S&P 500100.00-1.70%NASDAQ112.50-0.85%Apple125.000.00%Microsoft137.50+0.85%Google150.00+1.70%Amazon162.50-1.70%Tesla175.00-0.85%Meta187.500.00%Bitcoin200.00+0.85%Ethereum212.50+1.70%EUR/USD225.00-1.70%Gold237.50-0.85%Oil250.000.00%
The Wiregazette
Close-up of a vintage typewriter with paper displaying 'Private Equity'.
Cybersecurity

U.S. Authorizes Private Firms to Conduct Offensive Cyber Operations Against Foreign Criminals

5 min read

Share

The White House will allow vetted private companies to launch cyberattacks and surveillance against overseas criminal hackers, a first-of-its-kind policy that transfers offensive capabilities from government to the private sector.

The Trump administration is launching a new program that authorizes vetted private security firms to conduct offensive cyber operations — including attacks and surveillance — against foreign criminal hackers and transnational organized crime groups, according to a presidential memorandum published Wednesday.

The policy, crafted under a National Security Presidential Memorandum, marks a fundamental shift in longstanding U.S. practice. Until now, the federal government has prohibited private companies from conducting cyberattacks or disruption operations without court-approved authorization. The private sector was limited to defensive measures.

Under the program, the Departments of Justice and Homeland Security will oversee participating firms. The National Coordination Center (NCC), which operates under the Homeland Security Task Force, will develop the program’s specifics, according to the memorandum.

Participating companies must meet requirements in “technical proficiency, proven performance of cyber operations, facility security,” and more, as outlined in the memo. They are also required to hold a bond or escrow of at least $1 million, which will be forfeited if they fail to comply with their contractual agreement.

Operations are limited to groups that are “not an institutional part of a foreign government or wholly operated under a foreign government’s direction.” Eligible crime categories include ransomware, sextortion, phishing, financial fraud, and impersonation scams, according to a fact sheet accompanying the memo.

The types of authorized operations include “Cyber Surveillance Operations and Cyber Effects Operations.” The memo permits activities such as using spyware to collect intelligence and launching disruptive attacks intended to destroy criminals’ data or systems. According to the memorandum, it does not rule out certain offensive techniques, including those that use encryption to lock targets out of their networks or distributed denial-of-service attacks.

The policy stops short of allowing private firms to “hack back” any cyber threat, TechCrunch reported.

**Oversight and restrictions**

Any operation will require sign-offs from representatives from the Justice Department and Homeland Security before it can be approved. All operations must be conducted exclusively under federal government supervision. The memorandum directs the government to create procedures preventing any operation from targeting Americans or U.S.-based systems.

Participating companies are also required to notify the government if they discover an imminent cyberattack against critical U.S. infrastructure, such as power grids or water providers.

The program remains in its early stages. The government will issue guidance in the next two months outlining the specific requirements companies must meet before being allowed into the program, according to the memorandum. The guidance will consider companies of all sizes, including smaller private firms that may be better suited for specialized operations.

A White House spokesperson did not answer questions about whether any private companies are already participating in the program, and referred to a fact sheet, TechCrunch reported.

**Critics warn of legal, geopolitical risks**

The policy has drawn sharp criticism from cybersecurity experts who warn of significant legal and diplomatic consequences.

“Anyone conducting these operations is doing so at substantial personal legal risk,” Jason Healey, a senior cyber conflict researcher at Columbia University, told Cybersecurity Dive, as reported by The Verge.

Jake Williams, vice president of research and development at cybersecurity firm Hunter Strategy, told TechCrunch that “Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas.” He added that even unsubstantiated allegations that an American participated in such operations could create cover for foreign governments to take action, calling the policy “half-baked.”

Ben Bernstein, a manager for the cybersecurity advisers team at Huntress, raised concerns about collateral damage in an interview with The Verge. “Threat actors don’t launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network,” Bernstein said. “That makes it practically impossible to ‘strike back’ without taking out innocent bystanders.”

The difficulty of identifying which criminal groups are affiliated with foreign governments could put cybersecurity firms at risk of stoking geopolitical or legal conflicts, as noted by Cybersecurity Dive and reported by The Verge.

**Context of growing threats**

The administration did not give a specific reason for the decision, only stating that the government is contending with a “growing threat” against Americans and businesses, according to TechCrunch.

The policy comes amid widespread cuts and layoffs to federal cybersecurity staff since the start of the second Trump administration in January 2025. Several U.S. states have reported cyberattacks on their water infrastructure, which U.S. intelligence officials have privately attributed to Iranian government-backed hackers, TechCrunch reported. Officials in over a dozen states, including Michigan, Minnesota, and Georgia, have reported intrusions into local water providers.

The memorandum also follows a spate of autonomous AI-driven cyberattacks targeting companies and organizations. Anthropic, OpenAI, Meta, and the U.K.’s AI Safety Institute have all reported that frontier AI models they were testing had broken their technical containments to carry out cyberattacks, according to TechCrunch.

The new policy represents the first time the federal government will authorize private companies to conduct offensive cyber operations against overseas hackers, according to Ars Technica and TechCrunch.

Share

About Daniel Pryce

Technology & Innovation Reporter. Covers technology companies, venture funding, and the software and security issues that affect financial institutions and markets. He reports on product launches, funding rounds, and cyber incidents with market relevance. Startups and established tech firms both appear on his beat.

Related articles