
The Trump administration issued a National Security Presidential Memorandum on Thursday directing the establishment of a new program that will authorize private security firms to conduct cyberattacks against foreign transnational criminal organizations. The National Coordination Center, operating under the Homeland Security Task Force, will oversee the initiative with support from the Departments of Justice and Homeland Security.
The program targets criminal groups engaged in ransomware schemes, sextortion, phishing campaigns, financial fraud, and impersonation scams. Participating private companies would be permitted to conduct surveillance operations and offensive cyber effects operations against foreign groups classified as cyber-enabled transnational criminal organizations. These are defined as foreign entities that conduct cyber-enabled crime against the United States Government, US persons, or American interests, excluding institutional parts of foreign governments or entities operating under foreign government direction.
This marks the first instance of the federal government formally authorizing private sector companies to conduct offensive cyber operations against overseas hackers. The memo permits participating firms to potentially deploy spyware, launch attacks designed to destroy criminal organization data or systems, or conduct other offensive operations such as encryption-based network lockouts or distributed denial-of-service attacks. Previously, the government had prohibited private sector entities from undertaking such actions without court authorization.
The program includes several oversight mechanisms and restrictions. Private companies must receive approval following vetting by Justice and Homeland Security departments and meet minimum standards including technical proficiency, proven cyber operations experience, facility security, and personnel clearance. Companies must deposit $1 million into an escrow account, forfeitable upon contract non-compliance. Additionally, authorized operations are prohibited from causing critical outcomes defined as loss of life, serious injury, or actions rising to the level of armed attack under international law.
Many implementation details remain unspecified, with the Justice and Homeland Security departments directed to provide comprehensive specifications within 60 days. Security researcher commentary suggests potential benefits to targeting ransomware operations but raises questions about whether appropriate incentive structures will ensure the program functions effectively.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI