Editor’s Note: Volunteer hackers now shadow armed conflict, from the collectives that hit Aeroflot last July to the pro-Iran groups claiming attacks in this year’s conflict. Scenario 36 of the Cyber Law Toolkit answers with a detailed map of what international humanitarian law demands of them: which operations cross into attacks, when participants become lawful targets and what the states hosting them must do.
For cybersecurity, data privacy, regulatory compliance and eDiscovery professionals, the scenario reads as advance warning. The target it chooses, a civil registry wiped along with its backups, is the kind of records system these readers defend, and the evidence such operations generate is the kind their teams may be asked to preserve.
Watch two threads from here: whether additional states adopt the functionality view of cyber attacks, narrowing the wiper question, and whether governments act on their obligation to restrain the hackers on their soil.
Content Assessment: When hacktivists join the fight: A closer read of Cyber Law Toolkit scenario 36
Information - 93%
Insight - 92%
Relevance - 92%
Objectivity - 93%
Authority - 94%
93%
Excellent
A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "When hacktivists join the fight: A closer read of Cyber Law Toolkit scenario 36]."
Industry News – Cybersecurity Beat
When hacktivists join the fight: A closer read of Cyber Law Toolkit scenario 36
ComplexDiscovery Staff
Erasing a nation’s birth records, their backups and the software that processes document requests is not protest. Under the interpretation of wartime law that most published state positions support, it is a prohibited attack on a civilian object, and, if the criminal elements are met, a war crime.
That is where Scenario 36 of the Cyber Law Toolkit ends up after walking a volunteer hacker collective through three operations against an enemy state. The scenario, titled “Civilian hacktivists during armed conflict,” postdates the toolkit’s 2025 annual update, which closed at Scenario 35, and it asks a question with sharp real-world edges: what does international humanitarian law (IHL) demand of civilians who join a war from their keyboards, and what do they forfeit when they do?
The toolkit is an informational academic resource, not binding law. Six partner institutions support it, including the NATO Cooperative Cyber Defence Centre of Excellence, the International Committee of the Red Cross (ICRC), the University of Exeter, the U.S. Naval War College, Wuhan University and the Czech National Cyber and Information Security Agency, with University of Exeter law professor Kubo Mačák serving as general editor. Its scenarios pair invented fact patterns with analysis that tracks where states agree, and where they split, on how international law applies in cyberspace.
A hypothetical built from real-world operations
The setup is spare. Two states are at war. IT specialists inside State A pull together a loose online collective united, in the scenario’s words, by the publicly stated purpose of “disrupting and inflicting damage on State B’s infrastructure, economy and administrative systems.” The group runs its own operations, though State A officials sometimes praise its work and the two sides occasionally connect and cooperate.
Three incidents follow. Supporters first flood the e-portal of State B’s civil registry, the system that records births, deaths and marriages, with a distributed denial-of-service (DDoS) operation that knocks it offline for 10 days. The group’s most skilled members then break into the servers behind the registry and deploy a wiper that destroys civilian records and their backups outright and ruins the software that processes document requests. Finally, members who have been mining soldiers’ social media accounts infect their phones with commercial spyware through spear-phishing, and, at the request of a State A frontline unit, collect location data so the unit can target State B soldiers in a contested city.
None of this strains the imagination. The toolkit’s own example list, which mixes wartime operations with peacetime analogues of the same methods, runs from the DDoS waves that battered Estonia in 2007 and the Shamoon wiper that destroyed data on about 30,000 computers at Saudi Aramco in 2012 to two operations from last year: the July 2025 attack on Aeroflot, claimed jointly by the Belarusian Cyber Partisans and the pro-Ukraine group Silent Crow, which forced the Russian carrier to cancel dozens of flights in a day and prompted Russian prosecutors to open a criminal investigation, and Predatory Sparrow’s June 2025 strikes on Iran’s Bank Sepah and the Nobitex cryptocurrency exchange, where blockchain analytics firms said the pro-Israel group destroyed roughly $90 million in cryptocurrency. The pattern has continued into this year’s conflict between Iran and the United States and Israel: dozens of pro-Iran hacktivist groups have claimed cyberattacks since the fighting began in late February, including operations aimed at payment systems and airport services, according to March reporting from Axios.
Civilian hackers still answer to the law of war
Because the collective belongs to neither state’s armed forces and answers to no responsible command, its members are civilians under IHL. Nor, in the toolkit’s assessment, is the loose collective organized enough, or its campaign intense enough, to make the group a party to its own separate conflict. Civilian status, however, does not place the hackers beyond the law of war. It places them squarely inside it.
Many IHL rules are written as flat prohibitions, and international criminal tribunals have held that they bind individuals whatever their official status. The analysis puts the structural point plainly: “for IHL to be effective, it must bind anyone who conducts hostilities,” including civilians running cyber operations connected to a war. The International Criminal Court’s Office of the Prosecutor reached the same conclusion in its first policy on cyber-enabled crimes, published in December 2025, which states, as quoted in the toolkit’s analysis, that “any person may be the perpetrator of a cyber-enabled war crime, irrespective of whether they act on behalf of a party to the armed conflict.”
The hinge is nexus. IHL reaches a cyber operation only when the operation is tied to the fighting, occurring in its context and in association with it. A group formed to damage the adversary in support of one belligerent’s war effort, the toolkit finds, clears that bar easily.
Where disruption ends and attack begins
The doctrinal center of the scenario is the meaning of “attack” under Article 49 of Additional Protocol I to the Geneva Conventions, because the strongest protections for civilian objects, including the civil registry, attach to attacks. States divide over what counts. Some, including Denmark, Israel and Peru, read the notion to require physical damage. A larger group of published national positions, among them Austria, Costa Rica, France, Germany, Ireland, Italy, Japan and New Zealand, treats a cyber operation that disables a system, destroying its functionality without breaking hardware, as an attack. The ICRC shares the functionality view, and the roster of published positions keeps growing: the European Union issued a common position addressing these questions in 2024, the same year the African Union set out a common position on how international law, including IHL, applies in cyberspace.
The toolkit sorts the two registry operations onto opposite sides of that line. The DDoS campaign leaves the portal unavailable for 10 days but causes no damage to the system, which resumes service once the traffic stops, so the analysis concludes it does not appear to qualify as an attack. The wiper is different. Records and backups are permanently deleted, the request-processing software is ruined, and State B must rebuild the system. Under the functionality view, which the toolkit says commands the larger share of published positions, the wiper is an attack on a civilian object and breaches the ban on attacking civilian objects. For states that insist on physical damage, neither operation would qualify as an attack, a divergence the analysis acknowledges. The same conclusion would follow, the toolkit adds, if civilian data itself were protected as a civilian object, a contested question it examines separately in Scenario 12. The label carries criminal stakes, the analysis says, because it also frames whether the conduct can be charged as a war crime.
Even the operation that is not an attack does not walk free. Wartime military operations still demand “constant care,” as Additional Protocol I puts it, to spare civilians and civilian objects, and the analysis sees no way to square a cyber operation aimed at a civil registry with that duty, or with any legitimate military purpose.
Direct participation carries a price
The scenario then flips the lens: what do the hackers lose? Civilians are protected against attack, in the words of Additional Protocol I, “unless and for such time as they take a direct part in hostilities.” Under the ICRC’s interpretive guidance, an act crosses that line only if it meets three cumulative criteria: a threshold of harm, direct causation of that harm, and a belligerent nexus, an act designed, in the guidance’s words, “in support of a party to the conflict and to the detriment of another.” The test itself is contested ground: the toolkit says the line for when conduct crosses into direct participation stays unsettled, and its notes pair the ICRC guidance with Michael Schmitt’s critical analysis, which argues the guidance tilts further toward civilian protection than state practice supports.
