Indictments Don’t Deter Cyberattacks, So Why Does the U.S. Keep Using Them? An Analysis in Response to the U.S.’s Recent Indictment of Six Russian Hackers

*Ellen Pruitt

I. Introduction

On October 19, 2020, the U.S. Justice Department indicted six Russian Military Officers in connection with a series of cyberattacks.[1]  The indictment charges the officers in connection with the 2015 and 2016 blackouts in Ukraine, 2017 economic losses to three corporations, 2018 attacks on computers supporting the PyeongChang Olympics, meddling in the 2017 French elections, targeting Georgian companies and government offices, and damaging computer networks in the U.S. and six other countries.[2]

The indictments are not a new strategy—the U.S. has also indicted Chinese, Iranian, and other Russian hackers.[3]  U.S. use of indictments to target international hackers has received sharp criticism as being ineffective and weakening international norms to combat cyberattacks.[4]  Critics of U.S. preference for indicting foreign hackers point to another tool used, though sparingly, to penalize foreign hackers: sanctions.[5]  Sanctions may be preferable to indictments in their ability to deter broader engagement in cyberattacks and their protection of national cyber capabilities.[6]  The continued use of indictments instead of sanctions for cyber actors raises the questions: which works better?  And why does the trend favor indictments?

II. The Pros and Cons of the Indictment Strategy

Realistically, it is highly unlikely that the individuals named in the indictments will ever stand trial in a U.S. courtroom.[7]  As of 2019, out of over fifty indictments since the Obama Administration, only five of the indicted individuals have been arrested for their crimes.[8]

Proponents of indictments argue that regardless of the actual conviction of the individual cyber actor, indictments are an effective tool for deterring future cyberattacks.[9]  The main way indictments achieve deterrence is through deterrence messaging.[10]  The message is intended for both U.S. adversaries and potential targets of the cyberattacks.[11]  Indictments notify adversaries that the U.S. is aware of ongoing cyberactivity and possesses the capability to trace cyberattacks to their perpetrators.[12]  Targets named in the indictments and the industries affiliated with those targets are also notified that potential interference is occurring.[13]  Indictments achieve this level of broad messaging because they include a detailed report on the cyberattacks and incriminating acts of the named parties.[14]  These reports contain information so damning that if an indicted individual were ever brought to trial, a conviction would be almost certain.[15]

However, the indictment’s content also poses problems for broader national security interests.[16]  Because the indictments lay out the entire investigation and case of the prosecution, they typically include national security details.[17]  These national security details tell adversaries in no uncertain terms how the U.S. is obtaining the information on the cyber actors.[18]  Because cyber space is an area of rapid technological development, the methods and channels to monitor malicious cyber activity are dependent on their confidentiality. [19]  Once the U.S. intelligence community reveals its hand, its ability to continue utilizing those resources becomes extremely limited.[20]  The named cyber actors can simply stop operating via the channels identified in the indictment and switch to an alternative method that the U.S. cannot monitor or track.[21]

In addition, it is unclear if deterrence is actually achieved through indictments.[22]  While there is some evidence that Chinese officials at least publicly agreed to limit cyber espionage following the indictments issued by the Obama Administration, it is questionable whether the cyberattacks actually decreased as a result.[23]  Indictments also typically target individual actors, not government entities.[24]  As a result, there is a gray area between official government action and private hackers acting with a government’s blessing.[25]  Many critics of the indictments argue the unlikely result of an actual conviction or any deterrence at the expense of revealing U.S. intelligence efforts is disproportionate; in laymen’s terms, the juice just isn’t worth the squeeze.[26]

III. Potential Congruent Use of Sanctions to Deter Cybersecurity Threats

Sanctioning of these same cyber actors poses an alternative to indictments.[27]  Sanctions could be used with indictments to further deter cyberattacks.[28]  Sanctions are issued pursuant to the International Emergency Economic Powers Act (IEEPA), which allows the Executive Branch to sanction individuals following the declaration of a state of emergency.[29]  It is not a new idea for sanctions to be applied to cyber hackers; the U.S. sanctioned Iranian and North Korean hacking teams in congruence with indictments.[30]  Sanctions have also recently been applied by the European Union in response to cyber threats.[31]  The benefit of sanctions as opposed to indictments is three-fold.[32]  First, sanctions can be imposed quickly without exposure of sensitive information detailed in indictments.[33]  Second, sanctions can reach a broader group cooperating with¾or orchestrating¾cyberattacks.[34]  And third, sanctions have immediate consequences, as opposed to the long waiting period to prepare an indictment.[35]  Sanctions grant the power to immediately seize all assets and restrict travel of any actors named, as well as any actors who are connected with and support the cyber operation.[36]  Arguably, this could also lead to greater deterrence as it puts pressure on businesses and governments to restrict access to technology and funds by known cyber operators.[37]

A potential drawback of sanctions is they do not have the same weight as indictments or the same powerful messaging.[38]  The best apparent solution is for the congruent use of both sanctions and indictments.[39]  While this has been done in the past, it is unclear why it is not done consistently in response to cyberattacks on U.S. assets.[40]  It is clear, however, that the U.S. strategy to deter cyberattacks needs adjusting to meet the increased disruption of U.S. interests both domestically and abroad.[41]

*Ellen Pruitt is a second-year day student at the University of Baltimore School of Law where she is a Staff Editor for Law Review. Ellen is a student fellow with the Center for International and Comparative Law, research assistant for Professor Grossman and Professor Sellers, teaching assistant for Professor Modesitt’s Torts course, and Career Development Officer for the International Law Society. Ellen is currently preparing for the International Committee of the Red Cross’s Clara Barton International Humanitarian Law Competition. Later this year, Ellen will join DLA Piper as a Summer Associate. 

