U.S. Allows Private Firms to Target Foreign Cybercrime Groups

Into new territory.
Elizabeth Rigsby
Contributing Writer
Stylized red-and-black world map with country labels and geometric connecting lines.
stock.adobe.com - max_776

A new U.S. government program allows vetted American companies to conduct cyberattacks against foreign criminal groups, including operations to disrupt or destroy their systems and infrastructure.

The presidential memorandum gives participating companies a direct role in certain federal cyber operations, with activity subject to government approval, direction, and oversight.

This effort follows a March executive order addressing cyber-enabled crime affecting Americans. According to the White House, consumers have reported an estimated $20.8 billion in losses tied to cyber-enabled crime.

Why It Matters: Cybersecurity providers could serve commercial customers while participating in government-directed operations, raising questions about how customer information is handled and separated from federal work. The program also allows commercial threat information to support proposed operations. Rules due within 60 days are expected to provide more detail on the controls involved.

  • Commercial Threat Intelligence Could Support Operations: Threat information already collected through normal business activity could become part of a proposed federal operation. Participating firms can bring that information to the National Coordination Center when identifying criminal targets, while government agencies can provide relevant threat information of their own. Any commercial agreements used to support this process must be disclosed to the NCC.
  • Private Firms Can Take Part in Offensive Operations: Approved companies could covertly access criminal systems to gather intelligence that may later support disruptive action. Depending on the operation, that authority can extend to interfering with or destroying systems, infrastructure, or data. Companies cannot act independently, with each operation requiring written federal approval and remaining under government supervision.
  • Smaller Security Firms Can Participate: The program is open to companies of different sizes, including smaller firms that may be suited to specialized assignments. Participants will need to demonstrate their technical capabilities and meet requirements for areas such as personnel and facility security before contracting with Department of Justice or Department of Homeland Security. Companies will be reviewed at least annually and may be required to maintain a bond or escrow of at least $1 million, which can be forfeited for noncompliance.
  • Targeting Comes With Federal and Legal Controls: The program is limited to foreign cybercrime groups targeting U.S. interests, with groups treated as independent of foreign governments unless intelligence shows otherwise. Operations must be coordinated across relevant federal agencies and the intelligence community, with additional procedures outlined in a classified annex. If activity crosses approved boundaries, participating companies must stop, follow required procedures for handling any collected information, and immediately notify the NCC.
  • More Operating Rules Are Coming: DOJ and DHS have 60 days to establish procedures covering company eligibility, target identification, legal review, reporting, and approvals. Participating firms must notify the NCC if they discover an imminent cyberattack against U.S. critical infrastructure or reasonably believe an approved operation could produce a Critical Outcome. That includes activity likely to cause death or serious injury, or rise to the level of a use of force or armed attack under international law. Program directors cannot approve such outcomes under their delegated authority. An initial status report is due within 180 days, followed by annual reports.

Go Deeper -> EXPANDING CAPABILITIES TO COMBAT TRANSNATIONAL CYBER-ENABLED CRIME – The White House

Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups – TheHackerNews

In a first, US will allow some private firms to carry out cyberattacks – TechCrunch

Cybersecurity updates, executive insights, and the stories shaping the enterprise.

Browse past editions of TNCR newsletters. 

Technology news, cybersecurity, & executive insights.

×
You have free article(s) left this month courtesy of the CIO Professional Network.

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Would You Like To Save Articles?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Thanks for subscribing!

We’re excited to have you on board. Stay tuned for the latest technology news delivered straight to your inbox.

Save My Spot For TNCR LIVE!

Thursday April 18th

9 AM Pacific / 11 PM Central / 12 PM Eastern

Register for Unlimited Access

Already a member?

Digital Monthly

$12.00/ month

Billed Monthly

Digital Annual

$10.00/ month

Billed Annually

Would You Like To Save Books?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Log In To Access Premium Features

Sign Up For A Free Account

Name
Newsletters