Cyber terrorism is a label that does more work in policy than in doctrine. Whether it names a distinct legal category, or describes conduct already reached by criminal law, intelligence law and — where an armed conflict exists — international humanitarian law, is itself contested. The scholarship the Journal has published in this subject engages mainly the second half of that question: the surveillance powers built to detect non-state threats, the constitutional limits on those powers, and the classification of operations conducted by actors who are not states.
Surveillance powers and the Fourth Amendment
Is Uncle Sam Stalking You? Abandoning Warrantless Electronic Surveillance to Preclude Intrusive Government Searches argues that warrantless electronic surveillance by the government violates the Fourth Amendment's protection against unreasonable searches even when conducted for national-security purposes. The article traces the Foreign Intelligence Surveillance Act and the Foreign Intelligence Surveillance Court as responses to earlier abuses of unchecked government power, contends that the foreign-intelligence exception to the warrant requirement should be abandoned entirely, and argues that relying solely on FISC-approved surveillance would strengthen public trust and accountability in intelligence gathering.
Digital Surveillance Privacy and Civil Liberties in the Cyber Age frames the same tension structurally. Its argument is that modern surveillance differs from earlier forms in scale, persistence and automation: bulk collection, metadata analysis, location tracking and behavioural profiling have displaced individualised targeting, and doctrines developed around discrete searches and physical intrusions map poorly onto continuous monitoring of the digital exhaust of ordinary activity. The article takes up the reasonable-expectation-of-privacy problem for records held by third parties, the limits on meaningful judicial review where programmes operate under classification, the chilling effect of persistent monitoring on expression, association and political participation, and the position of telecommunications providers and data brokers on whom governments rely for access — a reliance that blurs the line between public authority and private enterprise.
Espionage, economic harm and the ordinary criminal statutes
Is Cyber Espionage a Form of Market Manipulation? proposes reading state-linked intrusion through securities and commodities law rather than through the law of armed conflict. The argument is that China's cyber espionage may be driven in part by an intent to manipulate United States stock and commodities markets using illegally obtained information, and that this can be addressed by enforcing existing market-manipulation law and by using data analytics to identify and investigate the conduct. The same instinct — reaching cyber conduct through statutes written for ordinary crime — appears in AI‑Powered Phishing: Regulating Social‑Engineering Campaigns, which examines the Computer Fraud and Abuse Act (18 U.S.C. § 1030) and the wire fraud statute (18 U.S.C. § 1343) alongside the European Union's NIS2 Directive, and argues that definitions assuming a human author who composes messages manually do not capture campaigns generated at scale by trained language models, or the attribution problem inside a botnet-as-a-service ecosystem.
Non-state actors and the classification of an attack
Where an operation by a non-state actor is alleged to reach the threshold of an armed conflict, the classification questions move into the humanitarian-law analysis. Internet Communication Blackout: Attack Under Non-International Armed Conflict? draws the distinction directly: a government-imposed blackout of the kind seen in the 2011 Egyptian uprising is, on that article's argument, not an attack in a non-international armed conflict because it produces neither violence nor physical damage, while a blackout imposed by a non-state actor carries a different potential for violence and destruction. Cyber Warfare Legal Frameworks and International Law addresses the same actors from the state-responsibility side: reliance on proxies and criminal groups obscures responsibility, the involvement of private companies and individual hackers blurs the distinction between civilian and combatant, and states may be held responsible for failing to prevent harmful cyber activity originating within their jurisdiction. Where a company considers responding to such an actor on its own account, the constraints are set out in Cyber Countermeasures by Private Actors.