Cyber Attacks Become the New Weapon of State Conflict

Cybersecurity explained through conflict: why it matters for India, the evidence, global stakes and risks to watch next for serious readers in a changing world.

Cyber Attacks Become the New Weapon of State Conflict
Image credit not supplied for this legacy article.
Text size

Cyber Attacks Become the New Weapon of State Conflict

The next war may not begin with a missile.

It may begin with a login.

A power grid may fail. A hospital database may be locked. A port may stop processing cargo. A telecom network may be silently compromised. A satellite link may be disrupted. A military email system may be breached. A fake video may spread before an election. A banking system may slow down just when panic begins.

No border is crossed. No war is declared. No soldier appears on television.

Yet the state is already under attack.

This is the new logic of conflict. Cyber attacks have become instruments of state power because they allow countries to spy, sabotage, coerce and destabilise without immediately triggering conventional war. They are cheaper than missiles, harder to attribute than tanks, faster than diplomacy and more deniable than invasion.

Cyber conflict is not science fiction anymore. It is now part of national security, foreign policy, economic competition and military strategy.

Microsoft’s 2025 Digital Defense Report says nation-state threat actors are using more advanced, targeted and scalable cyber and influence operations, including AI-enabled campaigns designed to shape narratives and manipulate public perception. The UK’s National Cyber Security Centre also warned in its 2025 annual review that state actors remain a significant threat to global cyber security and that incident teams faced a record number of nationally significant incidents.

Cyber attacks are no longer a technical nuisance. They are the new weapon of state conflict.

The Battlefield Has Moved Into Networks

Traditional war attacks territory. Cyber warfare attacks systems.

A country’s sovereignty today does not exist only on land, sea and air. It also exists in data centres, cloud systems, payment networks, telecom exchanges, railway control systems, power grids, military networks, identity databases, satellite communications, ports and hospitals.

That is why the modern state is vulnerable in a new way. It may defend its border with soldiers while leaving its digital nervous system exposed. It may have fighter jets, tanks and missiles, but if its electricity grid, banking network or military communication system is compromised, national security is already weakened.

Cyber attacks are powerful because modern societies run on digital trust. Citizens trust that money will move, hospitals will function, trains will run, electricity will flow, government records will remain intact and emergency services will respond. A cyber attack targets that trust directly.

The weapon is invisible, but the effect is physical.

Why States Prefer Cyber Weapons

Cyber weapons are attractive to states for five reasons.

First, they are deniable. A missile leaves a launch trail. A cyber attack can be routed through compromised servers, criminal groups, proxy networks and foreign infrastructure.

Second, they are scalable. A small team can attack thousands of systems across borders.

Third, they are relatively cheap. A cyber operation costs far less than a conventional military campaign.

Fourth, they can be used in peacetime. States can spy, pre-position malware, steal secrets and test defences without formally going to war.

Fifth, they create strategic ambiguity. The victim may know it has been attacked but struggle to prove who did it publicly.

This is why cyber attacks fit perfectly into grey-zone conflict. They allow states to act aggressively while remaining below the threshold of open war.

Critical Infrastructure Is the New Strategic Target

In earlier wars, armies attacked bridges, ports, factories and railways. In cyber conflict, the same logic continues through digital systems.

Power grids, telecom networks, pipelines, water systems, ports, banks and transport systems are now high-value targets. A cyber attack on these systems can create economic disruption, public panic and political pressure without a single bomb being dropped.

CISA and partner agencies warned in 2024 that China-linked Volt Typhoon actors had compromised IT environments across multiple U.S. critical infrastructure sectors, including communications, energy, transportation, and water and wastewater systems. In 2025, NSA and allied agencies also issued guidance on Chinese state-sponsored actors linked to global espionage activity, including reporting that overlaps with Salt Typhoon.

This is the future danger: malware placed today may be used tomorrow.

A cyber actor may enter a network not to attack immediately, but to wait. In a future crisis, that access could be activated to disrupt military logistics, civilian infrastructure or public communication. Cyber warfare is therefore not only about what happens during war. It is also about preparation before war.

Cyber Espionage Has Become Permanent

Not all cyber attacks are designed to destroy. Many are designed to steal.

States use cyber espionage to collect military secrets, diplomatic cables, industrial designs, research data, technology blueprints, negotiation positions, political intelligence and personal information on officials. This is espionage at industrial scale.

