Estimated reading time: 22 minutes
A commander in a cyber operation rarely sees who he is fighting. An operation arrives across a network. The person behind it wears no uniform, carries no rifle, and may be sitting in a flat a thousand miles from any front. Whether he may lawfully be attacked turns on a question the law answers through conduct rather than appearance: is he a civilian taking a direct part in hostilities? Under Article 51 (3) of Additional Protocol I (AP I), a civilian loses protection against attack, and only “for such time as” he takes such a part. Direct participation in hostilities is, in that sense, the hinge on which the whole distinction between the protected and the targetable turns.
This post works through the four questions a commander or legal adviser has to answer, in the order they arise. Who counts as a civilian in the first place, and how is doubt about that status resolved? What conduct crosses the line into participation? Once it is crossed, for how long is the participant exposed? And is the person an individual civilian, assessed act by act, or a member of an armed force, targetable by status? Each question has a settled legal answer. The difficulty lies in applying settled law to a domain where the facts are hard to see.
The line between those who may be attacked and those who may not is one I have written about before, in my post on the principle of distinction. This post is the companion to my last, on persons renderedhors de combat: two different ways a person crosses the line that separates the protected from the targetable. My argument here is an optimistic one. Civilian hackers, volunteer “IT armies” and hacktivist collectives can look like a problem the existing law was never built to handle. I will suggest the opposite. The rules on direct participation in hostilities were made for precisely this question, and they hold in the cyber domain without any new legal category.
I. Who starts protected: the civilian and the doubt rule
The negative definition
Everyone who is not a combatant is a civilian, and every civilian is protected until his own conduct forfeits that protection. That is the architecture of Additional Protocol I, and it begins with a definition by exclusion. Article 50 (1) AP I defines a civilian as any person who does not fall within the combatant categories of the Third Geneva Convention and Article 43 AP I. The definition sets no threshold of innocence and asks for no good conduct. A person is a civilian because of what he is not.
That negative definition is not confined to the treaty’s parties. The ICRC Customary IHL Study records it as customary international law (Rule 5), binding in both international and non-international armed conflict. No contrary State practice was found, and the rule holds even for States that never ratified AP I. Absent membership in the armed forces, then, a person is a civilian, and Article 51 (2) AP I provides that civilians “shall not be the object of attack”.
That protection is broad, but it is not unconditional. Article 51 (3) AP I withdraws it from any civilian who takes “a direct part in hostilities”, and only “for such time as” he does so. That exception, direct participation in hostilities (DPH), occupies the rest of this post. This section addresses the prior question. Before a commander asks whether an act crosses the line, he must decide whether the person before him is a civilian at all.
The doubt rule and its cyber edge
The law resolves genuine doubt in the civilian’s favour, and it does so through a specific instruction rather than a general presumption.Article 50 (1) AP I provides that where there is doubt whether a person is a civilian, “that person shall be considered to be a civilian”. The verb is doing careful work. For objects, Article 52 (3) AP I directs that a civilian-purpose object in doubt “shall be presumed” not to be a military objective. The treaty chose “considered” for persons and “presumed” for objects, and Mina Radončić and Ash Stanley-Ryan, writing for the Lieber Institute, record that this choice was deliberate and is carried through in the French text.
Practitioners often call the rule a “presumption of civilian status”. The shorthand is convenient, and it also flattens the distinction the treaty draws between its two verbs. I have set out elsewhere why persons under Article 50(1) do not enjoy a true presumption of the kind Article 52 (3) creates for objects, and I will not rehearse that argument here (see my post on the presumption of civilian status in case of doubt). For present purposes the operative point is narrower. In genuine doubt about a person’s status, the commander must treat him as a civilian.
In the cyber domain, that doubt is not the exception. It is the normal condition. When an operation arrives across a network, the party on the receiving end frequently cannot identify the human behind it, still less establish his status. Macák and Pircher divide the difficulty in two. Attributing a cyber operation to an identifiable individual is often impractical in the moment, and cyberspace makes a person’s status and activity hard to determine at all (Macák and Pircher, at p. 12). Both difficulties feed the same doubt, and the doubt rule then governs how the commander may act.
In operational terms, the cyber setting reorders the questions a commander faces. Against a kinetic target, identity and status are usually visible, and doubt is the occasional hard case. A cyber actor, by contrast, is usually hidden, so doubt becomes the default. The Article 50 (1) instruction therefore carries more weight in the cyber context than in the kinetic one. It governs the ordinary case, until the commander can establish that the person’s conduct has crossed the threshold of direct participation in hostilities. That threshold, with its three constitutive elements, is the subject of the next section.
