Hutchinson Kansas Newspaper

collapse
Home / Daily News Analysis / The US government wants private companies to start hacking the hackers

The US government wants private companies to start hacking the hackers

Aug 16, 2026  Twila Rosenbaum 18 views
The US government wants private companies to start hacking the hackers

The Trump administration is preparing to turn the tables on cybercriminals. Under a new presidential memorandum, the US government will allow vetted private companies to conduct offensive cyber operations against foreign criminal groups. The initiative, which requires federal oversight, marks a watershed moment in the long-running debate over whether private cybersecurity firms should be allowed to fight fire with fire.

As reported by multiple outlets, the memorandum establishes a federal program under which private companies could carry out both surveillance and disruptive cyber operations against foreign cyber-enabled criminal organizations. The stated goal is to tackle threats such as ransomware, fraud, and other cybercrimes that target American citizens and businesses. The program is being developed jointly by the Department of Justice and the Department of Homeland Security, with officials given 60 days to establish detailed operating procedures.

What the Program Allows

The powers granted to participating companies are significant. Under the memorandum, approved firms may conduct operations that can manipulate, disrupt, degrade, or destroy computer systems and data belonging to foreign criminal groups. Surveillance operations could involve secretly accessing those systems without the owner's permission to gather intelligence. This goes far beyond the traditional defensive activities that cybersecurity companies typically perform, such as monitoring networks, patching vulnerabilities, and removing malware from compromised machines.

However, the companies will not be given a blank check. Every operation will require written approval from program directors at the Justice Department and the Department of Homeland Security. The firms must act under federal supervision and follow a rulebook that is still being finalized. Additionally, participating companies may be required to put up at least $1 million in a bond or escrow account. That money could be forfeited if the companies break the rules, providing a financial incentive to stay within legal and operational boundaries.

Guardrails and Exemptions

The program includes several guardrails aimed at preventing abuse. It is intended to target foreign criminal groups rather than foreign governments, meaning operations against nation-state actors would remain outside the program's scope. Companies must also stop and report any operation that accidentally targets a US person or a US-based system. This is a critical safeguard, given the risk of collateral damage in cyberspace where infrastructure is often shared across borders.

Officials have acknowledged that the precise rules are not yet complete. The 60-day window for establishing operating procedures suggests that the memorandum is more of a framework than a fully detailed set of instructions. The final regulations will presumably define what constitutes a foreign criminal group, how approval requests are evaluated, and what kinds of operations are considered proportionate.

A Major Policy Shift

The move marks a clear departure from the US government's traditional position on private sector involvement in offensive cyber operations. For years, the official stance was that private companies could defend against hackers—by building firewalls, writing detection signatures, and cleaning up after intrusions—but they should not launch attacks themselves. That line was rooted in legal, ethical, and practical concerns. The new memorandum effectively erases that line for approved companies operating under federal supervision.

This shift reflects a growing frustration with the escalating threat from ransomware gangs and other cybercriminal enterprises. In recent years, high-profile attacks have disrupted hospitals, schools, gas pipelines, and major corporations, causing billions of dollars in damage. Many of these groups operate from countries that are unwilling or unable to take action against them, and traditional law enforcement methods have often proven too slow or ineffective. By allowing private companies to take the fight directly to the criminals, the US government hopes to gain a new tool in disrupting these networks.

Concerns from Cybersecurity Experts

Not everyone in the cybersecurity community is convinced the plan is a good idea. Jake Williams, a veteran cybersecurity professional, described the plan as “half-baked” in comments to the press. He warned that Americans involved in such operations could face legal trouble or accusations from foreign governments while traveling overseas. This is a legitimate concern: even if the federal government authorizes an operation, other countries may view it as an unauthorized intrusion into their sovereign systems. Private security contractors could be exposed to prosecution abroad, diplomatic fallout, or retaliation from criminal groups

There are also questions about how accountability will work. If a private company conducts an offensive operation that goes wrong, who is responsible? The company? The government? The individual operator? The memorandum's requirement for written approval and federal supervision suggests that the government would share responsibility, but the details of that arrangement remain unclear. Legal experts note that the use of private contractors in military and intelligence operations has a long history, but the full extent of their immunity is often murky.

International Law and Ethical Questions

The program also raises substantial questions under international law. Cyber operations that cross borders can violate the sovereignty of the countries where the targeted systems are located. The United Nations Group of Governmental Experts has acknowledged that cyber activities may constitute a breach of international law in some circumstances, but there is no consensus on exactly where the line is. Allowing private companies to conduct these operations could further blur the boundaries between state actions and private conduct, creating potential legal precedent that other nations might follow.

Ethically, the program is a double-edged sword. On one hand, private companies exist to protect clients, and being able to disrupt a ransomware gang before it strikes could be seen as a form of self-defense. On the other hand, granting private entities the power to break into systems and destroy data—even with government approval—could lead to abuse or misjudgment. The requirement to report accidental targeting of US persons is a recognition of these risks, but it does not eliminate them.

Potential Impact on the Cybersecurity Industry

The policy could reshape the cybersecurity industry itself. Companies that possess sophisticated offensive capabilities may seek to join the program, seeing it as a lucrative new market. Others, however, may prefer to avoid the legal and reputational risks associated with offensive operations. The escrow requirement, while modest for large firms, could still serve as a barrier for smaller companies. The program may also attract firms with prior experience in government contracting, given the stringent vetting and supervision requirements.

Cybersecurity experts point out that offensive operations are not a silver bullet. Even the most skilled hackers cannot completely eliminate cybercrime. Criminal groups are often resilient, adapting to disruptions and moving to new infrastructure. The memorandum's focus on foreign criminal groups might also drive some of these organizations to shift tactics, perhaps by using more encryption or operating in jurisdictions where the US government has less influence. Nevertheless, the ability to disrupt, degrade, and destroy criminal infrastructure in a coordinated manner could provide a meaningful advantage.

What Comes Next

Over the next 60 days, officials from the Justice Department and the Department of Homeland Security will work to establish the operational rules. The memorandum does not specify how many companies will be selected, what vetting standards will be used, or how operations will be monitored in real time. Public input is unlikely to be invited, as this is an executive branch initiative, but industry stakeholders may be consulted privately.

The result will be a pilot program of sorts—a test of whether private companies can be trusted with offensive cyber power under government supervision. If successful, it could become a permanent feature of US cyber strategy. If it fails, either operationally or legally, the backlash could set back the idea of public-private cyber cooperation for years. For now, the memo represents a bold bet: that private companies can hack the hackers without turning cyberspace into a lawless frontier where anyone can attack anyone else under the guise of self-defense. The world will be watching to see how that bet plays out.


Source:Android Authority News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy