Tech

US permits vetted private firms to conduct offensive cyber operations

New rules require $1 million escrow deposits and dual sign-offs from the Justice Department and Homeland Security, raising concerns over diplomatic fallout and personnel safety

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: TechCrunch · View original source
In a first, US will allow some private firms to carry out cyberattacks
Trump administration memorandum marks significant policy shift, allowing companies to target international cybercriminals under strict federal supervision

The Trump administration has issued a presidential memorandum permitting vetted private companies to launch offensive cyber operations against international criminal gangs and hackers. This policy represents a significant departure from previous prohibitions on private sector 'hack back' activities, marking a seismic shift in US cybersecurity strategy. The move aims to leverage the innovative capabilities of the private sector to combat cybercrimes such as ransomware, financial scams, and sextortion.

Under the new framework, participating firms must deposit $1 million in escrow, which will be forfeited if the government determines the company has not complied with operational rules. The memorandum allows these companies to conduct surveillance, including the use of spyware to collect intelligence, and to execute disruptive attacks aimed at destroying criminals’ data or systems. However, the policy stops short of allowing general 'hack back' activities against any cyber threat, focusing instead on specific international criminal targets.

Operations are subject to strict federal supervision and require mandatory sign-offs from the Justice Department and Homeland Security before approval. The memorandum explicitly directs the creation of procedures to prevent any operation from targeting Americans or US-based systems. Additionally, participating companies are required to notify the government immediately if they discover an imminent cyberattack against critical US infrastructure, such as power grids or water providers.

The implementation of this policy occurs amid widespread cuts and layoffs to federal cybersecurity staff since the start of the second Trump administration in January 2025. Several US states, including Michigan, Minnesota, and Georgia, have reported intrusions into local water providers, which US intelligence officials have reportedly attributed to Iranian government-backed hackers. These incidents follow the start of a US-led war in February, during which the Iranian military has reportedly launched cyberattacks disrupting US businesses and targeted Western-owned data centres.

The policy faces potential legal challenges and criticism regarding international diplomatic ramifications. Industry experts have warned that Americans participating in these operations could be classified as non-uniformed combatants, risking indictment or custody by foreign governments. A White House spokesperson did not confirm if any private companies are already participating in the program, referring inquiries to the administration’s fact sheet. Detailed guidance outlining the specific requirements for participating companies, which may include smaller firms suited for specialised operations, is expected to be issued within the next two months.

Continue reading

More from Tech

Read next: Apple’s Screen Time offers tools to rein in iPhone usage
Read next: GameCube’s library still commands attention 25 years on
Read next: US AI leaders urge restraint as Trump team prioritises China competition