For the first time, the US federal government has authorized private sector firms to launch cyberattacks against foreign criminal groups engaged in cyber-enabled crimes like ransomware and phishing that impact US entities, under strict oversight and new regulatory conditions.

  • Trump administration creates program for private firms to fight foreign cybercrime
  • Private companies must pass rigorous vetting and financial guarantees
  • Offensive cyber operations limited to avoid lethal or force-level outcomes

What happened

The US government, under a directive from President Trump, has launched a program allowing vetted private security firms to conduct offensive cyber operations against foreign transnational criminal organizations (TCOs) that perpetrate cybercrimes against US interests. This memorandum marks the first time private companies are authorized to engage in government-sanctioned hacking activities, including surveillance and data disruption operations targeting cyber-enabled criminals overseas.

The Departments of Justice and Homeland Security will tightly oversee the program, ensuring companies meet high standards of technical ability, personnel vetting, and operational reliability. Firms must also place a $1 million escrow deposit to participate and adhere to strict limits, including prohibitions on actions causing loss of life, serious injury, or escalation to armed conflict scenarios under international law.

Why it matters

This policy shift represents a new model in cybersecurity strategy by leveraging private sector capabilities for active defense measures. Previously, only government entities could conduct offensive cyber operations, with the private sector limited to defensive roles unless court authorization was obtained. By integrating capable private firms into offensive operations, the government aims to counter increasingly sophisticated and damaging foreign cyber threats more flexibly and responsively.

However, the program's success will hinge on effective oversight and clear operational rules. Allowing private companies to perform attacks raises concerns about accountability, the potential for misuse, and the ethical boundaries of cyber conflict. Experts emphasize the need for proper incentives and operational integrity to ensure companies contribute constructively to US cyber defense without unintended negative consequences.

What to watch next

The Departments of Justice and Homeland Security have been tasked with developing program specifics within 60 days, including technical and legal frameworks guiding private cybersecurity firms’ operations. Observers will look closely at these details to assess how the program balances aggressive cyber defense with regulatory controls to prevent abuses or escalation.

Monitoring how private firms implement Cyber Surveillance Operations and Cyber Effects Operations against overseas cybercriminals will also be crucial. Key factors include adherence to restrictions on lethal or force-level outcomes, the effectiveness in disrupting criminal networks like ransomware groups, and transparency in oversight mechanisms. This program’s evolution will likely influence future public-private collaborations in US cyber policy.

Source assisted: This briefing began from a discovered source item from Ars Technica Tech Policy. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings