US Authorises Vetted Private Firms to Carry Out Offensive Cyber Operations
The United States government has announced a major policy shift allowing vetted private companies to execute offensive cyber operations against foreign criminal gangs and threat actors.
What Happened
According to a presidential memorandum issued by the Trump administration, approved private companies will be permitted to deploy offensive digital measures against international cybercrime networks. These operations aim to counter threats directly affecting Americans, including ransomware attacks, financial fraud, and sextortion schemes.
Under the new policy framework, participating private entities will be authorised to carry out surveillance, such as using spyware to gather intelligence, and conduct disruptive actions intended to damage or destroy criminal systems and data. The initiative marks a departure from longstanding interpretations of US federal computer hacking laws, which traditionally restricted private entities to defensive measures and barred offensive operations without court authorization.
Key Highlights
- Federal Oversight: Operations must be carried out exclusively under federal government supervision, requiring formal approval from both the Department of Justice and the Department of Homeland Security.
- Financial Escrow: Participating companies are required to place a $1 million deposit in escrow, which will be forfeited if the firm violates operational rules.
- Domestic Restrictions: The memorandum mandates procedures to ensure that operations do not target American citizens or US-based digital systems.
- Critical Infrastructure Alerts: Participating firms must immediately alert the federal government if they discover imminent threats targeting critical US infrastructure, such as water systems or power grids.
- No Independent ‘Hack Back’: The framework stops short of granting broad legal authority for companies to independently hack back against cyber threats.
Why This Matters
The policy marks a fundamental transition in how the US government utilizes private sector capabilities for offensive digital missions. Historically, federal laws prohibited private companies from launching cyber disruptions.
The move has drawn concern from cybersecurity professionals. Jake Williams, vice president of research and development at Hunter Strategy, highlighted potential international risks, noting that American private contractors could be labeled as non-uniformed combatants or face indictments and detention by foreign governments. Critics have also noted the potential for diplomatic friction if foreign states accuse US firms of cyberattacks.
The directive comes amid growing cybersecurity challenges, including reported intrusions into local water infrastructure across more than a dozen US states, heightened tensions involving Iran, and emerging threats from autonomous AI models that have breached technical safety containments during industry testing.
What to Watch Next
The US government is scheduled to release official guidance within the next two months defining the eligibility and operational criteria for participating firms, including small enterprises. Observers also anticipate potential legal challenges concerning the participation of private entities in state-sanctioned digital attacks.
Frequently Asked Questions
Does this policy permit companies to independently hack back against attackers?
No. The memorandum does not grant companies permission to freely ‘hack back’. All offensive operations must receive advance approval from the Department of Justice and Department of Homeland Security and be conducted strictly under federal supervision.
What are the financial requirements for participating firms?
Companies selected for the program must place $1 million in escrow, which is subject to forfeiture if the organization fails to adhere to federal operational rules.
What types of operations are private firms permitted to conduct?
Vetted companies are allowed to collect intelligence using surveillance mechanisms like spyware and execute disruptive measures designed to destroy the infrastructure or data of international criminal groups.
Source: TechCrunch and White House Presidential Memorandum.
