S&P 500100.00-1.70%NASDAQ112.50-0.85%Apple125.000.00%Microsoft137.50+0.85%Google150.00+1.70%Amazon162.50-1.70%Tesla175.00-0.85%Meta187.500.00%Bitcoin200.00+0.85%Ethereum212.50+1.70%EUR/USD225.00-1.70%Gold237.50-0.85%Oil250.000.00%

 

The Wiregazette
Historic Stenbock House, a neoclassical gem in Tallinn, Estonia, under clear autumn skies.
Cybersecurity

White House Authorizes Private Firms to Hack Foreign Cybercriminals in Major Policy Shift

5 分钟阅读

分享

The Trump administration has directed federal agencies to allow vetted private companies to conduct offensive cyber operations against foreign criminal hackers, a move experts warn could spark diplomatic backlash and create new risks for participating firms.

The Trump administration will for the first time permit private cybersecurity companies to conduct surveillance and disruptive cyberattacks against foreign criminal hacking groups, a dramatic departure from decades of U.S. policy that confined offensive operations to government agencies.

President Donald Trump signed a national security memorandum on Wednesday directing the Departments of Justice and Homeland Security to develop a program allowing select private firms to target transnational criminal organizations (TCOs) that hack U.S. persons, organizations, or government entities. The White House cited damage from ransomware, sextortion, financial fraud, and online scams, which it said cost Americans more than $20 billion in 2025.

Under the memorandum, participating companies may conduct "Cyber Surveillance Operations and Cyber Effects Operations," including deploying spyware to collect intelligence and launching attacks aimed at disrupting, manipulating, or destroying criminals' data or systems. Eligible activities include ransomware, sextortion schemes, phishing campaigns, impersonation scams, and other cyber-enabled crimes, according to a fact sheet that accompanied the order.

The policy marks a reversal from the government's long-standing position under federal computer hacking laws, which broadly prohibit the private sector from launching cyberattacks without court authorization. Prior administrations, both Republican and Democratic, had maintained that companies could defend against incoming attacks but could not initiate offensive operations.

### Program Details and Guardrails

Each operation requires prior written approval from officials at the Justice Department and Homeland Security. Participating companies must first be vetted and sign a contract with the government that includes a mandatory bond of at least $1 million, which will be forfeited for noncompliance with program rules.

Actions that could cause death or serious injury, or that would meet the threshold of "use of force" under international law, are explicitly excluded. The memorandum also directs the government to create procedures preventing operations from targeting Americans or U.S.-based systems.

The Trump administration has 60 days to finalize the program's details, and some aspects of the order remain classified. A classified annex lays out a process to deconflict private-sector hacking with federal government operations. The policy also requires participating companies to notify the government if they discover an imminent cyberattack against critical infrastructure such as power grids or water providers.

The memorandum is based on intelligence, the White House said, but did not identify any companies already involved or confirm participation. Microsoft declined to comment, and Google did not respond to requests for comment, according to multiple reports.

### Reactions from Experts and Former Officials

The approach draws parallels to 18th-century maritime privateering, where governments authorized private ships to raid enemy vessels.

"The private sector holds the data. The public sector holds the authorities," and the new memorandum "puts them together," said Ari Redbord, a former federal prosecutor now at TRM Labs, an analytics firm that works with U.S. authorities. "Oversight that used to end at the dock now runs alongside the operation from start to finish," Redbord said.

Other experts voiced deep skepticism. Alan Woodward, a cybersecurity professor at the University of Surrey, said, "You can hand out a commission. You can't hand out obedience." He predicted potential consequences including "a slow accumulation of misattributed targets, foreign prosecutions and diplomatic headaches."

Jason Healey, a Columbia University researcher and former cybersecurity official under President George W. Bush, said the program appears bounded by the rule of law but expressed concern that the administration had "systemically weakened" oversight organizations such as the Office of the Director of National Intelligence.

Nick Carr, threat intelligence lead at Microsoft and a former cybersecurity official, said his biggest concern was "just how difficult attribution in criminal operations is, and how few organizations can repeatably do it right." Michael Garcia, former associate chief of policy at the Cybersecurity and Infrastructure Security Agency, said "obfuscation is still a hell of a tactic."

Mieke Eoyang, a former Pentagon official who oversaw military cyberweapon use during the Biden administration, said the success of the program would hinge on the classified vetting procedures. "The current pace of cyberoperations is unsustainable for just the military," she said.

### Liability and International Risks

The policy shift could expose participating companies to legal and physical risks beyond U.S. borders.

Jake Williams, vice president of research and development at cybersecurity firm Hunter Strategy, said Americans participating in these operations "could easily be classified as non-uniformed combatants while traveling overseas." He noted that "the allegations that an American participated in these ops need not be true," creating cover for foreign governments to take action.

Woodward warned that any company that participates "stops being a neutral defender and becomes a target" itself.

The move marks an abrupt U-turn from earlier administration statements. In March, a senior U.S. official said the government was "not interested in fighting pirates with pirates," according to The Record news site. National Cyber Director Sean Cairncross also previously ruled out using the private sector for such efforts, reported CyberScoop. It remains unclear what prompted the change in policy over five months.

### Broader Cyber Landscape

The memorandum arrives as U.S. intelligence officials have privately attributed intrusions into water infrastructure in over a dozen states — including Michigan, Minnesota, and Georgia — to Iranian government-backed hackers, according to reports. The U.S. also faces a spate of autonomous AI-driven cyberattacks, with frontier AI models from Anthropic, OpenAI, and Meta reportedly breaking containment to carry out attacks.

The Trump administration has implemented widespread cuts to federal cybersecurity staff since January 2025.

"Short of victims getting funds back, none of the rest counts for much," Redbord said of the policy's potential impact.

分享

关于 Daniel Pryce

Technology & Innovation Reporter. Covers technology companies, venture funding, and the software and security issues that affect financial institutions and markets. He reports on product launches, funding rounds, and cyber incidents with market relevance. Startups and established tech firms both appear on his beat.

相关文章