Editor’s Note: Volunteer hackers now shadow armed conflict, from the collectives that hit Aeroflot last July to the pro-Iran groups claiming attacks in this year’s conflict. Scenario 36 of the Cyber Law Toolkit answers with a detailed map of what international humanitarian law demands of them: which operations cross into attacks, when participants become lawful targets and what the states hosting them must do.

For cybersecurity, data privacy, regulatory compliance and eDiscovery professionals, the scenario reads as advance warning. The target it chooses, a civil registry wiped along with its backups, is the kind of records system these readers defend, and the evidence such operations generate is the kind their teams may be asked to preserve.

Watch two threads from here: whether additional states adopt the functionality view of cyber attacks, narrowing the wiper question, and whether governments act on their obligation to restrain the hackers on their soil.


Content Assessment: When hacktivists join the fight: A closer read of Cyber Law Toolkit scenario 36

Information - 93%
Insight - 92%
Relevance - 92%
Objectivity - 93%
Authority - 94%

93%

Excellent

A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "When hacktivists join the fight: A closer read of Cyber Law Toolkit scenario 36]."


Industry News – Cybersecurity Beat

When hacktivists join the fight: A closer read of Cyber Law Toolkit scenario 36

ComplexDiscovery Staff

Erasing a nation’s birth records, their backups and the software that processes document requests is not protest. Under the interpretation of wartime law that most published state positions support, it is a prohibited attack on a civilian object, and, if the criminal elements are met, a war crime.

That is where Scenario 36 of the Cyber Law Toolkit ends up after walking a volunteer hacker collective through three operations against an enemy state. The scenario, titled “Civilian hacktivists during armed conflict,” postdates the toolkit’s 2025 annual update, which closed at Scenario 35, and it asks a question with sharp real-world edges: what does international humanitarian law (IHL) demand of civilians who join a war from their keyboards, and what do they forfeit when they do?

The toolkit is an informational academic resource, not binding law. Six partner institutions support it, including the NATO Cooperative Cyber Defence Centre of Excellence, the International Committee of the Red Cross (ICRC), the University of Exeter, the U.S. Naval War College, Wuhan University and the Czech National Cyber and Information Security Agency, with University of Exeter law professor Kubo Mačák serving as general editor. Its scenarios pair invented fact patterns with analysis that tracks where states agree, and where they split, on how international law applies in cyberspace.



A hypothetical built from real-world operations

The setup is spare. Two states are at war. IT specialists inside State A pull together a loose online collective united, in the scenario’s words, by the publicly stated purpose of “disrupting and inflicting damage on State B’s infrastructure, economy and administrative systems.” The group runs its own operations, though State A officials sometimes praise its work and the two sides occasionally connect and cooperate.

Three incidents follow. Supporters first flood the e-portal of State B’s civil registry, the system that records births, deaths and marriages, with a distributed denial-of-service (DDoS) operation that knocks it offline for 10 days. The group’s most skilled members then break into the servers behind the registry and deploy a wiper that destroys civilian records and their backups outright and ruins the software that processes document requests. Finally, members who have been mining soldiers’ social media accounts infect their phones with commercial spyware through spear-phishing, and, at the request of a State A frontline unit, collect location data so the unit can target State B soldiers in a contested city.

None of this strains the imagination. The toolkit’s own example list, which mixes wartime operations with peacetime analogues of the same methods, runs from the DDoS waves that battered Estonia in 2007 and the Shamoon wiper that destroyed data on about 30,000 computers at Saudi Aramco in 2012 to two operations from last year: the July 2025 attack on Aeroflot, claimed jointly by the Belarusian Cyber Partisans and the pro-Ukraine group Silent Crow, which forced the Russian carrier to cancel dozens of flights in a day and prompted Russian prosecutors to open a criminal investigation, and Predatory Sparrow’s June 2025 strikes on Iran’s Bank Sepah and the Nobitex cryptocurrency exchange, where blockchain analytics firms said the pro-Israel group destroyed roughly $90 million in cryptocurrency. The pattern has continued into this year’s conflict between Iran and the United States and Israel: dozens of pro-Iran hacktivist groups have claimed cyberattacks since the fighting began in late February, including operations aimed at payment systems and airport services, according to March reporting from Axios.

Civilian hackers still answer to the law of war

Because the collective belongs to neither state’s armed forces and answers to no responsible command, its members are civilians under IHL. Nor, in the toolkit’s assessment, is the loose collective organized enough, or its campaign intense enough, to make the group a party to its own separate conflict. Civilian status, however, does not place the hackers beyond the law of war. It places them squarely inside it.

Many IHL rules are written as flat prohibitions, and international criminal tribunals have held that they bind individuals whatever their official status. The analysis puts the structural point plainly: “for IHL to be effective, it must bind anyone who conducts hostilities,” including civilians running cyber operations connected to a war. The International Criminal Court’s Office of the Prosecutor reached the same conclusion in its first policy on cyber-enabled crimes, published in December 2025, which states, as quoted in the toolkit’s analysis, that “any person may be the perpetrator of a cyber-enabled war crime, irrespective of whether they act on behalf of a party to the armed conflict.”

The hinge is nexus. IHL reaches a cyber operation only when the operation is tied to the fighting, occurring in its context and in association with it. A group formed to damage the adversary in support of one belligerent’s war effort, the toolkit finds, clears that bar easily.

Where disruption ends and attack begins

The doctrinal center of the scenario is the meaning of “attack” under Article 49 of Additional Protocol I to the Geneva Conventions, because the strongest protections for civilian objects, including the civil registry, attach to attacks. States divide over what counts. Some, including Denmark, Israel and Peru, read the notion to require physical damage. A larger group of published national positions, among them Austria, Costa Rica, France, Germany, Ireland, Italy, Japan and New Zealand, treats a cyber operation that disables a system, destroying its functionality without breaking hardware, as an attack. The ICRC shares the functionality view, and the roster of published positions keeps growing: the European Union issued a common position addressing these questions in 2024, the same year the African Union set out a common position on how international law, including IHL, applies in cyberspace.

The toolkit sorts the two registry operations onto opposite sides of that line. The DDoS campaign leaves the portal unavailable for 10 days but causes no damage to the system, which resumes service once the traffic stops, so the analysis concludes it does not appear to qualify as an attack. The wiper is different. Records and backups are permanently deleted, the request-processing software is ruined, and State B must rebuild the system. Under the functionality view, which the toolkit says commands the larger share of published positions, the wiper is an attack on a civilian object and breaches the ban on attacking civilian objects. For states that insist on physical damage, neither operation would qualify as an attack, a divergence the analysis acknowledges. The same conclusion would follow, the toolkit adds, if civilian data itself were protected as a civilian object, a contested question it examines separately in Scenario 12. The label carries criminal stakes, the analysis says, because it also frames whether the conduct can be charged as a war crime.

Even the operation that is not an attack does not walk free. Wartime military operations still demand “constant care,” as Additional Protocol I puts it, to spare civilians and civilian objects, and the analysis sees no way to square a cyber operation aimed at a civil registry with that duty, or with any legitimate military purpose.

Direct participation carries a price

The scenario then flips the lens: what do the hackers lose? Civilians are protected against attack, in the words of Additional Protocol I, “unless and for such time as they take a direct part in hostilities.” Under the ICRC’s interpretive guidance, an act crosses that line only if it meets three cumulative criteria: a threshold of harm, direct causation of that harm, and a belligerent nexus, an act designed, in the guidance’s words, “in support of a party to the conflict and to the detriment of another.” The test itself is contested ground: the toolkit says the line for when conduct crosses into direct participation stays unsettled, and its notes pair the ICRC guidance with Michael Schmitt’s critical analysis, which argues the guidance tilts further toward civilian protection than state practice supports.

Applied here, the analysis reaches a split verdict. Hackers who deploy the wiper likely satisfy all three criteria, on the same functionality reasoning that makes the operation an attack, and may be lawfully attacked for such time as they participate. Volunteers who join the DDoS campaign likely do not reach the threshold of harm and keep their protection. The phone-hacking operation divides down the middle: harvesting general information from soldiers’ social media and passing it along is one thing, but collecting location data for a frontline unit planning strikes on specific soldiers is, in the analysis’s words, “an integral part of a coordinated military operation,” and those hackers may lose protection.

Loss of protection is only half the exposure. As the ICRC has emphasized, civilian hackers lack the immunity from prosecution that members of armed forces enjoy for lawful acts of war, which leaves them open to criminal charges under domestic law for their intrusions. The ICRC has also cautioned belligerents to weigh carefully whether kinetic force against civilian hackers is necessary at all, or whether less destructive cyber or electromagnetic means would achieve the objective.

What the state hosting the hackers owes

On the facts as given, the toolkit concludes the group’s operations are not attributable to State A. Occasional praise, contact and cooperation do not amount to instruction, direction or control, the standard for attributing private conduct to a state. The closest call is the third incident, where a State A frontline unit asked the group for targeting data, and the analysis counts even that request, on these facts, as falling short of that standard. But non-attribution is not a free pass. Common Article 1 of the Geneva Conventions obliges State A to ensure respect for IHL, which the analysis reads as a due diligence obligation to prevent and repress violations by private persons under its authority. The measures required scale with what the state knows, how grave the breach is, what means it has and how much sway it holds over the hackers. The toolkit’s menu includes calling on hackers to stand down, disseminating IHL to the public, providing model codes of conduct, enacting effective penal sanctions for grave breaches and enforcing existing cybercrime laws.

