by
Lika Chimchiuri
CyJurII Theorist
PDF Available
Abstract
This paper is dedicated to the evolution of the international crime of genocide and its adaptation to the modern digital space. In the context of technological progress, the acts prescribed by the Rome Statute transcend traditional, physical (kinetic) boundaries and shift into the cybernetic dimension. Based on the principles of functional equivalence and technological neutrality, the study analyzes how digital manipulations, code, mass data harvesting, or social media algorithms can be equated to traditional weapons. The paper provides an in-depth examination of legal challenges such as the subjective element (Mens Rea), the identification of the place of the commission of the crime (Locus Delicti) in cyberspace, and the determination of state responsibility against the backdrop of the conflict between the "effective" and "overall" control tests.
KEYWORDS: ICC, Cyber Genocide, Mens rea, Actus Reus, Locus Delicti.
Introduction
The evolution of genocide the gravest crime against humanity and its adaptation to digital reality represent one of the most paramount challenges of our time. In the wake of technological progress, the methods of committing crimes transcend material boundaries; social media algorithms (as seen in the Myanmar case), mass data harvesting, and digital surveillance emerge as functional equivalents to traditional weapons, creating a severe legal vacuum.
The aim of this paper is to analyze the legal aspects of genocide in the digital age and to substantiate a functional approach where the nature of a weapon is evaluated based on its consequential effect. To achieve this aim, the study focuses on the following objectives: Equating digital manipulations with traditional weapons through the principle of functional equivalence; Analyzing the specificities of proving specific genocidal intent (Dolus Specialis) within a digital context; Identifying the place of the commission of the crime (Locus Delicti) in cyberspace against the backdrop of the territoriality principle.
This paper is grounded in comparative-legal and dogmatic methods. The comparative approach evaluates the compatibility of the Rome Statute's provisions with cyber-reality. Meanwhile, the dogmatic method ensures an in-depth analysis of the jurisprudence of international tribunals (such as the cases of Rwanda, Yugoslavia, Myanmar, and the Düsseldorf jurisprudence), normative acts, and legal doctrine.
This study examines algorithmic "echo chambers," coded software, and tech giants (Big Tech) not merely as auxiliary tools, but as modern weapons of mass destruction. The conclusions of the research will provide a significant theoretical and practical contribution to the development of international criminal law and digital humanitarian law.
1. The Cyber Dimension in International Criminal Law
The norms governing international crimes under the Rome Statute (Office of the Prosecutor 2025) are technologically neutral. Based on the principle of functional equivalence a legal approach where the consequence of an act, rather than its form or technology, is decisive; meaning that if a cyberattack causes the exact same result as a physical weapon (e.g., human casualties or the destruction of a building), these actions are legally equivalent these norms apply fully to conduct committed within cyberspace, despite the absence of physical violence at the immediate moment of execution.
The term "cyber" does not denote the Internet alone. It encompasses any information and communications technology (ICT), including digital networks and devices (computers, servers, smartphones), artificial intelligence (AI) algorithms capable of being utilized to plan crimes, and offline systems. Crucially, a technology does not need to be connected to the Internet to fall within the "cyber" category, as demonstrated by closed military networks or localized databases.
The policy document on "cyber-enabled" crimes under the Rome Statute elucidates precisely how technology facilitates a crime, distinguishing between direct commission, preparation, and facilitation. Direct commission entails the manipulation or shutting down of a computer system (e.g., disconnecting power to a hospital). Preparation and facilitation involve data harvesting to identify victims, determine their location, or monitor them (Tracking). This is particularly relevant in cases of genocide and persecution (Office of the Prosecutor 2025).
Within contemporary international criminal law doctrine, fundamental importance is attached to distinguishing the forms of criminal commission, expressed via the dichotomy the division of a phenomenon into two strictly separated categories; in this context, the legal separation between traditional (kinetic) and cyber means between kinetic and cybernetic means.
This separation is based not on the consequence of the crime, which may be identical in both instances, but on the methodology through which the attack is carried out.
Specifically, kinetic (physical) means committing a crime using traditional, material weapons (such as firearms, bombs, or physical violence), where harm is caused by the physical impact of material objects. Conversely, cybernetic means involve committing a crime through immaterial instruments: code, algorithms, malicious software, or digital manipulations. In the latter case, the attack is directed against information systems and networks, though its ultimate effect may transcend the virtual space and cause physical destruction or casualties equivalent to those of a kinetic weapon (Melzer 2011, 23–26).
This dichotomy underscores a core challenge facing international law: the legal qualification of acts that lack a physical dimension at the moment of commission but trigger the grave consequences prescribed by the Rome Statute. In this context, scholarly literature increasingly turns to the principle of functional equivalence, which equates a cyber-intervention with a kinetic attack provided their consequential gravity is identical.
Thus, modern international legal doctrine establishes a functional approach; a methodological principle that prioritizes the substance, function, and consequence of an act over its technical form or method of execution wherein the material nature of a weapon (physical or digital) is superseded by its consequential effect. Technology is viewed here as a new dimension of the "Use of Force." This allows the jurisdiction of the Rome Statute to extend to actions committed in the digital space that fundamentally violate human rights. While the concept of the
"use of force" is traditionally interpreted within the framework of Article 2(4) of the UN Charter (United Nations 1945), contemporary doctrine, including the Tallinn Manual 2.0 (Schmitt 2017), recognizes that a cyber-operation can be qualified as a use of force if its effects are comparable to those of a kinetic attack, including the paralysis of infrastructure or the loss of life.
The policy document on cyber-enabled crimes under the Rome Statute further emphasizes that these offenses do not constitute a new legal category but rather a factual term, meaning that core crimes under the Statute (such as genocide or war crimes) simply assume a new form (Office of the Prosecutor 2025, paras. 12–14).
Regarding commission (Commission), a crime is committed via cyber means if the objective element (Actus Reus) is directly executed digitally, such as disabling a hospital's management system, which subsequently causes fatalities (Office of the Prosecutor 2024). To analyze this topic, we can utilize a methodological analogy; a method of cognition involving the logical extension of familiar legal institutions to a new, technologically distinct reality, provided their essence and legal nature are identical drawn from domestic criminal practice by examining the case of the attack on the Düsseldorf University Clinic (2020).
This case is considered precedential because it marks the first instance where law enforcement initiated a homicide investigation (specifically, "negligent homicide") triggered by a cyberattack. In September 2020, hackers exploited a software vulnerability on the clinic's servers and encrypted data using ransomware (Ransomware), completely paralyzing the clinic's systems. Consequently, an ambulance could not admit a patient in critical condition, forcing a redirection to another city (Wuppertal) 30 kilometers away. Due to the delayed medical intervention, the patient passed away.
If this exact conduct were replicated during an armed conflict, it would satisfy the qualification of a war crime under Article 8 of the Rome Statute (International Criminal Court 2021). This is a "commission" of a crime via cyber means because the digital act (the system shutdown) directly caused the death of a civilian.