II. When the act crosses the line: the elements of direct participation in hostilities
Once a person is established as a civilian, the law does not ask what he believes or which side he favours. It asks what he does. A civilian loses protection only through a specific act, and only through an act that satisfies three cumulative tests. The act must harm the adversary militarily, or kill, injure, or destroy protected persons or objects. It must cause that harm directly. And it must be designed to cause it in the conflict, for one party against another. The ICRC’s Interpretive Guidance sets out these three elements as the frame for direct participation in hostilities (at p. 46): threshold of harm, direct causation, and belligerent nexus. The frame is contested at its edges, yet its structure commands wide agreement. Schmitt, who sat through the ICRC’s expert process and dissented on much else, still calls the three elements the Guidance’s “most satisfactory” part (at p. 738). I take the same view. The elements are the right tool. The difficulty lies in applying them, and cyber operations are where that difficulty surfaces.
Threshold of harm
The first test is the least demanding, and cyber operations meet it easily. An act crosses the threshold when it is likely to affect a party’s military operations or capacity, or to kill, injure, or destroy protected persons or objects. Harm of a military kind qualifies whatever its scale. The Guidance says so, and it names electronic interference with military computer networks as a sufficient example, whether the operation is a computer network attack or computer network exploitation (Interpretive Guidance, at p. 48). Wiretapping an enemy command, or feeding targeting data to an attacking force, reaches the threshold as well.
State practice already applies this test to cyber conduct, which puts cyber direct participation beyond the theoretical. Germany takes the most explicit position: a civilian in cyberspace directly participates once the three conditions are met, and Germany endorses the Guidance’s computer-network examples (Germany, position paper, at p. 8). France applies the same threshold and is more concrete still, treating the penetration of a military system to gather tactical intelligence for an attack, the installation of malicious code, and the preparation of a botnet for a denial-of-service attack as direct participation (France, International Law Applied to Operations in Cyberspace at p. 15). The United Kingdom frames its formulation more narrowly, around cyber operations that amount to attacks (UK statement, at para. 25). Macák and Pircher collect these positions in their survey (at p. 12). The divergence is instructive: Germany and France track the Guidance’s threshold, which reaches any adverse military effect, whereas the United Kingdom’s attack-based wording sets a higher entry point.
Two refinements sharpen the picture. First, the test turns on the harm’s military character rather than its scale; the Guidance counts any military effect regardless of quantitative gravity (Interpretive Guidance, at p. 47), and Schmitt adds that calling it a threshold, a quantitative word, misleads for that reason (Schmitt, at pp. 716–717). Second, the Guidance counts only harm to the enemy and passes over acts that strengthen one’s own side without measurably weakening the other. Schmitt reads that omission as under-inclusive (Schmitt, at pp. 718–720). The gap can matter in the cyber domain, where an operation may harden a party’s own position without a traceable loss to its opponent.
Direct causation
The second test is the one that cyber operations strain the most. Direct causation asks for a close causal link between the act and the harm. The act must cause the harm, not merely build or sustain the capacity to cause it. The Guidance draws the line between direct participation and the wider war effort here, and it requires the harm to arise in a single causal step (Interpretive Guidance, at pp. 51–53). Financing, weapons production, and recruitment build general capacity and stay on the indirect side of that line, so they do not forfeit protection.
Distance does not defeat causation. A cyber operation launched from another continent causes its harm as directly as a shell fired across a field, because causal proximity is not geographic or temporal proximity. The Guidance says as much for remote-controlled and delayed weapons (Interpretive Guidance, at p. 55), and Schmitt agrees (Schmitt, at p. 728). The hacker gains no protection from sitting far from the fighting.
The harder cyber problem is that one operation is rarely the work of one hand in one step. A network intrusion may be coded by one person, delivered by another, and triggered by a third, with its effect surfacing days later. A literal single-step reading of causation would excuse most of that chain. The Guidance does not stop there. An act that does not itself cause the harm still qualifies when it forms an integral part of a coordinated operation that does (Interpretive Guidance, at pp. 54–55). Schmitt would go further and apply that integral-part test to individual as well as coordinated operations, faulting the single-step formula as too narrow (Schmitt, at pp. 727–732). In operational terms, the integral-part test is the one that fits a cyber kill chain.
Belligerent nexus
The third test separates an act of war from a crime that merely happens in a war. Belligerent nexus requires that the act be designed to harm one party for the benefit of another, as part of the conflict itself. The Guidance treats this as an objective question about the design of the act rather than the state of mind behind it (Interpretive Guidance, at p. 59). A civilian’s private motives, his distress, even his ignorance of his own role, do not decide the matter. Schmitt calls this the least contested of the three elements, and on the design-not-intent point he and the Guidance agree (Schmitt, at pp. 735–736).
The nexus is what keeps ordinary crime and unrest beyond the reach of targeting. Violence that merely exploits the disorder of war lacks it: an ordinary robbery, a private score settled with a looted rifle, self-defence against a marauding soldier (Interpretive Guidance, at pp. 60–61). The Guidance groups the recurring failures into four categories: individual self-defence, the exercise of power over persons or territory, civil unrest against the authorities, and violence between civilians unconnected to the conflict (Interpretive Guidance, at p. 64).
For civilian hackers, the nexus is often the element that decides the case. A hacktivist who defaces a ministry website in protest, or a criminal who extorts a company while a war runs in the background, may cause real disruption and still remain a civilian, because neither act is designed to serve one belligerent against another. What forfeits protection is the operation built to harm a party’s military effort, such as an intrusion that blocks a military rail deployment (Macák and Pircher, at p. 12). In operational terms, the question is not how strongly the hacker feels or how much damage he causes, but whether his act, read objectively, is designed to serve one side’s fight against the other.
The three elements decide whether a single act crosses the line. They leave two harder questions for later. The first is temporal. Once an act qualifies, for how long does the hacker stay targetable, and does protection return the moment he leaves the keyboard? That is the subject of the next section. The second arises when a cyber act sits in the grey zone between direct and indirect participation in hostilities, where reasonable observers differ; I return to it when I reach the commander’s determination in Section IV.
III. For such time as: the duration of direct participation in hostilities
The harder question is temporal. A cyber operation can forfeit a civilian’s protection; the real difficulty is how long that forfeiture lasts. Article 51 (3) AP I makes it temporary, exposing a civilian “for such time as” he takes a direct part in hostilities and no longer. Civilian hackers almost never participate without interruption. An operation is followed by a return to ordinary life, and then, sometimes, by another. This is the digital form of the old farmer by day, fighter by night problem, and it is where the doctrine is least settled and where defence readiness is most exposed.
The revolving door and the spectrum
The text fixes protection to conduct but never defines when participation ends, and four readings compete for that gap. The ICRC takes the narrowest. Protection resumes the moment each hostile act ends, so the civilian loses and regains it in step with his acts. On this view the revolving door is “an integral part, not a malfunction” of the law (at p. 70), and between acts a persistent participant may be met only under law-enforcement or self-defence standards. The ICRC rests the reading on the difficulty of predicting future conduct. It also confines the argument to participation that is one-off or occasional and not organised (at p. 71), and it sends the genuinely continuous case to the separate category of organized-group membership, which I take up in Section IV.
Three other readings converge against that safe haven. Boothby separates the occasional, one-off act, after which protection returns, from sustained or repeated participation, which he treats as a continuous loss for as long as it lasts (at pp. 757–758). The United States reaches the same result by policy. It denies revolving-door protection to a civilian engaged in a pattern of participation, while sparing the one-off who has permanently ceased (at § 5.8.4.2). The alternative, it reasons, would give the part-time fighter better protection than a lawful combatant (at p. 244). Schmitt states the test most directly: a participant stays a lawful target until he unambiguously opts out, whether by an affirmative act of withdrawal or by extended non-participation, and he may be “attacked between episodes of participation” (at p. 38).
Where the burden belongs
In my view, the burden of ending participation belongs on the person who began it. A civilian who has taken a direct part in hostilities does not recover his protection by pausing. He recovers it by disengaging. The gap between those two is decisive for the recurring hacker.
The reason is an ex ante one. When a commander has to decide, he cannot know whether he faces a single episode or the first of a series. A rule that restores protection in every lull forces him to wait for the next operation before he may act. The attacker is then exposed only in the instant of each strike and safe the rest of the time. That is not a workable allocation of risk, and it is not one the text compels.
A pattern test alone does not close the gap. The occasional attacker who strikes, waits, and strikes again may never form the steady pattern that Boothby’s and the U.S. tests look for, yet he is plainly no bystander. The opt-out approach reaches him where a pattern test does not, because sporadic participation without any genuine disengagement leaves his protection forfeit. This is why I do not accept the ICRC’s carve-out for occasional participation. It rewards the freelancer who keeps the next strike in reserve.
