All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

US government enlists tech firms for offensive cyber operations

Created at 13 Aug · 4:56 PM1 source↑ Market-relevant
IN SHORT

The U.S. government is authorizing private tech companies to conduct offensive cyber operations against criminal adversaries, a significant shift in its cybersecurity strategy. The initiative aims to leverage the private sector's capabilities to combat cybercrime and protect critical infrastructure.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Who's Involved

Joe Lin
CEO and co-founder of Twenty, a start-up building offensive cyber tools
Twenty
start-up building offensive cyber tools for the U.S. government

↳ Why This Matters

This policy shift represents a significant change in U.S. cybersecurity strategy, potentially enhancing the nation's ability to combat cybercrime by mobilizing private sector offensive capabilities, while also introducing complexities in distinguishing between state-sponsored and criminal actors.

Key facts

  • The U.S. government is authorizing private tech companies to conduct offensive cyber operations against criminal adversaries.
  • Companies must target criminals not directly affiliated with foreign governments.
  • The initiative aims to combat cybercrime and protect critical infrastructure.
  • Distinguishing between criminal gangs and state-sponsored actors is a noted challenge.
  • Accidental targeting of U.S. persons or networks requires immediate notification to the government.

The U.S. government is shifting its cybersecurity strategy to enlist private technology companies in conducting offensive cyber operations against criminal adversaries. This move aims to leverage the private sector's capabilities to combat cybercrime and protect critical infrastructure, which has been persistently targeted by state-sponsored actors and multinational crime syndicates.

Under the new directive, companies will be authorized to target criminals who are not considered an institutional part of a foreign government or wholly operated under its direction. However, the memo acknowledges that making this distinction can be difficult, as cyber gangs in Eastern Europe are often thought to operate with tacit government consent, and state hackers in Iran and China sometimes engage in cybercriminal activities for financial gain or to deflect blame.

Determining responsibility for cyberattacks and identifying the owners of computer networks can also be challenging for digital investigators. The memo addresses this by requiring companies to immediately pause and notify the U.S. government if they accidentally target a U.S. citizen or network. Operations deliberately directed at a U.S. person would require necessary authorization prior to approval.

While many lawmakers and security experts support a greater role for the private sector in responding to cybercrime, not all agree with granting them the authority to launch active hacking efforts.

Frequently asked questions

The main goal is to recruit private tech companies to help conduct offensive cyber operations against criminal adversaries, thereby enhancing the nation's ability to combat cybercrime and protect critical infrastructure.

Companies are only authorized to target criminals that are not an institutional part of a foreign government or wholly operated under a foreign government’s direction.

Companies are required to immediately pause the operation and notify the U.S. government.

Yes, concerns include the difficulty in distinguishing between criminal gangs and state-sponsored actors, and not all experts agree with granting private firms the ability to launch active hacking efforts.

What Happens Next

01Companies must obtain necessary authorization for operations deliberately targeting U.S. persons.
02Companies must pause and notify the U.S. government if they accidentally target U.S. persons or networks.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

The U.S. government is recruiting tech companies to assist in offensive cyber operations.
Companies will target criminals not directly affiliated with foreign governments.
Distinguishing between criminal gangs and state-sponsored actors may prove difficult.
Adversaries like Russia, China, and Iran have targeted U.S. critical infrastructure.
Cyber gangs in Eastern Europe are believed to have tacit Russian government consent.
State hackers in Iran and China sometimes engage in cybercriminal activities.
Determining responsibility for cyberattacks can be challenging.
Companies must pause and notify the government if they accidentally target U.S. persons or networks.

Sources

T1
The government is recruiting tech companies to help fight its cyber battlesPolitico

Related Stories

US to allow private firms to conduct offensive cyberattacks
13 Aug · 2:32 PM
Trump signs memo to empower cyber tools against transnational criminal organizations
12 Aug · 10:07 PM
Wall Street banks invest in American economic security
13 Aug · 9:21 AM
US Deploys Drones to Track Screwworms Spreading in Texas
12 Aug · 7:46 PM
UK Defence Civilian Staff Face Pay Rise Delay Until 2027
13 Aug · 8:11 AM