The Journal of Law & Cyber Warfare is a peer-reviewed law journal, published since 2012, on how law applies to hostile cyber operations: sovereignty and attribution, the use of force, the law of armed conflict, sanctions, critical-infrastructure security and private-sector liability. This page gathers what is most useful to someone drafting a memo, preparing a hearing or evaluating a proposal. Everything linked is free to read without an account.

Policymakers’ guide contents

Scholarship on federal and international cyber policy

Peer-reviewed articles from the bound volumes are listed with their authors and year of publication; where a page carries a Free PDFlink, the typeset article is hosted here in full. Pieces credited to a JLCW desk are the Journal’s own analysis. Every article is in the full article index.

Scholarship addressed to Congress and federal policy

Articles that propose or evaluate specific U.S. statutory, regulatory or enforcement measures.

International law, state behaviour and norms

How sovereignty, attribution, the use-of-force rules and the law of armed conflict apply to state cyber operations — and where treaty or norm-building efforts stand.

Critical infrastructure, industry and emerging technology

Liability, insurance and defensive measures where private operators sit on the front line.

  • The Ransomware Assault on the Healthcare Sector — Malcolm Harkins & Anthony M. Freed (2018) · Free PDF
    This article examines the growing threat of ransomware attacks on the healthcare industry. It highlights the vulnerabilities created by the transition to electronic health records (EHRs), which…
  • Cyber Countermeasures by Private Actors — JLCW Editor (2026)
    State linked cyber operations now target private infrastructure with regularity. Energy grids, telecommunications networks, financial institutions, and cloud providers serve as both economic assets…
  • Cyber Insurance and Corporate Risk in Cybercrime — JLCW Editor (2026)
    Cybercrime now imposes direct financial, operational, and reputational costs on companies across every sector. Ransomware, business email compromise, supply chain infiltration, and data theft no…
  • Regulating Dual Use AI in Cyber Operations — JLCW Editor (2026)
    Artificial intelligence now drives many core cybersecurity functions. Machine learning systems detect anomalies, triage alerts, and predict intrusion patterns. These same technologies can also…

Notes on the federal cases that shape cyber law

20structured case notes on decisions that recur in cyber legislation and oversight. Each note states the issue, the rule, the court’s reasoning and the holding, quotes the opinion with locators, and links to the full opinion on CourtListener, the Free Law Project’s public archive. All notes are on the case law page.

Computer Fraud and Abuse Act

How the federal courts have drawn the line of “authorization” under 18 U.S.C. § 1030.

  • Van Buren v. United States, 593 U.S. 374 (2021)
    Supreme Court limits the CFAA: "exceeds authorized access" means entering off-limits files or databases, not misusing data you are allowed to obtain.
  • hiQ Labs, Inc. v. LinkedIn Corporation, 31 F.4th 1180 (9th Cir. 2022)
    Ninth Circuit: CFAA 'without authorization' likely does not reach scraping of public web pages, because a public server erects no authorization gate.
  • United States v. David Nosal, 828 F.3d 865 (9th Cir. 2016), amended and superseded on denial of rehearing en banc, 844 F.3d 1024 (9th Cir. 2016)
    Ninth Circuit held revoked CFAA access stays revoked: borrowing a current employee's credentials is still access 'without authorization' under 1030(a)(4).
  • Facebook, Inc. v. Power Ventures, Inc., 844 F.3d 1058 (9th Cir. 2016), amending and superseding 828 F.3d 1068 (9th Cir. 2016)
    Ninth Circuit held a cease-and-desist letter and IP blocks revoked Power Ventures' CFAA authorization, and Facebook users' consent could not restore it.
  • Sandvig v. Sessions, 315 F. Supp. 3d 1 (D.D.C. 2018)
    D.D.C. read the CFAA access provision narrowly: breaching terms of service is not exceeding authorized access, and researchers' as-applied claim survived.
  • United States v. Andrew Auernheimer, 748 F.3d 525 (3d Cir. 2014)
    Third Circuit vacated a CFAA conviction for improper venue: neither the unauthorized access nor the data collection occurred in the charging district.
  • United States v. Ivanov, 175 F. Supp. 2d 367 (D. Conn. 2001)
    A Russian hacker's intrusion happened where the servers sat: the CFAA reaches conduct abroad whose detrimental effects land on U.S. protected computers.
  • United States v. Robert Tappan Morris, 928 F.2d 504 (2d Cir. 1991)
    Second Circuit held CFAA intent runs only to the access, not the damage, and that the Morris Worm's spread was access without authorization.

