Skip to content
Breaking:

Trump Memorandum Authorizes Private Cybersecurity Firms to Conduct State-Sanctioned Cyberattacks

A new federal directive allows private tech companies to execute offensive cyber operations against criminal networks, requiring vetting and a $1 million compliance bond.

By The Company Wire3 min read
Share
U.S. Government — Trump Memorandum Authorizes Private Cybersecurity Firms to Conduct State-Sanctioned Cyberattacks
U.S. Government — Trump Memorandum Authorizes Private Cybersecurity Firms to Conduct State-Sanctioned Cyberattacks. Photo: Engadget.

President Donald Trump has signed a national security presidential memorandum allowing private technology and cybersecurity companies to conduct offensive cyber operations targeting international criminal networks on behalf of the U.S. government, as first reported by Engadget.

According to the administration, the executive order aims to tap into private sector innovation and technical capabilities to counter digital threats. The directive specifically targets criminal activities such as ransomware attacks, financial fraud schemes, phishing campaigns, and digital extortion.

Historically, civilian cyber operations have been tightly restricted under federal law. The Computer Fraud and Abuse Act (CFAA) serves as the primary legislation outlawing unauthorized computer breaches, digital intrusions, and cyberattacks by private citizens and commercial entities.

In 2022, the Department of Justice updated its policy to protect security researchers and white-hat hackers from CFAA prosecution when engaging in good-faith security analysis. However, this new presidential directive significantly expands the range of offensive cyber activities that federal prosecutors can choose not to charge.

Key operational details regarding how the initiative will function remain to be established. The memorandum assigns the Homeland Security Task Force to create vetting protocols for participating contractors and formal procedure guidelines for conducting offensive operations.

The task force has been given 60 days to formulate these technical standards and participant selection criteria, which will establish the baseline rules for private companies entering the program.

To ensure oversight and adherence to federal mandates, participating businesses will be required to post a $1 million performance bond. Companies that fail to comply with government orders or exceed their authorized scope will lose the financial deposit.

While the memorandum shields participants from domestic federal prosecution when acting on government directives, it does not clarify legal protections for companies or individual workers facing potential criminal charges in foreign nations hosting targeted computer infrastructure.

The policy directive follows recent cyberattacks aimed at water utility infrastructure in Michigan and Minnesota, which federal officials attributed to Iranian state-linked groups. Because the U.S. government routinely indicts foreign hackers in domestic courts, industry analysts note American-backed private contractors could face similar legal exposure from international authorities.

Sources

  1. Engadget

Company: U.S. Government

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.