The U.S. administration has announced for the first time that vetted private companies may participate in offensive cyber operations against criminal gangs and international hackers under a new presidential memorandum. The memorandum says the goal is to leverage private-sector capabilities to counter threats targeting Americans, including ransomware attacks, financial fraud and sextortion.
The policy does not constitute a general authorization for companies to launch attacks on their own, as the memorandum stipulates that operations will be conducted exclusively under federal government supervision and after approval from representatives of the Department of Justice and the Department of Homeland Security. The government has also not yet finalized the program’s operational details, and participation guidelines are expected to be issued within the next two months.
Offensive Powers With Financial and Legal Controls
The new framework allows participating companies to conduct surveillance operations, such as using spyware to gather information, as well as disruptive attacks aimed at destroying criminals’ data or systems. In return, companies will be required to deposit $1 million into an escrow account, which they could forfeit if the government determines that they failed to comply with the rules governing these operations.
The government will establish procedures to prevent the targeting of Americans or systems located inside the United States. Companies must also notify the government if they discover an imminent cyberattack against critical U.S. infrastructure, such as power grids or water facilities. The anticipated guidelines will cover companies of all sizes, including small businesses that may be better suited to conducting specialized operations.
A Shift From Previous U.S. Policy
The decision represents a major change from the U.S. position maintained across successive administrations, which allowed the private sector to defend itself against incoming attacks but prohibited it from launching attacks or carrying out disruptive operations. Private companies remain subject to the same federal laws that prohibit conducting cyberattacks without appropriate judicial authorization.
However, the memorandum does not go so far as to allow companies to independently conduct “hack-back” operations against any party that threatens them. The White House also did not clarify whether private companies have already joined the program, referring TechCrunch’s questions to a fact sheet it issued.
Concerns About International Repercussions
Critics say involving private companies in government operations could open the door to legal and diplomatic disputes, particularly if a foreign government claims that a U.S. company carried out an attack on its territory or systems. The policy may face legal challenges and opposition from groups that have long rejected private-sector participation in government hacking operations.
Jake Williams, vice president of research and development at cybersecurity company Hunter Strategy, said the policy could expose U.S. employees at cybersecurity companies to the risk of being accused or detained abroad. He added that these employees could be classified as “unlawful combatants” while traveling, even if their participation in the operations had not been established. Williams described the policy as “immature,” expressing doubts that its misuse could be prevented.
A Context of Escalating Threats
The memorandum comes as the administration says the United States is facing a growing threat, amid attacks targeting water infrastructure in several states that, according to intelligence assessments shared with local authorities, were attributed to hackers backed by the Iranian government. The report also pointed to attacks that disrupted U.S. companies and infrastructure, alongside escalating cyber threats supported by autonomous artificial intelligence software.