
Cyberattacks and the Use of Force
An interview with Prof. Duncan Hollis
When does a cyberattack become a use of force under international law, and what may a state do in response? States now agree that international law applies in cyberspace. They still disagree about how it applies.
In this TalksOnLaw interview, recorded in March 2022 in the first weeks of Russia's full-scale invasion of Ukraine, Joel Cohen speaks with Duncan Hollis, Laura H. Carnell Professor of Law at Temple University Beasley School of Law and a former attorney-adviser at the State Department. Hollis explains how cyber operations work, the debates over applying international law to them, the line between a use of force and an armed attack, Estonia and the Tallinn Manual, proxies and attribution, influence operations, and countermeasures.
Lead Time, Spillover, and the Cyber Arsenal
Serious cyber operations can take months or years to prepare, Hollis explains: gaining access, mapping a network, then deploying exploits. States that follow the rule of law tend to act with care and target narrowly, unlike the 2017 NotPetya and WannaCry malware, which caused billions of dollars in damage worldwide. Tools can be turned against their makers. EternalBlue, leaked NSA software, was repurposed by criminals, and operations can spill back onto a state's own population. Computer scientists sort threats by the "CIA triad": losses of confidentiality (espionage and data breaches), integrity (making a system do something other than intended, such as moving decimal places in bank records), and availability (ransomware and distributed denial of service attacks). For national security lawyers, he notes, the indirect effects often matter most.
Rules of the Road and Three Kinds of Dispute
John Perry Barlow's declaration of cyberspace's independence from government is now a cautionary tale; states, China with its "great cyber wall" among them, have asserted control. In 1998 Russia asked the UN to negotiate rules for the information environment, with an eye, Hollis says, to regulating speech. Only in 2013 did states agree that existing international law applies. Since then the fight has been over how. Hollis sorts the disputes with three images. Sartre stands for existential debates over whether whole bodies of law apply; China long resisted applying international humanitarian law, until a consensus report said it might. Baby carriages recall H.L.A. Hart and Lon Fuller's "no vehicles in the park" debate: states accept the ban on force but disagree on what it covers. Horses refer to Judge Frank Easterbrook's "law of the horse" and Larry Lessig's reply that cyberspace is different. A fourth problem, the "sound of silence," is that covert operations leave little visible practice.
Treaties, Custom, and the Budapest Convention
International law has no global police force or court, so enforcement is largely horizontal, more like peers in a community steering one another. Its main sources are treaties and customary international law, which arises from consistent state practice followed out of a sense of legal obligation. The United States, for example, is not party to the UN Convention on the Law of the Sea but accepts its 12-mile territorial sea as custom. The one cyber treaty Hollis identifies is the Council of Europe's Budapest Convention, which addresses cybercrime and was negotiated to exclude conduct a state authorizes. That leaves custom, which is hard to identify when state practice is hidden. Some would presume general rules apply until states say otherwise; others would build the law from observed practice.
Stuxnet and the Gray Zone
Hollis calls the Stuxnet worm the seminal moment. In an operation attributed to the United States and Israel, which have never admitted it, malware manipulated the controllers of centrifuges at Iran's Natanz facility, spinning them to destruction while telling operators all was well. Reaching a system not connected to the internet was hard, reportedly through thumb drives, and the worm spread to Siemens systems worldwide, though it stayed dormant outside Natanz. Stuxnet showed that cyber means could damage physical things. States have since built cyber forces; U.S. Cyber Command then had more than 6,000 personnel. Most activity has stayed in a gray zone, such as the 2015 attack, attributed to Russia, that cut power in parts of Ukraine for about six hours. No "digital Pearl Harbor" has come, and nothing in cyber, he said then, approached the horrors of the war in Ukraine.
Use of Force, Armed Attack, and War
Article 2(4) of the UN Charter bars the use of force except in self-defense or with Security Council approval. Written with World War II in mind, the idea has grown to cover non-kinetic means such as chemical and biological weapons. In cyberspace the main approach looks to effects: if the effects are like those of a kinetic use of force, the operation is one. States rarely label specific operations, but the Tallinn Manual experts considered Stuxnet a use of force. Clear lines matter because one state's espionage may look like force to another. "War" largely left the legal vocabulary after the 1928 Kellogg-Briand Pact; Russia calls its invasion a "special military operation." What matters is the armed attack that triggers self-defense. The United States treats any use of force as an armed attack, a minority view; most states require greater scale and effects. A victim of an armed attack need not answer cyber with cyber.
Estonia, NATO, and the Tallinn Manual
If Stuxnet showed cyber's physical potential, Estonia in 2007 showed that cyberspace would be contested between states. As Tallinn prepared to move a Soviet war memorial, a massive denial of service attack took government, bank, and university websites offline for weeks. Estonia blamed Russia, which denied it and refused to help. Estonia asked whether NATO's Article 5, invoked after September 11, applied. NATO said no, since there were no deaths or physical destruction, but it set up a center of excellence in Tallinn, which hosts the annual CyCon conference, where Hollis has spoken. The center funded independent experts who produced the Tallinn Manual 1.0 and 2.0, a book of several hundred pages. It has become a reference point, Hollis says, but it is not binding: it is neither a treaty nor custom.
Proxies and Due Diligence
Many states act through proxies, for capacity or deniability, and Russia, Hollis says, has green-lighted criminal hacking so long as it is aimed abroad. A state is responsible for its organs and agents. For private actors, the International Court of Justice requires "effective control," a standard from Nicaragua's case over U.S. support for the Contras, rather than the broader "overall control" test of the Yugoslavia tribunal. Funding, or even supplying malware, may not be enough, and foreign ministries know where the lines are. Another path is due diligence: a state should not allow its territory to be used to violate other states' rights. After the Colonial Pipeline ransomware shutdown, traced to criminals in Russia, President Biden pressed President Putin to act. Hollis separates a duty to act from the contested "unwilling or unable" theory, noting that Russia used similar logic as a thin veil for invading Ukraine.
Attribution and False Flags
The internet, which grew from the government's ARPANET, was not designed for attribution, and operations can be routed through many "stepping stones." Early on, some thought cyber threats had to be handled like hurricanes, through defense alone. In 1998's Solar Sunrise, the Defense Department suspected Iraq, but the intruders were three teenagers. Attribution has since improved. A handful of states and large tech companies, especially cloud providers, see enough traffic to recognize patterns, and governments combine forensics with human and other intelligence. False flags remain a worry: an attack that shut down French broadcaster TV5Monde, made to look like the work of Middle Eastern terrorists, was later attributed to Russia. States now name one another, as President Obama did over the Sony Pictures hack, and increasingly join in collective accusations.
Influence Operations
Influence operations descend from psychological operations; they aim at the minds of a public or its decision-makers rather than at things. Experts focused on catastrophic attacks, Hollis says, missed the "death by a thousand cuts" of disinformation, as when Russia's Internet Research Agency used fake social media personas to deepen polarization around the 2016 U.S. election. During COVID, governments encouraged vaccine hesitancy abroad and at home. A government that promotes a harmful false cure may violate its own people's rights to life, health, and health information. Abroad, the duty of non-intervention turns on coercion, but the best influence operation leaves targets believing they chose freely. Hollis finds international law "not up to the task" and suggests regulating form rather than content: governments should have to identify themselves when they speak.
Countermeasures and a Hopeful Close
In practice, Hollis observes, Iran answered Stuxnet not with international law but by hacking U.S. banks, and Russian troll farm workers got text messages from the U.S. government suggesting they "think about [their] travel plans." International law's horizontal answer is countermeasures: a proportionate, otherwise unlawful act in response to another state's wrongful act, as in trade disputes. Armed reprisals were abandoned after the world wars, and the International Law Commission's work on state responsibility frames the modern rule. Countermeasures must respect human rights. Whether they can be collective is contested. Estonia supports collective countermeasures, as with collective self-defense; France warns they would be escalatory. Hollis closes with cautious hope. States rallied to the rule of law over Ukraine and declared hospitals off-limits, and he hopes the world can move from normalizing cyber insecurity to normalizing cybersecurity.
