CyCon 2026 Series – Cyber Operations in the Multidomain Battlespace: A Legal View from the Ministry of Defence of Ukraine

by | Sep 4, 2026

Ukraine

Editors’ note: This post introduces a series derived from panels and discussions that took place in 2026 at the 18th annual International Conference on Cyber Conflict (CyCon) event hosted by the NATO Cooperative Cyber Defence Centre of Excellence in Tallinn, Estonia. This year’s theme was “Securing Tomorrow.”

At this year’s CyCon panel, “Battle Without Borders: Cyber Warfare and the Law in Multi-Domain Operations,” discussion circled back to a simple but uncomfortable observation: modern militaries no longer have the option of fighting in cyber, on land, at sea, and in the air as siloed domains. Instead, they fight across all of them at once, often through the same command-and-control systems and the same civilian-owned networks. For Ukraine, this is not a theoretical idea borrowed from a NATO concept paper. It is what the war has looked like since the first hours of the Russian Federation’s full-scale invasion of Ukraine in 2022.

This post addresses the following questions raised during CyCon 2026. How does Ukraine deal with the legal complexity of multidomain operations (MDO) at the national level? What practical examples illustrate the problems of MDO? And what does Ukraine’s approach mean for those who must make legal calls about these operations in real time?

Cyber as the Connective Tissue of MDO

The Viasat KA-SAT hack is probably one of the clearest illustrations of what “multidomain” means in practice, and it is worth dwelling on. Hours before Russian troops crossed the Ukrainian border on February 24, 2022, a cyberattack disrupted broadband satellite internet access and disabled modems that communicate with Viasat Inc’s KA-SAT satellite network, which supplies internet access to tens of thousands of people in Ukraine and Europe. Different sources have shown that the attack was the result of a new strain of wiper malware called “AcidRain,” which was attributed to the Russian Federation. AcidRain was designed to remotely erase vulnerable modems and routers, including terminals used by the Armed Forces of Ukraine for command and control at exactly the moment that control matters most.

The operation was timed and targeted to degrade Ukraine’s command-and-control capability in the opening hours of a ground offensive. It was, in other words, not a stand-alone operation at all, but a supporting fire in a much larger kinetic plan: the cyber equivalent of taking out an adversary’s communications before an assault.

However, the military effectiveness of the Viasat attack and the concrete military advantage it actually yielded are open to serious doubt. Ukrainian officials have stated that the attack ultimately “had no tactical impact on Ukrainian military communications and operations” because the Armed Forces of Ukraine were prepared for such an attack. The military had anticipated the possibility of satellite disruption and were prepared to use alternative communication networks, such as those of Inmarsat and SpaceX, which enabled Ukrainian forces to remain resilient and adaptable in the face of cyber threats. Moreover, the most critical services had already relocated their data centres to other European countries.

The Viasat attack impacted not only military objects but also caused extensive civilian damage that extended far beyond the borders of Ukraine. Several States experienced a loss of internet access and possible disruptions to systems in the energy sector. The European satellite network suffered for more than two weeks. In France, nearly 9,000 subscribers of a satellite internet service provider experienced an internet outage, and nearly a third of the 40,000 subscribers of another European satellite internet service provider were affected. Additionally, the attack impacted a major German energy company, which lost remote monitoring access to over 5,800 wind turbines. Overall, the attack impacted thousands of customers in Ukraine and tens of thousands across Europe.

The cyber operation clearly served a supporting role before the full-scale invasion, however, it violated international law. The operation and its harm were not limited to the territory of the two States engaged in the international armed conflict and also constituted clear violations of the foundational IHL prohibition of indiscriminate attacks.

Public statements by cybersecurity companies, international organizations (including the EU), and more than 20 governments (including all Five Eyes members: the United States, United Kingdom, Australia, New Zealand, and Canada) attributed AcidRain to Russia and, in some cases, specifically to Russia’s military intelligence agency, the GRU. These statements also linked AcidRain to multiple families of destructive wiper malware, including WhisperGate, which targeted Ukrainian government and private sector networks. The public response marked an important step in promoting the attribution of cyberattacks and the development of States’ practice.

Not All Cyber Operations Do the Same Job

The distinction between cyber activity that stands on its own and cyber activity undertaken to enable something else provides a more useful way to understand the last four years of experience than any single “type” of cyber operation.

Some cyber operations are integrated directly into a kinetic plan, and their value lies entirely in that integration. In October 2022, at the same time Russia launched one of its largest waves of missile strikes against Ukrainian infrastructure, the Sandworm group used low-level “living off the land” techniques to trip circuit breakers at a Ukrainian grid operator. The resulting blackout augmented, rather than replaced, the missile campaign by layering a cyber-induced outage on top of the ongoing strikes. On its own, the cyber operation barely would have registered, but when combined with the missile strikes, it compounded the effect on the civilian population at the same moment, precisely the kind of integrated targeting package the CyCon panel had in mind.

However, this operation clearly violated international humanitarian law (IHL) for, at a minimum, two reasons. First, energy infrastructure is a civilian object, and any attacks on it are prohibited. However, even if there were a reasonable basis to believe that energy infrastructure was used for military purposes, core IHL principles, including proportionality, would still apply. In this case, the principle of proportionality was clearly violated. The marginal military advantage of the cyber component, layered on top of the simultaneous and already devastating missile campaign against the same infrastructure, would have been insufficient to justify the additional civilian harm it produced.

Secondly, the operation supported a general pattern of illegal Russian actions aimed at terrorizing the civilian population. It should be assessed not in isolation but as part of a sustained, systematic campaign to destroy Ukraine’s civilian energy infrastructure across the 2022–2024 winter periods, a pattern the UN, International Criminal Court, and multiple governments have characterized as a serious IHL violation. The Sandworm operation was one element of what amounts to an unlawful course of conduct.

Other operations are designed to stand alone, aiming at a strategic or psychological effect independent of any single kinetic strike. In April 2022, Industroyer2, a lineal descendant of the malware that caused blackouts in Kyiv in 2016, was deployed against a Ukrainian electricity provider. The attack was intended to cut power to roughly two million people through the direct manipulation of substation control systems. It was foiled only through last-minute detection by CERT-UA and ESET. Ukrainian officials at the time suggested that the cyberattack was meant to support Russia’s ground operations in the east, but its design and scale meant that it would have had a severe and longstanding effect on the civilian population regardless of what was happening on the front line at the time.

The December 2023 attack on Kyivstar, Ukraine’s largest mobile operator, falls into the same category. That attack knocked out mobile and internet service for roughly 24 million subscribers for two days, disabled bank terminals and air-raid alert relays, and inflicted financial losses initially estimated at close to $100 million (subsequently revised in Veon’s financial filings), without being tied to any single, contemporaneous kinetic operation. The attack on Kyivstar clearly was part of the Russian policy to terrorize Ukrainian civilians.

Alongside both categories sit quieter activities—persistent espionage and network reconnaissance for intelligence purposes, and information operations aimed at eroding morale or shaping public perception—that rarely rise to the level of an “attack” in the IHL sense but still form part of the same broader campaign. The legal significance of sorting operations this way is not academic. Whether a cyber operation is assessed as an integrated part of a kinetic attack, as a stand-alone attack in its own right, or as an operation falling short of an “attack” altogether changes which rules on distinction, proportionality, and precaution apply, and to what.

A Ministry-Wide Reference Point

Having cyber as an integral domain of MDO, conducted against illegal aggression of the Russian Federation, the Ministry of Defence of Ukraine (MoDU) has been developing an internal Green Paper on the application of international law to cyber operations that draws on the Tallinn Manual 2.0 and the published national positions collected in the Cyber Law Toolkit. Its aim is modest and institutional rather than doctrinal: provide Ukrainian detachments a single, coherent reference point on how sovereignty, non-intervention, IHL, international criminal law, and human rights law apply to cyber activity to ensure consistency in the application of the Ministry’s normative acts, including the 2017 Instruction on IHL implementation in the Armed Forces.

One useful test of the framework is the Kyivstar case itself. Not every disruptive cyber operation qualifies as an “attack” under Additional Protocol I, which requires an act of violence, traditionally understood as death, injury, or physical damage, though States increasingly disagree over whether “loss of functionality” alone can suffice. The Green Paper deliberately adopts a middle position between the majority view of the Tallinn Manual 2.0 experts (which limits “attack” to operations causing physical damage) and a broader reading. The Green Paper maintains that an operation qualifies as an attack where it causes injury or death, damages or destroys physical objects, or causes a loss of functionality serious enough to require replacing physical components. This threshold is not universally accepted but reflects an emerging State practice-oriented approach.

Measured against that standard, Kyivstar can plausibly be treated as an attack, which in turn opens the door to assessing it against the ordinary rules on the conduct of hostilities, and, if those rules were seriously breached, to treating it as a war crime. The document works through comparable questions on the status of civilian versus military data and on when civilian hacking activity crosses into direct participation in hostilities. The underlying method is the same throughout: take the general international law framework seriously, then test it against what our own networks have actually experienced.

The Role of Legal Advisers and Technologists

None of this is useful if it stays on paper. The recurring lesson from Viasat, the October 2022 grid attack, Industroyer2, and Kyivstar is that a legal adviser who does not understand, at a working level, how these systems function and interact cannot meaningfully classify them, let alone advise a commander on them. Recognizing that a strike on a “communications node” is really a supporting fire for a kinetic operation three time zones away, or that it will also take down a civilian air-raid warning system three hops down the same network, is as much a technical judgment as a legal one.

That is why the Ministry has invested in building IHL literacy well beyond the traditional infantry commander. The existing Basic IHL Training Package, the 2024 Voluntary report on IHL implementation, and now the Green Paper are all meant to reach the officers running electronic warfare and the technical staff supporting cyber units, not just legal officers reading a targeting file.

Concluding Thoughts

Multidomain operations may be a relatively new label, but for Ukraine the underlying problem is not new. The problem has been an aggressor who treats cyberspace as one more axis of attack against civilian and military infrastructure, sometimes as a supporting fire and sometimes as a strategic strike in its own right. What is new is the speed and integration of these operations, and the pressure they place on legal advisers to tell the two apart in real time, in the absence of clear IHL regulation.

Our own experience suggests that the answer cannot lie in wait for a new treaty. Rather, an effective response must begin with case-by-case classification and analysis of each operation and its purpose, informed by past incidents such as the Viasat hack, the October 2022 grid attack, and the Kyivstar attack. It must also involve a genuine investment in the people who advise on and conduct these operations, to ensure they understand both the law and the technology applicable to cyber operations in the multidomain battlespace.

***

Inna Zavorotko, PhD is a colonel in the Armed Forces of Ukraine. She currently serves as the Head of the International Law Division of the Ministry of Defence.

The views expressed are those of the author, and do not necessarily reflect the official position of the United States Military Academy, Department of the Army, or Department of Defense. 

Articles of War is a forum for professionals to share opinions and cultivate ideas. Articles of War does not screen articles to fit a particular editorial agenda, nor endorse or advocate material that is published. Authorship does not indicate affiliation with Articles of War, the Lieber Institute, or the United States Military Academy West Point.

 

 

 

 

 

 

 

 

 

Photo credit: Unsplash