Skip to content
Tech News
← Back to articles

In a first, US will allow some private firms to carry out cyberattacks

read original more articles
Why This Matters

The U.S. government's decision to permit vetted private firms to conduct offensive cyber operations marks a groundbreaking shift in cybersecurity policy, enabling private sector innovation to combat cybercriminals more effectively. This move could enhance the nation's ability to respond swiftly to cyber threats but also raises legal and ethical concerns about private sector involvement in offensive hacking. The policy's implementation will shape future cybersecurity strategies and regulatory frameworks in the industry.

Key Takeaways

The U.S. government will for the first time allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers, the White House said on Wednesday.

In a newly published presidential memorandum, the Trump administration said the move will allow the federal government to use “innovative capabilities of the private sector” to combat cybercrime and threats targeting Americans, such as ransomware attacks, financial scams, and sextortion.

The memorandum allows private companies participating in the government’s program to conduct surveillance, like using spyware to collect intelligence, as well as make disruptive attacks aimed at the destruction of criminals’ data or systems.

The policy change marks a seismic shift in the U.S. government’s long-standing position under U.S. federal computer hacking laws, which broadly prohibit private companies from conducting cyberattacks or disruption operations without a court-authorized approval.

Private companies are regulated under the same computer hacking laws as anyone else in the United States, which prohibit people or companies from carrying out cyberattacks. The U.S. government’s position to date, through multiple administrations, has been that the private sector can defend against incoming cyberattacks, but not launch or operate them.

While the presidential memorandum establishes the new policy, it’s still in its early days and the government has not yet fully established how the program will operate. The new policy is likely to face legal challenges and opposition by critics, who have for years argued that private companies should not get involved with government hacking operations.

The government will issue guidance in the next two months outlining the requirements participating companies will have to meet before being allowed into the program. This guidance would consider companies of all sizes, including smaller private companies, which might be better suited for specialized operations, the memorandum reads.

Participating companies must deposit $1 million in escrow, which will be forfeited if the government finds out a company isn’t complying with its rules on how to conduct these operations. The memorandum directs the federal government to create procedures preventing any operation from targeting Americans or U.S.-based systems.

Any operation will require sign-offs from representatives from the Justice Department and Homeland Security before it can be approved. Operations are to be conducted exclusively under the supervision of the federal government.

The policy also requires any participating company to notify the government if it discovers an imminent cyberattack against critical U.S. infrastructure, such as power grids or water providers.

... continue reading