What to Know Now
The legal framework Hollis describes still governs, and his point about lead time has gained weight. As of October 2026 the war in Ukraine continues, with cyber operations alongside, not in place of, kinetic force. An attack on Viasat's KA-SAT satellite network on February 24, 2022, disrupted service in Ukraine and elsewhere in Europe; the EU, the UK, the United States, and others attributed it to Russia that May. An April 2022 attempt to cut Ukrainian power with Industroyer2 malware was foiled. In 2024 U.S. and allied agencies warned that China-linked Volt Typhoon actors were pre-positioning in critical infrastructure networks for possible disruption in a crisis, and in 2025 the FBI said the Salt Typhoon espionage campaign had reached more than 80 countries. China denies the allegations.
At the UN, a working group's July 2025 final report created a permanent Global Mechanism on ICT security, which held its first substantive session in July 2026. The UN Convention against Cybercrime, adopted in December 2024, had 95 signatories and 3 parties as of October 6, 2026, and is not yet in force; it needs 40. It covers criminal cooperation, not state operations, and the United States has not signed. The Budapest Convention now has 83 parties. The silence Hollis described has partly lifted: SIPRI counts 35 published national positions, plus common positions from the African Union and the EU in 2024, which tie a use of force to scale and effects. States remain split on collective countermeasures, and Tallinn Manual 3.0 is still in progress.
U.S. policy has grown more assertive. The March 2026 Cyber Strategy for America commits to the "full suite" of defensive and offensive cyber operations and says responses will not be confined to cyberspace. A companion executive order calls for diplomatic pressure, including possible sanctions, on countries that fail to act against cybercriminals, an echo of the due diligence debate. NATO allies have said a cyberattack could trigger Article 5 case by case. Hollis co-convenes the Oxford Process, whose expert statements address health care, elections, information operations, and ransomware.
Additional Resources
Resources Mentioned in the Program
- John Perry Barlow, A Declaration of the Independence of Cyberspace (1996): The manifesto Hollis cites as a cautionary tale about a government-free cyberspace.
- Frank H. Easterbrook, Cyberspace and the Law of the Horse, 1996 U. Chi. Legal F. 207: The essay arguing that general legal rules suffice and no separate "law of cyberspace" is needed.
- Lawrence Lessig, The Law of the Horse: What Cyberlaw Might Teach, 113 Harv. L. Rev. 501 (1999): Lessig's reply that cyberspace has features that justify studying it on its own terms.
- NATO CCDCOE, The Tallinn Manual: The center's page on the Tallinn Manual (2013), Tallinn Manual 2.0 (2017), and the Tallinn Manual 3.0 project now under way.
- NATO CCDCOE, CyCon: The annual International Conference on Cyber Conflict in Tallinn that Hollis mentions.
- Kellogg-Briand Pact (1928): The interwar treaty renouncing war as an instrument of national policy.
Treaties, Cases, and Codifications
- Charter of the United Nations: Article 2(4) prohibits the threat or use of force; Article 51 preserves the right of self-defense against an armed attack.
- The North Atlantic Treaty (1949): Article 5 provides that an armed attack against one ally is an attack against all.
- Military and Paramilitary Activities in and against Nicaragua (Nicaragua v. United States), I.C.J. (1986): The source of the "effective control" test and the distinction between the gravest uses of force and lesser ones.
- International Law Commission, Articles on Responsibility of States for Internationally Wrongful Acts (2001): The rules on attribution and countermeasures that Hollis discusses.
- Council of Europe, The Budapest Convention on Cybercrime: The 2001 cybercrime treaty, now with 83 parties.
- UNODC, United Nations Convention against Cybercrime: The convention adopted in 2024; see the UN Treaty Collection for current signatures and ratifications.
UN Processes and State Positions
- Report of the Group of Governmental Experts on Advancing Responsible State Behaviour in Cyberspace, U.N. Doc. A/76/135 (2021): The consensus report that noted international humanitarian law applies in situations of armed conflict and addressed proxies and due diligence.
- Digital Watch, UN Global Mechanism on ICT Security: A tracker of the UN cyber processes, from the GGEs and the working group to the permanent Global Mechanism that began in 2026.
