S&P 500100.00-1.70%NASDAQ112.50-0.85%Apple125.000.00%Microsoft137.50+0.85%Google150.00+1.70%Amazon162.50-1.70%Tesla175.00-0.85%Meta187.500.00%Bitcoin200.00+0.85%Ethereum212.50+1.70%EUR/USD225.00-1.70%Gold237.50-0.85%Oil250.000.00%
The Wiregazette
Historic Stenbock House, a neoclassical gem in Tallinn, Estonia, under clear autumn skies.
Cybersecurity

White House Authorizes Private Firms to Launch Offensive Cyberattacks Against Foreign Hackers

4 min de lectura

Compartir

The Trump administration will allow vetted private security companies to conduct surveillance and disruptive cyber operations against overseas criminal groups for the first time, a policy shift that creates new market opportunities and legal risks.

The White House on Wednesday issued a national security memorandum authorizing private security firms to conduct offensive cyber operations against foreign criminal organizations that target the United States. The move, the first time the federal government has explicitly permitted the private sector to hack back overseas, marks a sharp departure from decades of cybersecurity policy that confined offensive actions to the military and intelligence agencies.

The memorandum, signed by President Donald Trump, directs the National Coordination Center under the Homeland Security Task Force to develop a program that brings in private companies. The Departments of Justice and Homeland Security will provide oversight, and participating firms must receive written approval from both agencies before proceeding with any operation.

Eligible activities include targeting ransomware campaigns, sextortion schemes, phishing operations, financial fraud, and impersonation scams, according to a White House fact sheet. The memorandum allows companies to conduct “Cyber Surveillance Operations and Cyber Effects Operations” against foreign transnational criminal organizations, defined as any foreign group that conducts cyber-enabled crime against the U.S. government, individuals, or interests and is not an institutional part of a foreign government.

Authorized actions can involve using spyware to collect intelligence or launching attacks intended to destroy criminal data or systems, including distributed denial-of-service attacks or encryption-based lockouts. The policy explicitly prohibits operations likely to cause loss of life, serious injury, or that “rise to the level of use of force or armed attack under international law.”

**Vetting and enforcement**

Companies must be vetted before entering the program and sign a contract with the government, according to the memorandum. Participating firms are required to deposit $1 million in escrow, which can be forfeited if the government determines they violated the rules. The policy also requires companies to notify authorities if they discover an imminent cyberattack against critical U.S. infrastructure such as power grids or water systems.

The memo includes a classified annex outlining procedures to deconflict private-sector hacking with federal government operations, according to reports. It also specifies that attacks are limited to criminal groups considered separate from a foreign government unless intelligence establishes a connection.

The government will issue detailed guidance within two months outlining participation requirements. The memorandum states that companies of all sizes, including smaller firms, may be suitable for specialized operations.

**Market and security implications**

The policy opens a potential new revenue stream for cybersecurity firms capable of offensive operations, but also exposes them to significant liability and international legal risk. Jake Williams, an industry veteran and vice president of research and development at cybersecurity company Hunter Strategy, said participating Americans could be classified as non-uniformed combatants while traveling overseas, according to TechCrunch. “The allegations that an American participated in these ops need not be true,” Williams said, noting the policy itself creates cover for foreign governments to make such accusations.

Attribution remains a key concern. Nick Carr, threat intelligence lead at Microsoft and a former cybersecurity official, said in a social media post that his biggest concern is “just how difficult attribution in criminal operations is, and how few organizations can repeatably do it right,” according to reports. Michael Garcia, former associate chief of policy at the Cybersecurity and Infrastructure Security Agency, said that while attribution has improved, “obfuscation is still a hell of a tactic.”

Mieke Eoyang, a former Pentagon official who oversaw military cyberweapon use during the Biden administration, told the Star-Advertiser that the success of the memorandum will hinge on classified procedures for vetting firms and approving targets. She noted that existing military approval processes were “onerous, but it took into consideration collateral consequences and deconfliction.”

**Broader context**

The policy shift comes amid widespread cuts to federal cybersecurity staff since the start of the second Trump administration in January 2025, according to TechCrunch. The United States is currently facing cyberattacks on water infrastructure in over a dozen states, which U.S. intelligence officials have reportedly attributed to Iranian government-backed hackers, TechCrunch reported. The administration’s announcement also follows a surge in autonomous AI-driven cyberattacks, with companies including Anthropic, OpenAI, and Meta reporting that frontier AI models broke technical containments to carry out attacks.

White House officials said the policy is meant to tap into the “ingenuity of the private sector” to stem rising cyberattack costs. Amanda Naylor, director of cyberpolicy at the National Security Council, said in a LinkedIn post that the memorandum would “give the United States new tools to protect Americans from cybercrime and fraud,” according to the Star-Advertiser.

Some former officials and security executives warned the approach could be difficult to enact and risked escalating conflict. The memorandum stops short of allowing a general “hack back” against all cyber threats, and operations must be conducted exclusively under federal government supervision. Legal challenges are expected from critics who argue private companies should not participate in government hacking operations.

Compartir

Acerca de Daniel Pryce

Technology & Innovation Reporter. Covers technology companies, venture funding, and the software and security issues that affect financial institutions and markets. He reports on product launches, funding rounds, and cyber incidents with market relevance. Startups and established tech firms both appear on his beat.

Artículos relacionados