← New search

Other meanings of Cyberwarfare

Cybersecurity & Conflict

Cyberwarfare

Cyberwarfare is the use of digital attacks by a nation-state to damage another state, targeting its computer systems, networks, and information infrastructure to achieve strategic military or political objectives. It encompasses a range of hostile actions, from espionage and sabotage to disruption of critical services, and has become a defining feature of modern international conflict.

2007
First widely recognized state-on-state cyberattack (Estonia)
2010
Stuxnet discovered, first known cyberweapon
~1,000
Russian GRU cyber operations since 2016 (per UK NCSC)
$10.5T
Projected annual global cost of cybercrime by 2025 (Cybersecurity Ventures)
1

Definition and scope

Cyberwarfare is defined as the use of digital attacks by a nation-state to damage another state, targeting its computer systems, networks, and information infrastructure to achieve strategic military or political objectives. It is distinguished from cybercrime (which is primarily financially motivated) and hacktivism (which is ideologically driven but not state-sponsored). The term gained prominence after the 2007 denial-of-service attacks on Estonia, which were widely attributed to Russia, and the 2010 discovery of Stuxnet, a US-Israeli worm that physically destroyed Iranian centrifuges.

Cyberwarfare can include espionage (theft of classified data), sabotage (disruption or destruction of systems), and influence operations (manipulation of public opinion). It may be conducted as a standalone operation or as part of a broader conventional conflict. The Tallinn Manual, a study by the NATO Cooperative Cyber Defence Centre of Excellence, provides a legal framework for how international law applies to cyber operations.

2

Historical milestones

The first recognized state-on-state cyberattack occurred in 2007 when Estonia, a NATO member, faced a month-long distributed denial-of-service (DDoS) campaign that targeted government, banking, and media websites. The attacks were traced to Russian state-sponsored actors, though Moscow denied involvement. This event prompted NATO to establish its Cooperative Cyber Defence Centre of Excellence in Tallinn.

In 2010, the Stuxnet worm was discovered, marking the first known use of a cyberweapon to cause physical damage. It targeted Siemens industrial control systems used in Iran's Natanz uranium enrichment facility, destroying roughly 1,000 centrifuges. Stuxnet was a joint US-Israeli operation, and its sophistication—including the use of multiple zero-day exploits—set a new benchmark for cyberweapons.

More recently, cyberwarfare has expanded to include influence operations, such as Russian interference in the 2016 US presidential election, which involved hacking and leaking emails and social media manipulation. These operations blur the line between espionage and warfare, as they aim to undermine trust in democratic institutions.

3

Tactics and targets

Common tactics in cyberwarfare include distributed denial-of-service (DDoS) attacks, which overwhelm a system with traffic; malware such as worms and ransomware; phishing and spear-phishing to gain access; and supply-chain attacks, where software or hardware is compromised before delivery. Advanced persistent threats (APTs) are long-term campaigns that maintain stealthy access to a network for extended periods.

Targets are typically critical infrastructure: power grids, water systems, transportation, and financial networks. The 2015 and 2016 attacks on Ukraine's power grid, attributed to Russia, left hundreds of thousands without electricity and demonstrated the potential for cyberattacks to cause physical disruption. Other targets include government agencies, military systems, and industrial control systems. Espionage often targets intellectual property and state secrets, as seen in the 2014 Sony Pictures hack, which was attributed to North Korea.

4

Attribution and deterrence

Attribution—determining who is responsible for a cyberattack—is notoriously difficult due to the anonymity of the internet and the use of proxies and false flags. However, advances in forensic analysis and intelligence sharing have improved attribution. For example, the US and UK publicly attributed the 2017 NotPetya ransomware attack to Russia's military intelligence (GRU), despite the malware being disguised as ransomware.

Deterrence in cyberspace is challenging because of the difficulty of attribution and the lack of clear thresholds for retaliation. The concept of "cyber deterrence" includes both deterrence by punishment (threatening retaliation) and deterrence by denial (making systems more resilient). Some states have adopted policies of "defend forward" and "persistent engagement," which involve disrupting adversaries' cyber operations before they reach their targets. The US Cyber Command's "defend forward" strategy, announced in 2018, is an example.

5

International law and norms

International law, particularly the UN Charter, applies to cyber operations, but its interpretation is contested. The Tallinn Manual 2.0, published in 2017, concludes that the principle of sovereignty applies to cyberspace, and that cyber operations that cause physical damage or injury may constitute an armed attack, triggering the right to self-defense under Article 51.

In 2015, a UN Group of Governmental Experts (GGE) agreed that international law applies to cyberspace, but subsequent negotiations have stalled. In 2021, the UN adopted a resolution affirming that international law applies to cyberspace and called for the development of norms of responsible state behavior. However, there is no binding treaty specifically governing cyberwarfare, and states have differing views on issues such as sovereignty and the use of force.

6

Lesser-known aspects

Beyond the headline attacks, cyberwarfare includes lesser-known but significant operations. For instance, the 2014 attack on Saudi Aramco, attributed to Iran, used a virus called Shamoon to wipe data from 30,000 computers, replacing them with an image of a burning American flag. The attack was a response to US sanctions and demonstrated the potential for cyberattacks to disrupt oil production.

Another overlooked dimension is the use of cyberwarfare in territorial disputes, such as the 2010 Google cyberattack, which was traced to China and targeted human rights activists, but also involved the theft of intellectual property. Additionally, the 2018 Olympic Destroyer attack, which disrupted the Pyeongchang Winter Olympics, was initially attributed to North Korea but later analysis suggested it was a false-flag operation by Russia to frame North Korea.

Cyberwarfare also includes the targeting of undersea cables, which carry 95% of international data. In 2017, Russian submarines were observed operating near cables, raising concerns about potential sabotage. The 2019 attack on the US power grid, which involved a vulnerability in a firewall, was attributed to Russia and highlighted the risk to critical infrastructure.

Glossary

DDoS
Distributed denial-of-service: an attack that floods a system with traffic to make it unavailable.
Stuxnet
A computer worm discovered in 2010 that targeted Iranian nuclear centrifuges, causing physical damage.
APT
Advanced persistent threat: a long-term, stealthy cyberattack campaign often conducted by state-sponsored actors.
Tallinn Manual
A NATO-affiliated academic study on how international law applies to cyber operations.
Zero-day exploit
A software vulnerability that is unknown to the vendor and can be exploited before a patch is available.

Cyberwarfare remains a rapidly evolving field, with new tactics and legal debates emerging as technology advances.