The Legal Status of Cyber Espionage Between Nations

This article is written by Beckswhite Justice Chukwujiukah. This article argues that asking whether cyber espionage is legal is the wrong question. Collecting intelligence is not itself prohibited by any treaty or settled custom, but the way it is done in cyberspace,

by remotely entering systems on another state’s territory,

can breach that state’s sovereignty and, in some cases,

the rule of non-intervention or the prohibition on the use of force.

Introduction

A government that wants to know what another government is planning no longer has to send anyone abroad. An operator at a desk can copy diplomatic cables, defense files,

or negotiating positions from servers thousands of kilometers away, and the target may never learn it happened.

Spying is ancient. What is new is that it can be done without anyone crossing a border,

and that is what unsettles the traditional legal answer

The traditional answer is that international law says very little. States punish spies under their own criminal law, and spying states rarely admit what they do. Because no treaty prohibits peacetime espionage in general, many writers conclude that it is simply tolerated.

This article argues that the conclusion no longer follows once espionage is carried out through computer networks. The legal question is better asked about the method than about the purpose. Wanting information is not wrong. Entering another state’s systems without consent to get them may be because it exercises power inside foreign territory. Sections 2 and 3 set out the classical position and the dispute over sovereignty. Sections 4 and 5 take non-intervention and the use of force.

Section 7 with attribution and the responses open to a victim state, and Section 8 with human rights. Section 9 draws these together in a table, and Section 10 looks at the African position, including Nigeria.

The Classical Position: Espionage and the Lotus Principle

The usual starting point is the Lotus case. France and Turkey disputed Turkey’s right to prosecute a French officer after a collision on the high seas. The Permanent Court of International Justice said that restrictions on the independence of states,

cannot be presumed, and that a state may act as it pleases unless a rule of international law forbids it.

Those who defend the legality of spying rely on this reasoning:

There is no treaty banning it; states have spied for centuries.

and no state treats its own spying as a breach of law.

The same judgment also sets a limit. The Court described the first and most basic restriction that international law places on a state as the rule that

Without a permissive rule to the contrary, it may not exercise its power in the territory of another state. Lotus, therefore, does not settle the matter for either side.

It tells us to look for a prohibitive rule, and it points to where one might be found:

in the law of territorial sovereignty.

Domestic law is where spies are actually punished.

R v. Delisle

In R v Delisle, a Canadian officer who passed secret material to Russian officers,

the Security of Information Act after pleading guilty.

That case concerned an insider and a human source, not a remote intrusion, but it shows the point:

The target state’s remedy against the individual is its own penal law.

while international law has traditionally been silent about the state behind him.

The Tallinn Manual 2.0,

written by a group of experts for the NATO Cooperative Cyber Defence Centre of Excellence, takes a middle path.

Its experts agreed that peacetime cyber espionage does not violate international law as such.

but that the way it is carried out might. That qualification about method is the idea this article builds on.

Sovereignty: A Rule or a Principle?

In the Corfu Channel case, the International Court of Justice held that

The United Kingdom had violated Albanian sovereignty by sweeping mines in Albanian waters without Albania’s consent.

The United Kingdom said it was securing evidence for later proceedings.

The Court rejected that justification and described respect for territorial sovereignty as an essential foundation of relations between independent states. The facts are not digital, but the logic carries over. Collecting evidence on another state’s territory without consent was not excused by the purpose.

In the Island of Palmas arbitration,

Sovereignty was defined as the right to exercise the functions of a state, to the exclusion of any other state.

States now divide into three groups on whether this applies to cyber operations.

The first treats sovereignty as a binding rule. France has taken the firmest stand.

saying that any unauthorized penetration of its systems is at least a breach of sovereignty

Germany and Switzerland also treat sovereignty as a rule.

although they differ on the threshold at which a cyber operation breaches it,

and the African Union’s 2024 Common African Position likewise treats sovereignty as an enforceable rule that applies in cyberspace.

Tallinn Manual 2.0

The second is the threshold approach in the Tallinn Manual 2.0. Rule 4 finds a violation where an operation infringes a state’s territorial integrity.

for instance, by causing physical damage or loss of functionality, or where it interferes with or usurps inherently governmental functions. On that view, copying data without affecting how a system works generally does not breach sovereignty by itself.

although the experts were not unanimous on every scenario.

The third is the United Kingdom’s position. In 2018 the Attorney General, Jeremy Wright,

said that the United Kingdom does not accept a standalone rule of sovereignty in cyberspace.

On his account sovereignty is a principle that informs other rules, such as non-intervention.

and a cyber operation is unlawful only if it breaks one of those rules.

I find the first view more persuasive for two reasons.

The principle-only position has difficulty with the Corfu Channel, where the Court found a violation of sovereignty as a wrong in itself, without asking whether Albania had been coerced. And a remote intrusion into government servers is an exercise of power in foreign territory, which is exactly what Lotus says a state may not do without permission. The harder question is where to draw the line. The Tallinn threshold is easier to apply, but it risks being too generous to the intruder, since a state can be harmed badly by the loss of confidential information even when no system stops working.

Timer- Leste v. Australia

The International Court has not yet ruled on espionage as such. The nearest it has come is Timor-Leste v Australia, which arose after Australian intelligence officers raided the Canberra office of a lawyer advising Timor-Leste in an arbitration and seized documents. The Court ordered provisional measures protecting the confidentiality of the seized material and communications with counsel, and the case was discontinued in 2015 once the documents were returned. The case shows that the Court will examine intelligence operations when a state’s legal rights are directly affected.

Non-Intervention and Hack-and-Leak

In Nicaragua the Court held that the principle of non-intervention forbids a state from interfering in matters in which every state is free to decide for itself, such as its political, economic, social, and cultural system and its foreign policy. Intervention is wrongful when it uses coercion over those choices. Two elements must therefore coexist: a protected domain and coercion.

Ordinary espionage rarely meets the second element. Copying files does not compel a government to do anything, and a government that does not know it has been watched cannot be forced by it. That is why passive collection is usually analyzed under sovereignty rather than non-intervention.

Election interference is harder. The United States indictment in United States v. Netyksho alleges that twelve Russian military intelligence officers stole emails from the Democratic National Committee and campaign staff in 2016 and released them through online personas. These are allegations in a criminal indictment, not findings of an international tribunal, but the pattern they describe is theft followed by deliberate release.

Whether that amounts to coercion is disputed. Altering voter registers or vote counts plainly takes a choice away from the electorate. Publishing true but stolen emails persuades rather than compels, and some writers treat it as influence, not coercion. My own view is that the answer depends on the effect: where an operation deprives a population of the ability to make a free electoral choice, the coercion requirement is met, and where it only adds information to a free debate, it is not.

Use of Force and Armed Attack

Article 2(4) of the UN Charter prohibits the threat or use of force against the territorial integrity or political independence of any state, and Article 51 preserves the right of self-defense if an armed attack occurs. In Nicaragua the Court distinguished the gravest forms of force, which amount to an armed attack, from less grave ones by reference to scale and effects. The Tallinn Manual applies the same test and treats a cyber operation as a use of force when its scale and effects are comparable to those of a non-cyber operation that would be one.

Espionage that only reads or copies data produces no destruction, casualties, or physical damage and falls well short of this threshold. The question arises only where an intrusion made for intelligence purposes also carries or enables a destructive payload, for example, one that wipes servers or disables the safety systems of critical infrastructure. At that point it is no longer espionage in the legal sense, and the law of force applies.

Economic Espionage: A Norm in Progress

Many states say that spying on governments for security purposes is different from stealing commercial secrets for the benefit of national companies. The Su Bin case shows how hard it is to keep the two apart. A Chinese businessman was prosecuted in the United States for conspiring with hackers in China to break into the networks of American defence contractors, including Boeing, and to take data on military aircraft such as the C-17, F-22 and F-35. He pleaded guilty to conspiracy to gain unauthorised access to protected computers and to violate the Arms Export Control Act. Data of this kind serves both commercial and military ends, so the line between economic and security espionage is thinner than the labels suggest.

The main political commitment on commercial theft was made in September 2015, when the United States and China agreed that neither government would conduct or knowingly support cyber-enabled theft of intellectual property for commercial advantage. The G20 leaders endorsed the same principle at Antalya two months later. The 2015 report of the UN Group of Governmental Experts, endorsed by the General Assembly, recommended a number of voluntary norms of responsible state behaviour, but the theft of intellectual property was not among them.

The prohibition on commercial cyber theft is therefore best described as an emerging norm. It rests on political commitments by some states, not on a treaty, and customary law needs consistent practice accompanied by a belief that the practice is legally required. That is not yet clearly shown.

Attribution and the Responses Open to a Victim State

Even where an intrusion breaches international law, the victim state must show that the conduct is attributable to a state. Under the International Law Commission’s Articles on State Responsibility (ARSIWA), the conduct of state organs, such as military cyber units and intelligence agencies, is attributable to the state. The conduct of private persons, such as hacker groups, is attributable only if they acted on the instructions of, or under the direction or control of, the state in carrying out that conduct (Article 8).

