Cybersecurity4 mins read

US to Let Some Private Firms Carry Out Offensive Cyber Operations

A new White House memorandum marks a major shift in U.S. cybersecurity policy by allowing vetted private companies to conduct government-supervised offensive cyber operations against international cybercriminals and hackers.

A Major Shift in U.S. Cyber Policy

The U.S. government will allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers, according to a White House memorandum reported by TechCrunch. The move breaks from a long-standing U.S. position that private companies can defend against cyberattacks but cannot launch or operate them. The stated goal is to use private-sector capabilities against threats targeting Americans, including ransomware, financial scams, and sextortion.

What Approved Companies Could Do

Participating companies would be able to conduct surveillance, including using spyware to collect intelligence, and carry out disruptive attacks aimed at destroying criminals’ data or systems. The program is not fully operational yet, and the government is expected to issue guidance within two months on what companies must meet to participate. The memorandum says companies of different sizes could be considered, including smaller firms suited for specialized operations.

Rules, Oversight, and Limits

Companies in the program must deposit $1 million in escrow, which can be forfeited if the government determines they violated program rules. Operations would require approval from representatives of the Justice Department and Homeland Security and must be conducted under federal supervision. The memorandum also directs the government to create procedures preventing operations from targeting Americans or U.S.-based systems.

Legal and Diplomatic Risks Ahead

The policy is likely to face legal challenges and criticism from those who argue private companies should not take part in government hacking operations. TechCrunch reports that critics warn of possible diplomatic fallout if a foreign government claims it was attacked by a U.S. company. Cybersecurity veteran Jake Williams told TechCrunch that Americans involved in such operations could face legal or custody risks abroad and described the policy as “half-baked.”

Why the Change Matters Now

The administration framed the decision around a growing cyber threat to Americans and businesses. The policy arrives as U.S. entities face ransomware, international hacking activity, reported attacks on water infrastructure, and broader concern over autonomous AI-driven cyberattacks. The practical impact will depend on the forthcoming guidance, the approval process, and how tightly the government supervises private-sector operations.

Discover More