President Donald Trump has signed a national security presidential memorandum authorizing U.S. private companies to conduct offensive cyber operations against foreign criminal organizations, marking the first time the federal government has permitted the private sector to carry out such attacks overseas.
The memorandum, signed on Wednesday, directs the administration to use the capability and innovation of private companies to conduct cyber operations under the direction, control, and authority of the U.S. government, the White House said. The policy gives private firms a role traditionally reserved for government agencies.
The White House cited ransomware attacks, financial frauds, sextortion schemes, phishing campaigns, and impersonation scams as activities eligible for targeting. The memo refers to foreign-based criminal organizations as transnational criminal organizations, or TCOs, defined as any foreign group that conducts cyber-enabled crime against the U.S. government, U.S. persons, or U.S. interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government’s direction.
How the program would work
The memo directs the Department of Homeland Security, through the Homeland Security Task Force’s National Coordination Center, to create a program to conduct specific cyber operations that disrupt foreign TCOs. Justice and Homeland Security will oversee. Under federal supervision, participating companies, once vetted, will conduct cyber surveillance operations and cyber effects operations against specified targets.
The memo defines cyber effects as including the potential manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon. The memo appears to permit companies to use spyware or launch offensive attacks intended to destroy TCO data or systems, according to Ars Technica. It does not rule out certain types of offensive attacks, such as those that use encryption to lock targets out of their networks or distributed denial-of-service attacks.
Until now, the government has prohibited the private sector from taking such actions without court-authorized approval. Many details remain undefined. Companies must meet requirements in technical proficiency, proven performance of cyber operations, facility security, and other areas. They must hold a bond or escrow of at least $1 million. They will forfeit it for noncompliance.
The memo creates a framework encouraging private companies to enter into agreements with other private entities, as well as federal, state, local, tribal, and territorial agencies, to gather threat information on TCOs and propose cyber operations to address those threats. The memo describes private businesses as “underutilized” forces for fighting criminal networks.
Concerns about escalation and legal risk
The idea is not new. Private-sector participation in cyber operations has encountered controversy over fears of escalation, inadvertent consequences, and inter-agency coordination issues. Legal experts have questioned what risks companies could face as they enmesh themselves in international digital conflicts.
Jason Healey, a senior cyber conflict researcher at Columbia University, told Cybersecurity Dive that anyone conducting these operations is doing so at substantial personal legal risk. Jake Williams, vice president of research and development at Hunter Strategy, told TechCrunch that Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas.
Ben Bernstein, a manager for the cybersecurity advisers team at Huntress, raised concerns about collateral damage. He said threat actors do not launch attacks from labeled servers but route traffic through compromised infrastructure, like a vulnerable router at an Ohio dental office or a hospital network. That makes it practically impossible to strike back without taking out innocent bystanders.
It can be difficult to identify which criminal groups are affiliated with foreign governments, which could put cybersecurity firms at risk of stoking geopolitical or legal conflicts. International concern over cyberattacks has grown after the release of increasingly powerful artificial intelligence models, which have shown they can hack into outdated security systems. In the U.S., hackers targeted critical infrastructure systems in several states earlier this year, resulting in disruptions at water facilities.
The Trump administration has previously vowed to give private firms a larger role in cybersecurity operations. A national cybersecurity policy released in March stated that the government would create incentives to “unleash the private sector” against foreign adversaries. The DHS and the White House did not immediately respond to requests for additional details. Trump began making plans to get private cybersecurity companies involved last year, Bloomberg reported.