Regarding the subjective element (Mens Rea), the Düsseldorf case centered on "negligent homicide." Article 30 of the Rome Statute assigns a paramount role to the subjective element, specifically requiring intent and knowledge (Intent and Knowledge). In this context, it is critical to distinguish these forms of culpability from negligence. Unlike domestic legal systems, the international criminal standard recognizes only conscious action as a basis for liability and explicitly excludes consequences caused by negligence from the Court's jurisdiction.
Intent (Intent / Dolus) under the Statute is twofold and depends on the direction of the individual's will, separating conduct from consequences:
● In Relation to Conduct: A person has intent when they mean to engage in the specific conduct. In a cyber-context, this means the person desires to launch malicious code.
● In Relation to Consequence: A person has intent when they mean to cause that consequence or are aware that it will occur in the ordinary course of events. In international law, this is known as Dolus Directus (direct intent). Here, the individual does not merely foresee a danger but actively seeks its realization (Werle and Jessberger 2020, 215–218).
Knowledge (Knowledge) is the intellectual element denoting an individual's awareness that a circumstance exists or a consequence will occur. This means being aware of the factual circumstances that render the conduct a crime (e.g., the perpetrator knows that their target server belongs to a civilian hospital rather than a military objective). Under Article 30, knowledge means the person is practically certain that the consequence will occur if the processes continue naturally. Within the jurisdiction of the International Criminal Court (ICC), forms of culpability are strictly partitioned, separating negligence from intent.
Under negligence (Negligence), a person fails to perceive a danger, although as a reasonable person they should have known of it and been able to avoid it. As a general rule, the Rome Statute does not punish such instances, except under Article 28 regarding command responsibility (Rome Statute 2021, Art. 28, Art. 30(1); Prosecutor v. Bemba 2016, para. 170).
Conversely, intent (Article 30) requires a positive mental attitude where the person both knows and desires the outcome. While many domestic jurisdictions recognize Dolus Eventualis (indirect intent) or "recklessness," where a person foresees a consequence but remains indifferent to it, the formulation of Article 30 of the Rome Statute requiring that the consequence occur "in the ordinary course of events" sets a high standard of culpability. It demands proof that the consequence was not merely a theoretical danger (a risk) to the individual, but a practically inevitable and logical result of their conduct. Consequently, liability arises only when the person fully appreciates that their behavior will naturally produce the criminal result (Prosecutor v.
Lubanga 2012, paras. 1007–1012).
Thus, the subjective standard of Article 30 of the Rome Statute rests upon a combination of cognitive (knowledge) and volitional (will) elements (Ambos 2014, 280–285). Unlike domestic systems where liability may stem from objective negligence, international law demands full awareness of the "essential characteristics" of the crime by the individual. This approach ensures that only those whose conduct constituted a conscious evil, rather than a technical error or inadvertence, stand before the Court.
In the prosecution of cyber-enhanced crimes, one of the primary obstacles is the attribution gap (The Attribution Gap). Within the Rome Statute, attribution is directly linked to Article 25 (Individual Criminal Responsibility) and Article 28 (Responsibility of Commanders and Other Superiors). However, the problem of attribution is most acute under Article 8 bis (The Crime of Aggression), which requires establishing that an individual was in a position effectively to exercise control over or to direct the political or military action of a State. In a cyber-context, the Prosecutor must prove that the conduct of a non-state actor (e.g., a hacking collective) is attributable to a state. Here, the Court relies on customary international law norms governing State Responsibility.
While the perpetrators in the Düsseldorf clinic case were identified as members of a criminal syndicate, the primary difficulty under the Rome Statute is linking a criminal act to a state. Due to the anonymity of cyberspace, it is remarkably difficult to prove that a specific individual operated under the "Effective Control" of a state, which is an indispensable prerequisite for assigning international responsibility. This standard has been developed through international jurisprudence, notably in Nicaragua v. United States, which formulated the "effective control" test, and was later refined in Bosnia and Herzegovina v. Serbia and Montenegro, making the determination of state responsibility in cyberspace particularly complex.
Specifically, the International Court of Justice (ICJ) relies on Article 8 of the Articles on State Responsibility (ASR) (International Law Commission 2001, Art. 8), under which the conduct of a private person or group is attributable to a state if they act on the instructions of, or under the direction or control of, that state. In Nicaragua v. United States (1986), the Court clarified that financial or logistical support alone does not suffice for attribution; it must be proven that "Effective Control" was exercised, implying detailed state management over each specific operation (Nicaragua v. United States 1986, 14, para. 115).
This approach was further tightened in Bosnia and Herzegovina v. Serbia and Montenegro (2007), where the Court emphasized that state responsibility for an act of genocide would arise only if the perpetrating group acted as a de facto organ of the state or under conditions of complete dependence (Bosnia and Herzegovina v. Serbia 2007, 43, paras. 391–393). In cyberspace, this standard creates a vacuum. Because states frequently utilize "patriotic hackers" or proxy groups providing them only with general strategic direction rather than tactical commands proving "effective control" becomes nearly impossible. Consequently, even when the geographical source of an attack is technically verified, linking it legally to the will of a state fails, leaving cyber-aggression beyond the reach of justice.
Furthermore, the definition of an "Attack" remains a subject of intense academic discourse.
Under the traditional definition in International Humanitarian Law (IHL), an attack implies an "act of violence." A segment of jurists contends that a cyber-operation causing only data deletion or systemic disruption without physical destruction does not qualify as an "attack."
However, the functional approach advanced in this study offers an alternative vision: if the consequence of a cyber-act is catastrophic from a humanitarian perspective (e.g., the paralysis of vital infrastructure), it must be equated with a traditional attack. The International Committee of the Red Cross holds an important position on this matter (ICRC 2019); while traditionally linking attacks to physical violence, modern interpretations increasingly recognize that a loss of functionality a term describing a condition where an object loses its operational capability as a result of a cyber-operation; under the Tallinn Manual 2.0, this qualifies as "damage" if restoring the system requires substantial resources, rendering it legally identical to physical damage such as shutting down a hospital's systems, can be equated with an attack if its humanitarian consequences are severe.
To qualify such an act as a war crime, it will be necessary to prove that the attacker knew that striking the hospital would cause fatalities and executed it regardless. Furthermore, the qualification of a war crime requires the existence of a "Nexus," meaning a direct link between the conduct and an armed conflict, which distinguishes it from ordinary cybercrime.
The principle of technological neutrality the principle according to which the law focuses on the essence and consequence of an act rather than the instrument utilized, allowing the norms of the Rome Statute to apply to cyber-enhanced crimes without requiring additional legislative amendments rests on the premise that legal evaluation focuses on the result rather than the method. In other words, the decisive factor in a legal assessment is not the technical manipulation used to damage an object, but the humanitarian consequence it produced.