None of this turns a single act into a life sentence, and the honest objection deserves a direct answer. Critics read “for such time as” to mean protection must return once the act is over, and they warn that shifting the burden risks exposing a civilian indefinitely for one past deed. The answer is that disengagement, and not the mere passage of time, is what restores protection, and disengagement lies within the participant’s own power. A genuine and unambiguous withdrawal ends his liability. What the law should not grant is an immunity bought by simple inactivity between operations.
In operational terms, this line is easier to draw in cyber than on the ground. Withdrawal by a hacker is a concrete, observable act: taking down the tool, dismantling the botnet, closing the access he opened. Where he has instead left a live capability in place, a logic bomb or a standing implant primed to fire, he has not withdrawn at all. The threat he built is still running, and his exposure runs with it. It is the same logic by which the person who leaves a device armed remains in the fight until it is cleared. The hacker who has genuinely stopped and taken down what he deployed has opted out, and he is a civilian again.
One clarification heads off a common misreading. The disagreement is not about the first operation. During it, including his preparation for it and his withdrawal from it, the hacker is a lawful target on every one of these views. The disagreement is only about the interval that follows. The revolving door offers him a sanctuary in that interval; the opt-out approach withholds it, and I think it is right to do so. The civilian who participates again and again without ever joining an organized group is the hard case this section resolves. The civilian who crosses into membership of such a group raises a different question, and it is the subject of Section IV.
IV. The commander’s problem: IT armies and hacktivist collectives
The three foregoing questions decide who is protected and when that protection lapses. A commander facing a volunteer “IT army” faces one more: is the person on the other end a civilian to be assessed act by act, or a member of an armed force who may be targeted by status? This is the question on which the operational value of everything above depends, and the one most easily run together in practice.
Group or individual?
There are two distinct routes out of civilian protection, and they must not be merged. The first is the civilian’s act-by-act loss under Article 51(3) AP I, the subject of the preceding sections. The second is status: a person who belongs to the organized armed forces of a party loses protection not for the duration of an act, but for the duration of his membership. In an international armed conflict, an armed group under a command responsible to a party, and fighting on that party’s behalf, forms part of that party’s armed forces under Article 43 AP I, and its functional members are combatants, targetable by status (ICRC Guidance, Section I.2(a)–(c) at pp. 22–25; Section I.4 at p. 26; Recommendation II at p. 27 in connection with fn 43 at p. 30).
Membership on this footing is narrow. It turns on continuous combat function: a lasting integration into the group and a continuous function involving direct participation in hostilities. Recruiters, financiers, propagandists, and those in political or administrative roles are excluded, and remain civilians unless their own function crosses into hostile acts (ICRC Guidance, at pp. 33–34). The narrowness is deliberate. It is why the ICRC refuses to treat a civilian’s mere pattern of recurrent acts as continuous loss (at pp. 44–45), and that refusal is what sends the persistent lone hacker back to Section III.
Ukraine’s IT Army shows why the distinction matters. It was stood up on 26 February 2022, two days into the invasion, when Ukraine’s Minister of Digital Transformation publicly called for volunteers and pointed them to a Telegram channel (Soesanto, at p. 6). Its following grew large: public reporting has put the number of participants at around 300,000, taken from the official channel’s subscriber count, though Soesanto cautions that the true figure is unknown (at p. 7). He describes the operation as two things at once: a loosely organized public side that pushes targets and tools to a volunteer crowd, and a small in-house team that he assesses likely draws on Ukrainian defence and intelligence personnel (at p. 4). That duality is the analysis.
A group forms part of a State’s armed forces only if it both belongs to that State and is organized under responsible command. The public state initiation, a government minister’s open call since publicly acknowledged, is enough to establish the first: the collective fights on Ukraine’s behalf with the State’s acceptance (Rodenhäuser, at p. 1291; ICRC Guidance, at p. 23). The second is where the volunteer crowd falls short. Rodenhäuser puts the point directly for cyber: a group that organizes and coordinates its acts only online, through open channels in which anyone can take part, is unlikely to have the collective character and responsible command that armed-force membership requires, so its participants are not members (Rodenhäuser, at pp. 1289–1290). They are civilians, assessed act by act, which returns them to Section III, where the persistent participant among them finds no safe haven and the genuine one-off keeps his protection. The in-house team is a different matter: to the extent it is composed of State personnel or functionally folded into Ukraine’s forces, its members are targetable by status.
