Key facts
- The U.S. government is authorizing private tech companies to conduct offensive cyber operations against criminal adversaries.
- Companies must target criminals not directly affiliated with foreign governments.
- The initiative aims to combat cybercrime and protect critical infrastructure.
- Distinguishing between criminal gangs and state-sponsored actors is a noted challenge.
- Accidental targeting of U.S. persons or networks requires immediate notification to the government.
The U.S. government is shifting its cybersecurity strategy to enlist private technology companies in conducting offensive cyber operations against criminal adversaries. This move aims to leverage the private sector's capabilities to combat cybercrime and protect critical infrastructure, which has been persistently targeted by state-sponsored actors and multinational crime syndicates.
Under the new directive, companies will be authorized to target criminals who are not considered an institutional part of a foreign government or wholly operated under its direction. However, the memo acknowledges that making this distinction can be difficult, as cyber gangs in Eastern Europe are often thought to operate with tacit government consent, and state hackers in Iran and China sometimes engage in cybercriminal activities for financial gain or to deflect blame.
Determining responsibility for cyberattacks and identifying the owners of computer networks can also be challenging for digital investigators. The memo addresses this by requiring companies to immediately pause and notify the U.S. government if they accidentally target a U.S. citizen or network. Operations deliberately directed at a U.S. person would require necessary authorization prior to approval.