Cyber warfare laws are the layered set of rules that govern state-sponsored cyberattacks: international law treats a destructive digital operation the same as a conventional armed attack when its effects are comparable, U.S. sanctions and criminal statutes reach the individuals and companies behind such operations, and federal reporting rules require critical infrastructure operators to disclose serious incidents within tight deadlines. The rules matter most at three moments: when a government decides how to respond to an attack, when a company decides whether it can lawfully pay a ransom, and when a covered entity decides how quickly it must tell the government what happened.
When a Cyberattack Counts as an Act of War
Article 2(4) of the United Nations Charter prohibits the threat or use of force against the territorial integrity or political independence of any state.1United Nations. United Nations Charter The provision was drafted with conventional weapons in mind, but legal consensus now extends it to digital operations that produce effects equivalent to a kinetic strike. A cyberattack that breaches a dam, collapses a power grid, or crashes an aircraft control system meets the threshold. Website defacements, brief outages, and routine intrusions do not.
The dividing line comes from the “scale and effects” test, which traces back to the International Court of Justice’s 1986 Nicaragua ruling. Rather than looking at the tool used, the test looks at what happened. If the physical consequences resemble those of a conventional armed attack, the operation is treated as one. The analysis weighs severity of damage, immediacy of harm, reversibility, and how deeply the operation penetrated the target’s systems.2Lieber Institute West Point. Evolving Interpretation of the Use of Force in Cyber Operations: Insights from State Practices
When a cyber operation clears that bar, the targeted state has the right to respond in self-defense under Article 51 of the UN Charter, which preserves the “inherent right of individual or collective self-defence if an armed attack occurs.” The defending state must immediately report its defensive measures to the UN Security Council, and any response must still be proportionate and necessary.1United Nations. United Nations Charter A brief network disruption does not license taking down another country’s hospital systems.
Most real disputes never reach that threshold. They live in the space governed by the principle of non-intervention, which prohibits states from using coercive means to interfere in another state’s internal or external affairs.3International Cyber Law: Interactive Toolkit. Prohibition of Intervention A state-backed operation that manipulates election infrastructure or corrupts a government database may not destroy anything physical, but the coercive intent to affect sovereign decision-making makes it unlawful.
The Attribution Problem
Every legal response depends on proving which government ordered the attack. Without attribution, a state cannot invoke self-defense, impose lawful countermeasures, or pursue reparations. Two competing standards govern how much proof is required, and the choice between them often determines whether a case goes anywhere.
Effective Control
The ICJ established the stricter test in Nicaragua. A state is responsible for the actions of a non-state group only if it directed or controlled the specific operations at issue.4ICRC. ICJ, Nicaragua v. United States General funding, training, or encouragement is not enough. Applied to cyber cases, this means proving that a government tasked a specific hacking operation, not merely that a group has ties to a state’s intelligence services. Digital forensics rarely reaches that far on its own.
Overall Control
The International Criminal Tribunal for the former Yugoslavia set a lower bar in its 1999 Tadić appeal. The “overall control” test holds a state responsible when it plays a role in organizing, coordinating, or planning a group’s actions, in addition to financing, training, or equipping it. Individual acts by the group can be attributed to the state without proof that the state ordered each one. The tribunal expressly acknowledged this standard is less rigorous than effective control.
Which test applies to cyber operations remains unresolved. States seeking to avoid accountability prefer the stricter ICJ test; states seeking to hold adversaries responsible push closer to overall control. The International Law Commission’s Articles on State Responsibility say conduct counts as an act of a state when a person or group was “acting on the instructions of, or under the direction or control of, that State.”5United Nations International Law Commission. Draft Articles on Responsibility of States for Internationally Wrongful Acts That phrasing accommodates both readings, and the ambiguity is deliberate.