Regarding facilitation (Facilitation) (Cassidy 2022, 645–669), cyberspace is frequently utilized to organize crimes, issue commands, or incite others (e.g., propagating hate speech for genocidal purposes). Here too, we can apply a methodological analogy by examining the case of Myanmar vs. Facebook (The Rohingya Genocide, 2017) (UN Human Rights Council 2018). This case is viewed in international legal discourse as a 21st-century genocide enabled by social media. The Myanmar military junta and radical groups weaponized the Facebook platform against Rohingya Muslims through several distinct actions:
● The dissemination of disinformation and fake news, claiming that the Rohingya were planning attacks.
● The amplification of hate speech (Incitement), including direct calls for violence and ethnic cleansing.
● The utilization of the platform by military units for tactical coordination and victim intimidation.
The Independent Investigative Mechanism for Myanmar (IIMM) (IIMM 2023, paras. 42–45) determined that Facebook’s algorithms facilitated the creation of an environment necessary for genocide. Under Article 25(3)(c) of the Rome Statute, this conduct is classified as "aiding and abetting" (Aiding and Abetting) (Rome Statute 2021, Art. 25(3)(c); Prosecutor v. Taylor 2013, paras. 360–365) because a digital tool was used to substantially facilitate the commission of a crime. Digital platforms in modern genocides fulfill the exact same role that the "Radio
Télévision Libre des Mille Collines" (RTLM) performed in Rwanda in 1994 (Prosecutor v.
Nahimana et al. 2007, paras. 450–465), highlighting a technological evolution rather than a shift in the essence of the crime.
The role of victim identification and tracking (Tracking/Harvesting) in international crimes warrants particular attention. Large-scale data harvesting frequently constitutes the "preparatory phase" of genocide, which is a punishable act under Article 25 of the Rome Statute (Office of the Prosecutor 2025, 19). This topic will be explored extensively in the subsequent chapters.
1.1. The Principle of Territoriality and Locus Delicti
The investigation and prosecution of cyber-enhanced crimes are conducted within a strictly defined normative framework established by Article 21 of the Rome Statute (Applicable Law) (Rome Statute 2021, Art. 21(1)(a)). According to the 2025 Policy Document of the Office of the Prosecutor, the Statute itself, the Elements of Crimes (International Criminal Court 2010), and the Rules of Procedure and Evidence (International Criminal Court 2013) apply in the first instance.
At the second hierarchical level, the Court applies applicable treaties and the principles and rules of international law, including the law of armed conflict (LOAC), and, where necessary, general principles of law derived by the Court from national legal systems of the world.
Furthermore, Article 21(3) of the Statute (Rome Statute 2021, Art. 21(3); Prosecutor v. Lubanga 2006, paras. 36–39) imperatively requires that the interpretation of norms must be consistent with internationally recognized human rights (without any adverse distinction). In prosecuting crimes within cyberspace, this particularly concerns the right to life, physical and mental health, freedom of expression, personal life, and privacy.
International criminal jurisdiction fundamentally relies on the concept of state sovereignty and physical borders. Article 12(2)(a) of the Rome Statute, which defines the preconditions for the exercise of the International Criminal Court's jurisdiction, establishes the territoriality principle (Rome Statute 2021, Art. 12(2)(a)). Pursuant to this norm, the Court has jurisdiction if the crime was committed on the territory of a State Party. However, the global and virtual nature of cyberspace challenges this classical normative framework, as digital acts do not recognize geographical borders.
In interpreting Article 12(2)(a) of the Rome Statute, the Office of the Prosecutor (OTP) relies on universal state practice and affirms that territorial jurisdiction equally covers both subjective territoriality (where the digital action initiated) and objective territoriality (where the action concluded). Applied mutatis mutandis (which, in the context of the Rome Statute, entails extending jurisdiction to vessels and aircraft just as on land, with necessary technical modifications), this principle also extends to maritime vessels or aircraft registered in a State Party (Flag Jurisdiction).
The primary legal challenge rests on identifying the place of the commission of the crime (Locus Delicti). Legal doctrine offers three main approaches to defining Locus Delicti during cyber-operations:
1. Subjective Territoriality (Place of Conduct): Focuses on the physical, geographical point where the perpetrator was physically located at the moment of carrying out the act (e.g., a hacker’s desk or the headquarters of a military cyber-unit) (Rome Statute 2021, Art. 12(2)(a)).
2. Objective Territoriality (Place of Effect): Recognizes the territory where the criminal consequence materialized as the basis for jurisdiction (e.g., the state where a hospital's management system was shut down and patients died) (Rome Statute 2021, Art. 12(2)(a)).
3. Technological/Infrastructural Approach: Places emphasis on the physical location of the servers, routers, or digital infrastructure utilized to transit the attack or host the malicious code (Office of the Prosecutor 2025, paras. 22–24).
For the purposes of the Rome Statute, the principle of functional equivalence requires a broad interpretation of objective territoriality. If a cyberattack launched from the territory of a non-State Party causes consequences prescribed by Article 6 (Genocide) or Article 8 (War Crimes) of the Statute on the territory of a State Party, the locus where the effect occurred must be deemed the place of the commission of the crime.
This approach fully aligns with the ICC’s established jurisprudence, specifically the ruling in the Myanmar/Bangladesh case (Situation in Bangladesh/Myanmar 2019, paras. 61–62). In that case, the Court determined that although the initial acts of forced displacement (deportation) occurred in Myanmar (a non-State Party to the Rome Statute), an essential element of the crime the crossing of the border and its consequence concluded in Bangladesh (a State Party), which was sufficient to establish jurisdiction. Consequently, Locus Delicti in cyberspace must not be restricted solely to the point where code is launched.
Beyond individual criminal responsibility, when cyber-operations are carried out by so-called "patriotic hackers," proxy groups, or private contractors, establishing a link between the conduct and a state (attribution) is of paramount importance.
In the case of Nicaragua v. United States (1986), the International Court of Justice (ICJ) clarified that the actions of non-state actors could only be attributed to the United States if it were proven that the state exercised effective control over the planning and commission of each specific operation. This strict standard was further consolidated in the Bosnian Genocide case (Bosnia and Herzegovina v. Serbia 2007, 43, paras. 391–394), where the Court determined that the Srebrenica genocide could not be attributed to the state of Serbia, as there was no evidence that Belgrade directly managed and gave orders to the "Scorpions" paramilitary group at the specific moment the killings were committed.
In cyberspace, the "effective control" standard creates a vacuum. States frequently grant strategic autonomy to hacking collectives (such as Advanced Persistent Threats APTs), providing them with general political directives rather than tactical commands. Consequently, finding a direct, material trace of a state's specific intent and order behind a particular digital attack is legally nearly impossible.
To fill this vacuum, international criminal law doctrine turns to the definition of "overall control" formulated by the Appeals Chamber of the International Criminal Tribunal for the former Yugoslavia (ICTY) in the case of Prosecutor v. Duško Tadić (1999). In the Tadić case, the Appeals Chamber ruled that to attribute the acts of organized military or paramilitary groups to a state, it is sufficient to prove that the state financed, equipped, or assisted the group and participated in the general strategic coordination of its actions, even without issuing specific orders.
