Skip to content
Tech News
← Back to articles

The US will let private companies hack back at cybercriminals for the first time

read original more articles
Why This Matters

The US government's decision to authorize private companies to conduct offensive cyber operations marks a significant shift in national cybersecurity strategy, enabling faster and more targeted responses to foreign cyber threats. This move could enhance the nation's ability to combat transnational cybercriminal organizations but also raises concerns about oversight, legal boundaries, and escalation risks for the tech industry and consumers alike.

Key Takeaways

What we know so far: Private companies in the US have traditionally been allowed to defend their own networks from bad actors, but launching their own attacks against hackers has been out of the question. That's about to change. A new White House program will let vetted security firms surveil, disrupt, and even destroy overseas cybercriminal infrastructure while operating under federal authority.

President Donald Trump signed the National Security Presidential Memorandum on Wednesday. The move marks the first time the federal government has authorized private companies to conduct offensive cyber operations.

The targets will be foreign cyber-enabled transnational criminal organizations that attack US people, businesses, or government bodies. The White House highlighted ransomware, phishing, financial fraud, sextortion, and impersonation scams as examples.

The Homeland Security Task Force's National Coordination Center will run the program, overseen jointly by executive directors from the Department of Justice and Department of Homeland Security.

Participating firms must contract with one department and pass vetting covering technical ability, operational experience, facility security, and personnel.

Rules are due within 60 days and must accommodate both large companies and smaller specialists.

Authorized companies will be able to perform covert cyber surveillance, including accessing systems without the owner's permission. They may also conduct more aggressive cyber effects operations that manipulate, disrupt, deny, degrade, or destroy systems, networks, infrastructure, and data.

The memorandum isn't a blanket license to hack the hackers. Every operation requires written approval and must remain under federal supervision. Program directors can't authorize actions likely to kill or seriously injure someone, or amount to a use of force or armed attack under international law. A firm that accidentally targets a US person or US-based system must stop and immediately report it.

Companies may also be required to place at least $1 million in a bond or escrow account, forfeitable for breaking their agreements.

Allowing firms to fight back might sound like a good thing, but there are some obvious risks. Criminals frequently route attacks through compromised systems belonging to innocent parties, creating the possibility of collateral damage.

... continue reading