US National WireUS NATIONAL WIRE
Tech

U.S. Authorizes Private Firms to Launch Offensive Cyberattacks

Portrait of Dana Kessler
Dana Kesslercybersecurity & privacyAug 14AI
U.S. Authorizes Private Firms to Launch Offensive Cyberattacks

AI-generated image · US National Wire

A new presidential memorandum allows vetted companies to conduct disruptive operations against international criminal gangs, marking a seismic shift in federal hacking policy.

The Trump administration has issued a presidential memorandum authorizing vetted private companies to carry out offensive cyber operations against international criminal gangs and transnational criminal organizations, according to reporting from TechCrunch and Engadget.

Under the new policy, participating firms may conduct surveillance using spyware and launch disruptive attacks intended to destroy the systems or data of criminals. The administration stated the move leverages the "innovative capabilities of the private sector" to combat threats including financial scams, sextortion, and ransomware attacks.

This represents a reversal of long-standing U.S. policy and federal computer hacking laws, such as the Computer Fraud and Abuse Act, which previously prohibited private entities from conducting such operations without court approval. While the government has not yet fully established the program's operational details, it will issue guidance within two months regarding requirements for participating companies of all sizes. Firms must deposit $1 million in escrow, a bond that will be forfeited if the government finds the company failed to comply with operational rules.

To mitigate risk, the memorandum directs the federal government to ensure operations do not target U.S.-based systems or citizens. All operations require sign-offs from the Justice Department and Homeland Security and must be conducted under federal supervision. Additionally, participating firms must notify the government of any imminent attacks on critical U.S. infrastructure, such as water providers or power grids.

The policy follows a series of cyberattacks on water infrastructure in states including Georgia, Minnesota, and Michigan, which officials within U.S. intelligence have reportedly linked in private to hackers backed by the Iranian government.

Critics cited by TechCrunch warn of severe international ramifications. Jake Williams, vice president of research and development at Hunter Strategy, told TechCrunch that the policy could lead foreign governments to classify American private-sector employees as "non-uniformed combatants," potentially leading to indictments or custody in foreign jurisdictions.

Sources

More from Dana Kessler