In a groundbreaking memorandum issued on August 12, President Trump announced that the U.S. government will now allow private firms to launch cyberattacks on transnational cybercriminals. The initiative aims to address concerns over rising international cybercrimes and threats to U.S. infrastructure.
Details of the initiative
According to the memorandum, the U.S. government seeks to expand its cybercrime fighting operations by “incorporating the ingenuity of the private sector.” With Department of Justice oversight, “vetted” private groups will now be allowed to conduct cyberoperations, including spyware campaigns and system-targeted attacks, against any known transnational cybercrime groups. The program is aimed at bringing down “criminal gangs, not nation-states,” and currently prohibits the targeting of any U.S.-based organizations. Participants are also forbidden to take part in “surveillance or disruption operations that would kill or seriously injure people or constitute the use of force or an armed attack under international law.”
To ensure that everything is above-board, each participating company is required to put down a $1 million dollar bond with the government (which would be forfeit, should they break any program rules), and all operations must be approved by the DOJ and DHS program directors before being set into motion. The memorandum also requires all participating organizations to inform the government if they “[discover] an imminent cyberattack against critical U.S. infrastructure, such as power grids or water providers.” This directive comes after Iranian hackers targeted hundreds of water systems around the U.S. earlier this year.
A new standard
In the past, hacking – even for well-intentioned purposes – was strictly prohibited and prosecuted under federal law. But in 2022, the U.S. Justice Department changed its policy, making allowances for “good faith” hackers, and instead directing its attention towards prosecuting malicious cybercriminals. This new initiative from President Trump reiterates that policy.
While the idea behind the memorandum is admirable, many within the cybersecurity sector have expressed multiple concerns about allowing private-sector agents to engage in dangerous cyberwarfare and potentially gain access to sensitive data. As Scott Shackelford, the head of the Center for Applied Cybersecurity Research at Indiana University, commented:
“This administration action is a meaningful response to a growing problem and does have some guardrails in place. But significant questions remain about unleashing the private sector in this way, and what accountability mechanisms will be in place for bad actors.”
As of this publication, the White House has not disclosed if any private organizations have reached out to the Department of Justice regarding the memorandum or if any attacks have been launched so far.