The U.S. government will allow vetted private companies to conduct offensive cyber operations against foreign criminal groups and hackers for the first time.
The Trump administration announced the major policy shift Wednesday through a new presidential memorandum targeting transnational cyber-enabled crime.
The government said the program will use private-sector expertise against ransomware operators, financial scammers and other cybercriminals targeting Americans. Additionally, approved companies could conduct surveillance operations to collect intelligence about criminal networks operating outside the United States.
They could also launch disruptive operations designed to damage or destroy criminal data, computer systems and other digital infrastructure. However, participating companies will operate under federal supervision rather than independently choosing targets or launching their own attacks.
The policy represents a significant departure from the U.S. government’s traditional approach toward private companies conducting offensive cyber operations. Federal computer hacking laws generally prohibit companies and individuals from accessing or damaging computer systems without legal authorization.
Previously, Washington largely allowed cybersecurity companies to defend customers against attacks without letting them retaliate against suspected attackers. The new program creates a framework for companies to move beyond that defensive role.
However, the administration still needs to establish many of the rules governing how participating companies will operate. Federal officials plan to release guidance within two months detailing requirements that companies must satisfy before joining the program.
Additionally, the administration said companies of different sizes could participate if they meet the government’s requirements. Smaller cybersecurity businesses could prove useful because some specialize in particular technologies, criminal groups or types of cyber operations.
Read more: Solana tests quantum-resistant crypto as early trials show major speed tradeoffs
Read more: IonQ outlines blueprint for fault tolerant quantum computer using trapped ions
Companies will have obligations to report threats
Participating companies must deposit USD$1 million into escrow before conducting operations under the program. The government can subsequently seize that money if officials determine a company violated the program’s operating requirements.
Federal officials must also develop procedures intended to prevent participating companies from targeting Americans or computer systems located inside the country. Representatives from the Justice Department and Department of Homeland Security must approve individual operations before companies can proceed.
Furthermore, private operators must conduct their activities exclusively under federal government supervision. Companies will also have reporting obligations when their work uncovers threats against important American infrastructure.
For example, participants must notify federal officials after discovering an imminent attack against power grids, water systems or similar infrastructure. The White House has not disclosed whether any private cybersecurity companies have already joined the program.
The memorandum also stops short of broadly authorizing companies to independently “hack back” against attackers. That practice generally involves a victim or cybersecurity company attacking systems believed to belong to the original attacker.
However, identifying the true source of a cyberattack can prove difficult because criminals routinely route operations through compromised systems. Critics have consequently warned for years that private offensive operations could strike innocent systems or create international disputes.
The new policy could create another problem for Americans working on government-authorized cyber operations abroad. Foreign governments could potentially treat private cybersecurity employees as hackers involved in attacks against systems inside their jurisdictions.
Jake Williams, vice president of research and development at cybersecurity company Hunter Strategy, raised concerns about that possibility. He warned that Americans participating in these operations could face accusations that they acted as non-uniformed combatants.
Read more: Canada launches CAD$900 million defence strategy to advance quantum and AI capabilities
Read more: BMW and Quantinuum deepen multi year quantum computing alliance
Iranian-linked hackers targeting American businesses
Additionally, foreign authorities could potentially detain or indict Americans accused of participating in an offensive operation. Williams argued that accusations would not necessarily need to be accurate to create serious problems for individual cybersecurity workers.
Foreign governments have already faced similar U.S. legal actions involving state-backed hacking campaigns. American prosecutors have charged alleged Chinese, Iranian and Russian government hackers over cyber operations targeting U.S. organizations.
Meanwhile, Williams described the administration’s policy as underdeveloped and questioned whether authorities could prevent companies from abusing it. A classified section of the memorandum may provide additional details about how officials will select and authorize targets.
The administration introduced the program as American governments and businesses face growing cyber threats from overseas. Several states have recently reported cyberattacks targeting water infrastructure, including Michigan, Minnesota and Georgia.
U.S. intelligence officials have reportedly attributed those intrusions to hackers connected with the Iranian government. However, authorities have not issued water safety alerts resulting from the reported intrusions.
The attacks follow months of conflict involving the United States, Israel and Iran. Iranian-linked hackers have also targeted American businesses and critical infrastructure during the conflict.
Furthermore, cybersecurity agencies face the expanding challenge of artificial intelligence systems capable of performing increasingly sophisticated hacking tasks. Researchers have demonstrated that advanced AI systems can identify vulnerabilities and carry out parts of cyberattacks with limited human involvement.
Anthropic and OpenAI have reported security research involving frontier AI models and autonomous cyber capabilities.
Meta Platforms Inc. (NASDAQ: META) and the United Kingdom’s AI Safety Institute have also investigated risks involving advanced models and cyberattacks.
Read more: SEALSQ targets post-quantum cybersecurity market with new migration strategy
Read more: Palo Alto Networks, AT&T launch quantum-resistant cybersecurity platform
Program gives federal agencies access to specialized talent
Consequently, governments face cyber threats that can operate faster and at greater scale than many traditional criminal hacking campaigns. The private-sector program could give federal agencies access to specialized cybersecurity talent and technology outside government departments.
At the same time, the administration has reduced parts of the federal cybersecurity workforce since President Donald Trump returned to office. Those cuts have raised concerns about the government’s capacity to respond to expanding foreign and criminal cyber threats.
Meanwhile, the new program will depend on federal agencies to supervise companies, approve operations and prevent attacks against unintended targets. The administration has not detailed how many companies it expects to approve once the program begins operating.
Federal guidance expected within two months should provide the first detailed rules governing eligibility, oversight and operational requirements.