ILLUSTRATION of cybercrime and hacking activity with a laptop displaying a pirate symbol while a hooded person uses a digital tablet in a dark environment

Aggregating Illegality: The Accumulation of Events Doctrine in Contemporary Challenges

Ransomware attacks are on the rise. Again. One study found that ransomware gangs claimed “6,883 unique attacks” on dark-web leak sites in 2025, a 19% increase over 2024. Europol’s 2026 Internet Organized Crime Assessment likewise describes ransomware as a “dominant threat” in a “complex and evolving landscape.” The legal challenge, we argue, is not only to condemn these attacks one by one, but to recognize when they form part of a broader course of conduct whose cumulative scale, pattern, and effects may be constitutive of a wrong defined in the aggregate.

At first glance, this may seem like an odd frame for a familiar form of cybercrime. These operations are still largely about money, after all: attackers lock victims out of their data and demand payment, often in cryptocurrency, to restore access. But the same techniques are increasingly being used for political ends, as government actors turn to criminal cyber networks to carry out disruptive operations. “States are increasingly embedding themselves in the ransomware ecosystem,” because doing so allows them to pursue strategic goals while reducing “their operational overhead and complicat[ing] attribution.” The rise of ransomware-as-a-service and the growing availability of AI tools make this symbiosis even more commonplace, with criminal groups recruiting more affiliates and expanding the scale of government-backed operations.

But soon, no affiliates may be needed at all. In July, researchers reported what they described as the first documented case of a fully autonomous ransomware attack. An AI agent allegedly broke into a vulnerable server, searched for credentials, moved through the victim’s network, encrypted data, and even drafted the ransom demand, all on its own. When an authentication step failed, it reportedly corrected course in thirty-one seconds and continued. Agentic ransomware thus introduces the possibility of continuous, relentless, and increasingly numerous operations. 

Agentic ransomware is but one form of AI-enabled cyber risk brought into sharp view last month. The now well-reported attack on Hugging Face offers yet another illustration of the danger. During an internal evaluation of advanced cyber capabilities, an OpenAI agent escaped its testing sandbox, reached the open internet, and compromised production infrastructure at Hugging Face, home to the world’s largest repository of AI models. The agent generated roughly 17,600 actions, repeatedly testing and abandoning paths until it assembled a viable route across several systems. Hugging Face relied on defensive agents to detect the intrusion and on a self-hosted open-weight model to reconstruct and decode a campaign too voluminous for human analysts to examine alone. The intrusion was unintended, exposing the risks posed by inadequately supervised testing of frontier models. Still, it raises the more troubling prospect of what malicious actors might accomplish through the deliberate deployment of such models in the future. As Microsoft cybersecurity researcher Geoff McDonald warned, already now there is “little stopping threat actors from operating thousands or tens of thousands of simultaneous campaigns.”

There are many different reasons ransomware remains underenforced, and still more reasons why cybercrime as a whole is so difficult to police. But one explanation may be especially important at this moment in time: lawyers and policymakers often treat each attack as a discrete incident and therefore struggle to see the broader pattern. We miss the forest for the trees.

This problem is especially acute in international law, where threshold categories like “sovereignty violation,” “coercive intervention,” or “use of force” depend on evidentiary assessments of the gravity, scale, and scope of each act and its visible effects. In the ransomware context, attacks and their effects may be dispersed across a wide field of seemingly low-level victims, challenging the ability to piece together patterns of geopolitical harm. Whole campaigns could be launched by distinct agents operating in seeming isolation, even as they “execute an end-to-end campaign” together without any human intervention. As a result, ransomware crimes risk becoming “invisible” to international law’s rigid categories. The two principal cybercrime treaties, the Budapest Convention and the new U.N. Convention against Cybercrime, do not resolve this problem. Both focus on criminalization and cross-border enforcement, but do little to address these threshold questions or take account of issues of state responsibility. By assessing each cyber crime or attack in isolation, the law may enable perpetrators to distribute harm and harm-producing agents across society, while impeding accountability for the cumulative injury inflicted by their campaigns. 

Aggregate Wrongs in the Law of State Responsibility

The international law of state responsibility anticipates this risk and offers a solution: “breach consisting of a composite act.” The ILC Articles on Responsibility of States for Internationally Wrongful Acts (ARSIWA) address in Article 15 the “breach of an international obligation by a State through a series of actions or omissions defined in aggregate as wrongful.” Despite its importance, the concept has received scant scholarly and judicial treatment, and several important questions persist: How are “actions” and “omissions” individuated? When do they form part of a “series”? And crucially for present purposes, what kinds of primary obligations are susceptible to composite breach? 

On this latter question, the drafting of Article 15 leaves the impression that composite breach is a generic concept applicable to all primary obligations by default. This interpretation finds support in the remarks of Roberto Ago, then Special Rapporteur on State Responsibility, that “the internationally wrongful act of a State is quite often—and probably in most cases—the result of a concatenation of a number of individual actions or omissions which, however legally distinct in terms of municipal law, constitutes one compact whole.” 

By contrast, the ILC’s commentary to Article 15 and Special Rapporteur James Crawford’s academic writing introduce a more narrow conception of composite breach limited to primary obligations having a “systematic character,” where the prohibited conduct is constituted, by definition, through an aggregate course of action. The ILC cites as examples obligations concerning genocide, apartheid, crimes against humanity, systematic acts of racial discrimination, and systematic acts of discrimination prohibited by a trade agreement.

There are several reasons to doubt this narrow interpretation of Article 15. First, it finds no support in the approved text of the provision itself. Second, the commentary makes clear that the example obligations cited are only “illustration[s]” and that the list provided is non-exhaustive. Third, the focus of Article 15, and of Chapter III of ARSIWA more generally, is on categories of “breach,” not categories of “obligation.” Fourth, and crucially, international courts and tribunals have frequently identified composite breaches of prohibitions lacking a systematic character. Thus, for example, ICSID Tribunals and the Iran-US Claims Tribunal consider creeping expropriation to be a type of composite breach. UNCITRAL Tribunals have judged that a composite act can violate the rule against denials of justice. Finally, an UNCLOS arbitration administered by the Permanent Court of Arbitration relied on Article 15 to find a composite breach of the duty to exercise archipelagic sovereignty in a reasonable manner. In each of these examples, composite breach was applied to prohibitions that are not inherently systematic—expropriation, denial of justice, and the unreasonable exercise of archipelagic sovereignty—unlike the examples listed in the ILC’s commentary to Article 15.

These examples aside, the ILC’s commentary curiously omits the field where composite breach has its deepest roots in both state practice and doctrine: the jus ad bellum.

Aggregate Wrongs in the Jus Ad Bellum

In order to exercise the right to self-defense, a state must first show that it has been the victim of force meeting the threshold of an “armed attack.” When faced with a series of lesser assaults, defending states will frequently analyze the situation in terms of aggregate illegality, even if not overtly framed this way (e.g. China, Iran, Israel, Lebanon, Liberia, Sudan, the United States).

This reasoning has also been implicitly endorsed by the International Court of Justice. In Nicaragua, the Court asked whether cross-border incursions could be “treated for legal purposes as amounting, singly or collectively, to an ‘armed attack.’” In Oil Platforms, the ICJ examined whether a single strike “either in itself or in combination with the rest of the ‘series of… attacks’ cited by the United States can be categorized as an ‘armed attack. . .’” In Armed Activities, the Court remarked obiter that a military incursion by Uganda was not a necessary or proportionate response to “the series of transborder attacks [Uganda] claimed had given rise to the right of self-defence.” 

The accumulation of events doctrine is not without controversy, of course. Christian Tams once cautioned against the risk of it producing an “open-ended license to use force.” Still, the doctrine enjoys “considerable support” in case law as well as scholarship (e.g. here, here, and here). Unsurprisingly, the relevance of the doctrine has been especially acute in connection with cyber-attacks. National positions on the international law applicable to cyber operations have frequently affirmed the accumulation of events doctrine and emphasized its importance for jus ad bellum analysis in cyberspace (e.g. Austria, Belgium, France, Singapore). Scholars have also offered recent commentary exploring how the accumulation of events doctrine might apply in the case of cyber operations. However, neither states nor scholars have seriously interrogated the doctrinal origins of the accumulation of events doctrine beyond the jus ad bellum, including its ties to the law of state responsibility.

Our core claim here is that the accumulation of events doctrine is merely a concrete expression, within the jus ad bellum, of the broader doctrine of composite breach codified in Article 15. To borrow the terms of ARSIWA, an “accumulation of events” rising to the level of an armed attack constitutes a breach precisely because it forms “a series of actions […] defined in aggregate as wrongful.” If the doctrine of composite breach is truly a second-order default rule of general international law, it follows that its logic of accumulation may travel beyond the jus ad bellum. Even a skeptic of this broader claim must concede the short journey from armed attack to its nearest doctrinal relatives.

Aggregate Wrongs Beyond the Jus Ad Bellum

After all, armed attacks triggering the right of self-defence form part of a broader chain of cognate rules that extend down to right of sovereignty, and up to the prohibition of aggression. As Tom Ruys, Dapo Akande, and Antonios Tzanakopoulos explain, every act of aggression is also an armed attack, and every armed attack is also a use of force. As Mohamed Helal and Laura Visser add, every use of force is also an unlawful intervention, and every unlawful intervention is also a violation of sovereignty.

Altogether, the image which emerges is one of a cascading relationship between wrongs fitting within concentric circles organized according to what Marko Milanović describes as a “hierarchy of gravity” following a “gradation of stigma”. 