- Council of the EU, Declaration on a Common Understanding of International Law in Cyberspace (Nov. 18, 2024): The EU's common position on sovereignty, non-intervention, the use of force, self-defense, and countermeasures.
- Russell Buchan & Nicholas Tsagourias, The African Union's Statement on the Application of International Law to Cyberspace, EJIL:Talk! (Feb. 20, 2024): An analysis of the African Union's January 2024 common position.
- International Cyber Law: Interactive Toolkit: Hypothetical scenarios, incident summaries, and a collection of national positions on international law in cyberspace.
Current Threats and Policy
- CISA, NSA, FBI, et al., PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure (Feb. 7, 2024): The joint advisory on Volt Typhoon's pre-positioning in critical infrastructure networks.
- The White House, President Trump's Cyber Strategy for America (Mar. 2026): The current U.S. national cyber strategy and its six policy pillars.
- NATO, Cyber Defence: NATO's overview of its cyber defense policy, including Article 5 and the Integrated Cyber Defence Centre.
Scholarship by the Speaker
- Duncan B. Hollis, A Brief Primer on International Law and Cyberspace (Carnegie Endowment, June 14, 2021): A short introduction to the issues covered in this program.
- The Oxford Process on International Law Protections in Cyberspace: The expert initiative Hollis co-convenes, with its statements on health care, vaccine research, elections, information operations, and ransomware.
- Martha Finnemore & Duncan B. Hollis, Beyond Naming and Shaming: Accusations and International Law in Cybersecurity, 31 Eur. J. Int'l L. 969 (2020): How public accusations shape attribution and the law of cyberspace.
- Jens David Ohlin & Duncan B. Hollis, eds., Defending Democracies: Combating Foreign Election Interference in a Digital Age (OUP 2021): Essays on legal and other responses to foreign election interference.
About Prof. Duncan Hollis
“That’s long been a worry about these cyber operations, that unless there’s at least enough sharing or agreement on those rules of the road, we might end up stumbling into a conflict.”
Duncan B. Hollis is the Laura H. Carnell Professor of Law at Temple University Beasley School of Law, where he is Faculty Co-Director of the Institute for Law, Innovation & Technology (iLIT) and directs the LL.M. and J.D./LL.M. programs in Transnational Law. His scholarship engages with issues of international law, interpretation, and cybersecurity, with a particular emphasis on treaties, norms, and other forms of international regulation. With Dapo Akande and Harold Koh, he co-convenes the Oxford Process on International Law Protections in Cyberspace, which has produced expert statements on international law protections for health care, vaccine research, and elections, and on information operations and ransomware. He is a member of the U.S. Department of State’s Advisory Committee on International Law and an elected member of the American Law Institute, where he has served as an Adviser on the Restatement (Fourth) of the Foreign Relations Law of the United States. Elected by the General Assembly of the Organization of American States in 2016, he served a four-year term (2017–2020) on the OAS’s Inter-American Juridical Committee, where he was the Rapporteur on binding and non-binding agreements and the Rapporteur on improving the transparency of State views on international law’s application to cyberspace. He was a non-resident Scholar at the Carnegie Endowment for International Peace from 2017 to 2024. Before joining Temple, he served as an Attorney-Adviser in the Office of the Legal Adviser at the U.S. Department of State, where he was a U.S. negotiator of the Budapest Convention on Cybercrime. Hollis has also been a Senior Fellow at Melbourne Law School, a Visiting Professor at LUISS Università Guido Carli, a Visiting Research Fellow at the University of Pennsylvania’s Perry World House, and a Short-Term Visiting Fellow at Jesus College, Oxford. For more than a decade he was a regular contributor to the international law blog Opinio Juris. His books include The Oxford Guide to Treaties (OUP, 2nd ed., 2020), International Law (Aspen, 8th ed., 2023) (with Allen Weiner and Chimène Keitner), and Defending Democracies: Combating Foreign Election Interference in a Digital Age (OUP, 2021) (co-edited with Jens David Ohlin). His articles have appeared in various journals and books.


