Russia Targets Ukrainian Data Centres: When Can the Strikes Be War Crimes?
Introduction
As Russia targets Ukrainian data centres, the legal question is not whether digital infrastructure is important, but when it may lawfully be attacked. On 23 September 2026, Russian drone attacks disrupted internet services to about 100,000 households in Kyiv and the surrounding region, according to Ukraine’s Digital Ministry. Russia’s Defence Ministry said its forces had struck several data centers that it claimed were being used for the benefit of the Ukrainian military, while Ukrainian Foreign Minister Andrii Sybiha described the targeted facilities as civilian infrastructure (Reuters, 2026).
International humanitarian law does not create a separate targeting regime for data centers. Under Article 52 of Additional Protocol I, civilian objects may not be made the object of attack, while an object qualifies as a military objective only when its nature, location, purpose, or use makes an effective contribution to military action and its destruction, capture, or neutralization offers a definite military advantage in the circumstances ruling at the time (Additional Protocol I, 1977, art. 52). A data center remains a civilian object unless that test is satisfied.
The difficulty is that civilian and military functions can coexist within the same digital infrastructure. The ICRC has specifically addressed data centers that store information collected by armed forces or provide computing capacity or digital space for military applications, emphasizing that their status requires a case-by-case assessment. Even where a data center, or part of it, qualifies as a military objective, proportionality and precautions remain applicable, including consideration of foreseeable direct and indirect harm to civilians who depend on the facility for essential services (ICRC, 2026).
An unlawful attack does not automatically amount to a war crime. Under Article 8(2)(b)(ii) of the Rome Statute, intentionally directing attacks against civilian objects is a war crime when the required elements are established. Article 8(2)(b)(iv) separately addresses attacks launched in the knowledge that expected incidental civilian harm or damage would be clearly excessive in relation to the concrete and direct overall military advantage anticipated (ICC, 2002). Current public reporting does not establish the military function of every facility struck, the information available to Russian planners, or the civilian effects anticipated in each attack. Those questions are central both to assessing the legality of particular strikes and to determining whether individual criminal responsibility could arise.
1. What the Recent Strikes Actually Affected
Russian attacks on 23 September 2026 damaged data-center and telecommunications infrastructure in Kyiv. Internet provider UTELS reported that a Kyiv data center containing its core equipment had been hit, while Pavutyna reported damage to one of its facilities. Ukraine’s Ministry of Digital Transformation said the attacks caused internet problems for approximately 100,000 households in Kyiv and Kyiv Oblast (Reuters, 2026; Interfax-Ukraine, 2026).
The disruption extended beyond residential internet access. The PFTS Stock Exchange reported significant operational problems connected to the loss of internet services. On 24 September, Ukrainian reporting also described the destruction of a Kyiv data center used by hosting provider MiroHost, although the company said services to most of its customers outside Ukraine continued normally (Interfax-Ukraine, 2026; Ukrainska Pravda, 2026).
The purpose of the strikes remains contested. Russia’s Defence Ministry claimed that some targeted data centers were being used for the benefit of the Ukrainian military. Ukrainian Foreign Minister Andrii Sybiha described the facilities as civilian infrastructure that provides access to essential information and stressed the importance of rapid missile and drone warnings. The Institute for the Study of War separately reported that Sybiha said the disruption affected access to mobile air-raid alerts. These competing characterizations do not determine the legal status of any facility; that status depends on its actual function and the circumstances existing when the attack was planned (Reuters, 2026; Institute for the Study of War, 2026).
2. When a Data Center Becomes a Military Objective
Article 52 of Additional Protocol I provides the central legal test. Russia and Ukraine are parties to the Protocol, which prohibits attacks against civilian objects and defines military objectives through two cumulative conditions. The object must make an effective contribution to military action by its nature, location, purpose, or use, and its destruction, capture, or neutralization must offer a definite military advantage in the circumstances ruling at the time (Additional Protocol I, 1977, art. 52).
Economic importance, government use, or domestic classification as critical infrastructure does not by itself satisfy that test. The ICRC has emphasized that infrastructure cannot be attacked merely because it contributes to the broader war effort or supports the economy. Its military significance must satisfy the narrower criteria established by Article 52 (ICRC, 2026).