One consequence follows for the hacker who is a member of a party’s armed forces, and it is worth stating plainly. He is a lawful target by status, but that does not make him a privileged combatant. Combatant privilege and prisoner-of-war status depend on four conditions: responsible command, a fixed distinctive sign, carrying arms openly, and operating under the laws of war (Article 4(A)(2) of the Third Geneva Convention; ICRC Guidance, at p. 22). The anonymous remote volunteer in a hoodie satisfies neither the distinctive sign nor, on most readings, the open carrying of arms, and there is no settled view on how these conditions translate to cyber at all (Rodenhäuser, at pp. 1291–1292). So he is continuously targetable as a member of a party’s armed forces. If captured, however, he enjoys no combatant immunity and may be prosecuted for his operations, though he remains entitled to the protections of the Fourth Geneva Convention or, at the least, Article 75 AP I. On the prosecution point the captured civilian hacker stands in the same place (ICRC “8 rules“).
Two boundary cases sit outside the question of enemy armed forces, and the Guidance is careful to keep them apart. A collective that operates within an international armed conflict but belongs to no party is not part of any party’s armed forces, and its members are therefore civilians for the purposes of that conflict (ICRC Guidance, at p. 23). If its own violence reaches the intensity of an armed conflict, it may constitute a separate non-international armed conflict, and whether its participants are then civilians or members is assessed under the rules governing that kind of conflict, by the continuous-combat-function test set out above (at p. 24). Organized violence that never reaches that intensity at all is different again: it is a matter for law enforcement, whether the actors are viewed as rioters, criminals or terrorists (at p. 24).
Running the determination
In operational terms, the four questions run in sequence. Is the person a civilian? In genuine doubt about status, Section I’s rule holds and he is treated as one. Does the act cross the three-element threshold? Section II supplies the test, and the state practice shows it is already applied to cyber conduct. For how long is he exposed? Section III governs: until he disengages, not merely until he pauses. Is he an individual or a member of an armed force? Only the last question turns on status, and for the volunteer crowd of an IT army the answer is almost always the former.
One kind of doubt remains, and here I part company with the ICRC. Where it is genuinely unclear whether a civilian’s act crosses into direct participation in hostilities, the ICRC would presume against it (ICRC Guidance, Recommendation VIII, at pp. 74–76). In my view that is the wrong default for a person already shown to be acting. The sounder approach is Schmitt’s: a civilian who has placed himself close enough to the hostilities to raise the question should carry the consequence of the doubt, rather than the commander (Schmitt, Deconstructing, at pp. 736–738). This is a question about conduct, and it leaves untouched the protective rule on status doubt that Section I settled.
Conclusion
Nothing in the cyber domain required a new legal category. That is the claim this post has been working towards, and each of the four questions bears it out. The civilian hacker is a civilian, defined negatively like any other. His acts are measured against the same three cumulative elements. His exposure lasts as long as his participation lasts and no longer. If he has joined the armed forces of a party, the ordinary law of membership applies to him as it would to any other member. What cyber changes is the difficulty of finding the facts, not the content of the rules applied to them.
Article 51(3) AP I is also where military necessity and civilian protection are reconciled, and it does that work through conduct. A civilian who stays out of the fighting keeps his protection completely, however strongly he feels about the war. A civilian who joins the fighting forfeits it for as long as he is in. The bargain is demanding on both sides, and it is a good one. It gives the commander a lawful answer to the recurring attacker, and it gives everyone else a protection that cannot be eroded by suspicion, proximity or sympathy.
On the temporal question I have taken a position that not every reader will share. Protection returns when the participant disengages, not when he merely pauses. In my view the burden of ending participation belongs to the person who chose to begin it, and a rule that restores protection in every interval between operations would leave a commander waiting for the next attack before he could lawfully act The genuine one-off who stops, and stops for good — leaving nothing of his behind still running — is a civilian again. The recurring participant who keeps his next operation in reserve remains exposed, and so does the one who has walked away in person but left a live capability in place: he has not stopped in the sense the rule requires.
That position raises a question I have left open here. Disengagement in the cyber domain usually means taking down what you deployed. But a civilian who releases a capability designed to propagate and act on its own may have nothing left to take down. He has no targeting staff behind him, no validated list, and no way to recall what he set in motion. Whether the loss of recall is also the loss of any way to opt out, and what his exposure looks like if it is not, is the subject of my next post.