
The Trump administration announced a new National Security Presidential Memorandum authorizing private security companies to conduct offensive cyber operations against foreign transnational criminal organizations. The memo, issued Thursday, directs the National Coordination Center to develop a program enabling private sector participation in cyberattacks targeting groups that commit crimes against US government, persons, or interests. The Departments of Justice and Homeland Security will provide oversight of the initiative.
The scope of eligible targets includes organizations engaged in ransomware attacks, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams. Approved companies may conduct surveillance operations and offensive cyber effects operations, potentially including deployment of spyware, data destruction attacks, encryption-based lockouts, and distributed denial-of-service operations. Previously, federal law prohibited private companies from conducting such offensive actions without court approval.
The program includes safeguards to limit potential harm. Private firms must undergo vetting by Justice and Homeland Security before participation and must meet technical proficiency standards, facility security requirements, and personnel screening criteria. Operations cannot result in loss of life, serious injury, or actions that constitute use of force under international law. Participating companies must also deposit $1 million into an escrow account, forfeitable if they violate contractual obligations.
Security experts have offered mixed assessments. Some acknowledge merit in offensive operations against ransomware groups, noting such activities already occur informally. However, concerns center on whether private firms have appropriate incentives to combat cybercrime, given that some companies have profited substantially from the ongoing ransomware problem.
Significant details remain undefined pending further guidance from the Justice and Homeland Security departments, which have 60 days to develop implementation specifications. These details will be essential for evaluating the program’s effectiveness and oversight mechanisms.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI