The United States is preparing to let approved private companies conduct offensive cyber operations against foreign cybercriminal groups under government supervision.

US Moves to Let Private Firms Hack Foreign Cybercriminal Networks

The420.in Staff
4 Min Read

The United States is preparing to allow selected private companies to conduct offensive cyber operations against foreign cybercriminal groups, under a new policy that would permit government-approved firms to infiltrate criminal networks, disable servers and deploy spyware against overseas targets.

President Donald Trump signed a memorandum directing the Justice Department and Department of Homeland Security to develop the approach. The measure is aimed at transnational criminal organisations blamed for ransomware, sextortion and online fraud, which the White House said cost Americans more than $20 billion in 2025.

The plan would require companies to obtain government approval before conducting operations and to post a bond of at least $1 million. Actions that could cause death or injury, or cross the threshold of a “use of force” under international law, would be excluded.

FCRF Launches Flagship Certified Cyber Security Auditor (CCSA) Program for Next-Generation Cyber Auditors

Private Firms Could Target Criminal Infrastructure

Under the memorandum, participating companies could be authorised to take down hackers’ servers or infiltrate their computers with spyware. The policy would expand the role of private cybersecurity companies beyond defending their own networks and customers.

Ari Redbord, head of policy and government affairs at TRM Labs and a former federal prosecutor, said the model combines private-sector access to data with public-sector legal authority.

The policy has been compared with 18th-century privateering, when governments authorised privately owned ships to attack enemy vessels. Redbord argued that modern digital operations could be subjected to continuous oversight in a way historical privateering could not.

The administration has 60 days to finalise details of the programme, although some aspects are expected to remain classified.

Cybersecurity Experts Warn of Escalation Risks

The proposal has divided cybersecurity specialists. Alan Woodward, a cybersecurity professor at the University of Surrey, warned that granting authority does not necessarily guarantee compliance and argued that privateering historically created more problems than it solved.

Woodward also cautioned that companies participating in government-sanctioned hacking could lose their status as neutral defenders and potentially become targets themselves.

Possible consequences cited in the report include misidentified targets, foreign prosecutions and diplomatic disputes arising from operations conducted across national borders.

Jason Healey, a Columbia University researcher and former cybersecurity official under President George W. Bush, said the programme appears to contain legal safeguards but raised concerns over whether government institutions responsible for oversight would be strong enough to supervise such operations effectively.

Policy Marks Shift From Earlier White House Position

The move represents a change from the administration’s earlier position. A senior US official had reportedly indicated in March that the government was not interested in using private actors to fight cybercriminals, while National Cyber Director Sean Cairncross had also previously ruled out such an approach.

The reason for the policy reversal within five months remains unclear from the information provided.

Major technology companies are already heavily involved in cybersecurity efforts to defend their own services, but the new programme would allow participating firms to go further under direct government authorisation. The report said the operations would function without judicial oversight, relying instead on government supervision.

Microsoft declined to comment, while Google did not respond to a request for comment.

Supporters argue that stronger offensive capabilities could disrupt cybercriminal infrastructure and improve the chances of recovering money for victims. Critics, however, say the strategy could create new legal, diplomatic and cybersecurity risks if private offensive operations extend beyond their intended targets.

Stay Connected