White House Deputizes Private Companies to Hack Back at Foreign Cybercriminals

by

in

White House Deputizes Private Companies to Hack Back at Foreign Cybercriminals

President Trump signed a National Security Presidential Memorandum on August 12 authorizing vetted private companies to conduct offensive cyber operations against foreign threat actors under federal government oversight. The memo establishes two categories of authorized activity: Cyber Surveillance Operations, which involve accessing a target’s systems without authorization to collect intelligence while remaining undetected, and Cyber Effects Operations, which can manipulate, disrupt, deny, degrade or destroy targeted information systems, networks or infrastructure. Both require written approval from the program’s executive directors before a company can act, and participants must be under federal contract [1, 2].

Coverage of the memo spread through mainstream outlets on Friday. The order does not change existing U.S. anti-hacking laws, but some cybersecurity experts warn it doesn’t resolve the legal exposure private companies would face for violating other nations’ domestic laws, or the risk of collateral damage if a targeted data center’s “blast radius” affects unrelated U.S. companies [2, 3].

Why It Sucks:

Cybersecurity Companies

  • Finally allowed to fight back. Vetted firms have spent years absorbing ransomware and intrusion losses while barred from taking offensive action, and supporters see this as the first real avenue to impose costs on foreign attackers directly [1, 2].
  • Government oversight adds legitimacy. Because operations require written approval from federal program directors, participating companies argue this isn’t vigilantism but a structured extension of national cyber defense [1].
  • Deterrence has been missing for too long. Industry backers argue that without any credible threat of retaliation, foreign ransomware groups have operated with near impunity, and this program finally changes that calculus [2].

Privacy and Civil Liberties Advocates

  • Private actors get offensive cyber weapons. Critics warn that authorizing companies to destroy or degrade foreign systems blurs the line between corporate security and state warfare, without the accountability structures that govern military cyber operations [2, 3].
  • Legal exposure doesn’t disappear because Washington says so. The memo doesn’t shield companies from the domestic laws of the countries where targets are located, meaning private firms could face real legal jeopardy for actions the U.S. government simply approved on paper [2].
  • Escalation risk falls on everyone. Advocates worry that private hack-back campaigns could trigger retaliatory cycles with foreign state and criminal actors that ordinary Americans, not just the companies involved, end up absorbing [3].

Ordinary Businesses Outside the Program

  • Collateral damage without a say. Cybersecurity experts specifically flag the risk that a targeted data center’s blast radius could mistakenly affect unrelated U.S. companies who never opted into the program and have no recourse if they’re caught in the crossfire [2].
  • A two-tier cyber defense system. Only large, federally vetted firms get the benefit of offensive tools, leaving small and midsize businesses, the most frequent targets of ransomware, stuck playing defense while bigger players go on offense [1, 2].
  • Retaliation could land on the wrong target. If a foreign actor retaliates against a hack-back campaign, there’s no guarantee the response hits the company that struck first rather than a smaller, unrelated business sharing the same infrastructure or supply chain [3].

Sources & Citations:

[1] NPR: Trump administration wants to allow companies to hack foreign cybercriminals
[2] Help Net Security: White House authorizes private US companies to hack foreign criminal networks
[3] Tom’s Hardware: White House authorizes private companies to launch ‘hack-back’ cyberattacks

Why It All Sucks

Sign up to receive updates about our website.

We don’t spam! Read our privacy policy for more info.


0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Oldest
Newest Most Voted