White House authorizes private companies to launch 'hack-back' cyberattacks that destroy data and systems, targeting foreign cybercrime organizations — vetted organizations can now conduct offensive cyber operations
President Trump signed a memorandum on August 12 establishing the first U.S. program that lets vetted private companies conduct offensive cyber operations.
On August 12, President Donald Trump signed a presidential memorandum launching a U.S. program allowing vetted private companies to engage in offensive cyber operations against foreign cybercrime organizations. To participate, firms must deposit at least $1 million in escrow, forfeitable if they violate program rules. Every operation requires written approval from Department of Justice and Department of Homeland Security officials.
The administration, which previously dismissed the idea, now permits two types of activities: Cyber Surveillance Operations, involving unauthorized access to foreign systems for intelligence collection while evading detection, and Cyber Effects Operations, aimed at disrupting or destroying systems and data. A National Coordination Center oversees the program, with implementation guidance due within 60 days. Eligibility is open to both large and small firms specializing in specific tasks.
Any unintentional strikes on U.S. persons or systems on U.S. soil require immediate cessation and notification to government authorities. A foreign entity qualifies as a target unless there is clear intelligence proving its institutional affiliation with a foreign government or complete operational control under one's direction. Ransomware groups operated with state tolerance but not formal state control are still eligible targets.
The DOJ and DHS directors cannot approve operations that may lead to loss of life or constitute an armed attack under international law. The memo does not outright prohibit such operations, with approval authority residing in a classified annex. Companies can also form commercial partnerships with other private firms and state/local agencies to share threat data and propose operations based on it.
Jake Williams, a cybersecurity expert, warned that Americans involved in the operations could be perceived as non-uniformed combatants while overseas. The memo comes in the wake of suspected Iranian cyberattacks on U.S. water suppliers and a CISA alert about Iranian hackers targeting water and energy companies' programmable logic controllers.
Congress allocated $1 billion for offensive cyber operations in last year's spending bill, and Google announced its intention to participate in disruptive actions against cybercriminals in August of the previous year.
Written by urgent.news from Tom's Hardware's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.