The two standards contrast as follows:
● Effective Control (ICJ Standard): Requires detailed management and the issuance of instructions for each specific operation. Proving this in a cyber-context is virtually impossible since states utilize anonymous, remote instructions and methods (Nicaragua v. United States 1986, 14, para. 115).
● Overall Control (ICTY Standard): Requires general financial, logistical support, or strategic coordination of the group. This is significantly more effective in a cyber-context because it focuses on who finances, provides infrastructure for, or directs the hacking collective (Prosecutor v. Tadić 1999, paras. 131–137, 145).
Within the context of the Rome Statute particularly when evaluating the crime of aggression under Article 8 bis or command and superior responsibility regulated by Article 28 the "overall control" approach serves as a more flexible and realistic legal instrument. It enables the Prosecutor to rely on facts such as financial transactions (e.g., cryptocurrency flows) and the utilization of state infrastructure (IP addresses, dedicated servers) to prove that "patriotic hackers" were realistically operating under a state's strategic umbrella (Rome Statute 2021, Art. 8 bis, Art. 28).
When interpreting Article 12(2)(a) of the Rome Statute in instances where a crime is committed in cyberspace (for example, when a blogger who is a citizen of a non-State Party, Russia, incites genocide from Moscow via a website hosted on a Russian server, targeting the territory of a State Party), a normative vacuum re-emerges (Rome Statute 2021, Art. 12(2)(a)). Because cyberspace is immaterial, doctrine has developed three alternative approaches to territorializing the "conduct in question" (a term utilized in the jurisdictional provisions of the Rome Statute that denotes the factual conduct action or omission constituting the material basis of the crime) (Situation in Kenya 2010, para. 39):
1. Access-Based Jurisdiction: This approach is based on the premise that communication in cyberspace is a chain consisting of several links (the content provider, the host server, the user's server, and the user themselves). The existence of any of these links within the territory of a State Party is sufficient to establish jurisdiction. A classic example of this approach is found in national judicial practice, specifically the famous Yahoo! Auction case in France (2000). The French court determined that it possessed jurisdiction over a US-based company for placing Nazi memorabilia on an online auction because this content was accessible and visible (displayed) to users located within French territory. In the context of the Rome Statute, the mere accessibility of material within the territory of a State Party is deemed the Locus Delicti (UEJF et Licra v. Yahoo! 2000).
2. The Effects Doctrine (Consequential Jurisdiction): Requires an interpretation of criminal norms where territoriality is recognized as the space where the real legal and physical effects of the action materialized, regardless of where the perpetrator was located. If information disseminated from a server located in a non-State Party causes severe consequences on the territory of a State Party, the latter is considered the state of territoriality.
3. The Technological Innovation Approach: Views actions carried out in cyberspace as a completely new, modernized method of committing a crime (UEJF et Licra v. Yahoo! 2000). A digital action followed by physical destruction is directly qualified as a material act for instance, an act of genocide under Article 6(a) of the Statute (Rome Statute 2021, Art. 6(a)).
As reinforced by the Kampala Declaration (International Criminal Court 2010) and the Preamble to the ICC Statute (Rome Statute 2021, Preamble, paras. 4–5), the primary mission of the Court is to put an end to impunity. Consequently, in the interests of justice, the guiding principle must be: "what is a crime in the physical space must also be a crime in the online space" (UN Human Rights Council 2016). If the Court fails to territorialize cyberspace using these approaches, it will lead to a collapse of justice.
A particular complexity within the jurisdiction of cyber-enhanced crimes involves the issue of accessorial conduct (complicity and facilitation). The 2025 Policy Document establishes a precedential vision: the Court will have jurisdiction even when a person facilitates the commission of a crime on the territory of a State Party (whether through kinetic or cyber means), regardless of whether the accomplice themselves operates physically within the territory of that State Party (Office of the Prosecutor 2025, 24). This approach effectively dismantles the possibility of impunity for digitally operating, remote accomplices.
1.3. The New Strategy of the ICC Office of the Prosecutor and the 2025
The International Criminal Court's response to digital threats has transitioned from theoretical discourse to the stage of practical enforcement. This turning point is directly linked to the new strategic vision of the ICC Chief Prosecutor, Karim Khan. As early as 2024, the Prosecutor clearly stated that cyberspace is no longer viewed as a realm beyond the reach of justice, and that the Court will actively exercise its jurisdiction over digital crimes (Office of the Prosecutor 2025). The legal culmination of this strategy is the policy document published in December 2025 concerning "cyber-enhanced" crimes under the Rome Statute (Policy on cyber-enabled crimes under the Rome Statute) (Khan 2024).
The fundamental postulate of the document is that the core crimes provided for under the Rome Statute (genocide, crimes against humanity, war crimes, and the crime of aggression) do not constitute new legal categories when committed digitally. Technology is merely a new, more malevolent tool to execute old, classical crimes.
The policy document officially defines two main avenues where cyber-operations directly trigger criminal responsibility:
1. Cyber-acts as War Crimes: The document emphasizes that attacks carried out against critical civilian infrastructure (e.g., power lines, water supplies, or digital hospital networks) that result in a mass humanitarian catastrophe qualify as war crimes.
2. Digital Tools as Means to Facilitate Genocide and Persecution: The document devotes particular attention to large-scale data harvesting, algorithmic surveillance, and the dissemination of hate speech via social media as instruments for the preparation and organization of genocide.
The real-world testing of this policy is currently underway within the framework of the ongoing armed conflict in Ukraine. The ICC Office of the Prosecutor, in coordination with partner organizations such as the CyberPeace Institute (Office of the Prosecutor 2025) and the Prosecutor General’s Office of Ukraine is investigating the actions of hacking collectives linked to Russian military intelligence (GRU Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation, whose specialized cyber-units, such as Unit 74455 / Sandworm, have been officially indicted by US and European justice systems for attacks on critical infrastructure) (CyberPeace Institute 2023).
Specifically, the case concerns malicious attacks carried out against the Ukrainian energy grid (utilizing the BlackEnergy and Industroyer malware), which caused mass heating and power outages for the civilian population during the winter period. The ICC Office of the Prosecutor evaluates these acts not as mere cyber-espionage or sabotage, but as a violation of Article 8 of the Rome Statute namely, intentional attacks directed against civilian objects causing severe, unjustified, and disproportionate suffering. This precedent conclusively establishes the principle of functional equivalence in international criminal law practice.
In international criminal law, technological progress triggers a reinterpretation of Actus Reus (the objective element) and Mens Rea (the subjective element) the fundamental elements of traditional criminal law dogmatics. Adapting the provisions of the Rome Statute to cyberspace requires an analysis of how an immaterial instrument (code) can cause material harm, and how the mental state of the perpetrator is measured during a digital attack (Office of the Prosecutor 2025, 31–33).
The objective element (Actus Reus) of crimes prescribed by the Rome Statute (specifically, war crimes and genocide) traditionally requires physical violence or the destruction of material objects. However, in the cyber-dimension, malicious software (malware) operating on digital networks acts as a weapon, yet its consequences in the physical world are of decisive importance.
