In a first, US will allow some private firms to carry out cyberattacks
The new order sweeps away decades of existing U.S. cybersecurity policy prohibiting private companies from conducting 'hack back' attacks or offensive cyber operations.
The United States government announced on Wednesday that it will, for the first time, permit select private firms to execute offensive cyber operations against international criminal groups and hackers, according to the White House. In a memorandum published by the administration, it stated that this move will enable leveraging the "innovative capabilities of the private sector" to combat cybercrime and threats targeting Americans, including ransomware attacks, financial scams, and sextortion.
Private companies participating in the program will be allowed to carry out surveillance, such as using spyware to gather intelligence, as well as disruptive attacks aimed at destroying criminals' data or systems. This policy change represents a significant departure from the U.S. government's previous stance under computer hacking laws that generally prohibited private companies from conducting cyberattacks or disruption operations without court approval.
Currently, private companies are subject to the same computer hacking laws as individuals, which restricts them from conducting cyberattacks. The government's position, consistent across administrations, has been that the private sector can defend against incoming cyberattacks but not launch or operate them. The new policy is still in its early stages and the government has yet to finalize how the program will operate.
It is expected to face legal challenges and opposition from critics who have argued against private companies being involved in government hacking operations for years. Participating companies must deposit $1 million in escrow, forfeitable if they are found non-compliant with the government's rules for conducting these operations.
The government must ensure that any operation does not target Americans or U.S.-based systems and requires sign-offs from representatives from the Justice Department and Homeland Security before approval. Operations will be conducted exclusively under federal supervision, and companies must notify the government if they discover an imminent cyberattack against critical U.S. infrastructure.
Critics have raised concerns that the involvement of private industry in government operations could lead to diplomatic and international ramifications and that Americans working for private cybersecurity companies could face indictment or custody by foreign governments. Cybersecurity expert Jake Williams warned that Americans participating in these operations could be classified as non-uniformed combatants while overseas, giving foreign governments cover to make such accusations.
The administration claims that the policy is necessary due to the growing threat against Americans and businesses, including widespread cyber threats faced by the U.S. in recent months.
Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.