Applied here, the analysis reaches a split verdict. Hackers who deploy the wiper likely satisfy all three criteria, on the same functionality reasoning that makes the operation an attack, and may be lawfully attacked for such time as they participate. Volunteers who join the DDoS campaign likely do not reach the threshold of harm and keep their protection. The phone-hacking operation divides down the middle: harvesting general information from soldiers’ social media and passing it along is one thing, but collecting location data for a frontline unit planning strikes on specific soldiers is, in the analysis’s words, “an integral part of a coordinated military operation,” and those hackers may lose protection.
Loss of protection is only half the exposure. As the ICRC has emphasized, civilian hackers lack the immunity from prosecution that members of armed forces enjoy for lawful acts of war, which leaves them open to criminal charges under domestic law for their intrusions. The ICRC has also cautioned belligerents to weigh carefully whether kinetic force against civilian hackers is necessary at all, or whether less destructive cyber or electromagnetic means would achieve the objective.
What the state hosting the hackers owes
On the facts as given, the toolkit concludes the group’s operations are not attributable to State A. Occasional praise, contact and cooperation do not amount to instruction, direction or control, the standard for attributing private conduct to a state. The closest call is the third incident, where a State A frontline unit asked the group for targeting data, and the analysis counts even that request, on these facts, as falling short of that standard. But non-attribution is not a free pass. Common Article 1 of the Geneva Conventions obliges State A to ensure respect for IHL, which the analysis reads as a due diligence obligation to prevent and repress violations by private persons under its authority. The measures required scale with what the state knows, how grave the breach is, what means it has and how much sway it holds over the hackers. The toolkit’s menu includes calling on hackers to stand down, disseminating IHL to the public, providing model codes of conduct, enacting effective penal sanctions for grave breaches and enforcing existing cybercrime laws.
That menu tracks guidance the ICRC has pressed publicly since October 2023, when legal adviser Tilman Rodenhäuser and Mauro Vignati, the organization’s adviser on digital technologies of warfare, published eight rules for civilian hackers during war and four obligations for states to restrain them. Reception was mixed. The founder of the pro-Russia collective Killnet announced his group would comply, a pledge Samuel White of the National University of Singapore questioned in a Lieber Institute analysis, writing that reposting the rules is not the same as internalizing them and concluding they had yet to restrain actual conduct. ICRC lawyers returned in November 2025 with sharper framing, writing with academic co-authors that a state cannot escape responsibility for hackers operating under its direction by labeling them independent, that genuinely private hackers inside its borders still engage its due diligence duties, and that tech companies as much as volunteers need to learn the rules. Rodenhäuser extends the argument in a 2026 International Review of the Red Cross article on the limits IHL imposes on volunteer IT armies.
Records systems are the quiet casualty
For cybersecurity, information governance and eDiscovery professionals, the scenario’s most instructive choice is its target. A civil registry is identity infrastructure. Birth, death and marriage records anchor inheritance, benefits, travel, voting and civil litigation, and the scenario’s wiper deletes the records, the backups and the software that processes replacement requests. That is the governance nightmare in miniature. The operating moves that follow are ComplexDiscovery’s translation, not the toolkit’s text: treat vital-records systems as critical infrastructure, keep immutable, offline backups of irreplaceable registers, segment registry databases from public-facing portals, and rehearse how documents get issued when the system is down. The ICRC made a parallel point in its 2023 report on protecting civilians against digital threats during armed conflict, which directs recommendations at states, belligerents and tech companies, including measures to safeguard civilian data.
The soldiers’ phones carry a second lesson. Spear-phishing plus commercial spyware plus location tracking is the same kill chain aimed at executives, deal teams and litigation groups, and the scenario elevates mobile device management, hardened personal devices and disciplined social media habits from compliance hygiene to battlefield controls.
The evidence trail matters as much as the malware. The ICC prosecutor’s cyber policy treats digital evidence as central to its investigations, acknowledging hard problems of collection, authentication, preservation and security, which means the logs, malware samples and attribution artifacts that incident responders generate can end up in a war crimes case file. Organizations that find themselves victim or conduit should extend familiar litigation-hold reflexes to conflict-linked intrusions: preserve forensic images, document chain of custody and expect cross-border requests to follow.