A classic, precedential example of this is the Stuxnet case (2010) (Office of the Prosecutor 2025, paras. 34–36). This was the first known cyber-operation in history to cause physical destruction through digital code. The malicious program infiltrated Iran's Natanz nuclear facility and manipulated Supervisory Control and Data Acquisition (SCADA) industrial control systems. The code altered the rotation speed of uranium enrichment centrifuges, leading to their mechanical failure and physical destruction, while operators' monitors displayed false, normal parameters.
Under International Humanitarian Law (IHL) and the Rome Statute, operations of the Stuxnet type confirm that code constitutes a functional weapon. If a similar attack is directed, for instance, against the control system of a hydroelectric dam, a nuclear power plant, or a hospital's power supply system, the full elements of Actus Reus are met. This is because the result physical destruction or mass human casualties is identical to the effect of a kinetic bombardment.
The issue of so-called "Loss of Functionality" is particularly topical in academic discourse. The question arises: does an action qualify as Actus Reus if the cyber-operation does not result in a physical explosion or destruction, but renders the system useless? According to Rule 92 of the Tallinn Manual 2.0 (Schmitt 2017, 415–420), a cyber-operation constitutes an "attack" if it causes damage to or the loss of functionality of an object. If, as a result of cyber-interference, a civilian infrastructure (e.g., a financial system, telecommunications, or a power grid) cannot be restored without reinstalling software or replacing physical components, this is considered material damage. For the purposes of the Rome Statute, if such a loss of functionality is intended, for example, to deliberately inflict on a specific group conditions of life calculated to bring about its physical destruction (Article 6(c) of the Statute), it fully satisfies the objective element of the crime.
As previously mentioned, Article 30 of the Rome Statute establishes a high standard of culpability for the jurisdiction of the International Criminal Court, requiring intent and knowledge. The Statute explicitly excludes negligence or mere inadvertence. Proving the perpetrator's mental state in a cyber-context requires specific technical analysis.
Let us consider a hypothetical, yet realistic, legal case: a hacker infiltrates a military base network but "accidentally" (due to an incorrect IP address or a technical error) erases and paralyzes the water supply system of an adjacent civilian town. Does "knowledge" as required by Article 30 exist in this instance?
In international criminal law, direct intent (Dolus Directus) and knowledge are proven not by the subject's subsequent testimony, but by a combination of objective, including technical, circumstances. During a cyber-operation, this form of culpability is confirmed by two main factors:
1. Targeting/Reconnaissance: Any large-scale cyberattack is preceded by network scanning and reconnaissance. If the perpetrator used specific tools that identified the target servers, it is legally impossible for them to deny "knowledge" that the target was a civilian, rather than a military, object.
2. Pre-testing and Architecture of Code: Cyber-weapons are typically created for a specific target. If the code contains commands directed exclusively against civilian infrastructure (e.g., SCADA water filtration systems), this confirms that the subject possessed positive knowledge of the expected result.
Per the wording of Article 30 of the Statute, a person is aware that a result will occur "in the ordinary course of events." When a highly qualified military or state actor releases destructive malware (for example, a virus like NotPetya (Rome Statute 2021, Art. 30; Prosecutor v. Bemba 2010, paras. 165–169), which spreads uncontrollably), they know precisely that this action will lead to the collapse of critical systems. Consequently, technical calculations, the specificity of the code, and prior reconnaissance data invalidate the argument of "accidentality" and legally establish Dolus Directus.
In the process of modern genocides and persecution, physical violence is always preceded by a preparatory phase, which has now shifted into the digital space. Large-scale data harvesting, compiling digital lists of protected group members, geolocational tracking, and algorithmic segmentation constitute the material preparation for committing international crimes.
These actions must be directly linked to Articles 25(3)(c) and 25(3)(d) of the Rome Statute, which regulate aiding, abetting, or otherwise assisting in the commission of a crime. Specifically, under Article 25(3)(c) (Aiding and Abetting) (Rome Statute 2021, Art. 25(3)(c)), liability is imposed on a person who, for the purpose of facilitating the commission of such a crime, aids, abets or otherwise assists in its commission, including providing the means for its commission. Meanwhile, Article 25(3)(d) (Rome Statute 2021, Art. 25(3)(d)) provides for liability for contributing to the commission or attempted commission of a crime by a group of persons acting with a common purpose (Contribution).
To illustrate this theoretical framework, the case of digital persecution carried out against
Uyghur Muslims in China (Xinjiang Data Harvesting) is of utmost importance (Human Rights Watch 2019). The Chinese authorities created the Integrated Joint Operations Platform (IJOP), a mass surveillance system that utilized artificial intelligence and data harvesting to collect
Uyghurs' biometric data, banking records, movement trajectories, and social network activities. Based on these digital algorithms, individuals were segmented and subsequently subjected to mass detention in so-called "re-education camps" (UN Human Rights Council 2022, paras. 42–55).
Under international criminal law standards, tech companies or engineers who deliberately design and supply such software to authoritarian regimes knowing that this data will be used for the destruction or persecution of a specific ethnic or religious group aid and abet the commission of crimes (Rome Statute 2021, Art. 25). The creation of digital lists serves as the necessary logistical base for genocide. It is functionally equivalent to the material lists compiled on paper by Nazi Germany or the extremist regime in Rwanda; however, digital segmentation leads to far more devastating consequences in terms of scale and precision.
Thus, the analysis of material and subjective elements demonstrates that the text of the Rome Statute is sufficiently flexible to cover cyber-means. As shown by the Stuxnet example, malicious code is recognized as a weapon of physical destruction (Delerue 2020, 272–276), forms of culpability (Article 30) are effectively proven through the analysis of technical premeditation, and large-scale data harvesting constitutes a dangerous new form of aiding and abetting (Article 25) in the digital era (Office of the Prosecutor 2025, para. 58).
Despite the specificities of cyberspace and the digital nature of evidence, the Court maintains that the standard of proof for technological crimes remains unchanged. In accordance with Article 66(3) of the Rome Statute, the guilt of the accused must be proven beyond a reasonable doubt (Rome Statute 2021, Art. 66(3); Prosecutor v. Katanga 2014, paras. 65–68).
The paramount legal characteristic of the crime of genocide, which distinguishes it from other international crimes (such as crimes against humanity), is the specific genocidal intent, Dolus Specialis. According to Article 6 of the Rome Statute, this is the highest standard of the subjective element, requiring proof that the perpetrator was motivated by the desire to destroy, in whole or in part, a national, ethnical, racial, or religious group, as such (Rome Statute 2021, Art. 6). The jurisprudence of the International Criminal Tribunals for the former Yugoslavia (ICTY) and Rwanda (ICTR) has established that, in the absence of a direct written or verbal admission, Dolus Specialis can be established on the basis of a specific inference drawn from the factual circumstances (e.g., Prosecutor v. Goran Jelisić, 1999) (Prosecutor v. Jelisić 2001, paras.
45–48).
