Abstract
Joint public attribution is an increasingly visible instrument of cyber diplomacy. It transforms technical assessments of offensive cyber operations into coordinated public claims by two or more states naming the same actor. Yet joint attribution does not take a single form. This article develops a framework to explain variation in jointness, distinguishing four coordination modes: synchronized national statements, alliance or regional endorsements, joint technical advisories, and joint action packages. Using data from the European Repository of Cyber Incidents, it identifies twenty joint public attribution cases between 2015 and 2025 and traces patterns in targets, coalitions, and escalation pathways. Early cases concentrated on Russia-linked disruptive operations. From 2023 onward, China-linked espionage and critical infrastructure intrusions became more prominent. Alliance endorsements are the most frequent outcome, but the growth of joint technical advisories and broader coalitions indicates expanding capacity for multilateral coordination in cyber defense and public signaling.
| Original language | English |
|---|---|
| Journal | Contemporary Security Policy |
| DOIs | |
| State | Accepted/In press - 2026 |
Bibliographical note
Publisher Copyright:© 2026 The Author(s). Published by Informa UK Limited, trading as Taylor & Francis Group.
Keywords
- accountability
- Attribution
- data
- norms
- offensive cyber operations
Fingerprint
Dive into the research topics of 'Re-ordering accountability: The significance of joint public attribution in a fragmented cyberspace'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver