The U.S. government will, for the first time, permit vetted private companies to conduct offensive cyber operations against international criminal organizations and hackers, the White House announced Wednesday. This significant policy shift, detailed in a new presidential memorandum, aims to leverage the private sector's "innovative capabilities" to combat cybercrime, including ransomware attacks, financial scams, and sextortion targeting Americans.
The memorandum allows participating companies to engage in surveillance, such as using spyware for intelligence gathering, and to execute disruptive attacks designed to destroy criminals' data or systems. This move represents a departure from long-standing U.S. federal computer hacking laws, which generally prohibit private entities from launching cyberattacks without court authorization. Previously, the government's stance was that the private sector could defend against cyber threats but not initiate offensive operations.
While the policy is in its early stages, the government plans to issue detailed guidance within two months outlining requirements for participating companies of all sizes. To join the program, companies must deposit $1 million in escrow, which will be forfeited for non-compliance. The memorandum mandates procedures to prevent operations from targeting Americans or U.S. systems, and all operations will require approval from representatives of the Justice Department and Homeland Security, operating under federal government supervision.
Participating companies will also be required to notify the government of any imminent cyberattacks against critical U.S. infrastructure. Critics, however, have raised concerns that the policy could lead to diplomatic issues and put American cybersecurity professionals at risk of foreign government detention, with one veteran calling the policy "half-baked" and potentially open to abuse.
The administration cited a "growing threat" from cybercrime and international hackers as the impetus for the policy change, noting widespread cuts to federal cybersecurity staff. The announcement comes amid ongoing cyberattacks targeting U.S. states' water infrastructure, which intelligence officials have reportedly attributed to Iranian-backed hackers, and as governments worldwide grapple with AI-driven cyber threats.