White House Lets Private Firms Hack Cybercriminals—At Their Own Legal Risk
Trump signed a memorandum creating a federal program to use vetted U.S. private companies in offensive cyber operations against foreign transnational criminal networks. The program sits within the Homeland Security Task Force’s National Coordination Center and is jointly run by executive directors from DOJ and DHS. Approved firms may be tasked to access, surveil, disrupt, or destroy overseas systems tied to ransomware, phishing, fraud, and sextortion operations, but only under federal direction and oversight. Companies must pass vetting, post at least a $1 million bond or escrow, and submit proposed operations for written government approval before acting. The government retains operational control. The memo authorizes cyber surveillance and other offensive actions, but bars operations causing “Critical Outcomes” and requires immediate stopping and minimization if U.S. persons or U.S.-based systems are affected. The White House says the goal is to expand the fight against transnational cybercrime by leveraging private-sector expertise. Public details are limited because key targeting rules are in a classified annex, and implementation guidance is due within 60 days.