The difference from traditional spying is volume. A human spy may steal a file. A cyber operation can extract entire databases.

This changes diplomacy. A country entering a trade negotiation, security dialogue or military crisis may already have had its internal communications compromised. A defence company may lose intellectual property before a weapon is even built. A research institute may unknowingly transfer years of work to a foreign intelligence service.

Mandiant’s M-Trends 2026 report noted that the global median dwell time for detected intrusions rose to 14 days in 2025, and that cyber espionage and North Korean IT-worker incidents had a median dwell time of 122 days.

This means many attackers are not rushing. They enter, observe, persist and extract value quietly.

The most dangerous cyber attack may be the one no one notices.

AI Has Changed the Cyber Battlefield

Artificial intelligence has made cyber conflict faster, cheaper and more deceptive.

AI can help attackers write phishing emails, translate messages, imitate voices, create fake identities, generate malware variants, scan vulnerabilities and automate influence campaigns. It can also help defenders detect anomalies, analyse malware and respond faster. But the offensive use of AI is growing rapidly.

Microsoft’s 2025 report said nation-state actors had rapidly adopted AI to produce automated, large-scale influence campaigns and synthetic media. AP’s coverage of the report noted that Russia, China, Iran and North Korea were increasingly using AI to support cyberattacks and disinformation, including phishing, deepfake official clones and automated hacking techniques.

This is a major shift.

Earlier, a phishing campaign often had grammatical mistakes, awkward phrasing and obvious warning signs. Now AI can produce culturally fluent, personalised, credible messages. A fake government order, a cloned CEO voice or a synthetic video can create immediate confusion.

AI does not need to create perfect deception. It only needs to create enough doubt before verification arrives.

In cyber conflict, speed is power.

Cyber Attacks and Information Warfare Are Merging

Cyber attacks no longer stand alone. They are often combined with information warfare.

A state may hack a database, leak selected documents, distort their meaning, amplify them through fake accounts and then use the controversy to influence public opinion. The attack is not only the breach. The attack is the narrative built around the breach.

This is especially dangerous before elections, during wars, during communal tensions, or in moments of economic stress.

A cyber operation can steal information. An influence operation can weaponise it. AI can scale the manipulation. Social media can distribute it. Domestic political actors may amplify it knowingly or unknowingly.

That is why cyber security and information integrity can no longer be separated.

A democracy can survive disagreement. It cannot function if its information environment is constantly poisoned by foreign manipulation, synthetic media and hacked material.

Ransomware Shows the Criminal-State Connection

Ransomware is often treated as cybercrime. But in many cases, the line between cybercrime and state conflict is blurred.

Criminal groups may operate from countries that tolerate them. Some may serve state interests directly or indirectly. Others may attack critical infrastructure during geopolitical crises, creating pressure on rival states while maintaining plausible deniability for the sponsoring or sheltering government.

This creates a dangerous hybrid model. Criminals provide the operational capability. States provide safe haven, intelligence or strategic tolerance.

ENISA’s 2025 Threat Landscape reported that threat groups were reusing tools and techniques, introducing new attack models, exploiting vulnerabilities and collaborating in ways that target the resilience of Europe’s digital infrastructure. IBM’s 2025 Cost of a Data Breach report put the global average cost of a data breach at USD 4.4 million, showing that cyber incidents now carry direct economic consequences for organisations.

Cybercrime is therefore not just a policing issue. It can become a strategic vulnerability.

A ransomware attack on a hospital, port, bank or power company may be financially motivated. But the effect can still serve a hostile state’s interest by weakening trust and disrupting society.

Attribution Is the Central Problem

In conventional conflict, identifying the attacker is usually easier. In cyber conflict, attribution is difficult.

Attackers use proxy servers, stolen credentials, compromised devices, false flags, criminal intermediaries and shared malware tools. They may operate from one country, use infrastructure in another, and target a third. Evidence may exist but remain classified.

This creates a dilemma for the victim state.

If it responds too quickly, it may act on incomplete evidence. If it waits too long, the attacker gains confidence. If it shares too little evidence, allies may hesitate. If it reveals too much, intelligence sources may be exposed.

Cyber conflict is therefore a war of proof as much as a war of code.

Deniability is not about convincing everyone of innocence. It is about creating enough uncertainty to delay response.

