Trump Administration Plans to Authorize Private Cyberattacks Against Foreign Criminal Groups
The Trump administration is recruiting private cybersecurity firms to support federally authorized operations, including potential offensive cyberattacks, against foreign-based criminal organizations that target U.S. individuals, businesses, and government agencies.
In a national security presidential memorandum, President Donald Trump announced Thursday that he has directed the National Coordination Center (NCC), which operates under the Select Committee on Homeland Security, to create programs targeting foreign transnational criminal organizations (TCOs) involved in cybercrime. The Department of Justice and Department of Homeland Security will oversee the initiative, with participation from private cybersecurity companies serving as a central component.
Key Details of the Private Cyber Operations Program Remain Unclear
A fact sheet accompanying Thursday’s memorandum identifies ransomware, sextortion, phishing campaigns, financial fraud, and identity theft as potential targets for participating security firms. The memo says authorized companies may conduct “cyber surveillance and cyber influence activities” against cyber-enabled TCOs.
The memorandum defines these organizations as foreign groups that commit cybercrimes against the U.S. government, American individuals, or U.S. interests, while operating independently of a foreign government. The definition excludes groups that are formally organized by, or operate entirely under the direction of, a foreign state.
If implemented as described, the program would mark the first time the federal government has explicitly authorized private companies to conduct offensive cyber operations against foreign-based hackers. The memo appears to permit tools such as spyware and attacks designed to disrupt or destroy criminal networks, data, and computer systems.
The language does not clearly rule out other forms of offensive cyber activity, including attacks that encrypt systems to block access or distributed denial-of-service (DDoS) operations. Previously, private companies were generally prohibited from launching such actions without court approval. The scope of the authorization, legal safeguards, and rules governing private-sector participation have yet to be fully defined.
Source: arstechnica.com


