Trump has authorized the use of private companies in cyber operations against criminal groups
U.S. President Donald Trump has signed a national security memorandum that calls for the involvement of private companies in limited offensive cyber operations against foreign transnational criminal organizations. Such operations are to be conducted under the direction, supervision, and within the authority of the U.S. government, according to The Guardian.
The White House stated that the document directs the administration to leverage the capabilities and innovations of the private sector to conduct cyber operations. At the same time, the memorandum does not grant companies unlimited authority to carry out hacking operations on their own: it refers to limited actions carried out at the direction of the U.S. government.
In its explanation of the document, the White House cited ransomware attacks, financial fraud, and other crimes committed by groups based outside the U.S. The memorandum establishes a mechanism through which private companies can enter into agreements with one another, as well as with federal, state, local, tribal, and territorial authorities to gather information on threats posed by such groups and submit proposals for retaliatory cyber operations.
For more breaking news, follow the UA.News Telegram channel.
The U.S. Department of Homeland Security, through the National Coordination Center of the Homeland Security Operational Task Force, is set to launch a program to conduct specific cyber operations aimed at disrupting the activities of foreign criminal groups. The program will be overseen by the Department of Homeland Security and the Department of Justice.
After undergoing vetting, participating companies will be able to conduct cyber surveillance and cyber influence operations against designated targets under federal oversight. The document defines cyber influence as the potential manipulation, disruption, blocking, degradation, or destruction of information systems, networks, physical or virtual infrastructure, and data. To participate in the program, companies must maintain a bond or funds in an escrow account totaling at least $1 million.
Previously, the involvement of the private sector in cyber operations against criminal and other targets has been controversial due to risks of escalation, unintended consequences, and coordination issues among government agencies.