Cyber Deterrence Is Harder Than Nuclear Deterrence

Nuclear deterrence works partly because attacks are visible, attribution is clearer and consequences are catastrophic.

Cyber deterrence is more complicated.

Attacks may be small, frequent and ambiguous. Some are espionage, some are sabotage, some are crime, some are influence operations and some are preparation for future conflict. The threshold for retaliation is unclear.

What level of cyber attack justifies sanctions?What level justifies counter-cyber operations?What level justifies military response?What if a cyber attack causes civilian deaths indirectly?What if the attacker is a proxy group?

These questions remain unresolved.

CISA’s “Shields Up” guidance reflects the need for organisations to prepare for heightened cyber risk and strengthen readiness before attacks occur. This is the practical reality: because deterrence is imperfect, resilience becomes essential.

A country must not only threaten retaliation. It must be able to absorb attacks, recover quickly and continue functioning.

International Law Is Still Catching Up

Cyber warfare has exposed gaps in international law.

The United Nations has recognised the need for norms of responsible state behaviour in cyberspace. The UN Open-Ended Working Group on security and ICTs concluded in July 2025 with a consensus report recommending a permanent global mechanism to continue negotiations on responsible state behaviour in cyberspace.

This is important, but norms are not enough.

States may agree in principle that critical infrastructure should not be attacked in peacetime, but enforcement remains weak. A country can deny responsibility. A cyber operation can be disguised as criminal activity. Legal standards for proportional response remain contested.

The world has rules for war at sea, air and land. It still lacks equally enforceable rules for war through networks.

Until that changes, cyber conflict will remain a domain where power often moves faster than law.

The Military Is Now Digitally Dependent

Modern militaries are digital systems.

They rely on satellite communications, GPS, encrypted networks, sensors, drones, logistics software, targeting systems, command-and-control platforms, surveillance data and cloud-based tools. This creates enormous capability, but also vulnerability.

A cyber attack can disrupt logistics, corrupt battlefield data, interfere with communications, expose troop locations or disable weapons-support systems. Even if it does not destroy a weapon physically, it can make that weapon less useful.

Cyber operations can also support kinetic warfare. Before a missile strike, an adversary may try to blind radar, disrupt communications or paralyse emergency response. During a conflict, cyber attacks can target both military and civilian systems to create confusion.

This means cyber warfare is no longer separate from conventional warfare. It is part of it.

Ukraine Has Shown the Cyber-Physical War Model

The Russia-Ukraine war demonstrated that cyber operations and conventional war can occur together.

Before and after the full-scale invasion, Ukraine faced cyberattacks on government, energy, communications and public systems. Cyber operations were used to disrupt, spy, influence and intimidate.

CSIS’s significant cyber incidents tracker noted that Russian cyberattacks on Ukraine surged in 2024, with thousands of incidents targeting critical infrastructure, government services, energy and defence-related entities.

The lesson is clear: cyber operations are now part of modern military campaigns.

A state preparing for war may not begin with troop movements. It may begin by mapping networks, compromising infrastructure and shaping narratives. The cyber battlefield opens before the physical battlefield.

India’s Digital Expansion Increases Its Exposure

India has a special vulnerability because its digital transformation is massive.

Digital payments, Aadhaar-linked services, online governance, telecom expansion, health platforms, education systems, banking networks, logistics platforms and smart infrastructure have increased state capacity. But they have also increased the attack surface.

CERT-In reported that it handled more than 29.44 lakh cyber incidents in 2025, issued 1,530 alerts, 390 vulnerability notes and 65 advisories, reflecting the scale of India’s cyber response challenge. CERT-In also launched the Cyber Bharat Setu programme to promote cybersecurity culture among states and union territories.

This is the central contradiction of Digital India.

The more India digitises, the more efficient it becomes. But the more it digitises, the more it must secure.

A paper-based state is slow but less exposed to cyber attack. A digital state is fast but vulnerable if security does not keep pace.

Cyber Attacks Can Become Economic Warfare

Cyber attacks can damage an economy without formal sanctions or military conflict.

A successful attack on banks can affect trust. An attack on stock exchanges can create panic. An attack on ports can delay trade. An attack on energy companies can raise costs. An attack on manufacturing systems can stop production. A data breach can damage corporate value and consumer confidence.

