US Opens Door for Private Firms to Hack Foreign Cybercriminals in Landmark Policy Shift
The Trump administration will for the first time authorize vetted private companies to conduct offensive cyber operations against foreign criminal hacking groups, a reversal of decades of policy that experts say could unleash new capabilities but also risks spiraling out of control.
WASHINGTON — President Donald Trump signed a national security memorandum on Wednesday directing the Departments of Justice and Homeland Security to allow select US private-sector firms to carry out cyberattacks and intelligence-gathering operations against foreign transnational criminal organizations.
The policy marks the first time the federal government has authorized private companies to launch offensive cyber operations that were previously limited to US military and intelligence agencies. Under current law, private firms are subject to the same computer hacking prohibitions as individuals.
The memorandum, issued as a National Security Presidential Memorandum, tasks the National Coordination Center (NCC) under the Homeland Security Task Force with developing the program. According to a White House fact sheet, eligible targets include ransomware gangs, sextortion schemes, phishing campaigns, financial fraud operations, and impersonation scams.
Participating companies must be vetted, sign a contract, and post a bond of at least $1 million — funds that can be forfeited if a firm violates program rules. Each operation requires prior written approval from officials at the Justice Department and Homeland Security. The policy explicitly excludes any action likely to cause death, serious injury, or that meets the threshold of "use of force" under international law.
The White House cited the economic toll of cybercrime, saying ransomware, sextortion, and online fraud cost Americans more than $20 billion in 2025.
The memorandum allows companies to conduct "Cybersecurity Surveillance Operations and Cyber Effects Operations," including deploying spyware to gather intelligence or launching disruptive attacks intended to destroy or manipulate criminals' data and systems. The document does not rule out techniques such as denial-of-service attacks or using encryption to lock targets out of their networks.
A classified annex is included to lay out a deconfliction process ensuring private-sector hacking does not interfere with government operations.
**Experts divided; privateering parallel drawn**
The policy has drawn comparisons to 18th-century maritime privateering, where governments commissioned private ships to raid enemy vessels.
Ari Redbord, a former federal prosecutor now head of policy at analytics firm TRM Labs, said the approach makes sense in the digital age. "The private sector holds the data. The public sector holds the authorities," and the memorandum "puts them together," he told multiple outlets including AFP and The Taipei Times. He argued that modern oversight is far more continuous: "Oversight that used to end at the dock now runs alongside the operation from start to finish."
Other experts are skeptical. Alan Woodward, a cybersecurity professor at the University of Surrey, told AFP: "You can hand out a commission. You can't hand out obedience." He added, "History's verdict on privateering wasn't that it was immoral. It was that it became more trouble than it was worth."
**Reversal from earlier stance**
The initiative represents a notable policy reversal. According to The Record, a senior US official said in March the administration was "not interested in fighting pirates with pirates." National Cyber Director Sean Cairncross previously ruled out using the private sector for such efforts, per CyberScoop. It remains unclear what prompted the change in direction.
**Operational and oversight concerns**
Jason Healey, a Columbia University researcher and former cybersecurity official under President George W. Bush, said the program appears to have guardrails. "They're backing this by the rule of law, and so I don't feel like this is something crazy," he told AFP. However, he expressed concern that the administration has "systemically weakened those organizations that might provide oversight, like the Office of the Director of National Intelligence."
Tech giants including Microsoft and Google are already heavily engaged in defensive cybersecurity. Under the new program, they could go further and operate without judicial oversight, under government supervision alone. Microsoft declined to comment; Google did not respond to a request for comment.
Nick Carr, threat intelligence lead at Microsoft and a former cybersecurity official, said in a social media post that his biggest concern is "just how difficult attribution in criminal operations is, and how few organizations can repeatably do it right," according to the Honolulu Star-Advertiser. Michael Garcia, former associate chief of policy at CISA, noted that "obfuscation is still a hell of a tactic."
Jake Williams, vice president of research and development at cybersecurity firm Hunter Strategy, told TechCrunch that the policy could put US participants at legal risk abroad. "Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas," he said. He called the policy "half-baked," adding that the classified annex likely addresses some questions but he is not convinced the program will not be abused.
Woodward warned that any company participating "stops being a neutral defender and becomes a target."
**Implementation timeline and unanswered questions**
The administration has 60 days to finalize program details, though some aspects will remain classified. The White House did not respond to questions beyond stating operations would be "based on intelligence," and did not brief reporters before the order's release.
The memorandum prohibits operations targeting US persons or systems. Companies must notify the government if they discover an imminent cyberattack against critical infrastructure such as power grids or water providers.
Long-term concerns include the potential for "a slow accumulation of misattributed targets, foreign prosecutions and diplomatic headaches," Woodward said. Redbord offered a pragmatic view: "Short of victims getting funds back, none of the rest counts for much."
The policy shift comes amid ongoing Iranian-linked cyberattacks on US water infrastructure and a rise in autonomous AI-driven cyberattacks reported by Anthropic, OpenAI, Meta, and the UK's AI Safety Institute, according to TechCrunch. The US has also faced widespread cuts to federal cybersecurity staffing since the start of the second Trump administration in January 2025.
The memorandum does not yet name any participating companies, and the White House declined to say whether any are already involved.
Related articles
You might also like




