Trump administration to let private security firms hack overseas cybercriminals

Trump administration to let private security firms hack overseas cybercriminals

The Trump administration is building a program that would let private cybersecurity firms carry out government-authorized cyber operations, including offensive attacks, against foreign criminal groups that hack US persons, organizations, or government entities. President Donald Trump laid out the plan in a National Security Presidential Memorandum issued Thursday. It directs the National Coordination Center (NCC), which operates under the Homeland Security Task Force, to develop the program, with the Departments of Justice and Homeland Security providing oversight. Recruiting private companies to actually carry out the operations is the program's lynchpin.

A fact sheet released with the memo spells out which crimes make a target eligible: ransomware, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams. Participating firms, the memo states, could 'conduct Cyber Surveillance Operations and Cyber Effects Operations' against what it calls 'cyber-enabled' transnational criminal organizations, or TCOs. The memo defines a TCO as any foreign group that commits cyber-enabled crime against the US government, a US person, or US interests, provided the group is not an institutional part of a foreign government or wholly run under a foreign government's direction.

This would be the first time the federal government authorizes private companies to conduct offensive cyber operations against overseas hackers. Until now, the government has prohibited the private sector from taking such actions without court-authorized approval. The memo appears to permit participating firms to use spyware or launch attacks meant to destroy a target's data or systems, though that reading is the reporting's own inference rather than an explicit statement in the memo. The memo also does not rule out other offensive techniques, such as encryption-based attacks that lock a target out of its network, or distributed denial-of-service attacks; neither is spelled out as expressly authorized.

Much is still undefined. As reported, the memo and its fact sheet do not name a specific security firm expected to take part or set a timeline for when the program would start operating.

Key facts

  • President Trump issued a National Security Presidential Memorandum on Thursday directing the National Coordination Center (NCC), under the Homeland Security Task Force, to build a program letting private security firms conduct government-authorized cyber operations against foreign criminal groups.
  • The Departments of Justice and Homeland Security will oversee the program; recruiting private companies to carry out the operations is described as the program's lynchpin.
  • A fact sheet accompanying the memo lists ransomware, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams as the crime categories eligible for firms to target.
  • This would be the first time the federal government authorizes private companies to conduct offensive cyber operations against overseas hackers; previously, such actions required court-authorized approval.
  • The memo appears to permit spyware use and attacks meant to destroy a target's systems, and does not rule out encryption-based lockouts or denial-of-service attacks, though the article flags both readings as inference rather than explicit permission.

Why it matters

This would be a real break from precedent. Until now, the government has prohibited the private sector from taking actions like these without court-authorized approval; the administration frames the new program as the first time the federal government would authorize private companies to conduct offensive cyber operations against overseas hackers. Recruiting private firms to participate is described as the program's lynchpin, and their assigned targets would be the groups behind ransomware, sextortion, phishing, financial fraud, and impersonation scams aimed at US persons, organizations, and government entities.

Who it affects

Private security firms are the intended operators: the program is built around recruiting them to carry out the cyber operations directly. Their targets would be transnational criminal organizations, foreign groups engaged in cyber-enabled crime against the US government, US persons, or US interests, provided the group is not part of or run by a foreign government. US individuals, companies, and government entities victimized by ransomware, sextortion, phishing, financial fraud, or impersonation scams are the intended beneficiaries. The National Coordination Center, under the Homeland Security Task Force, would run the program, with the Departments of Justice and Homeland Security providing oversight.

How to use it

Once running, the program would let a security firm work with the National Coordination Center to carry out one of two kinds of operations against a qualifying target: what the memo calls Cyber Surveillance Operations and Cyber Effects Operations. A target qualifies as a TCO if it is a foreign group committing cyber-enabled crime against the US government, a US person, or US interests, and it is not an institutional part of, or wholly run by, a foreign government. The fact sheet sets the scope by naming the qualifying crimes: ransomware, sextortion, phishing, financial fraud, and impersonation scams.

How solid is it

The account leans directly on the memo's own language and the fact sheet that came with it: the list of qualifying crimes, the phrase 'Cyber Surveillance Operations and Cyber Effects Operations,' and the definition of a transnational criminal organization are all quoted rather than paraphrased. Where the reporting goes further, on whether the memo permits spyware use or attacks meant to destroy a target's systems, it flags that as its own reading rather than the memo's explicit words. Substantial gaps remain: as reported, no specific firm or start date for the program has been disclosed.

Risks and caveats

The reporting is careful to mark its stronger claims as inference: the memo 'appears to permit' spyware use or attacks meant to destroy a target's data or systems, and it 'doesn't rule out' encryption-based attacks that lock a target out of its network or distributed denial-of-service attacks, without explicitly authorizing any of them. Until now, the private sector needed court-authorized approval before taking actions like these; this program would instead route such operations through Justice and Homeland Security oversight, though neither the memo nor the fact sheet, as reported, spells out what that oversight would actually consist of beyond the fact that the two departments would provide it.

“any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government's direction.”

— Trump's memo, defining a transnational criminal organization