Trump turns to private sector in offensive hacking operations memo
Trump signed a national security memorandum authorizing vetted private companies to conduct offensive cyber operations against transnational criminal organizations under federal oversight.
The memorandum creates a federal coordination center program authorizing 'Participating Companies' to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign cyber-enabled transnational criminal organizations. Participating firms must contract with the Justice Department or Department of Homeland Security, undergo vetting, and comply with existing laws including the Computer Fraud and Abuse Act. The White House cited sustained fraud and cyber-enabled campaigns from TCOs as justification, building on a March fraud-focused executive order. Experts including Veracode co-founder Chris Wysopal called it a major shift in U.S. cyber policy, though it stops short of broader 'hack back' proposals.
- Memo establishes a program for vetted private companies to conduct offensive cyber operations against transnational criminal organizations.
- Participating companies must sign contracts with DOJ or DHS and operate under federal control and oversight.
- Operations must adhere to existing laws, including the Computer Fraud and Abuse Act.
- Companies may sign commercial agreements to share threat information with other private sector entities.
- Experts call it a major policy shift but note it stops short of full 'hack back' authorization.
Full article750 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
One expert called it a “pretty big shift in U.S. cyber policy,” and there have been reservations in the past about opening the door to private sector involvement in cyber offense.
Listen to this article
0:00
Learn more.
President Donald Trump signed a national security memorandum Wednesday that lays the groundwork for private sector companies to take a larger role in helping law enforcement carry out offensive hacking operations against transnational criminal organizations.
The White House said sustained fraud and other cyber-enabled campaigns from transnational criminal organizations (TCOs) warranted the memo, and cited a fraud-focused executive order from March as only the first step.
”This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector,” it reads.
Under the memorandum, a federal coordination center “shall create, manage, and maintain a Program to authorize Participating Companies … to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government“ that would be “part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement.”
Participating companies would have to sign contracts with the Justice Department or Department of Homeland Security to “undergo rigorous vetting.” It would also allow participating companies to sign commercial agreements with other private sector entities to receive threat information. And participating companies’ agreements with federal, state and local governments would be geared toward identifying threats, and proposing cyber operations to the coordination center to address those threats.
The program would have to adhere to existing laws, according to the memo. That includes the Computer Fraud and Abuse Act, the main federal anti-hacking statute that prior proposals to open private sector participation in hacking operations would have amended. The memo mandates oversight to evaluate companies’ technical proficiency, ensures both small and large companies can participate, and requires regular reporting to federal officials.
In recent years, there has been some sentiment in conservative circles to authorize “letters of marque” for private-sector cyber firms similar to those for early-U.S. sea privateers. Some have suggested the government could lean on more private sector cyber experts to conduct offensive operations.
But there also has been deep concern in cyber circles about giving the private sector too much leeway in offensive operations, from industry condemnation of “hack back” legislative proposals that would authorize steps that are currently illegal as a dangerous precedent that critics fear could open cyberspace to wider chaos.
One former Cyber Command official, Jason Kitka, criticized several elements of the memorandum, calling it “a perpetual motion machine for billable threats” in a social media post.
But a former top White House cyber official during Trump’s first term, Galvanick co-founder Josh Steinman, cheered the development.
Cyber pioneer Chris Wysopal, now co-founder of Veracode, called it “a pretty big shift in US cyber policy” that nonetheless stopped short of going as far as other “hack back” proposals.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/trump-memo-private-sector-offensive-hacking/