Tech

Trump administration permits private firms to conduct international cyberattacks under federal oversight

The Department of Justice and Department of Homeland Security will supervise the programme, though experts warn of significant legal risks and collateral damage due to the difficulty of distinguishing criminal infrastructure from innocent bystanders.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: The Verge · View original source
The Trump admin will start letting private firms launch international cyberattacks
New memorandum allows cybersecurity companies to disrupt foreign criminal networks, subject to strict government supervision and financial bonds

President Donald Trump has signed a memorandum authorising private cybersecurity firms to conduct international cyberattacks against foreign criminal networks. The directive, published on Wednesday, establishes a new programme where private companies will operate under the control and oversight of the federal government, specifically the Department of Justice and the Department of Homeland Security.

Under the terms of the memorandum, participating firms must demonstrate technical proficiency, proven performance in cyber operations, and adherence to facility security standards. Companies are required to hold a bond or escrow of at least $1 million, which will be forfeited if they fail to comply with their contractual agreements. The administration describes private businesses as "underutilized" forces in the fight against cybercrime, stating it is US policy to utilise all instruments of national power, including the innovative capabilities of the private sector.

The directive explicitly prohibits targeting groups that are an institutional part of a foreign government or wholly operated under a foreign government’s direction. This restriction aims to prevent the programme from escalating into state-level conflict, although experts note that distinguishing between independent criminal networks and those with government affiliations remains a significant operational challenge.

Jason Healey, a senior cyber conflict researcher at Columbia University, warned that individuals conducting these operations face substantial personal legal risk. Jake Williams, vice president of research and development at Hunter Strategy, added that Americans participating in such activities could be classified as non-uniformed combatants while travelling overseas, complicating their legal status under international law.

Ben Bernstein, a manager for the cybersecurity advisers team at Huntress, highlighted the technical difficulties of the programme, noting that threat actors route traffic through compromised, innocent infrastructure. He argued that this makes it practically impossible to strike back without taking out innocent bystanders, such as vulnerable routers at hospitals or dental offices, raising concerns about potential collateral damage.

The United States government previously conducted its own cyber operations rather than relying on third-party private entities. Bloomberg reported last year that President Trump began making plans to involve private cybersecurity companies in these activities, marking a shift in how the administration intends to combat digital threats.

Continue reading

More from Tech

Read next: Namecheap services disrupted by Phoenix data centre cooling failure
Read next: Trump administration authorises private firms to conduct cyber attacks on overseas criminals
Read next: Virgin Galactic opens public vote to name new Delta-class spaceship