US authorises private firms to conduct offensive cyber operations against foreign criminals

The Trump administration has issued a directive permitting private security companies to carry out government-authorised cyberattacks against overseas criminal organisations that target United States persons, businesses or government entities. This significant policy shift marks the first time the federal government has explicitly authorised private sector entities to conduct offensive cyber operations against external hackers, moving beyond previous restrictions that required court approval for such actions.

The initiative was announced in a National Security Presidential Memorandum issued by President Donald Trump on Thursday. The memorandum instructs the National Coordination Center, which operates under the Homeland Security Task Force, to develop a dedicated programme aimed at combating foreign transnational criminal organisations. The Departments of Justice and Homeland Security will provide oversight for the scheme, with private sector participation identified as a central component of the strategy.

According to an accompanying fact sheet, eligible targets include groups engaged in ransomware attacks, sextortion schemes, phishing campaigns, financial fraud and impersonation scams. The memorandum defines these transnational criminal organisations as foreign groups that commit cyber-enabled crimes against US interests but are not part of or directed by a foreign government. Participating firms will be authorised to conduct both cyber surveillance and cyber effects operations. These measures may involve the use of spyware or offensive attacks designed to destroy data or systems belonging to the criminal groups. The directive does not exclude specific types of offensive actions, such as distributed denial-of-service attacks or the use of encryption to lock targets out of their networks.

Strict conditions have been imposed on companies wishing to join the programme. Firms must undergo vetting by the Justice and Homeland Security departments before approval. They are required to deposit one million dollars into an escrow account, which will be forfeited if they fail to comply with contractual agreements. Furthermore, operations are prohibited from resulting in critical outcomes, defined as actions causing loss of life, serious injury or rising to the level of armed attack under international law. Minimum standards for participation include technical proficiency, proven performance, facility security and personnel vetting.

Independent security researcher Kevin Beamont acknowledged the potential merit in hacking ransomware groups, noting that such activities already occur informally. However, he expressed scepticism regarding the incentives, suggesting that private cyber companies have historically lobbied against regulatory changes to protect their profits. Many operational details remain undefined, with the Justice and Homeland Security departments directed to provide specific particulars within the next 60 days.

Post Disclaimer

The following content has been published by Stockmark.IT. All information utilised in the creation of this communication has been gathered from publicly available sources that we consider reliable. Nevertheless, we cannot guarantee the accuracy or completeness of this communication.

This communication is intended solely for informational purposes and should not be construed as an offer, recommendation, solicitation, inducement, or invitation by or on behalf of the Company or any affiliates to engage in any investment activities. The opinions and views expressed by the authors are their own and do not necessarily reflect those of the Company, its affiliates, or any other third party.

The services and products mentioned in this communication may not be suitable for all recipients, by continuing to read this website and its content you agree to the terms of this disclaimer.

Our Socials

Recent Posts

Stockmark.1T logo with computer monitor icon from Stockmark.it
Loading Next Post...
Popular Now
Loading

Signing-in 3 seconds...

Signing-up 3 seconds...