Oxford Statement on the International Law Protections Against Cyber Operations Targeting the Health Care Sector

Many have recently written about the application of international law in cyberspace and to the global COVID-19 pandemic, but relatively few have examined the intersection between these two areas. Notwithstanding that oversight, recent weeks have seen cyberattacks on organizations at the frontline of the response to the COVID-19 pandemic, including malicious cyber operations against the World Health Organization, medical providers, research institutes, pharmaceutical manufacturers, hospitals and hospital networks. In response to these attacks, the European Union issued a statement in which "the European Union and its Member States call[ed] upon every country to exercise due diligence and take appropriate actions against actors conducting such activities from its territory, consistent with international law". Twelve other countries aligned themselves with this declaration. In late March, three authors from the International Committee of the Red Cross (ICRC), writing in their personal capacities, examined the international law protections prohibiting cyberattacks against medical facilities during the pandemic. These events triggered a two-day virtual workshop at the University of Oxford—co-sponsored by the Oxford Institute…