Article 25(3)(e) of the Rome Statute explicitly considers direct and public incitement to commit genocide as an inchoate crime. This means that for criminal liability to arise, it is not necessary for the incitement to actually be followed by a factual attempt or the commission of genocide. The crime is deemed completed from the moment the harmful and subhuman material is placed in the public space (Rome Statute 2021, Art. 25(3)(e); Prosecutor v. Akayesu 1998, paras. 561–562).
The specific nature of the digital space allows subjects to carry out incitement remotely, bypassing physical borders. The travaux préparatoires (preparatory works) of the Rome Statute and international doctrine confirm (United Nations 1998) that since incitement is by its nature an inchoate offense, the mere uploading and availability of hate speech and appeals on a digital network within the territory where the protected group is located constitutes the material fact of committing the crime.
While the essential element of genocide intent (dolus specialis) is directed toward the physical or biological destruction of a protected group, this does not mean that the means used to bring about this destruction must necessarily be physical or material. All five forms provided for under Article 6 of the Statute (killing, causing serious bodily or mental harm, deliberately inflicting conditions of life calculated to bring about physical destruction, etc.) can also be executed digitally, for instance, through cyberattacks with harmful consequences on essential civilian services (water, heating, medical facilities). From a legal standpoint, there is no distinction between death caused by a bullet and death caused by a cyber-operation, provided that a causal link is established (Office of the Prosecutor 2025, paras. 41–43). The Myanmar precedent clearly demonstrated that social media posts are not virtual abstractions; they possess the capacity to mobilize people and inflict the gravest physical harm.
In the digital era, the identification and proof of genocidal intent move into a new phase, which entails retrieving evidence from virtual and algorithmic spaces:
Closed Military Networks and Encrypted Communication Platforms: Encrypted platforms (e.g., Signal, Telegram) and internal departmental chats become an essential evidentiary base. While traditionally, genocidal plans were written on paper (such as the minutes of the Wannsee Conference during the Holocaust (Holocaust Encyclopedia 2020)), under modern conditions, orders and coordination for the destruction of a group leave a digital footprint. The subhuman vocabulary used in these communications, the sharing of target group location coordinates, and the digital monitoring of "cleansing" operations point directly to the existence of Dolus Specialis.
Algorithmic Optimization and Manipulation: This occurs when state actors or subjects controlled by them optimize or manipulate social media platforms through specialized bots, troll factories, and fake accounts to deliberately cultivate hatred against a specific ethnic or religious minority. Such deliberate "training" of algorithms and facilitation of ideological radicalization demonstrate that the attack is not accidental, but is underpinned by a conscious strategy to destroy the group.
3.2. Material Forms of Cyber-Genocide and the Interpretation of Article
Genocide does not strictly denote killing by physical means (for example, shooting with firearms). Article 6(c) of the Rome Statute of the International Criminal Court criminalizes the deliberate infliction on a group of conditions of life calculated to bring about its physical destruction in whole or in part (Rome Statute 2021, Art. 6(c)).
The jurisprudence of international courts such as the International Criminal Tribunal for Rwanda in its 1998 Akayesu judgment (Prosecutor v. Akayesu 1998, paras. 505–508) has interpreted the "infliction of conditions of life" as the intentional deprivation or exhaustion of a group. This encompasses depriving them of food, medical care, shelter, and hygiene products, or subjecting them to forced deportation.
In the contemporary world, the principle of technological neutrality applies (Schmitt 2017, 4). Under this principle, the law does not concern itself with the specific nature of the weapon used to commit a crime whether traditional or digital as the primary focus rests on the resulting effect. Consequently, this article fully adapts to cyberattacks. While in the past, a military blockade and artillery were required to exhaust a population, today the same effect can be achieved through computer code and algorithms.
The primary forms of cyber-genocide involve the paralysis of vital digital infrastructure. An example of this occurs when a region populated by a specific ethnic or religious minority is left without electricity and heating during severe winter frosts through a cyberattack (by shutting down SCADA industrial control systems).
Another form is the collapse of healthcare and supply systems. This entails blocking the computer systems of hospitals, medical equipment, or food and water supply reserves using malicious software (Office of the Prosecutor 2025, 22–24).
When these digital attacks are deliberately targeted against a specific group to create conditions incompatible with human life, the resulting humanitarian catastrophe is functionally equivalent to a traditional military siege. Consequently, the objective element of the crime (Actus Reus) is established, fitting directly within the international legal definition of genocide.
Article 25(3)(e) of the Rome Statute establishes individual criminal responsibility for anyone who "directly and publicly incites others to commit genocide." In international law, this is categorized as an inchoate crime (an incomplete or anticipatory offense). This means that an individual can be punished solely for the act of incitement, regardless of whether their appeals actually result in a subsequent or completed genocide (Rome Statute 2021, Art. 25(3)(e)).
Two core criteria must be fulfilled to establish this offense:
1. "Publicity," which requires that the appeal be accessible to a mass audience;
2. "Directness," which dictates that the appeal must be a clear, unambiguous call to violence, perceived as such by the target group.
A watershed moment in international legal history was the 2003 judgment by the
International Criminal Tribunal for Rwanda (ICTR) in the Media Case. The Tribunal ruled that the notorious radio station RTLM had transformed into a weapon of genocide. It disseminated subhuman propaganda (referring to the Tutsi victims as "cockroaches") and broadcasted their live, real-time coordinates to reveal where they were hiding (Prosecutor v. Nahimana et al. 2003, paras. 945–953).
In the 21st century, during the genocide of Rohingya Muslims in Myanmar, the social media platform Facebook assumed the exact same role as the radio did in 1994, albeit on a far more massive and rapid scale. The Myanmar military junta and extremists weaponized the platform to dehumanize the Rohingya, spread fake news, and organize ethnic cleansing. A UN Fact-Finding
Mission explicitly noted in 2018 that social media played a determining role in fueling hatred (UN Human Rights Council 2018, paras. 74–76).
Incitement in the online space reaches millions of individuals significantly faster than traditional media. The International Criminal Court has made a revolutionary caveat regarding this environment:
"While the Court is not a day-to-day content moderator for internet service providers, this does not exempt specific natural persons (including the executives of Big Tech companies) from criminal liability if they possessed knowledge of what was occurring on their platforms. However, to initiate a case, the Court will always rely on the criterion of 'sufficient gravity' (Office of the Prosecutor 2025, paras. 17–19) to exclude minor instances that did not result in catastrophic consequences on an international scale."
Although the ultimate objective remains identical, modern digital platforms are far more dangerous weapons than the radio of the 1990s. Radio broadcasts a uniform signal to everyone, leaving the listener as a passive consumer. Conversely, social media algorithms are engineered to maximize user engagement and screen-time via likes and comments. Neuropsychologically, human engagement is most effectively sustained by anger, fear, and outrage. Consequently, the algorithm proactively amplifies and popularizes radical and hateful content because it is more "viral" (Vosoughi, Roy, and Aral 2018, 1146–1151).
Furthermore, unlike radio where the existence of opposing views cannot be entirely concealed algorithms trap individuals inside information bubbles ("echo chambers"). Users encounter only content that reinforces their radical beliefs. This leads to rapid societal polarization and the dissolution of moral barriers, which serves as a prerequisite for the outbreak of mass violence.
