The U.S. government will for the first time allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers, the White House said on Wednesday. In a newly published presidential memorandum, the Trump administration said the move will let the federal government use the "innovative capabilities of the private sector" to combat cybercrime and threats targeting Americans, such as ransomware attacks, financial scams, and sextortion.
The memorandum allows companies participating in the government's program to conduct surveillance — including using spyware to collect intelligence — as well as make disruptive attacks aimed at destroying criminals' data or systems. The policy change marks a seismic shift in the U.S. government's long-standing position under federal computer hacking laws, which broadly prohibit private companies from conducting cyberattacks or disruption operations without court-authorized approval. Through multiple administrations, the position had been that the private sector can defend against incoming cyberattacks, but not launch or operate them.
The program is still in its early days: the government has not yet fully established how it will operate, and the new policy is likely to face legal challenges from critics who have argued for years that private companies should not be involved in government hacking operations. The government will issue guidance in the next two months outlining the requirements participating companies must meet. Companies must deposit $1 million in escrow, forfeited if they fail to comply with the rules. Any operation requires sign-offs from representatives of the Justice Department and Homeland Security, must be conducted under federal supervision, and procedures must prevent operations from targeting Americans or U.S.-based systems. Participants must also notify the government if they discover an imminent cyberattack against critical U.S. infrastructure, such as power grids or water providers.
The memorandum stops short of allowing companies to "hack back" any cyber threat. Critics warn the policy could have diplomatic ramifications — for instance, if a foreign government complains it was attacked by a U.S. company. "Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas," said Jake Williams, vice president of R&D at cybersecurity firm Hunter Strategy, who called the policy "half-baked." The move comes amid a wave of autonomous AI-driven cyberattacks reported by major labs, and as U.S. officials attribute intrusions on water infrastructure in over a dozen states to Iranian government-backed hackers.
Sources
- techcrunch.comTechCrunch: In a first, US will allow some private firms to carry out cyberattacks
- whitehouse.govWhite House: Expanding Capabilities to Combat Transnational Cyber-Enabled Crime
- cyberscoop.comCyberScoop: Trump turns to private sector in offensive hacking memo
- lawfaremedia.orgLawfare: Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations




