Sovereignty and attribution are the two doctrines on which most international-law claims about cyber operations succeed or fail. Whether an unauthorised intrusion into another state's networks breaches sovereignty as a primary rule, and what evidence is required before that intrusion can be attributed to a state, together decide whether an injured state has any lawful response available at all. The Journal's scholarship in this subject concentrates on those two questions and on the incidents that expose them.

Sovereignty, non-intervention and due diligence after Salt Typhoon

Salt Typhoon, the intrusion campaign attributed to a China-linked actor and publicly confirmed by CISA and the FBI in late 2024, compromised United States telecommunications carriers and reached the lawful-intercept systems maintained under the Communications Assistance for Law Enforcement Act. Salt Typhoon and the Law of Cyber Espionage: Sovereignty, Attribution, and the Limits of International Law works through the candidate legal hooks and finds none of them clean. Tallinn Manual 2.0 Rule 32 records that international law neither expressly prohibits nor expressly permits cyber espionage, leaving it unregulated at the level of primary prohibition. The sovereignty theory — that intrusion causing effects in a target state violates its territorial sovereignty — commanded a bare majority of the Tallinn Manual experts, with a significant minority dissenting; the article notes that the United Kingdom and the United States have not formally endorsed a per se rule. Non-intervention requires coercion over matters within the target state's domaine réservé under the Nicaragua formulation, and a collection operation is difficult to characterise as coercive. Due diligence, drawn from Trail Smelter and elaborated for cyber contexts, remains contested as to its threshold of harm and hard to prove.

Attribution, state responsibility and the response options

Legal attribution is a separate exercise from technical attribution. The Articles on Responsibility of States for Internationally Wrongful Acts set the tests at Articles 4–8 — whether the actors were organs of the state, or acted on its instructions, direction or control — while Articles 49–54 govern countermeasures by an injured state. The Salt Typhoon analysis describes the gap this leaves: the United States attributed the campaign to the PRC with high confidence and imposed Treasury sanctions in December 2024 on a Shanghai-based company assessed to be linked to the operation, without asserting the antecedent legal claim that the countermeasures route would require.

Earlier work in the Journal proposed alternatives to the prevailing tests. Cyberwarfare: Attribution, Preemption, and National Self Defense advances an "Effects Test" for when a cyberattack constitutes an armed attack, and would modify the Caroline Doctrine on anticipatory self-defence to require stricter scrutiny of intelligence. Cyber Redux: The Schmitt Analysis, Tallinn Manual and US Cyber Policy sets out James McGhee's view that the Schmitt Analysis is outdated and that the Tallinn Manual does not supply concrete, actionable guidance. Cyber Warfare Legal Frameworks and International Law treats attribution as the central obstacle to accountability, given state reliance on proxies and covert operations. Tallinn Manual 3.0: Sovereignty and Attribution in 2025 adds a newer difficulty: the effective-control and overall-control tests assume a directing human, and autonomous agents that adapt and act without explicit instruction strain them.

Targeting, distinction and how an operation is classified

Targeting in the Cyber Domain: Legal Challenges Arising from the Application of the Principle of Distinction to Cyber Attacks applies the principle of distinction to cyber operations, taking up the definition of a military objective, the targeting of dual-use cyber infrastructure and the legal status of digital data. Internet Communication Blackout: Attack Under Non-International Armed Conflict? argues that a government-imposed blackout of the kind seen in the 2011 Egyptian uprising is not an attack in a non-international armed conflict, because it involves neither violence nor physical damage, and distinguishes blackouts imposed by non-state actors. No More Humans? Cybernetically-Enhanced Soldiers Under the Legal Review of Article 36 asks whether brain-computer interfaces, and the soldiers using them, are weapons, means or methods of warfare for the purposes of the Article 36 review required by Additional Protocol I.

Whether the answer is a new instrument

Responding to the Call for a Digital Geneva Convention: An Open Letter to Brad Smith and the Technology Community answers the Microsoft proposal by arguing that an international legal framework already covers state-sponsored cyberattacks, that states are unlikely to accept a treaty limiting their own operations, and that the technology sector's useful contribution is informed participation in the international-law dialogue. The Tallinn Manual 3.0 article takes the other side, setting out three areas a third edition would have to address: AI-initiated conduct, digital sovereignty, and hybrid operations combining cyber, kinetic and information activity. The intergovernmental track runs meanwhile through the UN Group of Governmental Experts and the Open-Ended Working Group, whose outputs are voluntary norms rather than binding rules.

Sovereignty, immunity, and whether a new instrument is the answer

Sovereignty in Cyberspace on the Usurpation of Political Independence goes to the question underneath most of this subject: Peter B.M.J. Pijpers and Bart G.L.C. van den Bosch ask whether sovereignty in cyberspace is a mere principle of international law or a binding rule as it is in the physical domains, and observe that while a growing number of states have offered legal opinions, many remain reticent — leaving cooperation difficult when the rules of the game are unsettled.

Two articles take the classification problem directly. A Brave New World: Applying International Law of War to Cyber Attacks argues that existing use-of-force and armed-attack analysis under the UN Charter does not account for cyber operations, and proposes treating an operation as an armed attack where a state uses kinetic or virtual force intending to alter another state's sovereign or strategic power by significantly disrupting military or critical infrastructure. Hack, Attack or Whack; The Politics of Imprecision in Cyber Law attacks the vocabulary instead: James E. McGhee argues that incidents are routinely called "hacks" or "attacks" with no consistent standard, and that the looseness has consequences for how law and policy respond.

Where remedies are concerned, A Call to Congress: The Urgent Need for Cyberattack Amendments to the Foreign Sovereign Immunities Act is the most concrete. Matthew A. Powell argues that the Foreign Sovereign Immunities Act, enacted in 1976, is out of date, and that the "entire tort" rule adopted by most federal courts — requiring a cyberattack to occur wholly within United States territory from inception to execution — yields almost no remedy, since attackers rarely travel to the United States to launch them. No State is an Island in Cyberspace asks the parallel deterrence question for economic espionage, where anonymity lets perpetrators evade sanctions. An International Cyber Warfare Treaty: Historical Analogies and Future Prospects weighs whether a treaty is the answer at all, reading the prospects against the arms-control instruments that preceded it, and Cybernetic Enhancement of Soldiers: Conserving hors de combat Protections for Combatants Under the Third Geneva Convention asks what becomes of hors de combat protection under the Third Geneva Convention when the combatant is technologically augmented.