All cases

Stuxnet

circa 2007 – 2010

Record reviewed: 2026-07

SabotagePeak: DestructionAttribution: High ConfidenceEnergyCritical Infrastructure
Year
2010
Actor country
United States / Israel
Target regions
Iran
Unpeace score
9

Executive Summary

A precision cyber weapon that targeted Siemens SCADA systems controlling uranium-enrichment centrifuges at Iran's Natanz facility. It caused physical destruction of centrifuges while reporting normal telemetry to operators. Widely regarded as the first publicly known cyber operation to cause physical damage to industrial equipment.

Why This Matters

Stuxnet proved that software alone can destroy physical infrastructure, fundamentally changing how states, lawyers, and strategists think about the threshold between cyber operations and armed conflict.

Escalation Profile

7-Dimension Profile

Escalation Ladder

Probing
Intrusion
Disruption
Degradation
Destruction
Strategic

Phases

2007
Intrusion

Air-gapped network penetration

Malware introduced via removable media into an air-gapped industrial control network.

2008
Degradation

Centrifuge manipulation

Altered PLC code caused centrifuges to spin outside safe parameters while masking anomalies from monitoring systems.

2009-2010
Destruction

Physical equipment damage

Approximately 1,000 IR-1 centrifuges destroyed, temporarily setting back Iran's enrichment program.

Threshold Crossings

  • First known cyber operation to cause physical destruction of industrial equipment
  • Demonstrated that cyber means can achieve strategic effects previously requiring kinetic action

Restraint Factors

  • Highly targeted, designed to affect only specific Siemens S7-315/417 configurations
  • No broader disruption to Iranian civilian infrastructure intended

Attribution Assessment

High ConfidenceWidely attributed to a joint US–Israeli operation
United States / Israel
Olympic Games
1. Technical

Threat actor mapped to United States / Israel based on infrastructure analysis, malware attribution, and operational patterns.

Evidence: Falliere, Murchu & Chien (Symantec): W32.Stuxnet Dossier; Ralph Langner, 'To Kill a Centrifuge'; Ralph Langner, 'Stuxnet: Dissecting a Cyberwarfare Weapon,' IEEE Security & Privacy 9(3)

2. Political / Legal
No formal state response
  • Accelerated international discussion of cyber norms (UN GGE 2013 mandate)
  • Iran expanded its own offensive cyber program in the years following

Sources: ICS-CERT Advisory ICSA-10-272-01

3. Open Source
  • David E. Sanger, 'Obama Order Sped Up Wave of Cyberattacks Against Iran,' The New York Times(2012-06-01)

High Confidence” reflects available public evidence. All assessments carry inherent uncertainty and should be read alongside source material.

Unpeace Position

9

Unpeace Score

Composite severity rating on the peace–conflict spectrum (1–10)

Stable
Contested
Escalatory
03060100

Unpeace · score breakdown

9/10
Escalation peak5 × 1.2 = +6

Peak tier reached (destruction), ranked 1–6.

Threshold crossings2 × 1 = +2

Distinct escalation thresholds the operation crossed.

Governance weight2 × 0.5 = +1

Formal governance responses flagged (attribution, sanctions, indictments…).

Raw sum 9= 9/10

round( escalationPeak×1.2 + crossings×1 + governance×0.5 ), capped at 10. These weights are an interpretive heuristic, not a validated metric — see the scoring methodology for rationale and limits.

Entanglement · score breakdown

4/10
Sectors affected2 × 1 = +2

Distinct critical-infrastructure sectors touched.

Countries / regions1 × 1 = +1

Geographic spread of impact.

Threshold crossings2 × 1 = +2

Escalation thresholds crossed (collateral-spread proxy).

Baseline offset1 × -1 = -1

Constant offset so a single-sector, single-country event floors at 1.

Raw sum 4= 4/10

clamp( sectors + countries + crossings − 1, 1, 10 ). These weights are an interpretive heuristic, not a validated metric — see the scoring methodology for rationale and limits.

Coercive Function

Sabotage

Physical or functional disruption of systems, coercive value through demonstrating capability to cause real-world harm.

Observed coercive effects

  • First known cyber operation to cause physical destruction of industrial equipment
  • Demonstrated that cyber means can achieve strategic effects previously requiring kinetic action

Entanglement Risk

Entanglement score4

Sectors affected

EnergyCritical Infrastructure

Countries / regions

Iran

Impact summary

~1,000 IR-1 centrifuges destroyed at Natanz; temporary disruption to Iran's uranium enrichment timeline.

Infrastructure Meaning

Malware / tooling

Stuxnet

Capability profile

~1,000 IR-1 centrifuges destroyed at Natanz; temporary disruption to Iran's uranium enrichment timeline.

4 ATT&CK techniques mapped — see ATT&CK mapping below.

Governance Analysis

Governance Flags

!Norm Violation
APublic Attribution
SSanctions Imposed
IIndictment
UUN Discussion
RRegulatory Change
CInternational Cooperation
DDeterrence Signal

Norms invoked

  • Sovereignty and non-intervention (UN Charter Art. 2(4) by analogy)
  • Debate over whether cyber sabotage constitutes a use of force

Policy responses

  • Accelerated international discussion of cyber norms (UN GGE 2013 mandate)
  • Iran expanded its own offensive cyber program in the years following

Regulatory changes

  • Increased ICS/SCADA security guidance from NIST and ICS-CERT
  • Heightened focus on air-gap integrity in critical infrastructure policy

Governance impact assessment

Opened the global debate on whether cyber operations can constitute acts of force under international law, and catalyzed both defensive and offensive cyber investment worldwide.

Rules whose application to this operation is debated in the literature. These are analytical questions, not findings — the Atlas records where a case sits in legal debate, it does not adjudicate legality (see methodology §09).

Tallinn Manual 2.0

  • Rule 32, Proportionality

    Targeted sabotage with limited collateral is often cited as proportionate; uncontrolled spread outside Iran complicates this assessment

UN Charter

  • Article 2(4), Prohibition on the Use of Force

    Physical destruction of centrifuges is the strongest candidate for a cyber 'use of force' in the dataset

Geneva Conventions / IHL

  • Precaution in Attack

    Designed with targeting constraints but still spread beyond Natanz, testing precautionary obligations

Explore the full Legal Mapper

Sources

Sources listed reflect publicly available materials used to construct this case entry. Inclusion does not imply endorsement. Where no URL is provided, the source may be found via its title and date.