Compare

Side-by-side comparison of cases across escalation, infrastructure, and governance dimensions. Select two or more cases to analyze commonalities and divergences.

Sample comparison (NotPetya vs Stuxnet). Pick cases from the sidebar to build your own — the URL updates so any comparison is shareable.

Same across casesDifferent or partial
NotPetya

June 2017 · Russia

DestructiveStrategic Impact
Stuxnet

circa 2007 – 2010 · United States / Israel

SabotageDestruction

Comparative Profile

0–100 · derived heuristic

Axes normalise each case to a 0–100 scale from the same heuristic fields used elsewhere in the Atlas (peak tier, sector/country spread, governance-response density, attribution strength, entanglement). A comparison aid, not a measurement.

Unpeace Score

Different
Stable
Contested
Escalatory
03060100
Stable
Contested
Escalatory
03060100

Key Metrics

Different

100

Unpeace

5

Entanglement

6/6

Peak Tier

90

Unpeace

4

Entanglement

5/6

Peak Tier

Escalation Profile

Attribution

Different
Confirmed

GRU (Main Intelligence Directorate)

SandwormVoodoo BearIRIDIUM
High Confidence

Widely attributed to a joint US–Israeli operation

Olympic Games

Target Sectors

Partial overlap
Multiple SectorsCritical Infrastructure

Ukraine, Global

EnergyCritical Infrastructure

Iran

Threshold Crossings

  • ·First cyber operation to cause >$10B in collateral economic damage
  • ·Indiscriminate global propagation beyond intended target set
  • ·First known cyber operation to cause physical destruction of industrial equipment
  • ·Demonstrated that cyber means can achieve strategic effects previously requiring kinetic action

Restraint Factors

  • ·Disguised as criminal ransomware, providing deniability
  • ·No direct military targeting
  • ·Highly targeted, designed to affect only specific Siemens S7-315/417 configurations
  • ·No broader disruption to Iranian civilian infrastructure intended

Governance Flags

Partial overlap
!Norm Violation
APublic Attribution
SSanctions Imposed
IIndictment
UUN Discussion
RRegulatory Change
CInternational Cooperation
DDeterrence Signal
!Norm Violation
APublic Attribution
SSanctions Imposed
IIndictment
UUN Discussion
RRegulatory Change
CInternational Cooperation
DDeterrence Signal

Governance Impact

Established precedent for multilateral public attribution of destructive cyber operations and highlighted supply chain risk as a policy priority.

Norms invoked

  • UN GGE 2015 norm against damaging critical infrastructure
  • Due diligence obligations (Tallinn Manual Rule 6)

Opened the global debate on whether cyber operations can constitute acts of force under international law, and catalyzed both defensive and offensive cyber investment worldwide.

Norms invoked

  • Sovereignty and non-intervention (UN Charter Art. 2(4) by analogy)
  • Debate over whether cyber sabotage constitutes a use of force

Key Question

When does a cyber operation targeting one country become a matter of international concern?

Does a cyber operation that causes physical destruction cross the use-of-force threshold under international law?