Platforms, terrorism and Section 230

Anti-Terrorism Act aiding-and-abetting claims and Section 230 immunity for online platforms.

  • Twitter, Inc. v. Taamneh, 598 U.S. 471 (2023)
    Neutral platforms and content algorithms are not culpable participation: the Supreme Court's substantial-assistance test for ATA aiding-and-abetting.
  • Gonzalez v. Google LLC, 598 U.S. 617 (2023)
    Supreme Court left Section 230 immunity for algorithmic recommendations undecided, vacating and remanding an ISIS-attack claim against Google.
  • Force v. Facebook, Inc., 934 F.3d 53 (2d Cir. 2019)
    Recommendation algorithms are publishing conduct: the Second Circuit held Section 230 bars anti-terrorism claims over Hamas content on Facebook.
  • Crosby v. Twitter, Inc., 921 F.3d 617 (6th Cir. 2019)
    No proximate cause: the Sixth Circuit rejected Anti-Terrorism Act claims against platforms hosting ISIS propaganda a lone shooter consumed.
  • Colon v. Twitter, Inc., 14 F.4th 1213 (11th Cir. 2021)
    ISIS claimed credit after the Pulse attack. The Eleventh Circuit held that is not enough to make a lone gunman's rampage international terrorism.

Sovereign immunity, state sponsors and sanctions

The FSIA, JASTA and jurisdiction over foreign states, their agents and their banks.

  • WhatsApp Inc. v. NSO Group Technologies Ltd., 17 F.4th 930 (9th Cir. 2021)
    Ninth Circuit: the FSIA occupies the field for entities, so spyware vendor NSO Group gets no sovereign immunity for Pegasus operations run by states.
  • In re Terrorist Attacks on September 11, 2001, 117 F.4th 13 (2d Cir. 2024)
    FSIA section 1605A(f) bars collateral-order appeals from nonfinal orders in state-sponsored terrorism suits, so Sudan's 9/11 appeal was dismissed.
  • Fuld v. Palestine Liberation Organization, 82 F.4th 74 (2d Cir. 2023), rev'd and remanded, 606 U.S. 1 (2025)
    Second Circuit held the PSJVTA's deemed-consent jurisdiction over the PLO and PA violated Fifth Amendment due process; the Supreme Court reversed in 2025.
  • Ofisi v. BNP Paribas, S.A., 77 F.4th 667 (D.C. Cir. 2023)
    Evading Sudan sanctions was not conspiracy with or assistance to al-Qaeda: D.C. Circuit affirmed dismissal of embassy-bombing claims against BNP Paribas.
  • Wildman v. Deutsche Bank Aktiengesellschaft, No. 23-132 (2d Cir. July 21, 2025)
    Knowing that terrorists exploit your banking services is not culpable assistance: Second Circuit affirmed dismissal of JASTA claims against global banks.

Insurance and the meaning of “war”

Whether war exclusions reach hostile acts by non-state actors — the question behind cyber-insurance war clauses.

Subject guides

Each guide opens with an overview of where the law stands in its field, followed by every article the Journal has filed under that subject.

Policy dispatches

Shorter analysis of current developments — strategy documents, rulemakings, sanctions and alliance commitments. Dispatches bylined JLCW Research Desk are drafted with AI assistance, have their cited sources resolved, and are approved by a human editor before publication, as the editing policy sets out. The full archive is under news & dispatches.

Citing, downloading and following the Journal

Contacting the editors

Questions about a piece, permission requests and suggestions for coverage can be sent through the contact form. Published views are their authors’ own, and nothing on this site is legal advice — see the disclaimer.