Faced with this reality, international legal discourse increasingly focuses on the liability of Big Tech CEOs and algorithmic software engineers under Article 25(3)(c) of the Rome Statute, which governs Aiding and Abetting (Prosecutor v. Karadžić 2016, paras. 577–582). Under international standards (such as the Radovan Karadžić case in 2016), this requires two components:
● The Objective Element (Actus Reus): The individual’s action (or inaction) must have a substantial effect on the commission of the crime.
● The Subjective Element (Mens Rea): The individual must have knowledge
(Knowledge) that their action or inaction facilitates the crime.
If platform leadership or lead engineers receive precise information from international organizations or internal audits confirming that their algorithm is being weaponized for genocide (as occurred in Myanmar, where Facebook was warned for years) and they fail to act due to fear of losing financial profit, their inaction (Omission) can be legally classified as aiding and abetting. A deliberate refusal to alter code, implement content moderation, or temporarily suspend a platform while knowing that such a refusal invites imminent danger fully satisfies the international legal standard of "knowledge." This provides a solid framework for the Court to hold specific individuals criminally responsible.
4. Conclusion
The comprehensive legal analysis conducted in this study demonstrates that international criminal law faces fundamental transformations in the 21st century. While the development of the Internet has unified the world into a single space, it has simultaneously generated a new threat: the adaptation of the gravest international crimes (genocide, crimes against humanity, war crimes, and aggression) to the virtual domain and their commission through digital means.
The latest strategy of the International Criminal Court confirms that the law is technologically neutral the specific weapon is irrelevant; the primary focus is the resulting effect. Russian cyberattacks launched against a Düsseldorf clinic (2020) and the Ukrainian power grid have proven in practice that system shutdowns caused by digital code or malware (Ransomware/Wipers) are identical in their humanitarian consequences to traditional military bombardments. Consequently, when a digital act causes mass casualties or paralyzes critical infrastructure, it fully constitutes a war crime or genocide (Actus Reus).
The Internet lacks physical borders, which has challenged the traditional principle of territorial boundaries. The approaches examined in this paper (such as arguments advanced by researchers at the Jindal Global Law School) offer pathways to fill this vacuum:
● Accessibility-Based Jurisdiction and the "Effects Doctrine": If the destructive effect or criminal appeal of a malicious code launched from a non-State Party to the
Rome Statute materializes and manifests within the territory of a State Party, the International Court has full authority to extend its jurisdiction over the case (as demonstrated by the French judiciary as early as 2000 in the Yahoo! case).
● The "Overall Control" Test: Because it is difficult to prove which state stands behind a specific hacker in cyberspace, the outdated and rigid standard of "effective control" should be replaced by the "overall control" test. This will facilitate the attribution of a crime to a specific state that manages proxy groups and "patriotic hackers."
The Rome Statute requires the highest standard of culpability: direct intent and knowledge (Dolus Criminalis/Dolus Directus). In a cyber-context, this is proven not by the perpetrator's admission, but by objective technical circumstances: prior digital reconnaissance, precise targeting, and the specific architecture of the malicious code itself. The exact technical calculations embedded within the code invalidate the argument of "accidentality" and prove that the subject knew precisely what catastrophe their action would cause.
Contemporary genocidal intent (Dolus Specialis) has transcended physical boundaries. Large-scale data harvesting and digital surveillance (as occurred against the Uyghurs in the Xinjiang region of China) represent, in reality, a covert preparatory phase of genocide.
The transformation of incitement to commit genocide is particularly alarming. The tragedy of the Rohingya Muslims in Myanmar demonstrated that social media algorithms which artificially construct bubbles of radicalization ("echo chambers") are far more dangerous weapons than the Rwandan radio of 1994. This establishes a new legal reality: Tech giants (Big Tech CEOs) and engineers who blind themselves to the weaponization of their platforms for genocidal purposes for the sake of financial profit can be held personally liable for aiding and abetting (Aiding and Abetting).
The supreme objective of international justice is to ensure that no grave crime goes unpunished. Technological progress must not create a haven of legal anonymity for dictators and criminals; international law must adapt to digital reality.
The fundamental axiom "what is a crime in the physical space must also be considered a crime online" must become the core principle of modern justice, ensuring that cyberspace does not transform into an unchecked testing ground for global crimes.
1. Independent Investigative Mechanism for Myanmar (IIMM). (2023). Annual Report of the Independent Investigative Mechanism for Myanmar, A/HRC/54/19.
2. International Criminal Court. (2010). Kampala Declarations on the Crime of
Aggression, RC/Decl.1.
https://www.icc-cpi.int/news/review-conference-rome-statute-opened-kampala
3. International Criminal Court. (2011). Elements of Crimes. ISBN No.
92-9227-232-2. https://www.icc-cpi.int/publication/elements-crimes
4. International Criminal Court. (2013). Rules of Procedure and Evidence. https://www.icc-cpi.int/publications/core-legal-texts/rules-procedure-and-evidence
5. International Criminal Court. (2021). Rome Statute of the International Criminal Court. https://www.icc-cpi.int/sites/default/files/2024-05/Rome-Statute-eng.pdf
6. International Law Commission. (2001). Draft Articles on Responsibility of States for Internationally Wrongful Acts, with commentaries. United Nations.
https://legal.un.org/ilc/texts/instruments/english/commentaries/9_6_2001.pdf
7. Office of the Prosecutor of the International Criminal Court. (2024). Policy on cyber-enabled crimes under the Rome Statute. International Criminal Court. https://www.icc-cpi.int/sites/default/files/2025-12/2025-cyber-eng.pdf
8. Office of the Prosecutor of the International Criminal Court. (2025, December). Policy on cyber-enabled crimes under the Rome Statute. International Criminal Court.
https://www.icc-cpi.int/sites/default/files/2025-12/2025-cyber-eng.pdf
9. U.N. Charter. https://www.un.org/en/about-us/un-charter/full-text
10.UN Human Rights Council. (2016). The promotion, protection and enjoyment of
human rights on the Internet, A/HRC/RES/32/13.
https://ap.ohchr.org/documents/dpage_e.aspx?si=a/hrc/res/32/13
11.UN Human Rights Council. (2018). Report of the Independent International
Fact-Finding Mission on Myanmar, A/HRC/39/64. OHCHR.
https://www.ohchr.org/sites/default/files/Documents/HRBodies/HRCouncil/FFM-Myanm ar/A_HRC_39_64.pdf
12.UN Human Rights Council. (2022). OHCHR Assessment of human rights concerns in the Xinjiang Uyghur Autonomous Region, People's Republic of China.
United Nations.
13.United Nations. (1998). Official Records of the United Nations Diplomatic Conference of Plenipotentiaries on the Establishment of an International Criminal Court (Vol. III). United Nations. https://legal.un.org/icc/rome/proceedings/e/rome%20proceedings_v3_e.pdf
14.International Court of Justice (ICJ), Military and Paramilitary Activities in and against Nicaragua (Nicaragua v. United States of America), Merits, Judgment, I.C.J.
Reports 1986, p. 14. https://www.icj-cij.org/case/70
15.International Court of Justice (ICJ), Application of the Convention on the Prevention and Punishment of the Crime of Genocide (Bosnia and Herzegovina v. Serbia and Montenegro), Judgment, I.C.J. Reports 2007, p. 43. https://www.icj-cij.org/case/91
16.International Criminal Court (ICC), Prosecutor v. Charles Taylor, SCSL-03-01-A,
Appeals Chamber Judgment, 26 September 2013.
chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://www.rscsl.org/Documents
/Decisions/Taylor/Appeal/1389/SCSL-03-01-A-1389.pdf
17.International Criminal Court (ICC), Prosecutor v. Germain Katanga, ICC-01/04-01/07, Judgment pursuant to Article 74 of the Statute, 7 March 2014. https://www.icc-cpi.int/court-record/icc-01/04-01/07-3436-teng
18.International Criminal Court (ICC), Prosecutor v. Jean-Pierre Bemba Gombo,
ICC-01/05-01/08, Judgment on the merits, 21 March 2016.
chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://www.icc-cpi.int/sites/defa ult/files/CourtRecords/CR2016_02238.PDF
19.International Criminal Court (ICC), Prosecutor v. Thomas Lubanga Dyilo, ICC-01/04-01/06, Judgment pursuant to Article 74 of the Statute, 14 March 2012. https://www.icc-cpi.int/court-record/icc-01/04-01/06-2842
20.International Criminal Court (ICC), Situation in the People's Republic of
Bangladesh/Republic of the Union of Myanmar, ICC-01/19, Decision on the Prosecution's Request for Authorization of an Investigation Pursuant to Article 15, 14 November 2019. https://www.icc-cpi.int/court-record/icc-01/19-27
21.International Criminal Court (ICC), Situation in the Republic of Kenya, ICC-01/09, Decision Pursuant to Article 15 of the Rome Statute on the Authorization of an Investigation, 31 March 2010.
chrome-extension://efaidnbmnnnibpcajpcglclefindmkaj/https://www.icc-cpi.int/sites/defa ult/files/CourtRecords/CR2011_16025.PDF
22.International Criminal Tribunal for Rwanda (ICTR), Prosecutor v. Ferdinand Nahimana, Jean-Bosco Barayagwiza and Jean-Camille Ngezahayo (Media Case), ICTR-99-52-A, Appeals Chamber Judgment, 28 November 2007. https://unictr.irmct.org/en/cases/ictr-99-52
23.International Criminal Tribunal for Rwanda (ICTR), Prosecutor v. Jean-Paul
Akayesu, ICTR-96-4-T, Judgment, 2 September 1998.
https://www.globalhealthrights.org/wp-content/uploads/2013/10/Akayesu-ICTR-1998-Ju dgment.pdf
24.International Criminal Tribunal for the former Yugoslavia (ICTY), Prosecutor v.
Duško Tadić, Appeals Chamber, IT-94-1-A, Judgment, 15 July 1999. https://www.icty.org/case/tadic
25.International Criminal Tribunal for the former Yugoslavia (ICTY), Prosecutor v. Goran Jelisić, Appeals Chamber, IT-95-10-A, Judgment, 5 July 2001.
https://www.icty.org/x/cases/jelisic/acjug/en/jel-aj010705.pdf
26.International Criminal Tribunal for the former Yugoslavia (ICTY), Prosecutor v. Radovan Karadžić, IT-95-5/18-T, Public Redacted Version of Judgement, 24 March 2016. https://cld.irmct.org/assets/filings/2019.03.20-Karadzic-Appeal-Judgement.pdf
27.Tribunal de Grande Instance de Paris, UEJF et Licra v. Yahoo! Inc. and Yahoo
France, Decision of 22 May 2000 and 20 November 2000. https://www.jstor.org/stable/24120111
28.Ambos, K. (2014). Treatise on International Criminal Law: Volume I:
Foundations and General Part. Oxford University Press.
https://global.oup.com/academic/product/treatise-on-international-criminal-law-9780192
29.Cassidy, R. (2022). Cyber-Facilitated Genocide and the ICC: Extending Liability under Article 25(3)(c) of the Rome Statute. Journal of International Criminal Justice,
20(3), 645–669. https://doi.org/10.1093/jicj/mqac022
30.Delerue, F. (2020). Cyber Operations and International Law. Cambridge
University Press.
https://assets.cambridge.org/97811084/90276/frontmatter/9781108490276_frontmatter.pd f
31.Farwell, J. P., & Rohozinski, R. (2011). Stuxnet and the Future of Cyber War.
Survival, 53(1), 23-40.
https://www.tandfonline.com/doi/full/10.1080/00396338.2011.555586?needAccess=true
32.Melzer, N. (2011). Cyberwarfare and International Law. United Nations Institute
for Disarmament Research (UNIDIR).
https://unidir.org/publication/cyberwarfare-and-international-law
33.Schmitt, M. N. (Ed.). (2017). Tallinn Manual 2.0 on the international law applicable to cyber operations (2nd ed.). Cambridge University Press. https://doi.org/10.1017/9781316822524
34.Vosoughi, S., Roy, D., & Aral, S. (2018). The spread of true and false news online. Science, 359(6380), 1146-1151. https://doi.org/10.1126/science.aap9559
35.Werle, G., & Jessberger, F. (2020). Principles of International Criminal Law (4th
ed.). Oxford University Press.
https://global.oup.com/academic/product/principles-of-international-criminal-law-978019
36.CyberPeace Institute. (2023). Cyber Attacks in Times of Conflict: Analysis of
Cyber Operations in the Ukraine War. Geneva. https://cyberconflicts.protect.ngo/report/2023-q1
37.Holocaust Encyclopedia. (2020). The Wannsee Conference and the "Final
Solution". United States Holocaust Memorial Museum.
https://encyclopedia.ushmm.org/content/en/article/the-wannsee-conference-and-the-finalsolution
38.Human Rights Watch. (2018). China's Algorithms of Repression: Reverse
Engineering a Xinjiang Mass Surveillance App.
https://www.hrw.org/report/2019/05/01/chinas-algorithms-repression/reverse-engineering
39.International Committee of the Red Cross (ICRC). (2019). International Humanitarian Law and the Challenges of Contemporary Armed Conflicts. https://www.icrc.org/en/document/icrc-report-ihl-and-challenges-contemporary-armed-co nflicts
40.Khan, K. A. A. (2024). Keynote Address on the Digital Frontier of International Criminal Justice. CyberSpace and International Law Conference, Hague. https://www.icc-cpi.int/news/statement-icc-prosecutor-karim-aa-khan-kc-conference-addr essing-cyber-enabled-crimes-through
41.NLIU Centre for Research in International Law (CRIL). (2025). Inciting Genocide over Cyberspace: Invoking Territorial Jurisdiction of the ICC.