That menu tracks guidance the ICRC has pressed publicly since October 2023, when legal adviser Tilman Rodenhäuser and Mauro Vignati, the organization’s adviser on digital technologies of warfare, published eight rules for civilian hackers during war and four obligations for states to restrain them. Reception was mixed. The founder of the pro-Russia collective Killnet announced his group would comply, a pledge Samuel White of the National University of Singapore questioned in a Lieber Institute analysis, writing that reposting the rules is not the same as internalizing them and concluding they had yet to restrain actual conduct. ICRC lawyers returned in November 2025 with sharper framing, writing with academic co-authors that a state cannot escape responsibility for hackers operating under its direction by labeling them independent, that genuinely private hackers inside its borders still engage its due diligence duties, and that tech companies as much as volunteers need to learn the rules. Rodenhäuser extends the argument in a 2026 International Review of the Red Cross article on the limits IHL imposes on volunteer IT armies.

Records systems are the quiet casualty

For cybersecurity, information governance and eDiscovery professionals, the scenario’s most instructive choice is its target. A civil registry is identity infrastructure. Birth, death and marriage records anchor inheritance, benefits, travel, voting and civil litigation, and the scenario’s wiper deletes the records, the backups and the software that processes replacement requests. That is the governance nightmare in miniature. The operating moves that follow are ComplexDiscovery’s translation, not the toolkit’s text: treat vital-records systems as critical infrastructure, keep immutable, offline backups of irreplaceable registers, segment registry databases from public-facing portals, and rehearse how documents get issued when the system is down. The ICRC made a parallel point in its 2023 report on protecting civilians against digital threats during armed conflict, which directs recommendations at states, belligerents and tech companies, including measures to safeguard civilian data.

The soldiers’ phones carry a second lesson. Spear-phishing plus commercial spyware plus location tracking is the same kill chain aimed at executives, deal teams and litigation groups, and the scenario elevates mobile device management, hardened personal devices and disciplined social media habits from compliance hygiene to battlefield controls.

The evidence trail matters as much as the malware. The ICC prosecutor’s cyber policy treats digital evidence as central to its investigations, acknowledging hard problems of collection, authentication, preservation and security, which means the logs, malware samples and attribution artifacts that incident responders generate can end up in a war crimes case file. Organizations that find themselves victim or conduit should extend familiar litigation-hold reflexes to conflict-linked intrusions: preserve forensic images, document chain of custody and expect cross-border requests to follow.

Counsel advising companies have a related brief: write it down. The ICRC’s November 2025 commentary urges tech companies to learn IHL and to segregate military from civilian data and infrastructure to limit collateral harm when military systems are attacked. Acceptable-use and insider-risk policies should say plainly that employees who volunteer for a combatant’s cyber campaign risk losing their protection from attack for as long as they directly participate, along with criminal exposure at home and abroad. Employer infrastructure is a separate question: an employee’s freelancing does not by itself change the status of company systems, but assets that make an effective contribution to military action, and whose destruction or neutralization would offer a definite military advantage, can qualify as military objectives, one reason the ICRC presses for segregation.

Scenario 36 closes with a checklist that reads like an incident-response tabletop for the age of patriotic hacking: who is responsible, what conduct amounts to an attack, when participation turns direct, what states must do about the hackers on their soil. The questions are getting less hypothetical by the month, and the answers are firming up as more states and regional bodies publish positions. When a volunteer with a laptop can become a lawful military target, the governance question stops being abstract: does your organization know where support for a cause ends and participation in a conflict begins?



News sources



Assisted by GAI and LLM technologies

Additional reading

Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more legible for practitioners, policymakers, and business leaders.

 

Have a Request?

If you have information or offering requests that you would like to ask us about, please let us know, and we will make our response to you a priority.

ComplexDiscovery OÜ is an independent digital publication and research organization based in Tallinn, Estonia. ComplexDiscovery covers cybersecurity, data privacy, regulatory compliance, and eDiscovery, with reporting that connects legal and business technology developments—including high-growth startup trends—to international business, policy, and global security dynamics. Focusing on technology and risk issues shaped by cross-border regulation and geopolitical complexity, ComplexDiscovery delivers editorial coverage, original analysis, and curated briefings for a global audience of legal, compliance, security, and technology professionals. Learn more at ComplexDiscovery.com.

 

Generative Artificial Intelligence and Large Language Model Use

ComplexDiscovery OÜ recognizes the value of GAI and LLM tools in streamlining content creation processes and enhancing the overall quality of its research, writing, and editing efforts. To this end, ComplexDiscovery OÜ regularly employs GAI tools, including ChatGPT, Claude, Gemini, Grammarly, Midjourney, and Perplexity, to assist, augment, and accelerate the development and publication of both new and revised content in posts and pages published (initiated in late 2022).