中文

US Government to Authorize Private Firms for Offensive Cyber Operations Against Criminal Gangs

The Trump administration will permit private companies to conduct offensive cyber operations against foreign criminal groups under a new program overseen by the DOJ and DHS. The initiative aims to disrupt cybercrime but raises legal, ethical, and operational concerns among experts.

2026-08-1416views
US Government to Authorize Private Firms for Offensive Cyber Operations Against Criminal Gangs

The Trump administration will allow private companies to conduct hacking operations against foreign criminal organizations as part of a new initiative designed to bolster the U.S. government's ability to disrupt cybercrime. The program, which introduces significant legal and operational complexities, marks a notable expansion of the private sector's involvement in offensive cyber activities.

President Donald Trump issued a memorandum late Wednesday directing the Departments of Justice (DOJ) and Homeland Security (DHS) to establish a framework under which vetted companies could infiltrate criminal groups for surveillance or sabotage purposes. Trump stated that the program would help combat cybercrime schemes that cost the U.S. tens of billions of dollars annually.

The policy represents a dramatic shift in the role of private businesses in offensive cyber operations against U.S. adversaries, blurring the line between governmental foreign policy and commercial activities. While the program targets criminal gangs rather than nation-states, it is the largest step the U.S. government has taken toward enabling corporate "hacking back" against foreign entities on behalf of the nation.

Many cybersecurity experts have criticized the hack-back concept, citing risks of escalation and potential exposure of private companies to foreign military retaliation. However, the Trump administration has embraced aggressive measures against transnational criminal groups, showing less concern about collateral damage.

At the Black Hat USA conference in Las Vegas last week, a DHS official did not dismiss the idea. "Our long-term goal is to terrify those who would target Americans, such that they know we're actually the worst target in the world because we will mess you up," said Joseph Alm, assistant secretary of homeland security for cyber, infrastructure, risk, and resilience.

The program includes restrictions to limit unintended consequences. Co-executive directors from DOJ and DHS will review each proposed operation and provide written approval for those the government greenlights. Participating companies must meet requirements such as technical competency and personnel vetting, and they must post bonds of at least $1 million, which they would forfeit if they violate the program's rules.

Trump's memorandum prohibits authorizing operations that would kill or seriously injure people or constitute a use of force or armed attack under international law. The White House has given DHS and DOJ 60 days to establish operating procedures, including standards for company participation, deconfliction with military and intelligence operations, and reporting requirements for information gathered about criminal gangs.

The memorandum emphasizes the need for participation by both large companies, which provide critical capacity, and smaller, more agile firms, which may be better suited for specialized tasks. Trump stated, "American businesses' innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace. By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter [transnational criminal organization] threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens."

Mixed reactions

Some cybersecurity experts see potential in the program if properly designed and overseen. Scott Shackelford, a business law and ethics professor at Indiana University who leads its Center for Applied Cybersecurity Research, said, "This administration action is a meaningful response to a growing problem and does have some guardrails in place. But significant questions remain about unleashing the private sector in this way, and what accountability mechanisms will be in place for bad actors."

Jason Healey, a senior cyber conflict researcher at Columbia University, said he "would have hated this idea ten or fifteen years ago" when defense was still prioritized, but "that horse left the barn a long time ago, and we have to make decisions for the world we are in, not the one we prevented." He added, "So, sure, let's try to allow the private sector to get into the counter-offense game as well, but only with very specific criteria to know when it is working and when it is making things worse."

Kyle Hanslovan, CEO of cybersecurity firm Huntress, argued that sophisticated adversaries and "AI-powered autonomous threats" render old collaboration models insufficient. "The only viable solution is a stronger coalition of the willing," he said, "which we've been eager to support."

Other experts are more critical. Paul Rosenzweig, a former deputy assistant secretary for policy at DHS, called it "a bad idea," adding, "There are much better ways to revive what it seems to me is an essentially governmental function." Erica Lonergan, a professor and cyber conflict expert at Columbia, said "the devil will be in the details, but I have some significant concerns," pointing to uncertainties around vetting, goal setting, risk mitigation, and oversight. She asked, "Is this a slippery slope to enable private-sector offensive cyber operations directly against nation-state adversaries?"

Major legal question marks

The program is rife with risks for participating businesses, the government, and society. The memorandum requires procedures to address some risks: companies must stop and alert the government if they accidentally target a U.S. person or information system, and DOJ must ensure any operations involving U.S. persons follow applicable laws, including judicial authorizations.

However, other questions remain unresolved. Criminal organizations often steal data from U.S. businesses; it is unclear what would happen if a participating company encounters such sensitive data during an operation. Deconfliction with military and intelligence agencies is likely to be difficult due to the classified nature of government hacking operations. Officials would be reluctant to share information with private firms, even to warn them off overlapping targets.

Gary Corn, a former staff judge advocate at U.S. Cyber Command, noted, "There's overlap between the kind of things that might fall into Cyber Command's priorities and bailiwick, and what these entities would do. Deconfliction has always been a challenge, even internal to the government... That'll become exponentially more challenging here with this."

The vetting of companies and targets is another concern. Some self-proclaimed independent hacker teams are widely considered fronts for governments, such as the Iran-linked Handala group, while others like Russia-linked Evil Corp have close ties to their governments. A poorly vetted operation that accidentally targets foreign government employees or infrastructure could create a geopolitical crisis.

Healey warned, "Anyone conducting these operations is doing so at substantial personal legal risk." The memorandum allows hacking only foreign criminal groups that are "not an institutional part of a foreign government or wholly operated under a foreign government's direction," but it assumes a group does not meet those conditions "unless clear intelligence exists establishing such connection."

Corn, now director of the Technology, Law & Security Program at American University's Washington College of Law, explained, "A lot of the proxy actors don't operate wholly under a foreign government's direction. Foreign governments tap into these different non-state entities as they want." Under international law, the U.S. government is accountable for any cyberattack a private company conducts, even if it violates program rules.

Operations targeting criminal gangs might disrupt infrastructure in allied countries. Rosenzweig said, "The internet is not a seamless, direct-from-us-to-Russia kind of thing. To do whatever it is you're thinking you might do, you have to engage with systems that are subject to the jurisdiction of many, many other nations, each of whom would have something very negative to say about this prospect." He added that the administration has "misunderstood the interconnected nature of the world's cyber ecosystem."

The prohibition against piracy is one of the oldest principles of international law, and Rosenzweig said it was "quite likely" that companies would violate that prohibition if they participate. Shackelford noted that even Western allies that have increased their cyber engagements have not tapped private companies in this way, which "could serve to further isolate the U.S. diplomatically and set back cyber norm-building efforts."

It remains unclear how many companies will participate given the risks. Operations will likely be secret, so the only benefit is government payment for services. Hanslovan expressed confidence that program leaders would mitigate issues like collateral damage, saying, "I'm proud to see the U.S. government push the boundaries when it comes to denying, degrading, and disrupting these measurable threats to democracy."