks are conducted in everyday networks utilized by civilians. If an attack on the power grid affects both military bases and hospitals, how does one define the legitimacy of the target?

There are several scholars who suggest that war laws apply to cyberoperations as well. During warfare, all attacks should follow the same rules, irrespective of their modality. Thus, attacking a communications system belonging to the enemy is acceptable, while attacking the systems of a hospital would be illegal as hospitals are protected under international laws.

However, this becomes complicated. While the results of firing a missile can be somewhat predictable, cyberattacks cannot be controlled fully. The NotPetya malware attack of 2017 was initially meant to destroy Ukraine but ended up affecting countries worldwide. How does one define necessity and proportionality of damage in cases like that?

Second, military and civilian infrastructure are becoming inseparable on the Internet. The power grid supplies electricity not only to civilian facilities but also to military bases and hospitals; computer networks transport information belonging to civilians as well as government institutions; ISPs operate all these networks. In cyberspace, the distinction between military and civilian installations fades.

Third, humanitarian law presupposes that consequences of any attack come at once, while cyber attacks may be reversible or result in escalation of aggression. If a network is disabled for some time without being actually destroyed, this can have a long-term effect.

There seems to be consensus among experts that humanitarian law must be applied to cyber warfare, yet they differ greatly in terms of implementation. Who should be a target in cyberspace? How much collateral civilian damage can be permitted?


WHEN DOES HACKING BECOME AN ACT OF WAR?

The question for international lawyers, therefore, lies in determining the definition of the "use of force". Is a cyber attack considered the use of force? For years, it was not an issue since there was no such thing as cyber warfare. Now that there is, countries must clarify how to deal with this situation. Should a state like Russia conduct a cyber attack against the U.S., will its letter be allowed to retaliate using force in order to defend itself? Only if the cyber attack is defined as an armed attack as per the Charter.

The problem lies in the fact that the United Nations Charter, which dates back to 1945, was only made considering physical force – military invasions, weapon utilization, among others.

It is widely agreed that if a cyber attack results in significant physical destruction or casualties, it can be classified as an armed attack. When military installations are destroyed or individuals killed by a cyber attack, the situation seems unambiguous enough. But what happens when an act of cyberspace leads to economic damage or even disrupts vital services and infrastructure without harming anyone physically?

One event from Ukraine in 2015 provides insight into the problem. During January, attackers were able to disrupt the power supply network, resulting in the freezing of half a million Ukrainians for lack of heat and electricity. While the lives of many were made miserable, no one was killed directly by the cyber attack. But was it still an armed attack or a lesser form of action?

The problem of uncertainty is obvious here. The more uncertain the criteria for determining an armed attack are, the more unpredictable states' reactions will be. On one hand, the attack may be considered espionage, which is unlikely to provoke any serious counteraction. On the other hand, one state may consider a cyber operation as warfare and react accordingly.


THE MORAL QUESTIONS AROUND CYBER ATTACKS

Legalities are governed by laws. A cyber attack can thus be legal under international law yet morally wrong. Ethical questions require moral philosophy.

Just War Theory focuses on conditions for a valid war. Among them are the existence of just causes, the legitimacy of parties engaged, and compliance with conduct regulations. The two main principles are distinction, which states that no deliberate attack against innocent individuals is permitted, and proportionality, which means the force used is proportional to the need.

Adaptation of Just War to Cyberwarfare is a difficult task to accomplish. Self-defence and legitimate reasons for military activities could serve as grounds for cyber attacks, but they can hardly be regulated because it is impossible to regulate the use of cyber war weapons. Malware could be transmitted very quickly, and civilians would be their target.

For example, take the SolarWinds hack, which occurred in 2020. The Russian spies were able to hack the software update of an IT firm. The hackers were distributing malware through software updates to individuals who used them regularly. Organisations around the world, whether governments, hospitals or utilities, became the targets of this malware.

Who conducts cyber operations also raises moral issues. Increasingly, governments turn to private companies and hackers to conduct such attacks for them. Is there any moral responsibility of the company providing the software to build the hacking tools that end up causing death among civilians? Or is there any moral responsibility of a private security company training government hackers?

Civilian casualties constitute a further difficulty. An interruption of the computer systems of a hospital can prevent doctors from accessing patient data, and thus result in death. The hacker did not mean to cause death, but the fact that deaths were caused cannot be denied. Just War Theory permits some level of collateral damage if it is proportional and unintended, but calculating proportionality and the expected damage in cyberspace is difficult.

These questions do not have an easy answer, but it will be very dangerous for humanity to leave them unresolved. It is important to establish ethical principles of cyber warfare in addition to legal ones.


EXAMINING THE SKEPTICS’ POSITION

It is important to mention that not all scholars support the idea of creating new rules regarding cyber operations. Some people present very strong arguments against the creation of new rules and conventions.

First of all, it is stated by some people that no new rules and conventions are necessary because the UN Charter bans the use of force. As any cyber-attack uses force against another country's system and resources, this act falls under the category of banned ones according to the Charter. Therefore, there is no need to create any additional rules because they would bring chaos rather than help.

This idea is quite persuasive because it allows applying the already existing principles for cyber operations. It means there is no need to spend time on creating new rules. However, the use of such vague principles as the prohibition to use of force can be problematic because different countries understand what force is.

In addition to that, some scholars believe that the creation of clear cyber rules can be harmful to the world. The use of ambiguous international laws helps nations respond to any situation flexibly. In other words, a country can decide whether it is appropriate to act or not. Otherwise, it will have no other choice but to take drastic measures.

However, there is an element of truth behind this objection as well. However, at the moment, ambiguity drives adventurism, since countries engage in cyber operations because of a lack of clarity on their legality. As long as Russia is uncertain whether its cyber operation breaks international law, it faces no deterrent from launching it. Clarification of prohibitions would produce stronger restraints.

Thirdly, it may be argued that enforcement, rather than legislation, is crucial here. No matter how good or clear any treaty might be, enforcement of its provisions should precede everything else. The case in point is that Russia will still ignore such a treaty by virtue of having veto power within the UN Security Council, while nothing can be done about it.

However, although it is true, it is not a valid criticism. Enforcement of legislation is one thing, while the existence of legislation is quite another thing. Legislation, regardless of anything else, sets standards that can then be applied to assess the actions of other parties.


CONCLUSION

The discussion presented here ventures into difficult territory. Namely, how are offensive cyber operations regulated by existing laws? While international laws may provide tools for addressing cyber attacks, they were formulated during another age and cannot simply be applied to cyber conflicts.

Three fundamental findings emerged. The first problem is uncertainty about the definition of cyber operations. Where does espionage end and armed attack begin? Secondly, there is a problem with cyber operations' anonymity, as no one knows who the attacker might be, thus making prosecution impossible. Lastly, the lack of an ethical approach to the matter. Governments must agree on the moral considerations regarding the use of cyber technology in warfare.

None of these problems are insoluble, however. States have successfully resolved much more complicated coordination problems in the past. After World War II, they managed to come up with principles for warfare which were previously deemed unthinkable. Similarly, despite difficulties with verifying such treaties, arms control limited the proliferation of nuclear arsenals.

In today's reality, the only important thing is political will. It is obvious that major powers such as the US, Russia, and China have strong interests to develop their cyber capabilities; however, at the same time, it will cause problems for global stability. What needs to be done in order to reach an agreement is to maintain rational defensive measures along with the promise not to conduct devastating cyber warfare.

All this will require patience, concessions from both sides, and willingness to admit that nothing can be ideal. In the absence of certain norms and regulations, the escalation of cyber warfare is expected, which will inevitably lead to increasing damages and victimization of ordinary people due to vulnerabilities of critical infrastructure.

In future research, the influence of regional associations such as the European Union and ASEAN on cyber norms needs to be investigated. Research on attribution technology requires additional attention too. It will also be beneficial to study whether existing arms control systems may serve as examples of developing cyber agreements.

There are many uncertainties related to offensive cyber law; nonetheless, this does not mean that we should stop working on the problem.


REFERENCES

  • Andy Greenberg, Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers (Doubleday 2019).

  • Anja Damanik & Anna Riddervold, Corporate Responsibility in Cyber Warfare, 47 Harvard International Law Journal 31 (2024).

  • Charter of the United Nations, art. 51, June 26, 1945, 59 Stat. 1031.

  • Duncan Hollis, Why States Need an International Law for Information Operations, 11 Lewis & Clark Law Review 1023 (2007).

  • Eneken Tikk et al., Cyber Attacks Against Georgia: Legal Lessons Identified (NATO Cooperative Cyber Defence Centre of Excellence 2008).

  • Geneva Convention (I) for the Amelioration of the Condition of the Wounded and Sick in Armed Forces in the Field, Aug. 12, 1949, 6 U.S.T. 3114.

  • International Committee of the Red Cross, International Humanitarian Law and Cyber Operations During Armed Conflict (2019).

  • Kubo Macák, Cyber Operations and International Law, in Oxford Research Encyclopedia of International Law (2019).

  • Lee Ferran & James Gordon Meek, Cyber Warfare: Is the U.S. at Risk?, ABC News (Dec. 29, 2015), http://abcnews.go.com (accessed June 6, 2026).

  • Luciano Floridi & Josh Cowley, A Unified Framework of Five Principles for AI in Society, 1 Harvard Data Science Review, no. 1, 3 (2019).

  • Michael N. Schmitt (ed.), Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations 10 (Cambridge University Press 2017).

  • Oona Hathaway et al., The Law of Cyber Attack, 89 Columbia Law Review, no. 2, 347 (2012).

  • Scott J. Shackelford, From Nuclear War to Net War: Analogizing Cyber Attacks in International Law, 27 Berkeley Journal of International Law 192 (2009).

  • Thomas C. Schelling, The Strategy of Conflict 207 (Harvard University Press 1960).

  • U.S. Department of Justice, Criminal Charges Unsealed Against Six Russian GRU Officers (Oct. 19, 2020).






Comments


bottom of page