Experts weigh inWhy is state involvement in cyberattacks so difficult to prove?

Cédric Ferry
adapted for RTL Today
Technical data alone cannot reliably determine whether a state actor is behind a cyberattack.
© SILAS STEIN / dpa Picture-Alliance via AFP

Cyberattacks on public institutions, national infrastructure, and the companies that supply essential services have become a regular fixture in the headlines, and increasingly so.

Luxembourg, too, has had its share with the 2023 attack on POST still fresh in many minds, and more recent cases including a phishing attack on government systems, as well as a data breach at the Chamber of Employees around National Day. In each instance, though, authorities have withheld information on who was responsible for the attacks.

Such restraint stands in contrast to how quickly blame is assigned elsewhere. When EU institutions, state bodies, or critical infrastructure is hit, Russia or Russia-linked groups are often floated as suspects within days. For instance, a coordinated cyberattack on several water infrastructure systems in Minnesota, US, was quickly attributed to Iranian hackers, even when Minnesotan IT services weren't naming any responsible actors yet.

Hackers can erase their tracks

Experts caution that speed should not be mistaken for certainty. In discussions organised by the German Science Media Centre, three specialists in cybersecurity and encryption stressed how technically difficult it is to identify the originator of an attack with confidence.

In theory, digital traces such as router logs, timestamps, or IP addresses, can point back to a source. But in practice, there are significant obstacles: The infrastructure involved is usually spread across several countries and providers, so any investigation depends on bureaucratic international cooperation that some states simply refuse to give.

In addition, log files can be overwritten, and attackers have a series of tools for covering their tracks: IP spoofing disguises location, while VPNs and networks such as Tor reroute traffic to hide its origin.

Attacks are also frequently launched from machines infected with malware, meaning the device an attack appears to come from often has nothing to do with the actual perperator.

Professor Jörn Müller-Quade of the Karlsruhe Institute of Technology notes that because attacks can be run from compromised computers, the apparent point of origin says little about who is really responsible. Other clues, such as Russian words in the code, can just as easily be planted. That makes almost any attribution hard to substantiate.

State involvement rarely provable beyond doubt

The issue deepens when the question is not who, but on whose orders. According to the European Repository of Cyber Incidents’ 2025 report, most attributable cyberattacks on EU member states were linked to Russia or China, with 32 linked to Russian actors and four to Chinese ones. Yet, the authors caution that with Russian attacks in particular, it is especially hard to separate state-directed operations from those carried out by nominally independent groups.

Technical data alone cannot settle that distinction, says Dr Tibor Jager, Professor of IT Security and Cryptography at the University of Wuppertal. Whether a group acts autonomously, with state backing, or under direct orders cannot be read off the technical evidence. Sharper assessments come from elsewhere: funding sources, communication structures, personal networks, and known ties to state officials.

This is why attribution is ultimately a judgment rather than proof, as it rests on technical findings, recurring patterns, the programming languages used, the timing of code development, or intelligence reporting.

When the source is political, published evidence is often scarce, and accusations against an entire state are rarely open to independent verification. Even where technical data backs them, Jager notes, the reasoning is seldom transparent to the public. In the EU's view, he adds, attributing an attack to a state is a political decision, informed by technical evidence and intelligence, but not a public trial, which is why much of the underlying information stays classified.

Communicating uncertainty without giving perpetrators a free pass

Nonetheless, the suspicions aren't unfounded either. There is strong evidence that Russia, along with China, Iran, and North Korea, regularly run international cyber operations, says Dr Thorsten Holz of the Max Planck Institute for Security and Privacy in Bochum.

Those attributions come from multiple governments, agencies, and private firms, and are backed by indictments, sanctions, and sometimes the naming of individual intelligence operatives.

Still, the difficulty is the grey zone between hackers acting on government orders and criminals whose activities the state merely tolerates. This ambiguity enables perpetrators to deny their involvement, says Dr Müller-Quade, which is why it is crucial for media and officials to state the uncertainties plainly.

Dr Holz makes the same point from the other side: claims of the state may well be correct even when they cannot be proven, and it would be naive to dismiss, say, Russian involvement, simply because absolute proof is missing. A healthy scepticism cuts both ways.

The task, in the end, is to be honest about how difficult state involvement is to prove, without handing the states suspected of ordering these attacks an opportunity to sow doubt.

Back to Top
CIM LOGO