Cyber Warfare Fundamentals
How states use cyber operations as tools of conflict, from espionage and sabotage to influence campaigns and critical infrastructure attacks.
For the complete documentation index, see llms.txt.Skip to main content
For centuries, wars were fought on land and sea. The 20th century added air and space. The 21st century has added a fifth domain: cyberspace. Cyber warfare encompasses state-sponsored operations conducted through computer networks to spy on adversaries, sabotage their systems, or manipulate their information environment. Unlike conventional warfare, cyber operations can be conducted anonymously, at low cost, and from thousands of miles away.
The landmark event was Stuxnet, discovered in 2010. This sophisticated malware, widely attributed to the United States and Israel, targeted Iran's Natanz uranium enrichment facility. It caused centrifuges to spin out of control while reporting normal operations to monitoring systems. Stuxnet destroyed roughly 1,000 centrifuges and set Iran's nuclear program back by an estimated two years. It was the first known cyber weapon to cause physical destruction, crossing a threshold that transformed how governments think about digital conflict.
Today, dozens of states maintain offensive cyber capabilities. The United States, Russia, China, Israel, the United Kingdom, Iran, and North Korea are among the most active. Their operations fall into several categories. Cyber espionage involves penetrating foreign government, military, or corporate networks to steal sensitive information. China's alleged theft of US federal employee data in the 2015 OPM hack, affecting 21.5 million records, exemplifies this category.
Cyber sabotage aims to damage or disrupt systems. Russia's 2015 and 2016 attacks on Ukraine's power grid left hundreds of thousands without electricity in winter, demonstrating that cyber operations can have life-threatening physical consequences. Information operations use cyber tools to manipulate public opinion, as Russia did during the 2016 US presidential election through hacking and social media manipulation.
| Operation | Type | What it did |
|---|---|---|
| Stuxnet (2010) | Sabotage / physical destruction | Destroyed ~1,000 Iranian centrifuges; first cyber weapon to cause physical damage |
| OPM hack (2015) | Espionage | Theft of 21.5 million US federal personnel records |
| Ukraine power grid (2015–2016) | Sabotage | Cut electricity to hundreds of thousands of people in winter |
| 2016 US election interference | Information operation | Hacking plus social-media manipulation to influence public opinion |
| NotPetya (2017) | Destructive malware | Spread from Ukraine worldwide, causing an estimated $10 billion in global damage |
Reading down the table, the operations climb a rough ladder of severity — from quiet data theft, to disruption of services, to physical destruction that approaches an act of war. That severity ladder is exactly what makes cyber conflict so hard to govern: there is no agreed line for when a keystroke becomes an armed attack.
The international community is struggling to establish rules for cyber conflict. The UN Group of Governmental Experts has affirmed that existing international law, including the laws of armed conflict, applies to cyberspace. But application is contentious. When does a cyberattack constitute an armed attack justifying self-defense under Article 51 of the UN Charter? Most experts agree that Stuxnet-level physical destruction qualifies, but what about election interference or massive data theft?
The Tallinn Manual, produced by NATO-affiliated scholars, provides the most comprehensive analysis of how international law applies to cyber operations. But it is an academic exercise, not a binding treaty. Major cyber powers, particularly Russia and China, prefer a new treaty framework that emphasizes state sovereignty over internet governance, while Western nations advocate applying existing law. This disagreement means the rules of cyber conflict remain largely unwritten.