The report is the result of a collaborative effort within the Joint Initiative on the Digitalization of Armed Conflict, led by the International Committee of the Red Cross (ICRC) and the Geneva Academy of International Humanitarian Law and Human Rights. Its methodology combines rigorous legal analysis, case studies drawn from contemporary conflicts, and comparative insights from academics, government experts, and practitioners. At its core, the study seeks to understand how IHL applies to civilian digital activities—whether carried out by individuals, organized hacker groups, or private technology companies. The authors aim to identify emerging risks for civilians, clarify the responsibilities of states and non-state actors, and determine when civilian involvement in cyber operations might lead to a loss of protection from attack. Beyond this, the initiative strives to strengthen a shared understanding of how existing IHL rules function in today’s ICT environment, highlight potential legal gaps, and pinpoint areas where further dialogue and policy development are urgently needed.
What happens when anyone with a smartphone can influence a battlefield? When a teenager with a laptop can disrupt a military network? When private companies become part of a war’s digital infrastructure? The report begins by confronting these urgent questions, showing how digitalization has pulled civilians into armed conflicts in unprecedented and often invisible ways. As societies grow more dependent on interconnected technologies, everyday digital actions—sending data, using an app, sharing a location—can suddenly acquire military relevance. Governments have mobilized civilians through reporting apps; hacktivist groups have launched disruptive campaigns across borders; and tech companies have offered services that directly sustain the digital backbone of warring parties. The result is a dangerous erosion of the line between civilian and combatant, increasing the risk of misidentification, wrongful targeting, and widespread digital spillover effects.
A central part of the report explores how IHL responds to this shifting reality. Any cyber operation linked to armed conflict must still respect core principles: distinction, proportionality, and precautions. Yet civilians who operate in this digital space may lose protection from attack if their actions amount to direct participation in hostilities. Determining this is far from simple. When a civilian films troop movements with a smartphone, does that act meaningfully support an attack? And in a world where the same device is used for both personal safety and conflict-related reporting, how can a soldier in the field know the difference? The report stresses that IHL requires doubts to be resolved in favor of civilian status—meaning that a phone, an app, or a digital trace cannot, on their own, justify targeting a person.
The analysis then turns to hacker groups, whose roles have expanded rapidly. These groups range from disciplined, state-supported units to decentralized online collectives that emerge and dissolve with little structure. Under certain conditions, some could even qualify as organized armed groups and thus be bound by IHL. But most remain civilians, exposed to the dangers of conflict and at risk of losing protection only for the duration of their direct involvement. The report also raises the question of state responsibility: when do a hacker group’s actions become attributable to a government? When does “encouragement” turn into direction, control, or accountability?
Finally, the report examines the growing influence of private technology companies. By hosting data, securing networks, providing cloud services, or detecting vulnerabilities, they often operate at the crossroads of civilian life and military necessity. Their employees and infrastructure are protected under IHL, but that protection may be lost if their work directly supports military operations or if their assets become military objectives because of their use. The report urges companies to recognize the risks inherent in operating during conflict—both to their staff and their millions of civilian users—and underlines states’ responsibility to ensure these actors understand and respect IHL when their services intersect with warfare.
In conclusion, the report delivers a clear warning: as warfare moves into the digital domain, civilians face unprecedented risks. Simple online actions—using an app or sharing information—can suddenly have real battlefield consequences. To reduce these dangers, states should avoid involving civilians in cyber operations and ensure they fully understand the legal and personal implications when their engagement is unavoidable. Individuals, hacker groups, and technology companies also share responsibility for respecting IHL and recognising that digital behaviour can cause tangible harm.
States must likewise prevent and prosecute cyber-related IHL violations, helping close the accountability gaps created by digital conflict. Protecting civilians in the digital age requires sustained research, dialogue, and the development of clearer norms to keep IHL effective in an increasingly interconnected and contested battlespace. Looking ahead, the issue will stay high on the international agenda, with discussions continuing in the ICT Workstream of the Global Initiative to Galvanize Political Commitment to IHL into 2026.
To know more, please visit:




