A new U.S. government program allows vetted American companies to conduct cyberattacks against foreign criminal groups, including operations to disrupt or destroy their systems and infrastructure.
The presidential memorandum gives participating companies a direct role in certain federal cyber operations, with activity subject to government approval, direction, and oversight.
This effort follows a March executive order addressing cyber-enabled crime affecting Americans. According to the White House, consumers have reported an estimated $20.8 billion in losses tied to cyber-enabled crime.
Why It Matters: Cybersecurity providers could serve commercial customers while participating in government-directed operations, raising questions about how customer information is handled and separated from federal work. The program also allows commercial threat information to support proposed operations. Rules due within 60 days are expected to provide more detail on the controls involved.
- Commercial Threat Intelligence Could Support Operations: Threat information already collected through normal business activity could become part of a proposed federal operation. Participating firms can bring that information to the National Coordination Center when identifying criminal targets, while government agencies can provide relevant threat information of their own. Any commercial agreements used to support this process must be disclosed to the NCC.
- Private Firms Can Take Part in Offensive Operations: Approved companies could covertly access criminal systems to gather intelligence that may later support disruptive action. Depending on the operation, that authority can extend to interfering with or destroying systems, infrastructure, or data. Companies cannot act independently, with each operation requiring written federal approval and remaining under government supervision.
- Smaller Security Firms Can Participate: The program is open to companies of different sizes, including smaller firms that may be suited to specialized assignments. Participants will need to demonstrate their technical capabilities and meet requirements for areas such as personnel and facility security before contracting with Department of Justice or Department of Homeland Security. Companies will be reviewed at least annually and may be required to maintain a bond or escrow of at least $1 million, which can be forfeited for noncompliance.
- Targeting Comes With Federal and Legal Controls: The program is limited to foreign cybercrime groups targeting U.S. interests, with groups treated as independent of foreign governments unless intelligence shows otherwise. Operations must be coordinated across relevant federal agencies and the intelligence community, with additional procedures outlined in a classified annex. If activity crosses approved boundaries, participating companies must stop, follow required procedures for handling any collected information, and immediately notify the NCC.
- More Operating Rules Are Coming: DOJ and DHS have 60 days to establish procedures covering company eligibility, target identification, legal review, reporting, and approvals. Participating firms must notify the NCC if they discover an imminent cyberattack against U.S. critical infrastructure or reasonably believe an approved operation could produce a Critical Outcome. That includes activity likely to cause death or serious injury, or rise to the level of a use of force or armed attack under international law. Program directors cannot approve such outcomes under their delegated authority. An initial status report is due within 180 days, followed by annual reports.
Go Deeper -> EXPANDING CAPABILITIES TO COMBAT TRANSNATIONAL CYBER-ENABLED CRIME – The White House
Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups – TheHackerNews
In a first, US will allow some private firms to carry out cyberattacks – TechCrunch

