White House Authorizes Private Security Firms to Hack Overseas Cybercriminals
The Trump administration is recruiting private security firms to conduct government-authorized cyberattacks against overseas criminal organizations that target US persons, organizations, or government entities. A National Security Presidential Memorandum issued Thursday directs the National Coordination Center, which operates under the Homeland Security Task Force, to develop the program, with the Departments of Justice and Homeland Security providing oversight. The memo marks the first time the federal government authorizes private companies to carry out offensive cyber operations against foreign hackers.
The program targets foreign transnational criminal organizations engaged in cyber-enabled crime, defined as groups that conduct such crime against the US government, US persons, or US interests while not being part of a foreign government. A fact sheet accompanying the memo lists ransomware, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams as eligible targets. Participating firms may conduct cyber surveillance operations and cyber effects operations, which appear to permit the use of spyware and offensive attacks intended to destroy criminal groups' data or systems.
The memo does not rule out specific offensive tactics, including attacks that use encryption to lock targets out of their networks or distributed denial-of-service attacks. Until now, the government prohibits the private sector from taking such actions without court-authorized approval. While supporters see merit in hacking ransomware groups, observers note that many details of the program remain undefined, leaving significant questions about how it operates in practice.