Counsel advising companies have a related brief: write it down. The ICRC’s November 2025 commentary urges tech companies to learn IHL and to segregate military from civilian data and infrastructure to limit collateral harm when military systems are attacked. Acceptable-use and insider-risk policies should say plainly that employees who volunteer for a combatant’s cyber campaign risk losing their protection from attack for as long as they directly participate, along with criminal exposure at home and abroad. Employer infrastructure is a separate question: an employee’s freelancing does not by itself change the status of company systems, but assets that make an effective contribution to military action, and whose destruction or neutralization would offer a definite military advantage, can qualify as military objectives, one reason the ICRC presses for segregation.
Scenario 36 closes with a checklist that reads like an incident-response tabletop for the age of patriotic hacking: who is responsible, what conduct amounts to an attack, when participation turns direct, what states must do about the hackers on their soil. The questions are getting less hypothetical by the month, and the answers are firming up as more states and regional bodies publish positions. When a volunteer with a laptop can become a lawful military target, the governance question stops being abstract: does your organization know where support for a cause ends and participation in a conflict begins?

News sources
- Scenario 36: Civilian hacktivists during armed conflict (Cyber Law Toolkit)
- 8 rules for “civilian hackers” during war, and 4 obligations for states to restrain them (ICRC Humanitarian Law & Policy Blog)
- From hackers to tech companies: IHL and the involvement of civilians in ICT activities in armed conflict (ICRC Humanitarian Law & Policy Blog)
- Award-winning cyber law resource releases 2025 update and opens call for submissions (NATO CCDCOE)
- Policy on Cyber-Enabled Crimes under the Rome Statute (International Criminal Court)
- ICC OTP Issues First Policy on Cyber-Enabled Crimes (American Society of International Law)
- Protecting Civilians Against Digital Threats During Armed Conflict (ICRC)
- Russia’s flag carrier Aeroflot cancels flights after pro-Ukrainian group hacks systems (Euronews)
- Pro-Israel hackers destroy $90 million in Iran crypto exchange breach, analytics firm says (CNBC)
- One Year On: Are the ICRC’s Principles for Civilian Hackers Shaping the Laws of War? (Lieber Institute West Point)
- Civilian hackers in war: The limits that international humanitarian law imposes on volunteer IT armies, hacktivists, and other civilian hackers (International Review of the Red Cross)
- The Interpretive Guidance on the Notion of Direct Participation in Hostilities: A Critical Analysis (Harvard National Security Journal)
- Hackers join U.S. and Israel’s fight with Iran (Axios)
Assisted by GAI and LLM technologies
Additional reading
- Beijing contests House Salt Typhoon report as Congress weighs a wider cleanup
- Restore the controller, risk losing evidence: federal water guidance leaves the sequence open
- Policy without control: the AI governance gap in IBM’s 2026 Cost of a Data Breach Report
- ShinyHunters’ July 31 deadline for EY arrives after third-party tax-data breach
- The new negligence baseline: how voluntary CI Fortify guidance becomes Exhibit A in post-breach litigation
- Stadler rejects $12.3 million ransom after supplier-linked platform breach
- SharePoint attackers are stealing the keys, and patching alone will not evict them
- UK and EU impose first simultaneous cyber sanctions as Poland attack is attributed to the FSB
- The negotiator was the leak: insider who betrayed ransomware victims gets 70 months
- Why a single Signal recovery key is a preservation problem
- Europe’s critical sectors are maturing, but seven still sit in ENISA’s risk zone
- When the worm targets the assistant: Miasma turns AI coding agents into the trigger
- Glasswing widens: Anthropic puts Mythos inside power, water and hospital operators across more than 15 countries
- Canvas breach moves from disclosure to demand as ShinyHunters sets May 12 deadline
- CISA’s CI Fortify rewrites the disconnection playbook for critical infrastructure
- A 48-month federal benchmark resets the incident-response insider question
- Data collection in occupied territory: A closer read of Cyber Law Toolkit scenario 35
- Cyber Law Toolkit tests surveillance and data collection under occupation
Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more legible for practitioners, policymakers, and business leaders.



























