Biphoo.eu - Guest Posting Services

collapse
Home / Daily News Analysis / The US government wants private companies to start hacking the hackers

The US government wants private companies to start hacking the hackers

Aug 15, 2026  Twila Rosenbaum  21 views
The US government wants private companies to start hacking the hackers

The US government is preparing to change the rules of engagement in the fight against cybercrime. For years, cybersecurity firms have been expected to build digital walls, patch vulnerabilities, and repel intruders. But under a new presidential memorandum, the Trump administration intends to let private companies take the fight directly to foreign criminal hackers. The plan would authorize vetted American firms to conduct offensive cyber operations against foreign cyber-enabled criminal organizations, including surveillance and disruptive actions aimed at ransomware gangs, fraud rings, and other digital threats that target Americans.

The policy, first reported by TechCrunch, represents a significant departure from the long-standing US position that private-sector companies should defend against hackers rather than launch their own attacks. While the details are still being finalized, the memorandum outlines a framework in which private companies could legally hack back, exposing and disabling criminal infrastructure overseas. The shift has been met with both cautious optimism and sharp criticism from cybersecurity experts, legal scholars, and civil liberties advocates.

What the New Program Would Allow

The core of the memorandum is a federal program designed to give approved companies the authority to conduct two types of operations: surveillance and disruptive actions. Surveillance operations would allow companies to secretly access computer systems without the owner's permission in order to gather intelligence on criminal networks. Disruptive operations would go a step further, permitting firms to manipulate, disrupt, degrade, or even destroy computer systems and data belonging to foreign cybercriminal organizations.

These are powers traditionally reserved for the US military and intelligence agencies. Under the new framework, private-sector participants would act under federal supervision, but they would still be executing operations that could have significant geopolitical and legal consequences. The memorandum specifies that every operation must receive written approval from the program directors at the Justice Department and the Department of Homeland Security before it can proceed.

In addition to federal oversight, participating companies may be required to put up at least $1 million in a bond or escrow account. This money could be forfeited if the company violates the rules of the program, providing a financial deterrent against reckless behavior. The escrow requirement is intended to ensure that companies take their legal obligations seriously and that there is a meaningful penalty for overstepping boundaries.

Guardrails and Limitations

The memorandum does include some guardrails. The program is intended to target foreign criminal groups, not foreign governments. This distinction is important because offensive operations against nation-states could be interpreted as acts of war or lead to diplomatic crises. Companies must also stop and report any operation that accidentally targets a US person or a US-based system. This is a critical safeguard, given the difficulty of attributing cyberattacks with certainty and the risk of collateral damage in cyberspace.

However, the precise rulebook is not yet finished. Officials have been given 60 days to establish the operating procedures, including how companies will be vetted, what kind of training or certification will be required, and how oversight will be enforced. Until those procedures are published, the program exists mostly on paper, and it remains unclear which companies would qualify or how they would be selected.

A Major Shift in US Policy

To understand the significance of this move, it helps to look at the historical context. For more than two decades, the US government has maintained that private companies should not engage in offensive cyber operations. The reasoning was simple: hacking back could lead to misattribution, escalation, and unintended consequences. A private company might accidentally attack a hospital, a power grid, or another country's critical infrastructure, causing widespread harm and undermining US interests abroad.

That position was reinforced by the Computer Fraud and Abuse Act (CFAA), which criminalizes unauthorized access to computer systems. Even if a company knew that a hacker was operating from a specific server, breaking into that server to disrupt the attack or retrieve stolen data was generally illegal for private entities. The new presidential memorandum appears to carve out an exception to this prohibition for carefully supervised operations.

The policy shift reflects growing frustration with the persistence and sophistication of ransomware gangs and other cybercriminal networks. Many of these groups operate with impunity from countries that are unwilling or unable to take action against them. The US government has tried sanctions, indictments, and diplomatic pressure, but the attacks have continued to grow in frequency and severity. The idea behind the new program is to give the private sector the tools to fight back directly, rather than relying solely on law enforcement and military action.

