US allows private cybersecurity firms to hack foreign cybercriminals

AI-generated image

The US government now permits private companies to conduct cyberattacks against transnational criminal organizations abroad. These state-supervised operations target ransomware, financial scams, or phishing but exclude groups tied to foreign governments.

A first-of-its-kind federal-controlled program

A presidential memorandum signed on August 12, 2026, by Donald Trump formalizes the creation of a program led by the National Coordination Center (NCC), under the Homeland Security Task Force. Selected private companies may participate after a joint assessment by the Justice Department and the Department of Homeland Security (DHS). Their mission: conduct cyber surveillance operations (unauthorized access to systems) or offensive cyber operations (data or system destruction) against criminal groups targeting the US, its citizens, or its interests.

Eligible targets include networks behind ransomware, financial scams, phishing, or sextortion (online sexual blackmail). However, groups linked to or controlled by a foreign state are explicitly excluded. Prohibited operations are those that could cause critical consequences: loss of life, serious injury, or acts equivalent to armed aggression under international law.

Strict safeguards, but gray areas remain

To participate, companies must demonstrate proven technical expertise, secure facilities and personnel, and post a $1 million bond. This amount will be forfeited in case of rule violations. Each operation must be approved in writing by the program’s executive directors from the DOJ and DHS, who retain operational control.

The memorandum leaves several questions unanswered. Precise selection criteria for companies and attack procedures will be detailed within 60 days. Above all, nothing protects employees of these firms from prosecution abroad: "Americans involved in these operations could be considered unlawful combatants if they enter a target country," warns Jake Williams, VP of R&D at Hunter Strategy.

  • Operations must cease immediately if they affect a US system or individual.
  • Companies must report any imminent threat to critical infrastructure (power grids, water, etc.).
  • Target details are listed in a classified annex.

A controversial shift

This decision marks a reversal of US doctrine, which previously barred private actors from conducting cyberattacks without judicial approval. The Computer Fraud and Abuse Act (CFAA), the key anti-hacking law, applied to all, including businesses. In 2022, the DOJ softened its stance for white hat hackers (ethical hackers), but stopped short of authorizing offensive actions.

"There’s merit in hacking ransomware groups, and it’s already happening (don’t ask how I know). But the right incentives are needed." — Kevin Beaumont, independent cybersecurity researcherTranslated from French
"Malicious actors don’t attack from servers labeled in Moscow. They use compromised infrastructure, like a vulnerable router at an Ohio dentist’s office or a hospital. Retaliating without hitting innocents? Mission impossible." — Ben Bernstein, HuntressTranslated from French

The geopolitical context also weighs in: recent cyberattacks on water infrastructure in Minnesota and Michigan were attributed to Iranian hackers. The memorandum comes as the US faces a wave of autonomous attacks carried out by AI, as reported by Anthropic, OpenAI, or the UK AI Safety Institute.

If the program aims to fill gaps in the state response, its success will depend on the clarity of upcoming rules. Between legal risks for companies, ambiguity over targets, and international tensions, the balance will be delicate.

Sources

Ars Technica — Private security firms will soon be allowed to hack overseas cybercriminals

The Verge — The Trump admin will start letting private firms launch international cyberattacks

TechCrunch — In a first, US will allow some private firms to carry out cyberattacks

Decrypt — White House Lets Private Firms Hack Cybercriminals—At Their Own Legal Risk

Engadget — US government to allow private companies to carry out cyberattacks on its behalf

Comments 0

··
Account required · moderated after posting

Be the first to comment.