Ukraine Claims Russian Cyber Attacks Are War Crimes

Ukrainian officials seek to convince the International Criminal Court (ICC) in the Hague to investigate whether certain Russian cyber attacks could constitute war crimes and officials are gathering digital evidence for the ICC to prosecute. 

In a statement by ICC Prosecutor, Karim A.A. Khan QC, on the Situation in Ukraine, “I have decided to proceed with opening an investigation. In particular, I am satisfied that there is a reasonable basis to believe that both alleged war crimes and crimes against humanity have been committed in Ukraine in relation to the events already assessed during the preliminary examination by the Office.” 

Cyber attacks have increasingly become a part of modern warfare and have been repeatedly used by Russian forces amid the country’s war in Ukraine to target critical infrastructure.  “Given the expansion of the conflict in recent days, it is my intention that this investigation will also encompass any new alleged crimes falling within the jurisdiction of my Office that are committed by any party to the conflict on any part of the territory of Ukraine...“I will continue to closely follow developments on the ground in Ukraine, and again call for restraint and strict adherence to the applicable rules of international humanitarian law,” says Khan’s statement.

Cyber attacks are not listed as a form of war crime under the Geneva Convention and legal experts have previously contacted the ICC with the aim to prosecute Russian cyber attacks, but the reported push from Ukrainian officials marks the first time a sovereign government has made such a request to the court. 

Last year, a group of human rights lawyers and investigators in the Human Rights Center at UC Berkeley's School of Law sent a formal request to the ICC in which it urged the ICC to consider war crime prosecutions of Russian hackers for their cyber attacks in Ukraine, even as the prosecutors gather evidence of more traditional, ongoing war crimes there. 

Ukraine’s chief digital transformation officer, Victor Zhora said that his country is gathering evidence of cyber attacks tied to military operations and are sharing information with the ICC in the hopes of potentially charging Russia for those crimes. Zhora argued that since Russia used cyber attacks to support its kinetic military operations that targeted Ukraine’s critical infrastructure and civilians, the digital attacks should also be considered as war crimes against Ukrainian citizens. “When we observe the situation in cyberspace we notice some coordination between kinetic strikes and cyber attacks, and since the majority of kinetic attacks are organised against civilians, being a direct act of war crime, supportive actions in cyber can be considered as war crimes,.. ”

Zhora also noted last year’s Russian attacks against Ukraine’s largest private energy electricity generator, an example of when cyber attacks are used in conjunction with kinetic warfare.

Under the UN Convention war crimes can include willful killing of civilians, torture or inhuman treatment, including biological experiments; willfully causing great suffering; and the taking of hostages, among other actions. Written before the modern technological era, the definition makes no mention of digital warfare. 

The cyber domain  has no borders, and it allows attackers to instantly reach across the world, regardless of distance, which makes holding Russia's most dangerous hackers accountable, say Ukraine government sources. 

If the ICC does find that destructive Russian cyber attacks targeting critical infrastructure and civilians constitute war crimes, that could open grounds for potential prosecutions against the perpetrators of such attacks and possible reparations for the victims. 

Ukrainian officials aren’t the only ones trying to make the case before the ICC.  Last year, a group of human rights lawyers and investigators in the Human Rights Center at University of California, Berkeley’s School of Law made a similar request to the court, urging it to look into whether a group of Russian hackers, known as Sandworm, could be prosecuted for launching destructive cyber attacks against Ukraine in 2015 and 2016. Lindsay Freeman, the director of technology, law and policy at Berkley told Wired that the ICC prosecutor’s office responded to the group’s request and was looking into its recommendations. 

In contrast, some experts aren’t convinced that making the case that certain cyber attacks could fall under war crimes is necessary, because there’s already there is already evidence of Russian war crimes in Ukraine using conventional warfare. “I’m not sure we need to reach into cyber to figure that out,” said Jamil Jaffer, founder and executive director of the National Security Institute at George Mason University’s Antonin Scalia Law School. 

Although he agrees that the Russians have improved the way they coordinate their land and air warfare with their cyber operations, Jaffir said that a lot of analysis must still be conducted to determine whether destructive cyber attacks targeting civilians and critical infrastructure could be classified as war crimes. “Cyber attacks are more of a novel application of war crimes, which you can still do and go through and figure out, but there are so many other very clear violations of the laws of war..

If the goal is to prosecute the Russians for their war crimes, you don’t need to go through the cyber analysis, you need to look at what they’re doing on the battlefield,” Jaffir said.

Russian linked hacker groups have ramped up operations targeting critical industries and high-profile public figures, according to an advisory issued by the British National Cyber Security Centre (NCSC) in an alert warning that a hacker groups, based in Russia, have escalated attacks against government organisations, defence firms, media publications, and non-profits.  The Russian group Seaborgium, also known as ‘Cold River’, was found to have waged an “expansive” spear-phishing campaign against UK targets. 

Social media and professional networking sites have been used to identify targets, the advisory read, which enables the groups to engage with potential victims.  

The Cold River hacker group has claimed responsibility for a number of high-profile attacks over the last year.  
Traditionally, the group hasn’t targeted the public and has instead focused on compromising public figures to create political disruption.  In May last year, security researchers at Google accused the group of hacking into and leaking emails belonging to Richard Dearlove, the former director of the MI6 spy agency.  

Cold River also claimed responsibility for attacks on US-based nuclear research centres at the beginning of this year. That incident saw the group create fake login pages for staff working at three laboratories and a phishing campaign aimed at encouraging workers to divulge passwords. 

United Nations:   Wired:      The Hill:     Politico:     ICC-CPI:      ITPro:     DW

You Might Also Read: 

Ukraine Signs Cyber Security Deal With NATO:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Microsoft To Invest $10b In OpenAI 
Turla Hackers Deliver Andomeda Malware  »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Clearpath Solutions Group

Clearpath Solutions Group

Clearpath Solutions Group expertise covers virtualization and data storage technologies, networking, security and cloud computing.

Centre for Secure Information Technologies (CSIT)

Centre for Secure Information Technologies (CSIT)

CSIT is a UK Innovation and Knowledge Centre (IKC) for secure information technologies. Our vision is to be a global innovation hub for cyber security.

Zurich

Zurich

Zurich is a leading multi-line insurer providing a wide range of property and casualty, and life insurance products and services in more than 210 countries and territories.

Niksun

Niksun

Niksun's forensics-based cyber security and network performance monitoring products provide customers with actionable insight into security threats, performance issues, and compliance risks.

HYPR

HYPR

HYPR Decentralized Authentication minimizes the risk of enterprise data breaches while providing an enhanced user experience for your customers and employees.

Crashtest Security

Crashtest Security

Crashtest Security is a cyber security company that helps digital companies to continuously create secure software with the help of automated vulnerability assessments.

CPP Group UK

CPP Group UK

CPP Group UK develops products to help insurers add further value to their products and services through its innovative suite of new products in FinTech, InsurTech and cyber security.

NeuroChain

NeuroChain

NeuroChain is an intelligent ecosystem that is more secure, more reliable and much faster than blockchain.

Open Raven

Open Raven

Open Raven is the cloud native data security platform that prevents breaches driven by modern speed and sprawl. Restore full visibility and regain control within minutes, without agents.

Nubeva Technologies

Nubeva Technologies

Nubeva provide a breakthrough TLS Decrypt solution with Symmetric Key Intercept to gain the visibility needed to monitor and secure network traffic.

Security Risk Management (SRM)

Security Risk Management (SRM)

SRM provide a comprehensive security risk management service encompassing people, processes, technology, governance, compliance and risk management.

Prelude

Prelude

Prelude offer the first autonomous platform built to attack, defend and train critical assets through continuous red-teaming.

Balance Theory

Balance Theory

Balance Theory provides the knowledge infrastructure and collaboration center for the cybersecurity community. A networked community to build better cybersecurity outcomes.

NASK

NASK

NASK is a National Research Institute under the supervision of the Chancellery of the Prime Minister of Poland. Our key activities involve ensuring security online.

Cyber Risk International

Cyber Risk International

Cyber Risk International offer CyberPrism, a B2B SaaS solution that empowers businesses to perform a self-assessment of their cyber security program.

Lightpoint Global

Lightpoint Global

Lightpoint Global is a bespoke software development company. We also provide a spectrum of services such as IT consulting, business analysis, QA and testing, and DevOps services.