Countermeasures and Their Limits
Short of self-defense, a state’s main lawful response to a cyber operation is to take countermeasures: actions that would normally be unlawful but become temporarily permissible because they aim to make the offending state stop and comply with its obligations. The ILC framework imposes several constraints. Countermeasures must be proportionate to the harm suffered. They must be reversible, so normal relations can resume once compliance is achieved. And the injured state must first demand compliance and offer to negotiate, unless urgent action is needed to preserve its rights.5United Nations International Law Commission. Draft Articles on Responsibility of States for Internationally Wrongful Acts
In practice, countermeasures might include retaliatory cyber operations against the responsible state’s networks, suspension of treaty obligations, or blocking economic cooperation. Proportionality is where cases get hard. Destroying an attacker’s military communications network in response to a data-wiping operation against a financial system would likely fail the test. Countermeasures also have to end as soon as the offending state complies. They are a pressure tool, not punishment.
The Tallinn Manual
The Tallinn Manual is the reference text practitioners reach for when applying international law to cyber operations. The first edition, published in 2013 by legal experts at NATO’s Cooperative Cyber Defence Centre of Excellence, focused on cyber operations that rise to the level of armed conflict or use of force. It established that the laws of armed conflict apply in full to destructive cyber campaigns, meaning targeting, proportionality, and civilian-protection rules operate the same way they would in kinetic warfare.
Tallinn Manual 2.0, published in 2017, extended coverage to the peacetime operations states deal with every day: espionage, low-level intrusions, sovereignty violations, and interference causing economic harm without physical destruction.6CCDCOE. The Tallinn Manual Neither manual is binding law. They represent expert consensus on how existing rules apply, and governments increasingly cite them when publishing their own positions on cyber norms.
U.S. Criminal Exposure for State-Linked Hacking
International law does not explicitly ban peacetime espionage between states, but U.S. domestic law does. The Computer Fraud and Abuse Act makes it a federal crime to access a computer without authorization and obtain national defense information. A first offense carries up to 10 years in prison; a second offense carries up to 20.7Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers
When trade secret theft is done to benefit a foreign government, the charge escalates to economic espionage under a separate statute. Individuals face up to 15 years in prison and fines up to $5 million; organizations face fines up to $10 million or three times the value of the stolen trade secret, whichever is greater.8Office of the Law Revision Counsel. 18 USC 1831 – Economic Espionage The distinguishing factor is foreign government involvement. Stealing a competitor’s formula for personal profit is a federal crime; doing it at the direction of a foreign state moves the case into a different sentencing tier.
The Department of Justice has used these statutes to indict foreign nationals who will likely never stand trial in the United States. The indictments serve a public attribution function: they name individuals and their government affiliations, putting diplomatic pressure on the sponsoring state.
OFAC Sanctions and Ransomware Payments
Executive Order 13694, signed in 2015 and later amended, authorizes the Treasury Department to freeze the U.S.-based assets of any person or entity engaged in cyber-enabled activities that pose a significant threat to national security, foreign policy, or economic stability. The order covers compromising critical infrastructure, causing significant network disruptions, or stealing funds, trade secrets, or personal data for commercial gain.9eCFR. 31 CFR Part 578 – Cyber-Related Sanctions Regulations
The Treasury Department’s Office of Foreign Assets Control maintains the Specially Designated Nationals list. Once a person or entity is listed, all U.S. property is frozen and U.S. persons and companies are prohibited from transacting with them. OFAC has designated actors tied to Russian, Chinese, North Korean, and Iranian government cyber programs. In December 2024, OFAC designated a Chinese cybersecurity company and one of its employees for compromising firewall products and conducting ransomware attacks.10U.S. Department of the Treasury. Cyber-Related Sanctions
Penalties for Violations
Companies that inadvertently transact with a sanctioned cyber actor face steep consequences. The maximum civil penalty under the International Emergency Economic Powers Act is $377,700 per violation or twice the value of the transaction, whichever is greater. Willful violations carry criminal fines up to $1 million and up to 20 years in prison for individuals.9eCFR. 31 CFR Part 578 – Cyber-Related Sanctions Regulations
The Ransomware Payment Question
If your company receives a ransomware demand, paying it to a sanctioned entity is an OFAC violation regardless of whether you knew the attacker’s identity. OFAC’s 2021 advisory on ransomware payments made this explicit, warning that facilitating payments to sanctioned actors exposes both the victim and any third-party payment facilitator to enforcement. Companies can apply for a specific OFAC license to authorize an otherwise prohibited transaction, but the approval process is slow and the outcome uncertain. The safer path is building SDN and consolidated-list screening into your incident response plan before an attack forces the question. OFAC publishes industry-specific guidance for the sectors with the highest exposure, including virtual currency and ransomware payment negotiation services.
CIRCIA Reporting Deadlines
The Cyber Incident Reporting for Critical Infrastructure Act, signed into law in 2022, will require covered entities to report significant cyber incidents to CISA within 72 hours of reasonably believing the incident occurred.11Cybersecurity & Infrastructure Security Agency. Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) Ransom payments carry a tighter deadline: 24 hours after the payment is disbursed.12Regulations.gov. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements
The reporting requirements are not yet in effect. CISA published a proposed rule in April 2024 and has extended its rulemaking timeline, with the final rule expected in 2026.13Cybersecurity & Infrastructure Security Agency. CIRCIA FAQs The scope of “covered entities” tracks the 16 critical infrastructure sectors designated under Presidential Policy Directive 21, which span energy, water, financial services, healthcare, communications, transportation, the defense industrial base, and other sectors whose disruption would have a debilitating national effect.14Cybersecurity & Infrastructure Security Agency. Critical Infrastructure Sectors
Enforcement escalates once the rule takes effect. CISA can issue a formal request for information, follow it with an administrative subpoena, and refer non-compliance to the Attorney General for civil enforcement in federal court. A court can hold a non-compliant entity in contempt. Anyone who knowingly submits false information in a CIRCIA report faces criminal penalties under federal false statement laws, including up to five years in prison.15Federal Register. Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) Reporting Requirements State, local, tribal, and territorial government entities are exempt from CIRCIA’s enforcement provisions.
Cyber Insurance and War Exclusions After Merck
Most commercial property and casualty policies contain a “hostile or warlike action” exclusion that bars coverage for losses caused by acts of war. As state-sponsored attacks became more common, insurers argued the exclusion should reach government-backed digital strikes against private companies. A 2023 New Jersey appellate decision rejected that argument.
In Merck v. ACE American Insurance Co., the pharmaceutical company sought coverage for losses from the 2017 NotPetya attack, widely attributed to the Russian military. The insurers denied nearly $700 million in disputed coverage under the war exclusion. The court ruled the exclusion did not apply, reasoning that the “hostile or warlike action” language historically required military action in the traditional sense. Extending it to an attack on a non-military company that sold commercial products to non-military customers would stretch the exclusion beyond its plain meaning.16New Jersey Courts. Merck and Co., Inc. v. ACE American Insurance Co. The court noted that insurers had known about cyber warfare risks for years and could have updated their language.
Since Merck, many insurers have rewritten war exclusions to specifically reference cyber operations, and some policies now distinguish between attacks attributed to nation-states and those carried out by criminal organizations. If your company carries cyber insurance, the war and government-action exclusion language is worth a close read, because the coverage landscape has shifted materially since 2023.
NATO Article 5 and Cyberspace
NATO formally recognized cyberspace as a domain of operations in 2016, placing it alongside land, sea, and air. Defense ministers approved an updated Cyber Defence Action Plan in 2017. The unresolved question is whether a cyberattack against one member state can trigger Article 5, the collective defense provision that treats an attack on one ally as an attack on all. NATO has kept its position deliberately ambiguous, declining to define the threshold.
In practice, a large-scale cyber operation against a member’s critical infrastructure could theoretically invoke collective defense, but the decision would be political rather than automatic. Each member would need to agree the operation constituted an armed attack warranting a collective response. The ambiguity is the point: an attacker cannot know in advance whether a given operation will be treated as a nuisance, a bilateral matter, or a trigger for a response from 32 nations.
Where the Frameworks Are Heading
International law provides for reparations when a state is found responsible for an unlawful cyber operation, including restoration of damaged systems, compensation for economic losses, and guarantees of non-repetition. Enforcement is the weak spot. No international court can compel a sovereign nation to pay, and the states most likely to conduct destructive cyber operations are the least likely to submit to international jurisdiction. Financial isolation through sanctions, criminal indictments naming individual operatives, and the threat of countermeasures fills part of the gap. For companies, the practical upshot is that mandatory reporting is expanding, sanctions authority is broadening, and public attribution is becoming the norm rather than the exception.