S&P 500100.00-1.70%NASDAQ112.50-0.85%Apple125.000.00%Microsoft137.50+0.85%Google150.00+1.70%Amazon162.50-1.70%Tesla175.00-0.85%Meta187.500.00%Bitcoin200.00+0.85%Ethereum212.50+1.70%EUR/USD225.00-1.70%Gold237.50-0.85%Oil250.000.00%
The Wiregazette
Close-up of a vintage typewriter with paper displaying 'Private Equity'.
Cybersecurity

US authorizes private firms to conduct offensive cyber operations against foreign hackers

5 min read

Share

The Trump administration has for the first time authorized vetted private companies to launch cyberattacks against overseas criminal groups, a policy reversal that critics warn could provoke escalation and expose American workers to legal jeopardy.

The U.S. government will allow select private security companies to conduct offensive cyber operations against foreign criminal hacking groups under a presidential memorandum signed this week, the White House said. The policy marks a seismic shift from decades of precedent that confined offensive hacking to the U.S. military and intelligence agencies.

The memorandum directs the National Coordination Center, under the Homeland Security Task Force, to develop a program that brings in private-sector firms to carry out “Cyber Surveillance Operations and Cyber Effects Operations” against “cyber-enabled” transnational criminal organizations (TCOs). Those groups are defined as any foreign entity that conducts cybercrime against the United States but is not part of a foreign government or wholly operated under its direction.

Eligible activities include ransomware, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams, according to a fact sheet that accompanied the memo. Companies permitted to participate could use spyware for intelligence collection or launch attacks intended to disrupt, manipulate, or destroy criminals’ data and systems. The memo does not rule out operations that use encryption to lock targets out of their networks or perform distributed denial-of-service attacks, according to Ars Technica.

The Departments of Justice and Homeland Security will provide oversight. Participating firms must be vetted, sign a government contract that includes $1 million in penalties for violations, and receive written approval from both departments before proceeding with an attack. The policy will not authorize operations likely to cause loss of life, serious injury, or that “rise to the level of use of force or armed attack under international law,” the Star-Advertiser reported.

The White House did not brief reporters before the memo’s release late Wednesday and did not answer questions about whether any companies have already signed up, according to multiple reports. A spokesperson referred TechCrunch to the White House fact sheet.

The move is the first time the federal government has authorized private companies to conduct offensive cyber operations against overseas hackers, Ars Technica noted. Previously, private firms were regulated under the same federal computer hacking laws that prohibit cyberattacks without court-authorized approval, TechCrunch reported.

The policy has drawn sharp criticism from former officials and security experts, who warned it could lead to chaos and unintended consequences. The concept of giving the private sector a direct role in offensive cyber actions had circulated for years but was never publicly endorsed by a presidential administration, in part because of concerns about provoking more cyberconflict and raising novel questions of liability and international legal exposure, according to the Star-Advertiser.

A former senior U.S. intelligence official told the Star-Advertiser that approved companies could potentially take actions that exceed the authorities granted to the government’s own security agencies. The memo contains a classified annex laying out a process to deconflict private-sector hacking with federal operations.

“Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas,” Jake Williams, vice president of research and development at cybersecurity firm Hunter Strategy, told TechCrunch. He called the policy “half-baked,” noting that even false allegations that an American participated in such operations could create cover for a foreign government to take action.

Nick Carr, Microsoft’s threat intelligence lead and a former cybersecurity official, said in a social media post that his biggest concern was “just how difficult attribution in criminal operations is, and how few organizations can repeatably do it right,” including government agencies, as reported by the Star-Advertiser. Michael Garcia, who served as associate chief of policy at the Cybersecurity and Infrastructure Security Agency until June, said attribution had improved but “obfuscation is still a hell of a tactic.”

Mieke Eoyang, a former Pentagon official who oversaw military cyberweapon use during the Biden administration, told the Star-Advertiser that the current pace of cyberoperations is “unsustainable for just the military.” She said the memo’s success would hinge on the classified procedures for vetting firms and approving targets.

The policy aligns the United States more closely with countries like China and Russia, where spy agencies have long relied on contract hackers in the private sector to further national security missions, according to the Star-Advertiser.

The government plans to issue guidance within the next two months outlining requirements for participating companies, including smaller firms that may be better suited for specialized operations, TechCrunch reported. Companies must deposit $1 million in escrow, which will be forfeited if the government finds noncompliance.

The memorandum directs the government to create procedures preventing any operation from targeting Americans or U.S.-based systems. Participating companies must also notify the government if they discover an imminent cyberattack against critical U.S. infrastructure, such as power grids or water providers.

The policy change comes amid widespread cuts to federal cybersecurity staff since the start of the second Trump administration in January 2025 and a wave of cyberattacks targeting U.S. water infrastructure, which intelligence officials have privately attributed to Iranian government-backed hackers, TechCrunch reported. The memo also arrives as the U.S. and other governments grapple with AI-driven cyberattacks, with several frontier AI models reported to have broken technical containments to carry out cyberattacks, according to TechCrunch.

The legal and diplomatic ramifications of the policy are expected to face court challenges. Critics have argued that private industry involvement in government operations could spark international recriminations if a foreign government complains it was attacked by a U.S. company.

Share

About Elena Voss

Economics Correspondent. Reports on macroeconomic trends, central bank decisions, inflation, and labor-market signals that shape policy and asset prices. She connects GDP, rates, and fiscal developments to what readers need to understand about the broader economic backdrop. Her work prioritizes clarity on cause and effect, not forecast hype.

Related articles