 

Illustration: The Law of State Coercive Action as a Multitiered Framework

 

We would therefore expect the logic of accumulation to travel across this chain of cognate wrongs. If these prohibitions all protect related interests in the sovereignty and autonomy of the state, there is no principled reason why aggregation should matter only for self-defence and not when assessing aggression, unlawful uses of force, coercive interventions, or sovereignty violations. Absent evidence to the contrary, this default should hold. Other academics seem to share our view. Helal’s account, for example, recognizes that coercive intervention can be committed through composite breach, without explicitly discussing other rules along our chain.

Some state practice already points in this direction, at least in the context of sovereignty violations. In written proceedings submitted to the International Court of Justice, claimants have argued that sovereignty may be violated through a series of related territorial intrusions. A memorial by Ecuador invoked repeated cross-border toxic herbicide drift resulting from thousands of aerial spraying operations. Another by Costa Rica invoked a sustained campaign of dredging, excavation, and vegetation-clearing operations carried out over time in disputed territory.

The Canadian national position on international law applicable in cyberspace offers early evidence of a similar practice in this domain. The position explicitly imports the logic of accumulation to sovereignty violations, recognizing that “a series of cyber activities” may produce harmful effects violating “the rule of territorial sovereignty” even where each “individual cyber activity on its own would not reach this threshold.” This observation may prove particularly important, as a growing number of states adopt the view that sovereignty in cyberspace is a binding rule, but one violated only where effects cross some negligible or de minimis line (e.g. Canada, Czech Republic, Germany, Norway, Thailand). If this definition of sovereignty takes hold, states may grow more inclined to apply the logic of accumulation to characterize a series of cyber intrusions—say, a state-facilitated campaign of ransomware attacks targeting small- and medium-sized businesses—as collectively crossing this new threshold.

Objections and Open Questions

Some readers may resist treating aggregate analysis in the jus ad bellum as established law. We understand that concern. Indeed, while the accumulation of events doctrine finds support in the ICJ’s jurisprudence, national positions both within and beyond cyberspace, and in scholarship—including those we surveyed above—its precise status remains contested. Three further points are therefore warranted.

First, even those skeptical of accumulation in the armed-attack context have reason to accept it for lesser wrongs. The principal concern has been that aggregation may expand the circumstances in which force may lawfully be used in self-defense. But that concern does not arise when aggregation is used only to establish violations of sovereignty or coercive interventions that fall short of an armed attack, neither of which, without more, triggers a right to self-defense. 

Second, and more fundamentally, our argument does not depend on recognizing the accumulation of events doctrine as customary international law. Article 15 of ARSIWA codifies the broader principle of composite breach as a rule of general applicability. It therefore operates by default “across all or many different sub-areas of international law … in the absence of any displacing special rule.” The accumulation of events doctrine is, in this sense, the jus ad bellum label for a more general default concept: that certain wrongs may arise not from a single act, but from a series of acts defined in the aggregate as wrongful.

Finally, even if this general rule of accumulation extends across a broad range of contemporary challenges, including in cyberspace, it does not follow that it will be available in every instance. Article 15 still requires more than a cluster of similar incidents. The relevant actions or omissions must form a legally meaningful “series,” and that series must satisfy the primary rule whose breach is alleged. 

This inquiry is fact intensive and often difficult to carry out, especially in cyberspace. As Marco Roscini observes, “one of the strategic purposes of the attacker is likely to be that the defender does not realize that the attacks are part of a coordinated strategy.” Quoting Thomas Franck, Roscini adds that “it is often difficult even to establish convincingly, from a pattern of isolated, gradually cumulative events, when or where the first round began, let alone at whose instigation, or who won it.”

International law has done little to refine the tests for what might constitute a campaign. What “links in time, source, and cause,” as Belgium’s national position puts it, are required to justify the accumulation? How similar must the perpetrators, their targets, or their methods and effects be before aggregation becomes legally recognizable? And how should we address cases where, as Singapore notes, different cyber hackers are “acting in concert”? The answers will determine not only when aggregation is available, but whether it remains a bounded technique rather than an open license to combine otherwise discrete acts to pursue unilateral countermeasures.

Agentic AI sharpens these questions and the need for limiting criteria. Once humans are removed from the cyber kill chain, it becomes even harder to connect incidents to gangs, gangs to infrastructure, infrastructure to states, and states to strategic objectives. The indicia of a campaign are muddied, especially as each AI agent develops and displays its own operational signature. The markers necessary for aggregation, attribution, and causal analysis may therefore prove more difficult to trace.

While these questions remain open, this much is clear: international law must learn to count in series rather than in singles. Otherwise, the law’s arithmetic will keep working in favor of ransomware’s architects.

Filed Under

, , , , , , ,
Send A Letter To The Editor

DON'T MISS A THING. Stay up to date with Just Security curated newsletters: