Ukraine Claims Russian Cyber Attacks Are War Crimes

Ukrainian officials seek to convince the International Criminal Court (ICC) in the Hague to investigate whether certain Russian cyber attacks could constitute war crimes and officials are gathering digital evidence for the ICC to prosecute. 

In a statement by ICC Prosecutor, Karim A.A. Khan QC, on the Situation in Ukraine, “I have decided to proceed with opening an investigation. In particular, I am satisfied that there is a reasonable basis to believe that both alleged war crimes and crimes against humanity have been committed in Ukraine in relation to the events already assessed during the preliminary examination by the Office.” 

Cyber attacks have increasingly become a part of modern warfare and have been repeatedly used by Russian forces amid the country’s war in Ukraine to target critical infrastructure.  “Given the expansion of the conflict in recent days, it is my intention that this investigation will also encompass any new alleged crimes falling within the jurisdiction of my Office that are committed by any party to the conflict on any part of the territory of Ukraine...“I will continue to closely follow developments on the ground in Ukraine, and again call for restraint and strict adherence to the applicable rules of international humanitarian law,” says Khan’s statement.

Cyber attacks are not listed as a form of war crime under the Geneva Convention and legal experts have previously contacted the ICC with the aim to prosecute Russian cyber attacks, but the reported push from Ukrainian officials marks the first time a sovereign government has made such a request to the court. 

Last year, a group of human rights lawyers and investigators in the Human Rights Center at UC Berkeley's School of Law sent a formal request to the ICC in which it urged the ICC to consider war crime prosecutions of Russian hackers for their cyber attacks in Ukraine, even as the prosecutors gather evidence of more traditional, ongoing war crimes there. 

Ukraine’s chief digital transformation officer, Victor Zhora said that his country is gathering evidence of cyber attacks tied to military operations and are sharing information with the ICC in the hopes of potentially charging Russia for those crimes. Zhora argued that since Russia used cyber attacks to support its kinetic military operations that targeted Ukraine’s critical infrastructure and civilians, the digital attacks should also be considered as war crimes against Ukrainian citizens. “When we observe the situation in cyberspace we notice some coordination between kinetic strikes and cyber attacks, and since the majority of kinetic attacks are organised against civilians, being a direct act of war crime, supportive actions in cyber can be considered as war crimes,.. ”

Zhora also noted last year’s Russian attacks against Ukraine’s largest private energy electricity generator, an example of when cyber attacks are used in conjunction with kinetic warfare.

Under the UN Convention war crimes can include willful killing of civilians, torture or inhuman treatment, including biological experiments; willfully causing great suffering; and the taking of hostages, among other actions. Written before the modern technological era, the definition makes no mention of digital warfare. 

The cyber domain  has no borders, and it allows attackers to instantly reach across the world, regardless of distance, which makes holding Russia's most dangerous hackers accountable, say Ukraine government sources. 

If the ICC does find that destructive Russian cyber attacks targeting critical infrastructure and civilians constitute war crimes, that could open grounds for potential prosecutions against the perpetrators of such attacks and possible reparations for the victims. 

Ukrainian officials aren’t the only ones trying to make the case before the ICC.  Last year, a group of human rights lawyers and investigators in the Human Rights Center at University of California, Berkeley’s School of Law made a similar request to the court, urging it to look into whether a group of Russian hackers, known as Sandworm, could be prosecuted for launching destructive cyber attacks against Ukraine in 2015 and 2016. Lindsay Freeman, the director of technology, law and policy at Berkley told Wired that the ICC prosecutor’s office responded to the group’s request and was looking into its recommendations. 

In contrast, some experts aren’t convinced that making the case that certain cyber attacks could fall under war crimes is necessary, because there’s already there is already evidence of Russian war crimes in Ukraine using conventional warfare. “I’m not sure we need to reach into cyber to figure that out,” said Jamil Jaffer, founder and executive director of the National Security Institute at George Mason University’s Antonin Scalia Law School. 

Although he agrees that the Russians have improved the way they coordinate their land and air warfare with their cyber operations, Jaffir said that a lot of analysis must still be conducted to determine whether destructive cyber attacks targeting civilians and critical infrastructure could be classified as war crimes. “Cyber attacks are more of a novel application of war crimes, which you can still do and go through and figure out, but there are so many other very clear violations of the laws of war..

If the goal is to prosecute the Russians for their war crimes, you don’t need to go through the cyber analysis, you need to look at what they’re doing on the battlefield,” Jaffir said.

Russian linked hacker groups have ramped up operations targeting critical industries and high-profile public figures, according to an advisory issued by the British National Cyber Security Centre (NCSC) in an alert warning that a hacker groups, based in Russia, have escalated attacks against government organisations, defence firms, media publications, and non-profits.  The Russian group Seaborgium, also known as ‘Cold River’, was found to have waged an “expansive” spear-phishing campaign against UK targets. 

Social media and professional networking sites have been used to identify targets, the advisory read, which enables the groups to engage with potential victims.  

The Cold River hacker group has claimed responsibility for a number of high-profile attacks over the last year.  
Traditionally, the group hasn’t targeted the public and has instead focused on compromising public figures to create political disruption.  In May last year, security researchers at Google accused the group of hacking into and leaking emails belonging to Richard Dearlove, the former director of the MI6 spy agency.  

Cold River also claimed responsibility for attacks on US-based nuclear research centres at the beginning of this year. That incident saw the group create fake login pages for staff working at three laboratories and a phishing campaign aimed at encouraging workers to divulge passwords. 

United Nations:   Wired:      The Hill:     Politico:     ICC-CPI:      ITPro:     DW

You Might Also Read: 

Ukraine Signs Cyber Security Deal With NATO:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Microsoft To Invest $10b In OpenAI 
Turla Hackers Deliver Andomeda Malware  »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Masergy Communications

Masergy Communications

Masergy delivers hybrid networking, managed security and cloud communication solutions to enterprises around the globe.

Oppida

Oppida

Oppida provides tailored IT security services to help you identify security gaps and assist in finding the most effective remediation.

OIC-CERT

OIC-CERT

OIC-CERT is the Computer Emergency Response Team for Organisation of Islamic Cooperation (OIC) member countries.

Fraunhofer Institute for Secure Information Technology (SIT)

Fraunhofer Institute for Secure Information Technology (SIT)

Fraunhofer SIT is a research centre specialising in all areas of IT security.

CybSafe

CybSafe

CybSafe is a cloud-based platform focussed on addressing the human component of cyber security - an intelligent approach to awareness training.

ATIS Systems

ATIS Systems

ATIS Systems offers first-class complete solutions for legal interception, mediation, data retention, and IT forensics.

AKATI Sekurity

AKATI Sekurity

AKATI Sekurity is a security-focused consulting firm providing services specializing in Information Security and Information Forensics.

Shieldfy

Shieldfy

Shieldfy is a cloud-based security shield for your website to protect it from cyber attacks and malwares.

High Wire Networks

High Wire Networks

High Wire Network’s Overwatch Managed Security Plaform-as-a-Service offers organizations end-to-end protection for networks, data, endpoints and users.

Avertium

Avertium

Avertium is the managed security and consulting provider that companies turn to when they want more than check-the-box cybersecurity.

AML Global Solutions (AMLGS)

AML Global Solutions (AMLGS)

AMLGS delivers Financial Crime prevention training programmes and consultancy services encompassing Anti-Money Laundering (AML), Counter Terrorism Financing (CTF), Bribery & Corruption and Fraud.

ProCheckUp

ProCheckUp

ProCheckUp is a London-based independent provider of cyber security services, including IT Security, Assurance, Compliance and Incident Response.

Defimoon

Defimoon

DeFimoon is the International Blockchain Development & Security Agency. We provide professional services and solutions at the highest quality on world-leading chains.

Accelerynt

Accelerynt

Accelerynt was founded with a singular purpose: help teams like yours build cybersecurity resilience.

NSW IT Support

NSW IT Support

NSW IT Support: Your exclusive hub for comprehensive Business IT services in Sydney. Our skilled team ensures seamless technology solutions nationwide, consistently delivering top-tier IT support.

Acumen

Acumen

Acumen's cyber security engineers protect your critical systems, in critical moments. We are here when you need us most.