Bosnia v. Serbia

In Bosnia v Serbia the Court applied the effective control test, requiring proof that the state controlled the specific operation in which the wrong occurred, not merely that it gave general support.In cyberspace this is difficult to satisfy. Intelligence services use proxies, contractors and false-flag infrastructure, and technical evidence may be classified or inconclusive. This explains why formal claims before international tribunals over cyber operations are almost unknown, even though states often attribute operations publicly.

What the victim may do depends on the character of the intrusion. If the conduct breaches no international obligation, only retorsion is available. This covers unfriendly but lawful acts such as expelling diplomats, cancelling visas, or imposing sanctions on named officials. If the conduct is an internationally wrongful act, the victim may take countermeasures, which are otherwise unlawful acts directed at making the responsible state comply. They must be proportionate, reversible as far as possible, and preceded by a call on the responsible state to comply, except for urgent measures to preserve rights. Self-defence is available only against an armed attack, as discussed in Section 5. The 2015 GGE also recommended that states should not knowingly allow their territory to be used for internationally wrongful ICT acts against others, a due diligence norm that may matter where attacks are routed through third states.

Human Rights and Extraterritorial Surveillance

Cyber espionage often targets people, including journalists, diplomats, lawyers and activists, as well as governments. Human rights law therefore offers a route that does not depend on the sovereignty debate. In Big Brother Watch v United Kingdom the European Court of Human Rights Grand Chamber accepted that bulk interception can be a legitimate tool but held that it must be surrounded by end-to-end safeguards, including independent authorisation and oversight. The United Kingdom’s regime fell short of those requirements and breached Article 8 of the European Convention.

Article 17 of the International Covenant on Civil and Political Rights protects against arbitrary or unlawful interference with privacy and correspondence. The Human Rights Committee has said that a state owes Covenant obligations to those within its power or effective control, even outside its territory. Whether remote interception puts someone within a state’s power or effective control is debated. The General Assembly has affirmed that the rights people have offline must also be protected online, and has expressed concern about extraterritorial surveillance. This area is still unsettled, but it is moving towards recognising that surveillance of foreigners abroad is not a legal vacuum.

Summary: Thresholds and Responses

The analysis above can be summarised as a ladder in which the legal consequences rise with the effect of the operation.

LevelLegal basisExampleLawful response
Passive collectionNo settled prohibition of espionage as such; sovereignty position contestedCopying diplomatic files without affecting systemsRetorsion
Breach of sovereigntyCorfu Channel; French and African positions; Tallinn Rule 4Intrusion that disables systems or interferes with governmental functionsCountermeasures
Prohibited interventionNicaragua; customary non-interventionAltering voter registers or vote countsCountermeasures
Use of force or armed attackUN Charter, arts 2(4) and 51Intrusion carrying a destructive payloadSelf-defence, if an armed attack

The African Position and Nigeria

The 2024 Common African Position is significant because it brings a large group of states into the camp that treats sovereignty as a rule. For a state like Nigeria, which depends on foreign-hosted infrastructure and has limited capacity to trace intrusions to their source, a rule-based reading offers more protection than a threshold-based one. It does not oblige the victim to prove damage before it can say its sovereignty was breached.

Domestic and regional treaty law supplies a shared baseline. The Budapest Convention requires parties to criminalise illegal access, illegal interception, data interference and system interference, and the African Union’s Malabo Convention, in force since June 2023, requires similar protection in African states. In Nigeria, the Cybercrimes (Prohibition, Prevention, Etc) Act 2015, as amended in 2024, criminalises unlawful access to computer systems and protects critical national information infrastructure. These instruments show that unauthorised access is widely regarded as wrongful, but they regulate criminals and private actors. They cannot reach a foreign state’s intelligence officers operating abroad, who are beyond the practical reach of a Nigerian court.

Conclusion

Cyber espionage is neither plainly lawful nor plainly unlawful, and the reason is that the question treats a range of conduct as one thing. Intelligence gathering as an aim is tolerated. The remote entry into another state’s systems used to achieve it is more doubtful, and I have argued that it can breach sovereignty without any damage, because it exercises power in foreign territory without consent. Where the operation coerces a state’s political choices it can become unlawful intervention, and where it delivers destructive effects it falls under the law on the use of force.

Three steps would reduce the uncertainty. States should publish national positions on whether sovereignty is a rule and on the threshold at which an intrusion breaches it, as France, the United Kingdom and the African Union have begun to do. The UN processes on ICT security, including the successor to the Open-ended Working Group, should work towards agreed thresholds and a clearer norm on economic cyber theft

And states should develop ways to share technical evidence so that attribution does not remain the main obstacle to any legal remedy. Until then, the lawfulness of a cyber operation will depend on how it was done and what it did.