IBM reported that India recorded its highest average data breach cost in 2025 at INR 220 million. This shows that cyber insecurity is now a balance-sheet risk, not merely an IT issue.

For a country trying to attract investment, build manufacturing, expand digital public infrastructure and become a global services hub, cyber trust is part of economic competitiveness.

Investors do not only ask whether a country has talent and infrastructure. Increasingly, they ask whether its digital systems are secure.

The Private Sector Is on the Front Line

In cyber conflict, many national targets are privately owned.

Telecom networks, data centres, cloud platforms, banks, airlines, logistics firms, ports, hospitals, media companies and energy operators are often private or semi-private entities. Yet an attack on them can become a national-security crisis.

This means cyber defence cannot be handled by government alone.

Companies must invest in security, train employees, report incidents, protect supply chains and prepare recovery plans. Governments must share threat intelligence, issue advisories, create standards and coordinate crisis response.

The old separation between “business risk” and “national security risk” is collapsing.

A weak vendor can compromise a defence supplier. A careless employee can open a path into a bank. An unpatched router can become part of a state-sponsored operation. A small contractor can become the entry point into a major infrastructure network.

In cyber security, the weakest link is not a metaphor. It is often the attack route.

Supply Chains Are Cyber Targets

Modern organisations do not operate alone. They depend on software vendors, cloud providers, consultants, payment processors, logistics platforms, outsourced IT teams and third-party applications.

Attackers understand this.

Instead of attacking a hardened government or corporate network directly, they may attack a smaller vendor with weaker defences. Once inside, they move through trusted connections.

This makes cyber security a supply-chain issue.

A company is not secure merely because its own firewall is strong. It must know who has access to its systems, what software it uses, how updates are delivered, where data is stored and how third parties are monitored.

The digital supply chain is now part of national resilience.

Elections Are Vulnerable to Cyber and Influence Operations

Cyber attacks can also target democracy.

Election systems, political parties, voter databases, media platforms and campaign communications are attractive targets. An attacker may not need to change votes. It may only need to create doubt.

If citizens believe an election was hacked, trust falls. If parties accuse each other of foreign manipulation, polarisation rises. If fake videos or leaked documents dominate the campaign, democratic debate is distorted.

Cyber attacks and information manipulation are therefore twin threats to electoral legitimacy.

For democracies, the defence cannot be censorship. It must be transparency, rapid verification, secure election infrastructure, cyber hygiene for political parties and public education against manipulated content.

A democracy survives when citizens trust the process even after losing an election. Cyber conflict targets exactly that trust.

Cyber Attacks Can Trigger Real-World Harm

One mistake is to think cyber attacks are bloodless.

They can cause real-world harm. A hospital system locked by ransomware can delay treatment. A water treatment system compromised by attackers can threaten public health. A power grid disruption can endanger vulnerable people. A transport-system failure can cause accidents. A military cyber failure can expose troops.

The weapon is digital, but the victims are human.

This is why cyber attacks on critical civilian infrastructure must be treated as serious violations, not clever tactics. International norms must become stronger around hospitals, water systems, nuclear facilities, energy grids and emergency services.

A world that normalises cyber attacks on civilian systems will make every society less safe.

India Needs a Cyber Deterrence Doctrine

India must move beyond reactive cyber security.

It needs a cyber deterrence doctrine that defines priorities, thresholds, responsibilities and response options. This does not mean every detail should be public. But the broad architecture must be clear.

India should identify which systems are nationally critical. It should define mandatory cyber standards for those systems. It should improve public-private intelligence sharing. It should build stronger attribution capacity. It should develop lawful offensive cyber capabilities for deterrence. It should prepare cyber crisis exercises involving government, military, private sector and state governments.

India also needs deeper cyber diplomacy. Cyber norms, data protection, digital public infrastructure security, cross-border cybercrime cooperation and technology supply-chain security should become central to foreign policy.

Cyber security is no longer a ministry-level technical function. It is a strategic pillar of national power.

Cyber Skills Are a National Security Asset

The future of cyber conflict will be shaped by talent.

Countries need malware analysts, forensic investigators, cryptographers, AI security experts, cloud security architects, hardware security specialists, incident responders, threat-intelligence analysts, cyber lawyers, digital diplomats and ethical hackers.

India has a large technology workforce, but it must build deeper security specialisation. Cyber security cannot be treated as a short certification industry alone. It requires long-term capability, research, labs, public-sector career paths, university programmes and coordination with industry.

A country that wants digital sovereignty must invest in cyber talent at scale.

The most important cyber weapon may not be malware. It may be human expertise.

Citizens Are Part of Cyber Defence

Cyber security is not only for governments and companies.

Citizens are targets and entry points. Phishing, OTP fraud, fake customer-care numbers, malicious links, deepfake calls, loan-app scams and identity theft are everyday cyber threats. In a wider conflict, these same techniques can be scaled to create panic and distrust.

A digitally literate population is therefore part of national defence.

Citizens must know how to verify links, avoid sharing OTPs, protect passwords, use multi-factor authentication, update devices and identify fake information. Media literacy and cyber hygiene should become basic civic education.

In the cyber age, national security begins on the phone screen.

The Risk of Overreaction

States must protect themselves, but they must also avoid overreaction.

Cyber threats can become an excuse for excessive surveillance, censorship or arbitrary control. That would damage democratic freedoms and public trust. A secure digital state must also be a rights-respecting digital state.

The challenge is balance.

Governments need investigative powers, but those powers must be accountable. Platforms need regulation, but not political capture. Cybercrime must be punished, but dissent must not be labelled as cyber threat. Data must be protected, but innovation should not be suffocated.

Cyber security without liberty becomes digital authoritarianism. Liberty without security becomes digital vulnerability.

A democratic cyber doctrine must protect both.

Cyber Conflict Will Shape Geopolitics

The major geopolitical rivalries of the future will all have cyber dimensions.

U.S.-China rivalry will involve cyber espionage, semiconductor security, AI systems, telecom networks and critical infrastructure. Russia-West tensions will continue through cyber sabotage, disinformation and attacks linked to the Ukraine war. Iran-Israel tensions will include cyber operations against infrastructure and military systems. North Korea will continue using cyber tools for espionage, disruption and illicit finance.

Cyber operations are now part of every major strategic contest.

This is why cyber power will increasingly define state power. A country that cannot defend its networks will struggle to protect its economy, military and democracy. A country that can operate effectively in cyberspace will gain influence beyond its physical size.

The future great power will not only have aircraft carriers and nuclear weapons. It will have cyber resilience, data control, AI capability, secure supply chains and digital trust.

What India Must Do Now

India should adopt a ten-point cyber security agenda.

First, classify critical digital infrastructure and apply mandatory security standards.

Second, strengthen CERT-In coordination with state governments, sectoral regulators and private operators.

Third, build a national cyber incident reporting culture that rewards transparency rather than hiding breaches.

Fourth, create sector-specific cyber drills for power, banking, telecom, transport, health and ports.

Fifth, secure digital public infrastructure by design, not after incidents.

Sixth, improve cyber security for MSMEs, because small vendors can become supply-chain attack points.

Seventh, build AI-security capability to detect deepfakes, automated phishing and adversarial AI misuse.

Eighth, expand cyber education in schools, colleges and professional training.

Ninth, deepen cyber partnerships with trusted countries.

Tenth, develop clear legal and strategic frameworks for deterrence, response and accountability.

India’s cyber strategy must be preventive, not only reactive.

Conclusion: The Silent Front Line

Cyber attacks have become the new weapon of state conflict because power now flows through networks.

A state can be weakened without invasion. A society can be divided without occupation. A military can be disrupted without a battlefield defeat. An economy can be damaged without sanctions. An election can be questioned without changing a single vote.

This is why cyber conflict is so dangerous.

It is silent before it is visible.It is deniable before it is proven.It is cheap before it becomes costly.It is technical before it becomes political.It is digital before it becomes physical.

The world is entering an era where the first strike may be a compromised password, a poisoned software update, a fake video, a breached telecom network or malware waiting inside a power grid.

India and the world must understand the central lesson: cyber security is not an IT department’s responsibility. It is national security, economic security, democratic security and social security.

The border is no longer only guarded by soldiers.

It is also guarded by coders, analysts, engineers, investigators, teachers, companies and citizens.

The next war may still be fought with missiles and tanks. But before that war begins, the networks will already be under attack.

That is the silent front line of the twenty-first century.

Was this article helpful?

Spotted an error or want to suggest a clarification? Report a correction.

Comments (0)

Please login to post a comment.

No comments yet — be the first!