Kubo Mačák on Cyberattack Victims’ Missing Day in Court

Kubo Mačák helps answer how international law translates into cyberspace. With experience from the UN's ad hoc tribunals for the former Yugoslavia and Rwanda, the International Committee of the Red Cross, and now Professor of International Law at the University of Exeter and General Editor of the Cyber Law Toolkit, he guides governments in articulating their legal positions on cyber activities. As ransomware locks up vital services and state-linked operations increasingly hit critical infrastructure, Mačák argues the existing legal frameworks already have victims in view—the harder task is building the accountability to match.


“The technology may be new, but the law’s protective purpose endures.”


You worked at tribunals that prosecuted war crimes, institutions built on the idea of accountability. Cyberspace is not a lawless space, and yet accountability is often missing. When will the victims of cyberattacks see a day in court?

Some victims have already had their day in domestic courts, through cybercrime prosecutions, but on the international plane we are still waiting to see accountability through criminal prosecution. To take the most prominent international criminal judicial organ, the International Criminal Court, it deals only with the core international crimes such as genocide, crimes against humanity, and war crimes. A hostile cyber operation will thus only come within its purview if the conduct satisfies the elements of one of those crimes and the Court’s jurisdictional and admissibility requirements. 

In December 2025, the Office of the Prosecutor issued a policy paper explaining how the Rome Statute applies to cyber-enabled crimes. It recognizes, for example, that intentionally directing a cyber operation against a hospital during armed conflict, with fatal consequences for patients, could amount to a war crime. The Prosecutor has also received several communications to initiate investigations from civil society actors concerning alleged cyber-enabled crimes, including in relation to the ongoing armed conflict between Russia and Ukraine. The legal framework and at least some case material are thus now in place. But still, evidence, individual attribution, gravity, and jurisdiction remain formidable obstacles. I think it’s safe to say that we will eventually see such a case, although exactly when is hard to predict.


Over 130 countries have been hit by malicious cyber operations. Yet governments only respond to cyberattacks in public attributions, through statements of condemnation. No state has brought a case in an international court. What does that silence tell us?

It tells us that States remain more comfortable making political claims than legal ones. Public attributions usually condemn “irresponsible” behavior, but they very rarely identify the rule of international law that was allegedly breached. That is striking when you consider that nearly forty States have published detailed national positions on how international law applies to cyber activities. I would say the reason is that it is more challenging, and complex, to apply the law to specific incidents than to express a general view. It requires technical, factual, and legal judgments about attribution, while States may wish to protect their intelligence sources and preserve their own operational flexibility. Even a State confident of its case needs a jurisdictional basis before it can bring it before a judicial organ such as the International Court of Justice, and this usually requires the consent of the parties involved, which may not always be forthcoming. For individuals affected by hostile State-on-State cyber operations, the cost is real: fewer authoritative findings about what happened, less clarity about the applicable rules, and fewer routes to reparation. Still, some States have reportedly already begun seeking advice on bringing such claims, so this may well change in the foreseeable future.


The Geneva Conventions—the treaties governing how wars are fought and civilians are protected—were written for an analogue world. You helped update their Commentaries. What does it feel like to apply that language to a ransomware attack on a maternity ward, when the digital and the reality on the ground meet?

Governments and militaries worldwide turn to the International Committee of the Red Cross’s commentaries when they encounter difficult questions of interpretation of the rules of international humanitarian law—and applying rules written many decades ago to, say, a hospital paralyzed by ransomware is not always straightforward. The language can be dated, and the drafters could certainly not have foreseen the reality of modern warfare. The starting point when interpreting these rules today is the principle of technological neutrality. What this means is that the Geneva Conventions protect civilians and hospitals regardless of the weapon or technology used. If a cyber operation is linked to an armed conflict, the relevant humanitarian law rules govern it just as they govern more traditional, physical conduct. International humanitarian law requires parties to armed conflicts to respect and protect medical facilities. A ransomware operation against a maternity ward would breach that obligation and, if it was intentionally directed against a protected hospital, it might constitute a war crime. The technology may be new, but the law’s protective purpose endures.


Ransomware doesn’t just lock out patients’ data—it puts patients’ lives on the line. A breach exposing children’s personal records rarely gets the same attention, though the harm is no less real. Either way, it’s individuals who absorb the cost. What does international law offer them by way of recourse?

Several areas of international law provide important protections to people who may fall victim to harmful cyber conduct. International human rights law is the clearest example, alongside humanitarian law and criminal law. The theft of children’s records may engage rights to privacy and data protection; disruption of hospital services may engage the right to health. In armed conflict, international humanitarian law adds specific protections, including for civilians and medical facilities, as we have discussed. Specific responsibility may then arise because the operation is attributable to a State, or because a State has failed to take protective measures required by what lawyers call positive obligations, which exist under human rights law as well as under humanitarian law. There are certain difficult legal questions that must be resolved in particular cases, but victims are not absent from the legal framework. We explain some of these issues in a forthcoming chapter with Florentina Pircher on protecting civilian victims from cyber harm during armed conflicts.


Legal recourse is slow. Cyber harm is fast. What can law offer that quicker, more immediate responses cannot?

There are many things law can deliver. Let me highlight three: prevention, harm reduction, and accountability. First, prevention is its least visible—but perhaps the most important—function. When a State understands and follows its legal obligations, for example by respecting another State’s sovereignty, refraining from unlawful intervention, or conducting a cyber operation with regard to the protections imposed by international law, harm may never occur. Second, where harm is unavoidable, law constrains it. For example, international humanitarian law requires a party to an armed conflict launching a cyberattack against a dual-use communications system to take all feasible precautions to minimize incidental civilian harm, such as the loss of emergency communications on which civilians depend. And finally, law provides accountability after the event through a wide range of mechanisms, many of which will also be available to those affected by cyber operations: domestic prosecutions and civil litigation, proceedings before human rights courts and United Nations treaty bodies, international fact-finding mechanisms, and, as we discussed earlier, potentially international criminal proceedings and inter-State litigation.


Redress for victims of cybercrime remains an open question under international law. Do we have a blueprint from another area, such as compensation under the Montreal Convention on international air carrier liability, that can help with that?

It depends on who is seeking redress. States are not limited to international adjudication, for which there seems to be limited appetite right now. They also have other ways to bring the other party back to compliance, including diplomatic pressure, naming and shaming, acts of retorsion—such as sanctions or expelling diplomats—and, where the conditions are met, countermeasures. When it comes to individuals, they usually depend on domestic routes: submitting a criminal complaint, bringing a civil claim, or, in some cases, obtaining data-protection remedies or making a successful insurance claim for cyber-related losses. Some international human rights courts, such as the European or the Inter-American courts, can also award compensation or broader reparation for violations of protected rights.

The aviation analogy is interesting, but I’m not sure whether it’s directly transposable to this context. We don’t currently have a general compensation regime comparable to the 1999 Montreal Convention’s system of airline liability. Creating one for victims of malicious cyber operations would be very difficult in the current geopolitical context. A more plausible route is to explore how victims can use existing legal frameworks—as the Chatham House is doing in their work on securing justice for cyber-enabled international crimes and the Oxford Institute on Technology and Justice in their research into legal accountability for malicious cyber operations.


You have one year, one change. What would you do?

That’s probably your hardest question today: choosing only one is very difficult! But if I had to, I would make it a goal for every State without a national position on international law and cyber activities to at least consider developing one. This is an area I have worked on for over a decade. Back in, say, 2016, barely any States had expressed detailed views on this topic; today, almost forty have done so. A national position guides the State internally—that is, its various organs including its ministries, armed forces, and intelligence services—on what the law permits. It also gives the State an external voice, allowing it to explain its interpretation, influence the legal debate, and help establish common understandings. Following extensive consultations with almost fifty States from all parts of the world, we have recently published a practical Handbook on this topic to make this process easier. And it’s not just me and my co-authors who argue this would be helpful. States themselves agreed last year, in an important multilateral report adopted by consensus at the United Nations, on language that encourages continued voluntary sharing of such national views and positions. I would say that twelve months is just about enough for most States to think this through, appoint a penholder, and set the process in motion, even if finalizing and publishing the entire position might take a little longer.

Next
Next

Greg Rattray on Resilience Lessons Learned in Ukraine