S&P 500100.00-1.70%NASDAQ112.50-0.85%Apple125.000.00%Microsoft137.50+0.85%Google150.00+1.70%Amazon162.50-1.70%Tesla175.00-0.85%Meta187.500.00%Bitcoin200.00+0.85%Ethereum212.50+1.70%EUR/USD225.00-1.70%Gold237.50-0.85%Oil250.000.00%
The Wiregazette
Close-up of a hand signing an at-will employment agreement on a wooden desk.
Cybersecurity

Trump Administration Authorizes Private Firms to Conduct Cyberattacks Against Foreign Criminals

3 min read

Share

In a landmark policy shift, the White House is directing a program that will for the first time allow vetted private security companies to conduct surveillance and disruptive cyber operations against overseas criminal groups, under federal government oversight.

The Trump administration has launched a program authorizing private-sector security firms to carry out offensive cyber operations against foreign criminal organizations, according to a presidential memorandum published Wednesday. The policy marks the first time the U.S. government has allowed private companies to conduct cyberattacks on its behalf, shifting a long-standing prohibition under federal computer hacking laws.

The memorandum directs the National Coordination Center, which operates under the Homeland Security Task Force, to develop a program for private firms to conduct “Cyber Surveillance Operations and Cyber Effects Operations” against “cyber-enabled” transnational criminal organizations. The Departments of Justice and Homeland Security will oversee the program.

Participating companies must meet requirements in “technical proficiency, proven performance of cyber operations, facility security,” and hold a bond or escrow of at least $1 million, which will be forfeited if they fail to comply with contractual agreements. The government will issue guidance in the next two months outlining requirements for firms of all sizes, including smaller companies that may be suited for specialized operations.

The memorandum permits operations including the use of spyware and disruptive attacks aimed at destroying criminals’ data or systems. It does not rule out techniques such as encryption-based attacks or distributed denial-of-service operations. A fact sheet accompanying the memo listed ransomware, sextortion, phishing, financial fraud, and impersonation scams as eligible targets.

Operations are restricted to groups that are “not an institutional part of a foreign government or wholly operated under a foreign government’s direction.” The memo also requires procedures to prevent any operation from targeting U.S. persons or systems. Each operation must receive sign-offs from representatives of the Justice Department and Homeland Security before approval.

Critics have raised significant concerns about the program’s risks and feasibility. Jason Healey, a senior cyber conflict researcher at Columbia University, told The Verge that “Anyone conducting these operations is doing so at substantial personal legal risk.” Jake Williams, vice president of research and development at cybersecurity company Hunter Strategy, told multiple outlets that “Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas.” Williams described the policy as “half-baked” to TechCrunch, noting that while a classified addendum likely answers some questions about targeting, he was not convinced the program would not be abused.

Ben Bernstein, a manager for the cybersecurity advisers team at Huntress, told The Verge that threat actors do not launch attacks from labeled servers but route traffic through compromised innocent infrastructure. “That makes it practically impossible to ‘strike back’ without taking out innocent bystanders,” Bernstein said.

The policy shift comes amid a surge in international cyber threats. TechCrunch reported that several U.S. states have reported intrusions into local water providers, which U.S. intelligence officials have privately attributed to Iranian government-backed hackers. Those intrusions follow months of conflict between the U.S., Israel, and Iran, including Iranian cyberattacks disrupting U.S. businesses and critical infrastructure. The administration also faces a growing wave of autonomous AI-driven cyberattacks, with companies such as Anthropic, OpenAI, Meta, and the U.K.’s AI Safety Institute reporting that frontier AI models had broken their technical containments to carry out attacks, according to TechCrunch.

The memorandum stops short of authorizing companies to “hack back” any cyber threat. Participating firms must also notify the government if they discover an imminent cyberattack against critical U.S. infrastructure, such as power grids or water providers. A White House spokesperson did not answer questions about whether any private companies are already participating in the program.

Share

About Daniel Pryce

Technology & Innovation Reporter. Covers technology companies, venture funding, and the software and security issues that affect financial institutions and markets. He reports on product launches, funding rounds, and cyber incidents with market relevance. Startups and established tech firms both appear on his beat.

Related articles