News in Short
- The US government will allow vetted private companies to conduct offensive cyber operations.
- The companies will target international criminal gangs and hackers under government supervision.
- The move targets threats such as ransomware, financial scams and sextortion.
- Firms could conduct surveillance and disruptive operations against criminal infrastructure.
- Every operation will require approval from the Justice Department and Homeland Security.
- Participating companies must place $1 million in escrow.
- The policy could face legal challenges and raise international security concerns.
The US government is opening a new and controversial front in its fight against cybercrime. For the first time, vetted private companies could receive government approval to conduct offensive cyber operations against international criminal groups and hackers.
The move represents a major shift in how Washington approaches cyber defence. Instead of asking private companies to only protect their own networks, the government wants some of them to take the fight to cybercriminal infrastructure.
However, this does not mean US companies can independently “hack back” at attackers. The new framework places operations under government supervision and requires federal approval.
Why Is the US Government Making This Move?
The administration says the threat has grown beyond what traditional defensive measures can handle. Ransomware groups, financial scammers and other international criminal networks continue to target American businesses and citizens.
At the same time, cyberattacks have become more sophisticated. State-backed groups and criminal organisations can operate across borders while hiding behind compromised infrastructure.
The White House wants to use the technical capabilities of private cybersecurity companies to respond more aggressively. These firms often have specialised tools, threat intelligence and visibility into criminal networks that can complement government capabilities.
The administration’s broader cyber strategy had already signalled a move toward more aggressive operations against adversaries. Legal experts had warned, however, that US law did not clearly give private companies permission to conduct offensive operations.
The latest memorandum attempts to create a government-controlled framework for such activity.
What Will Private Companies Actually Be Allowed to Do?
The policy goes beyond conventional cybersecurity.
Participating companies could conduct surveillance operations, including using spyware to gather intelligence. They could also carry out disruptive operations designed to destroy or disable criminals’ data and systems.
However, the government says these operations must remain under its control.
Representatives from the Justice Department and Department of Homeland Security must approve each operation. The government will also establish procedures designed to prevent companies from targeting Americans or systems located in the US.
Companies must also report an imminent attack against critical infrastructure, such as power grids or water systems, if they discover one during their operations.
The administration will publish detailed requirements for participating companies within two months. The programme could include smaller cybersecurity firms with specialised capabilities.
Why Not Let the Government Do It Alone?
That is perhaps the biggest question behind the policy.
Offensive cyber operations have traditionally remained largely within the domain of government agencies and the military. Bringing private companies into the process could give Washington access to a much larger pool of cybersecurity expertise.
The move also comes at a time when the US faces pressure from increasingly aggressive cyber threats. Earlier policy discussions had already explored giving private firms a larger role in disrupting adversary networks.
The administration is therefore betting that private-sector expertise can help close the gap between the speed of cybercrime and the government’s ability to respond.
There is also a resource argument. Cybersecurity companies already spend heavily on tracking ransomware groups, finding vulnerabilities and mapping criminal infrastructure. Giving selected firms a formal role could allow the government to use that expertise for operations that go beyond defence.
Why Is the Policy So Controversial?
The biggest concern is what happens when a private operation crosses an international boundary.
A company targeting a criminal server may not know whether that infrastructure belongs solely to criminals. It could sit inside another country’s network or be controlled by a state-backed group.
That creates the possibility of diplomatic escalation.
Cybersecurity veteran Jake Williams also warned that employees involved in these operations could face consequences overseas. Foreign governments could potentially treat them as non-uniformed combatants or accuse them of conducting cyber operations against their interests.
The legal risks are equally significant. Earlier analysis of the administration’s cyber strategy noted that the Computer Fraud and Abuse Act and foreign hacking laws can prohibit exactly the kind of unauthorised access or disruption that offensive operations may involve.
That means the new framework will need to answer a difficult question: how much offensive power can a private company exercise before it effectively starts acting like an arm of the state?
For now, the US government appears to have chosen a middle path. It is not giving companies a free licence to attack hackers. Instead, it is creating a system where selected firms can conduct offensive operations with government approval.
The approach could strengthen the US response to cybercrime. However, it also blurs the traditional line between government cyber operations and private-sector cybersecurity. How Washington manages that line could determine whether the policy becomes a powerful new defence tool or creates a new source of legal and geopolitical risk.