2025 Conference on International Cyber Security | 4-5 November 2025
Register now

Alice Ternacle

Alliance over Evidence: How Credibility Replaces Law in Cyber Attribution

States have collectively agreed that attributions should be substantiated, yet they generally fail to abide by this standard. States are moving from a requirement of proof to a graduated approach of credibility within their attributions. Within political attributions, credibility is a measure of degree defined by the trust that external actors place in a state's attribution. Western states have developed credibility-based attributions through alliance coordination to fill the legal vacuum. I argue that credibility functions as a de facto standard in the absence of binding attribution law. Credibility is awarded to an attribution when several sources reach the same conclusion, which can involve several States collectively attributing the same cyberattack or corroborating one State's attribution. But because these sources are predominantly Western allies, credibility-based attribution politicizes international law. Thus, legitimacy depends on alignment with Western alliances rather than legal standards. If this logic seems to solve fragmentation, it risks reinforcing asymmetry in international law. Through a case-study analysis, namely of the WannaCry, NotPetya and the 2021/22 Albania Cyberattacks, this paper examines how credibility is constructed with and without evidentiary support, and how it influences the legitimacy of cyber attribution. Credibility works well for the West, allowing attribution without publicly sharing evidence. However, it does not replace legal requirements and risks deepening the fracture between Western and non-Western approaches to cyber norms.