Rethinking ‘Espionage’ in the Digital Space: When should it become a Use of Force?
I. Introduction
In September 2024, the FBI and the CISA notified the world of a sophisticated cyber espionage campaign aimed at critical U.S. infrastructure – Salt Typhoon. Chinese state-sponsored actors had made their way into networks like telecommunications, government, transportation, wiretapping networks and military infrastructure. In December 2025, Venezuela’s state oil company reported a ransomware attack, disrupting oil cargo deliveries. In the same month, French Ministers confirmed a data breach compromising e-mail servers, allowing hackers to access sensitive police files. These incidents show a growing global trend of such attacks. Salt Typhoon is not a one-and-done cyber-attack. It is a lasting occupation of digital space and an ongoing challenge to digital sovereignty, still active as of February 2026.
Espionage, in accordance with Rule 66 of the Tallinn Manual 2.0, is not prohibited under international law. Critics argue that it may constitute unfriendly activity, but is not a breach of international law, since it does not satisfy the ‘physical harm’ threshold laid down in the Nicaragua Case. Rule 66 explains that since there is no explicit prohibition on espionage in international law, it may not attract liability of breach. This represents a grey area wherein narrow definitions of espionage jeopardize the ability of states to litigate or sanction such acts.
The present contribution argues that incidents like Salt Typhoon exceed the definition of cyber espionage and qualify for ‘unlawful use of force’ under Article 2(4) of the UN Charter. It examines existing standards like the Scale-and-effects and the Caroline Test, which lays down a threshold for pre-emptive action for self-defense; to assess the application of use of force in cyberwarfare. It proposes reform based on duration, capability and establishment of an inter-governmental body to address presented gaps.
II. Beyond The Paradigm of Espionage – Why Should Unlawful Use of Force Apply?
Digital sovereignty refers to a nation’s ability to retain meaningful control over its digital assets, technologies and operations. Rule 1.3 of the Tallinn Manual states that a state enjoys “control over cyber infrastructure and activities within its territory”, while affirming that the existing law shall apply to the question of digital sovereignty.
Various modalities have been identified under the Manual to assess violations of digital sovereignty, i.e., (i) physical damage or injury by remote means; (ii) loss of functionality; (iii) interference with services necessary for governmental functions; (iv) usurpation of governmental functions.
Incidents like Salt Typhoon satisfy these criteria. Firstly, interference with services necessary for governmental functions, for instance, wiretapping systems, exists. Secondly, usurpation due to interference in critical infrastructure is evident. Thirdly, owing to this usurpation, loss of functionality can be orchestrated by the aggressors owing to embedded access, which may, lastly, lead to damage by remote means, which cannot be predicted. In other words, embedded access converts passive intrusion into a latent kill switch, making the timing and scale of remote damage inherently unknowable.
Invasion of digital space cannot be presumed to have begun when discovered. Possibilities of the intrusion occurring before such discovery cannot be negated, suggesting perpetual challenges to a state’s sovereignty without limitations.
An aggressor gaining permanent, embedded access to crucial systems, holds the ‘kill switch’ and force sufficient to establish a digital blockade, ready to be put in motion. Section 9, Part B of the Tallinn Manual acknowledges that weakening an enemy’s power is a major aim in armed attacks. For instance, it has been argued that a DDoS (Distributed Denial-of-Service) attack, which is an act that attempts to disrupt a service by flooding it with internet traffic, may also qualify as an armed attack if it jeopardizes economic performance or critical infrastructure on a scale comparable to physical blockades. In such cases, both forms of attack become functionally equivalent to one another.
The ICJ in Nicaragua v. United States of America laid down the Scale-and-Effects test. This test is used to determine whether use of force constitutes an ‘armed attack’ triggering self-defense under Article 51. Moreover, Article 2(4) prohibits states from utilizing the use of force to threaten sovereignty, while Article 51 provides that the right to self-defense shall not be impaired in case of an armed attack.
The ICJ held that only those attacks that seriously injure or kill several persons, cause significant damage, or destroy property would constitute armed attacks. However, it fails to account for intangible, irreparable effects that may occur when persistent access to digital infrastructure is gained. An intrusion of cyberspace is more perpetual, as it allows aggressors to impair the enemy’s functioning whenever they wish.
Unlawful use of force must apply since persistent, embedded cyber intrusion grants an aggressor the continuous capability to cause harm equivalent to an armed attack at any moment, the unlawfulness of such force must attach not only at the moment of visible damage but from the point of irreversible digital occupation. Without legal reform to redefine thresholds, states may remain defenseless against adversaries.
III. Recommendations
Considering the dangers presented by the traditional definitions of espionage in contemporary cyberspace, the following measures are proposed:
III.I. The Case for Pre-emptive Action
The Caroline Test as reaffirmed in the Nuremberg judgment, lays down a threshold for pre-emptive self-defense. The test propounds that pre-emptive action can be allowed if ‘necessity of self-defence is instant, overwhelming, leaving no choice of means and no moment for deliberation’.
In Salt Typhoon, the threat is instant and overwhelming since the adversary has already gained persistent, embedded access to critical systems risking a loss of functionality. Secondly, no moment of deliberation remains for countries attacked, as the threat is imminent. The aggressor’s access to critical infrastructure creates the last window of opportunity. The unpredictability of the exact nature or time of an attack allows no choice of means, except to put in place pre-emptive measures.
The Caroline Test’s rigid threshold should be expanded to account for modern, persistent cyber intrusions where the “last window of opportunity” opens long before a kinetic attack.
III.II Redefining Thresholds for Unlawful Use of Force
The threshold of an activity transcending the meaning of espionage and becoming unlawful use of force can be subject to two parameters:
Duration
A cyber operation should become an unlawful use of force when the unauthorized access persists for more than 90 days after discovery; and secondly, the intruder possesses a functional capability because of such access to deny, degrade, or destroy essential services at will.
90 days is an appropriate timeframe since the EU’s NIS2 directive provides for a maximum timeline of 90 days. Additional time can be granted, provided that investigation is underway, and sufficient cause can be proven for delays.
Nature of Infrastructure Under Threat
A cyber operation embedding persistent access into critical public infrastructure can be treated distinctly from operations against private entities, since it concerns survival of the state. Public critical infrastructure includes but is not limited to military/defence networks; government administrative and communications systems; emergency services and overseas financial settlement systems.
When a cyber operation meets both the standards of duration and intrusion to critical infrastructure, it should give rise to a rebuttable presumption constituting an unlawful use of force without requiring proof of physical damage.
III.III Establishment of an Inter-Governmental Authority
Cybersecurity governance is fragmented across various institutions, each possessing specific limitations, preventing adequate resolution of the challenges of persistent cyber intrusions. The following analysis shall discuss such limitations.
Firstly, the United Nations Group of Governmental Experts is a non-permanent body that develops norms for responsible state behavior in the cyberspace. While it is a welcome effort, the UNGGE being a non-permanent body significantly limits its ability to engage by reviewing and investigating specific cyber activity as alleged. Since decisions are based on consensus, dissent can curb progress significantly.
Secondly, the International Telecommunication Union provides empirical data with regard to trends in cyberspace. However, it lacks mechanisms to investigate state-sponsored intrusions or attribute malicious activity.
Institutions like the UN Convention Against Cybercrimes and Interpol, all deal with criminal acts rather than state-orchestrated use of force. No single body is currently equipped to tackle the threat of persistency in incidents such as Salt Typhoon.
The establishment of an international authority could address these limitations. The functions to be performed by such authority can be to, firstly, regularly review and notify threats, and simultaneously investigate qualification of cyberactivity as ‘unlawful use of force’ when alleged; secondly, R&D of assistance including deployment of open-source intrusion detection systems and development of country-specific security strategies.
IV. Conclusion
By transcending from extraction of data to the occupation of critical infrastructure, campaigns like Salt Typhoon call for a move away from the conventional international thresholds of espionage. Establishing clear thresholds for duration and infrastructure, supported by an international authority, is important to ensure that in the digital age, sovereignty is a right guaranteed to all nations, not just the technologically elite. In a paradigm where such recommendations are accepted, states would no longer face a legal vacuum against persistent digital occupation, which would enable timely pre-emptive action and assistance before irreparable harm occurs.






Comments