Skip to content
Breaking:

Trump Administration Program Allows Private Cybersecurity Firms to Launch Foreign Cyberattacks

Under federal oversight, approved security vendors will be permitted to infiltrate and dismantle overseas criminal networks.

By The Company Wire4 min read
Share
Department of Homeland Security — Trump Administration Program Allows Private Cybersecurity Firms to Launch Foreign Cyberattacks
Department of Homeland Security — Trump Administration Program Allows Private Cybersecurity Firms to Launch Foreign Cyberattacks. Photo: The Verge.

The Trump administration has launched a federal policy initiative that grants private cybersecurity firms authorization to carry out offensive cyberattacks against overseas criminal entities, according to an executive memorandum issued on Wednesday. Under the program, commercial technology companies will be permitted to monitor, infiltrate, and disrupt illicit networks, provided they operate under government control. The policy shift was first reported by Bloomberg and detailed in reporting by The Verge.

The Department of Justice and the Department of Homeland Security will share joint oversight responsibility for the commercial contractors admitted to the initiative. To secure authorization, firms must satisfy rigorous vetting criteria regarding technical proficiency, facility security protocols, and a verified track record in complex digital operations. Additionally, participating vendors are required to place a minimum of $1 million into escrow or hold an equivalent financial bond. This collateral will be subject to forfeiture if a company breaches the terms of its contractual agreement.

The presidential directive explicitly restricts the scope of targets that private vendors are allowed to engage. Commercial contractors are prohibited from launching cyber operations against entities that form an official part of a foreign sovereign government or operate under the complete direction of a foreign state. Instead, the initiative focuses strictly on independent criminal syndicates. The memorandum describes private enterprise as an underutilized force in national defense, stating that official policy aims "to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime."

Enlisting commercial vendors into offensive digital warfare marks a significant departure from historical federal strategy. Previously, offensive cyber strikes were conducted exclusively by federal military commands and intelligence agencies rather than third-party contractors. Plans to mobilize the commercial cybersecurity industry to assist in counter-cybercrime operations began developing within the Trump administration last year, Bloomberg reported.

However, cybersecurity researchers and policy analysts have highlighted severe operational and geopolitical risks inherent in delegating hack-back authority to private corporations. As noted by Cybersecurity Dive, establishing definitive attribution in cyberspace remains difficult, as independent cybercriminals frequently maintain informal ties to foreign state authorities. Targeting a group with undisclosed state links could unintentionally provoke diplomatic disputes. In an interview with Cybersecurity Dive, Jason Healey, a senior researcher specializing in cyber conflict at Columbia University, warned that "Anyone conducting these operations is doing so at substantial personal legal risk."

Legal experts also cautioned about the international standing of private-sector personnel participating in government-sanctioned counter-strikes. Jake Williams, vice president of research and development at Hunter Strategy, told TechCrunch that commercial operators could face legal exposure when traveling abroad. Williams noted that citizens taking part in these counter-cyber initiatives "could easily be classified as non-uniformed combatants while traveling overseas."

Technical specialists have raised further concerns regarding potential collateral damage to domestic and global digital infrastructure. Ben Bernstein, a manager on the cybersecurity advisors team at Huntress, emphasized that threat actors routinely obscure their origin by routing traffic through compromised third-party systems. Bernstein noted that criminal networks do not launch attacks from labeled servers in foreign capitals, but instead route malicious traffic through vulnerable infrastructure like compromised routers at a dental clinic in Ohio or a regional hospital network. "That makes it practically impossible to 'strike back' without taking out innocent bystanders," Bernstein said.

Despite these warnings from industry experts, the published directive creates the formal framework for federal agencies to begin selecting commercial partners. The Department of Justice and Department of Homeland Security will oversee the application and clearance process as security vendors seek to satisfy the program's technical and financial criteria.

Sources

  1. The Verge

Company: Department of Homeland Security

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.