The assessment is also time-specific. A facility may qualify as a military objective because of its current use and later regain civilian protection when that use ends or when its neutralization no longer offers a definite military advantage. The same reasoning applies to data centers: civilian ownership does not prevent military-objective status, but an assertion of military use does not establish it without the underlying factual basis (ICRC, 2019).
2.1 Military Use Inside Civilian Infrastructure
The more difficult situation arises when civilian and military functions coexist within the same commercial facility. The ICRC has recognized that particular data centers or servers may store information collected by armed forces, including intelligence, or provide computing capacity and digital space for military applications. Their status must be assessed individually under the ordinary military-objective test (ICRC, 2026).
Simultaneous civilian use does not necessarily prevent an object from becoming a military objective. If a particular facility makes an effective contribution to military action and neutralizing it offers a definite military advantage, Article 52 may permit it to be targeted even while civilian customers continue to rely on the same infrastructure. Expected civilian harm then becomes relevant primarily to proportionality and precautions rather than to the initial classification of the object (ICRC, 2019).
“Dual use” is consequently a descriptive term, not an independent legal category that automatically authorizes attack. The presence of some military activity within a commercial data center does not eliminate the need to determine which object satisfies Article 52 and what military advantage its neutralization is expected to provide.
Delerue identifies the commingling of civilian and military data and applications as a particular difficulty in applying the law of targeting to data centers. The problem becomes especially acute where only part of a facility supports military functions while the remainder serves civilian users (Delerue, 2024).
2.2 The Problem of Shared Servers and Networks
Data centers differ from many conventional targets because military and civilian activity may depend on the same physical and digital systems. Servers, network connections, power supplies, cooling systems, and storage infrastructure can support many users simultaneously, making the physical boundaries of the relevant military function difficult to isolate (Delerue, 2024).
A military use located within the facility may accordingly be narrower than the physical effects required to disable it. An attack intended to eliminate particular computing capacity could also interrupt unrelated civilian services that depend on common infrastructure. That possibility does not necessarily prevent the facility from qualifying as a military objective, but it affects the subsequent proportionality and precautions analysis.
Article 52 permits the total or partial destruction, capture, or neutralization of an object when the military-objective criteria are satisfied. The legal question is not simply whether some military activity occurs inside the data center, but whether the object selected for attack meets those criteria in the circumstances existing at the time (Additional Protocol I, 1977, art. 52).
3. Civilian Dependence and the Effects of Disconnection
The consequences of attacking a data center may extend far beyond the building itself. The September strikes produced documented internet disruption across Kyiv and Kyiv Oblast and caused significant technical problems for the PFTS Stock Exchange. These effects demonstrate how damage to a physical facility can spread through services used by people and institutions located elsewhere (Interfax-Ukraine, 2026).
Other possible consequences require a more cautious approach. Data centers can support banking, government administration, health services, commercial platforms, cloud applications, and communications systems, but the mere possibility of such dependence does not establish that each of those services was disrupted in a particular attack.
The ICRC nevertheless considers foreseeable indirect effects relevant when civilian populations depend on targeted infrastructure. Its 2026 guidance on data centers states that proportionality and precautions must account for foreseeable direct and indirect harm, including consequences for civilians who rely on the facility for essential services (ICRC, 2026).
3.1 Internet Access and Air-Raid Warnings
The connection between communications infrastructure and emergency warnings gives these attacks a particular civilian-protection dimension. Reuters recorded Sybiha’s statement that rapid missile and drone alerts save lives and that the affected infrastructure enables access to essential information. The Institute for the Study of War later reported that Sybiha said access to mobile air-raid alerts had been disrupted (Reuters, 2026; Institute for the Study of War, 2026).
Loss of ordinary connectivity and interference with an emergency-warning function can produce different humanitarian consequences. If a communications failure foreseeably prevents civilians from receiving timely warnings and thereby increases their exposure to subsequent attacks, that consequence may be relevant to the assessment of expected civilian harm.
The ICRC has taken the position that foreseeable second- and third-order effects should be considered in proportionality assessments where they are sufficiently connected to the attack. Its guidance specifically identifies telecommunications and other interconnected infrastructure as capable of producing consequences that extend beyond immediate physical damage (ICRC, 2019).
This does not mean that every internet outage renders an attack disproportionate. The legal inquiry remains whether the expected incidental civilian harm would be excessive in relation to the concrete and direct military advantage anticipated. The significance of a disrupted warning system lies in the foreseeability and gravity of the possible civilian consequences, not simply in the number of users who lose connectivity.
3.2 What Happens to Civilian Data?
The physical components of a data center present little conceptual difficulty under targeting law. Buildings, servers, communications hardware, power equipment, and other tangible infrastructure are objects whose civilian or military status can be assessed under the ordinary rules of distinction.
The legal status of data itself remains contested. A majority of experts involved in the non-binding Tallinn Manual process regarded data as intangible and therefore outside the ordinary meaning of an “object” for these targeting rules. Other experts have taken a broader view, while the ICRC has argued that excluding essential civilian data from protection as civilian objects could create a serious protection gap (Gisel, Rodenhäuser and Dörmann, 2020; ICRC, 2019).
The disagreement becomes practically significant where military operations delete or corrupt medical records, financial data, government records, or comparable civilian information without physically damaging the hardware on which they are stored. International humanitarian law has not yet produced a settled answer to every aspect of that problem.
3.3 Precautions Before Striking Digital Infrastructure
Article 57 of Additional Protocol I requires those who plan or decide upon an attack to do everything feasible to verify that the intended target is a military objective and is not otherwise protected from attack. For data centers, that obligation may depend on information about how particular servers, applications, or computing resources are being used at the relevant time (Additional Protocol I, 1977, art. 57).
Verification cannot rest solely on an outdated assessment. Article 52 ties military-objective status to the circumstances ruling at the time, while Article 57 requires an attack to be canceled or suspended if it becomes apparent that the target is not a military objective or that the expected civilian harm would be excessive (Additional Protocol I, 1977, arts. 52, 57).
Precautions also concern the means and methods selected for attack. Parties must take all feasible measures to avoid, and in any event minimize, incidental harm to civilians and civilian objects. Where a choice exists between military objectives offering a similar military advantage, the law requires selection of the objective expected to pose the least danger to civilian lives and civilian objects (Additional Protocol I, 1977, art. 57).
For data centers, these obligations connect target verification with civilian digital dependence. The fact that an object qualifies as a military objective does not make foreseeable civilian consequences legally irrelevant. Those consequences remain part of the assessment of how, when, and by what means the attack may lawfully be carried out.
4. When an Unlawful Strike Becomes a War Crime
A violation of international humanitarian law does not automatically establish a war crime. Individual criminal responsibility requires proof of the elements of a specific offense, including the relevant conduct, contextual requirements, and mental element. For the offenses considered here, the conduct must also occur in the context of and be associated with an international armed conflict (ICC, 2002).
The distinction is important in targeting cases. An attack may violate the rules of distinction, proportionality, or precautions without every element of a Rome Statute offense being established. Conversely, criminal responsibility concerns the conduct and state of mind of particular individuals rather than the legality of a military operation in the abstract.
The ICC may exercise territorial jurisdiction over alleged Rome Statute crimes committed on Ukrainian territory under Ukraine’s Article 12(3) declarations and, since 1 January 2025, its status as a State Party. Ukraine’s Article 124 declaration temporarily excludes jurisdiction over Article 8 crimes likely committed by Ukrainian nationals; it does not create the same exclusion for alleged crimes committed by Russian nationals (Rome Statute, 1998; United Nations, 2024).
4.1 Intentionally Attacking a Civilian Data Center
Article 8(2)(b)(ii) of the Rome Statute criminalizes intentionally directing attacks against civilian objects, meaning objects that are not military objectives. The Elements of Crimes require proof that an attack was directed against such an object and that the perpetrator intended the civilian object to be the object of the attack (Rome Statute, 1998, art. 8(2)(b)(ii); ICC, 2002).
The fact that a data center was physically damaged is not enough. Its status at the relevant time must first be established under the rules governing military objectives. A commercially operated facility may still qualify as a military objective if its actual use satisfies Article 52 of Additional Protocol I.
Criminal responsibility also turns on the perpetrator’s awareness of the relevant factual circumstances. It does not depend on proving that the person correctly understood the legal label attached to those facts. Evidence concerning the facility’s use, the information available before the strike, targeting decisions, and the conduct surrounding the attack may all bear on the required intent.
A public assertion that a facility supported military communications cannot itself establish military-objective status. Equally, civilian ownership or extensive civilian use does not conclusively establish that the facility remained a civilian object. The offense can be assessed only after the factual basis for the target’s classification is established.
4.2 Disproportionate Attacks on Military Objectives
A different offense may arise where the data center genuinely qualifies as a military objective. Article 8(2)(b)(iv) addresses attacks launched in the knowledge that the expected incidental civilian death, injury, or damage to civilian objects would be clearly excessive in relation to the concrete and direct overall military advantage anticipated (Rome Statute, 1998, art. 8(2)(b)(iv)).
The criminal threshold is more demanding than the underlying IHL proportionality rule. The Rome Statute requires harm that is clearly excessive and a specific knowledge element. The Elements of Crimes further indicate that this assessment must be based on the information available to the perpetrator at the relevant time (ICC, 2002).
Disruption of digital services can be relevant where foreseeable effects translate into civilian death, injury, or damage to civilian objects. A widespread internet outage, however, does not by itself establish the offense. The scale of disconnection, the services affected, the foreseeable humanitarian consequences, the anticipated military advantage, and the perpetrator’s knowledge must all be considered within the statutory test.
5. What the Public Evidence Can Establish
The current public record establishes that Russian strikes damaged Ukrainian data-center and telecommunications infrastructure and disrupted civilian internet services. Russian authorities have claimed that some of the facilities supported Ukrainian military functions. Ukrainian officials have characterized the affected infrastructure as civilian and emphasized its importance for public communications and access to information (Reuters, 2026; Institute for the Study of War, 2026).
Those competing accounts do not resolve the legal classification of the targets. Oleksandr Fedienko, a member of the Verkhovna Rada who chairs its cybersecurity and government communications subcommittee, was reported as saying that Ukrainian authorities had not identified damage to military or state-institution communications from the strikes (Institute for the Study of War, 2026). That statement does not establish what functions the facilities performed before they were attacked.
The publicly available material considered here does not provide sufficient evidence to determine the precise military role, if any, of every targeted facility, the intelligence available to those planning each strike, the exact object selected, or the military advantage anticipated from its neutralization. Those facts are central to the Article 52 analysis and to assessing whether the precautions required before an attack were observed.
The evidentiary threshold is higher still for individual criminal responsibility. The consequences of an attack alone do not prove intent or knowledge, although evidence obtained after the event may help establish those mental elements circumstantially. A categorical conclusion that the reported strikes collectively constitute war crimes would exceed what the present public record supports. Russia’s claims of military use are likewise insufficient, without supporting evidence, to establish that every targeted facility was a lawful military objective.
Also read
Conclusion
Attacking a Ukrainian data center can constitute a war crime, but not merely because civilian infrastructure is damaged. If a facility remained a civilian object and was intentionally made the object of attack, Article 8(2)(b)(ii) may apply when the other elements of the offense are established. If the facility was a genuine military objective, Article 8(2)(b)(iv) may become relevant where expected incidental civilian harm was clearly excessive and the required knowledge can be proven.
Digital infrastructure complicates these familiar rules because military and civilian functions can coexist within the same physical systems. A strike may be directed at a localized military function while foreseeable effects extend through communications networks and other civilian services that depend on the same infrastructure. The legality of such an attack, and any resulting criminal responsibility, depends on the status of the particular target, the information available before the strike, the military advantage anticipated, and the civilian harm that could reasonably be foreseen.
References
Delerue, F. (2024) ‘Data Centers and International Humanitarian Law’, in Dickinson, L.A. and Berg, E.W. (eds.) Big Data and Armed Conflict: Legal Issues Above and Below the Armed Conflict Threshold. New York, NY: Oxford University Press, pp. 207–228. Available at: https://academic.oup.com/book/55259/chapter-abstract/428636824 (Accessed: 26 September 2026).
Gisel, L., Rodenhäuser, T. and Dörmann, K. (2020) ‘Twenty years on: International humanitarian law and the protection of civilians against the effects of cyber operations during armed conflicts’, International Review of the Red Cross, 102(913), pp. 287–334. Available at: https://www.cambridge.org/core/journals/international-review-of-the-red-cross/article/twenty-years-on-international-humanitarian-law-and-the-protection-of-civilians-against-the-effects-of-cyber-operations-during-armed-conflicts/BE68981904487F07B9919836B78B6DAD (Accessed: 26 September 2026).
Institute for the Study of War (2026) ‘Russian Offensive Campaign Assessment, September 25, 2026’ [online]. Available at: https://understandingwar.org/research/russia-ukraine/russian-offensive-campaign-assessment-september-25-2026/ (Accessed: 26 September 2026).
Interfax-Ukraine (2026a) ‘About 100,000 households in Kyiv, region have internet problems following Russian attack – Digital Ministry’ [online]. Available at: https://en.interfax.com.ua/news/telecom/1208833.html (Accessed: 26 September 2026).
Interfax-Ukraine (2026b) ‘PFTS Stock Exchange operating with disruptions Wednesday due to internet problems following Russian attacks on Kyiv’ [online]. Available at: https://en.interfax.com.ua/news/economic/1208908.html (Accessed: 26 September 2026).
International Committee of the Red Cross (2019) International Humanitarian Law and Cyber Operations During Armed Conflicts: ICRC Position Paper. Geneva: International Committee of the Red Cross. Available at: https://www.icrc.org/en/document/international-humanitarian-law-and-cyber-operations-during-armed-conflicts (Accessed: 26 September 2026).
International Committee of the Red Cross (2026) ‘Frequently Asked Questions: IHL and the escalating conflict in the Middle East’ [online]. Available at: https://ir.icrc.org/en/2026/03/frequently-asked-questions-ihl-and-the-escalating-conflict-in-the-middle-east/ (Accessed: 26 September 2026).
International Criminal Court (2002) Elements of Crimes, ICC-ASP/1/3 (Part II-B), adopted 9 September 2002. Available at: https://www.icc-cpi.int/sites/default/files/iccdocs/PIDS/publications/ElementsOfCrimesEng.pdf (Accessed: 26 September 2026).
International Criminal Court (n.d.) ‘Ukraine’ [online]. Available at: https://www.icc-cpi.int/situations/ukraine (Accessed: 26 September 2026).
Melzer, N. (2019) International Humanitarian Law: A Comprehensive Introduction. Geneva: International Committee of the Red Cross. Available at: https://library.icrc.org/library/docs/DOC/icrc-4231-002-2019.pdf (Accessed: 26 September 2026).
Protocol Additional to the Geneva Conventions of 12 August 1949, and relating to the Protection of Victims of International Armed Conflicts (Protocol I) (1977) adopted 8 June 1977, entered into force 7 December 1978, 1125 UNTS 3. Available at: https://ihl-databases.icrc.org/en/ihl-treaties/api-1977 (Accessed: 26 September 2026).
Reuters (2026) ‘Russia’s attacks disrupt internet services to 100,000 households in Kyiv, Ukrainian ministry says’, 23 September [online]. Available at: https://www.internazionale.it/ultime-notizie-reuters/2026/09/23/russia-s-attacks-disrupt-internet-services-to-100-000-households-in-kyiv-ukrainian-ministry-says (Accessed: 26 September 2026).
Rome Statute of the International Criminal Court (1998) adopted 17 July 1998, entered into force 1 July 2002, 2187 UNTS 3. Available at: https://www.icc-cpi.int/sites/default/files/2024-05/Rome-Statute-eng.pdf (Accessed: 26 September 2026).
Ukrainska Pravda (2026) ‘Russia destroys another data centre in Kyiv, recovery timeframe unclear’, 24 September [online]. Available at: https://www.pravda.com.ua/eng/news/2026/09/24/8054904/ (Accessed: 26 September 2026).
United Nations (2024) Rome Statute of the International Criminal Court, Rome, 17 July 1998: Ukraine: Ratification, Depositary Notification C.N.440.2024.TREATIES-XVIII.10, 25 October. Available at: https://treaties.un.org/doc/Publication/CN/2024/CN.440.2024-Eng.pdf (Accessed: 26 September 2026).