The Role of Cybersecurity Companies

If the program goes into effect, cybersecurity companies would take on a role that is closer to that of a private military contractor than a traditional IT security vendor. They would be responsible for planning and executing operations that penetrate foreign networks, implant surveillance tools, and potentially destroy data. This is a high-stakes business, and not all companies are likely to want that responsibility.

Some firms may welcome the opportunity to develop new offensive capabilities and expand their services. Others may see it as a reputational risk, fearing that their involvement in covert operations could alienate customers or make their employees targets for retaliation. The requirement to post a $1 million bond adds a significant financial burden, and the legal exposure associated with offensive operations could be substantial, especially if something goes wrong.

Cybersecurity veteran Jake Williams, speaking to TechCrunch, described the plan as “half-baked.” He warned that Americans involved in these operations could face legal trouble or accusations from foreign governments when traveling overseas. If a private company conducts an operation that is perceived as an act of aggression by another country, the individuals involved could be arrested or charged with espionage or computer crimes when they enter that country's jurisdiction.

Legal and Ethical Concerns

The memo raises a host of legal and ethical questions. One of the most pressing is accountability. If a private company conducts a cyber operation that goes wrong, who is responsible? The company may face civil lawsuits, criminal charges, or the loss of its bond. But what if the operation causes collateral damage that harms innocent people? The memorandum requires companies to stop and report operations that accidentally target US persons, but it does not provide a clear framework for compensating victims or assessing liability.

There are also concerns about transparency and oversight. The program is designed to be classified or at least highly confidential, which means that Congress and the public may have limited ability to scrutinize operations. The Justice Department and the Department of Homeland Security would have significant power to approve operations without judicial review, raising the risk of mission creep. Will the program stay focused on criminal groups, or will it eventually expand to include other targets? The memorandum says foreign governments are off-limits, but the line between a state-sponsored hacker group and a criminal organization is often blurred. Many ransomware gangs are believed to operate with the tacit approval of their host governments, and some are directly linked to intelligence agencies.

Industy Reactions and Implications

The cybersecurity industry is divided on the plan. Some experts argue that it is long overdue, noting that private companies are often the first to detect and respond to cyber threats. If they can strike back at the source, they might be able to disrupt attacks before they occur, saving billions of dollars and preventing widespread harm. Others argue that the plan is dangerous and unworkable, pointing to the difficulty of attribution and the risk of unintended escalation.

There is also a concern that the program could set a precedent for other countries. If the US is willing to authorize private companies to conduct offensive cyber operations, authoritarian regimes may feel justified in doing the same. This could lead to a fragmenting of cybersecurity norms and an increase in global cyber conflict.

The program also has implications for the cybersecurity industry's business model. Companies that participate would need to develop offensive cyber teams, which require a different skill set from defensive work. They would need to acquire tools and techniques that are typically associated with nation-state hackers, and they would need to maintain operational security to prevent their methods from being exposed or stolen.

What Comes Next

Over the next 60 days, officials from the Justice Department and the Department of Homeland Security will work to establish the operating procedures for the program. They will need to answer questions about vetting, training, reporting, and oversight. They will also need to decide how to handle the escrow requirement and whether companies that are found to have violated the rules will face additional penalties, such as being banned from the program.

The memorandum represents a bold experiment in public-private cooperation in the realm of offensive cybersecurity. If it succeeds, it could fundamentally change the way the United States defends against cybercrime. If it fails, it could lead to a wave of legal and diplomatic fallout, as well as new threats to privacy and civil liberties.

For now, the policy is still in its early stages, and many details remain unclear. But one thing is certain: the idea that cybersecurity companies are purely defensive actors is becoming a thing of the past. The US government is signaling that it wants private firms to help fight fire with fire, and the consequences of that decision will be felt for years to come.


Source: Android Authority News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy