White House Greenlights Private Firm Cyber ‘Hack‑Back’ Strikes Against Foreign Criminal Groups

0
3

Key Takeaways

  • On August 12 President Trump issued a presidential memorandum creating the first U.S. program that authorizes vetted private companies to conduct offensive cyber operations against foreign cybercrime groups.
  • Participating firms must deposit at least $1 million in escrow (forfeited for rule violations) and obtain written approval from the Department of Justice (DOJ) and Department of Homeland Security (DHS) before each operation.
  • The memorandum distinguishes two activity types: Cyber Surveillance Operations (covert intelligence gathering) and Cyber Effects Operations (disruption or destruction of data and systems).
  • A National Coordination Center will oversee the program; implementation guidance is due within 60 days, and eligibility is open to both large corporations and smaller, niche‑focused firms.
  • Companies that unintentionally affect U.S. persons or domestic infrastructure must cease activity immediately and notify the government.
  • Targets are limited to foreign entities not clearly part of a foreign government; ransomware gangs that operate with state tolerance but without direct state control remain eligible.
  • Operations likely to cause loss of life or qualify as an armed attack under international law require additional, classified approval; the memo does not outright ban such actions.
  • The program follows a reversal of earlier administration statements that denied interest in private offensive cyber capabilities and comes amid heightened concern over Iranian cyber threats to U.S. water and energy infrastructure.
  • Congress has allocated $1 billion for offensive cyber initiatives, and major tech firms such as Google have signaled willingness to participate in disruptive actions against cybercriminals.

Background and Policy Shift
In March 2020, Thomas Lind, then a senior adviser at the Office of the National Cyber Director, publicly asserted that the administration had no plans to authorize private companies to conduct offensive cyber operations, likening such a move to “fighting pirates with pirates.” National Cyber Director Sean Cairncross echoed that sentiment, emphasizing that the government’s request for industry assistance was limited to defensive and intelligence‑sharing roles. The August 12 presidential memorandum represents a stark reversal of that stance, formally establishing a framework that permits private sector involvement in offensive cyber activities. This policy shift aligns with broader administration efforts to counter increasingly sophisticated cybercrime networks that have proven resistant to traditional law‑enforcement and diplomatic tools.

Escrow Requirement and Oversight Mechanism
To mitigate risks associated with delegating offensive capabilities to non‑governmental actors, the memorandum mandates that any participating company post at least $1 million in an escrow account. The funds are subject to forfeiture if the firm violates program rules, providing a financial incentive for compliance. Before any operation can commence, the company must obtain written approval from both the DOJ and DHS, ensuring that legal and national‑security considerations are vetted by civilian authorities. This dual‑agency sign‑off is intended to create a checks‑and‑balances system that prevents unilateral or rogue actions while still allowing the government to leverage private expertise and agility.

Authorized Activity Categories
The memorandum delineates two distinct categories of permissible activity. Cyber Surveillance Operations involve gaining unauthorized access to foreign computer systems to collect intelligence while remaining undetected—essentially a covert espionage function conducted by private contractors. Cyber Effects Operations, by contrast, entail the active disruption, degradation, or destruction of target systems and the data they hold, which could include ransomware‑style attacks, data wipes, or denial‑of‑service effects. By separating surveillance from effects, the framework seeks to clarify the legal and operational boundaries of each type of mission, facilitating clearer oversight and accountability.

Program Administration and Eligibility
A newly created National Coordination Center will manage the program’s day‑to‑day operations, overseeing the intake of proposals, tracking escrow accounts, and ensuring that all actions adhere to the established guidelines. Implementation guidance must be issued within 60 days of the memorandum’s signing, providing firms with detailed procedures for submitting requests, reporting outcomes, and handling inadvertent impacts on U.S. persons or infrastructure. Eligibility is deliberately broad: both large multinational corporations and smaller, specialized boutique firms may apply, allowing the government to match the scale and sophistication of a threat with the appropriate private partner.

Safeguards for Domestic Impact
Recognizing the potential for collateral damage, the memorandum includes an explicit provision requiring any company that unintentionally affects a U.S. person or a system located on U.S. soil to halt operations immediately and notify the relevant government agencies. This “stop‑and‑notify” rule aims to limit the risk of domestic harm while preserving the ability to pursue foreign targets aggressively. It also creates a feedback loop whereby incidents of accidental domestic impact can be reviewed to refine targeting criteria and improve operational discipline.

Target Definition and Limitations
The memorandum defines a valid target as any foreign group that is not “clearly intelligence‑established” to be institutionally part of a foreign government or wholly operated under a foreign government’s direction. Consequently, ransomware syndicates that operate with the tacit tolerance or indirect support of a state—such as many Russia‑based ransomware crews—remain within the program’s scope, as they do not meet the strict threshold of direct state control. However, the memorandum also notes that the DOJ and DHS directors cannot approve operations that are likely to cause loss of life or that would rise to the level of an armed attack under international law. While such operations are not categorically prohibited, they require additional, classified approval, indicating a recognition of the heightened legal and ethical stakes involved in lethal or war‑like cyber effects.

Context of Recent Threats and Legislative Support
The policy announcement comes shortly after a series of suspected Iranian cyberattacks targeting water suppliers in 45 U.S. municipalities, accompanied by a CISA warning about Iranian hackers seeking to compromise programmable logic controllers at water and energy facilities. Although state‑directed actors fall outside the program’s target definition, the administration appears to be using the private‑offensive framework as a tool to counter non‑state cybercriminal enterprises that often enable or amplify state‑linked threats. Legislatively, Congress has already earmarked $1 billion for offensive cyber operations in the most recent spending bill, underscoring bipartisan support for expanding the nation’s cyber‑offensive toolbox. Private sector interest has also been signaled: Google disclosed in August 2020 that it was preparing to participate in disruptive actions against cybercriminals, suggesting that major technology firms view the memorandum as an opportunity to contribute their capabilities within a regulated environment.

Implications for Private‑Sector Involvement and International Norms
By authorizing private companies to conduct offensive cyber operations, the United States is venturing into relatively uncharted territory regarding the normalization of non‑state actors in cyber warfare. Experts such as Jake Williams of Hunter Strategy warn that Americans participating in these operations could be classified as non‑uniformed combatants when operating abroad, raising questions about liability, the application of the law of armed conflict, and potential reprisals. Internationally, the move may prompt other nations to reconsider their own policies regarding private cyber militias, potentially accelerating a trend toward the privatization of offensive cyber capabilities. At the same time, the stringent escrow, approval, and notification requirements reflect an attempt to mitigate escalation risks and maintain governmental oversight, balancing the desire for agile, innovative responses to cybercrime with the need to uphold legal and ethical standards.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here