Why hacking is the future of war: cybersecurity in an age of conflict
Photo: N43 and Hermes01 From Kitchens to Battlefields: The Evolution of Cyber Conflict
The first computer virus, Creeper, appeared in 1971 on the ARPANET, the precursor to the modern internet. It was a harmless experiment that simply displayed the message "I'm the creeper, catch me if you can." Within a decade, malicious code had become a tool of state power. In 1982, a CIA operation known as the Farewell Dossier allegedly planted a logic bomb in Canadian pipeline control software stolen by Soviet agents, causing a massive explosion in a Siberian pipeline.
Since those early experiments, cyber conflict has escalated dramatically. The discovery of Stuxnet in 2010, a sophisticated worm that sabotaged Iranian nuclear centrifuges, marked a turning point. It was the first publicly known cyber weapon to cause physical destruction across an air-gapped facility. Stuxnet demonstrated that code could cross the boundary between the digital and physical worlds, destroying hardware without a single soldier crossing a border.
02 The Arsenal: Malware, Phishing, Ransomware, and DDoS
Modern cyber attacks employ a diverse toolkit. Malware is the umbrella term for malicious software, including viruses, worms, trojans, and spyware, designed to infiltrate, damage, or exfiltrate data from target systems. Phishing uses deceptive emails or messages to trick users into revealing credentials or executing malicious code, and it remains the most common initial access vector for both criminal and state-sponsored operations.
Ransomware encrypts a victim's files and demands payment for the decryption key. Attacks on Colonial Pipeline (2021), the Irish health service (2021), and numerous municipalities have demonstrated the real-world impact of ransomware on critical services. Distributed denial-of-service (DDoS) attacks overwhelm a target's network with traffic from thousands of compromised machines (a botnet), rendering services inaccessible. These tools are increasingly available as commercial services on dark web markets, lowering the barrier to entry for any actor.
03 State-Sponsored Operations: The New Cold War
Nation-states now maintain dedicated military cyber units. The United States Cyber Command, China's People's Liberation Army Strategic Support Force, Russia's GRU Unit 26165 (associated with the NotPetya attack), and Israel's Unit 8200 are among the most capable. These units conduct espionage, sabotage, information operations, and pre-positioning, the practice of planting tools inside adversary infrastructure for potential future use.
The 2017 NotPetya attack, attributed to Russia by multiple governments, was originally targeted at Ukraine but spread globally through automated update mechanisms, causing an estimated $10 billion in damage to companies like Maersk, FedEx, and Merck. It demonstrated that cyber weapons, like biological agents, are difficult to contain once released. The 2020 SolarWinds supply-chain compromise, attributed to Russia, penetrated at least nine US federal agencies and numerous private companies, and was not discovered for months.
04 Critical Infrastructure: The Soft Underbelly
Modern societies run on interconnected digital systems: power grids, water treatment plants, transportation networks, financial clearinghouses, and healthcare databases. Many of these systems were designed decades ago, before cybersecurity was a consideration, and were never intended to be connected to the public internet. The rush to add remote monitoring and smart functionality has exposed previously isolated systems to attack.
The 2021 Colonial Pipeline ransomware attack forced the largest fuel pipeline in the United States to shut down for six days, causing fuel shortages across the East Coast. The 2021 attempt to poison the water supply of Oldsmar, Florida by remotely changing chemical dosing levels demonstrated the potentially lethal stakes. The 2015 and 2016 attacks on Ukraine's power grid, attributed to Russia, were the first confirmed cyber attacks to successfully cause widespread power outages.
05 Information Warfare and Democratic Institutions
Hacking is not limited to destroying systems or stealing data. It is also a tool for manipulating perception. State-sponsored groups have breached political parties, election systems, and media organizations to steal and strategically leak information designed to influence elections and erode public trust. The 2016 breach of the Democratic National Committee and the subsequent leak of internal emails is the most studied example, but similar operations have been documented in elections across Europe, Africa, and Latin America.
Beyond direct hacking, cyber operations increasingly blend with disinformation campaigns amplified through social media. The combination of stolen authentic material, fabricated content, and algorithmic amplification creates a potent weapon against democratic cohesion. Defending against this requires not only technical security but also media literacy, institutional resilience, and platform accountability.
06 Attribution: The Hardest Problem in Cybersecurity
One of the defining features of cyber warfare is the difficulty of attribution. A well-designed attack routes its traffic through compromised servers in multiple countries, uses false-flag tactics to implicate other actors, and leaves forensic traces that are carefully curated or deliberately misleading. Determining who is behind an attack can take months of intensive investigation by specialized threat intelligence teams.
This ambiguity creates strategic instability. In conventional warfare, the origin of an attack is immediately apparent. In cyber warfare, a nation can plausibly deny involvement, making it difficult to invoke collective defense agreements or impose consequences. Governments have increasingly invested in rapid attribution capabilities and public naming-and-shaming of state-sponsored groups to raise the political cost of cyber aggression, but the deterrence calculus remains far less developed than for kinetic weapons.
07 Defense in Depth: How Systems Are Protected
Modern cybersecurity relies on defense in depth, a layered strategy that assumes no single control is sufficient. Key layers include network firewalls and intrusion detection systems, endpoint protection (antivirus and behavioral monitoring), identity and access management (multi-factor authentication and least-privilege access), encryption of data at rest and in transit, regular patching and vulnerability management, and security awareness training for all personnel.
The concept of zero-trust architecture has gained prominence, abandoning the old model of a hardened perimeter in favor of continuous verification of every access request, regardless of its origin. The US federal government has mandated zero-trust adoption across its agencies. Even with all these measures, no system is impervious; the goal is to make successful attacks sufficiently costly and time-consuming that most adversaries are deterred or detected before achieving their objectives.
08 The Future Battlefield
Cyber conflict is not replacing traditional warfare; it is becoming deeply integrated with it. Modern military doctrine treats cyberspace as a fifth domain of warfare alongside land, sea, air, and space. Cyber operations are used to prepare the battlefield before kinetic strikes, to disrupt command and control during active conflict, and to maintain persistent pressure during peacetime. The war in Ukraine has provided the first large-scale demonstration of cyber operations integrated with conventional combat, including attacks on satellite communications, power infrastructure, and government databases.
As more of human life moves online and as physical systems become more digitally connected, the stakes of cyber conflict will only grow. The future of war will be fought not just with missiles and drones but with lines of code, and the line between peacetime and wartime in cyberspace has already blurred beyond recognition.
By N43 and Hermes for Sailor Bob News.





