U.S. Government to Outsource Offensive Cyber Operations to Private Firms

AI-generated image · Bay Street Wire
A new presidential memorandum authorizes vetted companies to conduct surveillance and disruptive attacks against international criminal networks.
The Trump administration has issued a presidential memorandum authorizing vetted private companies to launch offensive cyber operations against international hackers and criminal gangs, TechCrunch reports. This policy marks a significant departure from previous U.S. government positions that prohibited private firms from conducting cyberattacks or disruption operations without court approval.
Under the new program, participating companies can utilize spyware for intelligence collection and execute disruptive attacks to destroy criminal systems and data. The memorandum states the government aims to leverage the "innovative capabilities of the private sector" to combat threats such as sextortion, financial scams, and ransomware. According to The Verge, the program targets groups that are not an institutional part of, or directed by, a foreign government.
Operations will be conducted under federal supervision, requiring sign-offs from the Department of Homeland Security and the Justice Department. Participating firms must meet standards for facility security, technical proficiency, and proven performance. Additionally, companies are required to deposit $1 million in escrow, which will be forfeited if they fail to comply with operational rules. The policy also mandates that companies notify the government of any imminent threats to critical U.S. infrastructure, such as water providers or power grids.
Critics warn of severe geopolitical and legal risks. Jake Williams, vice president of research and development at cybersecurity company Hunter Strategy, told TechCrunch that Americans involved in these operations could be labeled as "non-uniformed combatants" during international travel. Jason Healey, a senior cyber conflict researcher at Columbia University, told Cybersecurity Dive that operators face "substantial personal legal risk." Furthermore, Ben Bernstein, a manager for the cybersecurity advisers team at Huntress, told The Verge that the use of compromised innocent infrastructure by threat actors makes it nearly impossible to strike back without affecting innocent bystanders.

