ZeroHour
Risky Business Newspublished ()ingested Catalin Cimpanu

Risky Bulletin: White House lets private companies carry out offensive cyber ops

infoPolicy & legalimportance 65
AI summary · glm-5.3-flash

A White House memo directs DHS to create a program letting vetted private companies conduct US-government-directed offensive cyber operations against cybercrime.

A presidential memo tasks the DHS National Coordination Center with building a program, under DOJ and DHS oversight, through which private-sector companies can conduct offensive cyber operations against large-scale cybercrime organizations. Requirements include secure facilities, vetted personnel, a $1 million escrow for damages, and written approvals co-signed by DHS and DOJ executive directors. The program must launch within 60 days, around October 11, expanding a March executive order targeting scam compounds, ransomware, and other large-scale cybercrime.

  • Private companies may hack back under the DHS NCC program
  • $1 million escrow required to cover botched operations
  • Each operation needs written approval from DHS and DOJ directors
  • Launch deadline is roughly 60 days from the memo
  • Extends the March executive order on scam compounds and ransomware
Full article3,195 words · extracted from news.risky.biz · click to collapse

This newsletter is brought to you by enterprise browser maker Island . You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed . You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here .

In a presidential memo this week, the White House has directed the Department of Homeland Security to establish a program through which private sector companies can carry out offensive cyber operations on behalf of the US government against cybercrime organizations.

The new program will run under the DHS National Coordination Center (DHS NCC) and under oversight of both the Department of Justice and the Department of Homeland Security.

Private companies will be able to apply and receive specific tasks from the two agencies on what and who they can hack—to prevent rogue behavior from the private sector.

The DHS NCC was tasked with running and creating the program's actual rules, but the memo contains some guidance on what those rules should be.

Companies that apply will need to operate secure facilities, have vetted personnel, and have a proven record and technical proficiency in cyber operations.

Both large and small private companies can apply, but they'll need to provide the government with $1 million in escrow to be used to cover damages in case of a botched operation.

Contracted companies can sub-contract.

The DHS and DOJ will each name their own co-Executive Director to run the program together.

Each offensive operation will need to be co-signed by both.

Executive Directors will provide " written approval and direction " for each op.

Companies can also provide intelligence to the government and suggest possible operations.

Offensive ops can target US infrastructure and individuals, if they are involved in large cybercrime operations.

Contractors must cease all operations and notify the NCC and DOJ if an offensive op unintentionally disrupted US systems not involved in cybercrime activity and outside of targeting parameters.

Operations will be deconflicted to prevent stepping on the toes of other agencies, like the State Department, Treasury, or the US intel community.

The memo doesn't say anything about deconfliction with international partners, which opens the door for some random contractor borking Europol or Interpol operations.

Operations won't be approved if there's a risk they might cause loss of human life or an armed attack.

Companies must immediately notify the DHS NCC if they discover evidence of an " imminent cyber-attack " against US critical infrastructure, or if they believe the op might trigger one.

Participating companies have reporting requirements on the success and outcomes of their operations.

Companies will go through annual reviews to check if they're still compliant with the program's rules.

Per the presidential memo, the program must be up and running in the next 60 days, which should be around October 11.

The memo is an extension of a White House executive order from March that ordered government agencies to prioritize the fight against online scam compounds, ransomware, and other cybercrime operations operating at a large-scale.

The March EO contained a small paragraph about recruiting private companies from the US' extensive tech sector to help the government fight cybercrime cartels. The memo expands that small reference into an actual program, as well as its place and role within the US government apparatus.

While some program details and requirements have been shared in the memo, we'll learn the actual procedural details in the next two months, when the NCC publishes the actual requirements.

Details on the actual approval process will be essential and they'll dictate if the program will be accessible to regular cybersecurity and pen-testing vendors, or if this will be another closed party between the usual ex-blue badgers, RTX, and the usual government contracting crowd.

The requirement of running secure facilities and using vetted personnel will make all the difference for who might have a chance of getting approved and receive government work. This will likely eliminate all the smaller infosec vendors hoping to finally get a chance to hack back against some of the threat actors they've been tracking for years.

Cybersecurity companies that want to apply will need to make both financial and personnel investments to become eligible. The value of the contracts will also be something to keep an eye on and will determine if there's an appetite from the private sector.

A Mastodon thread from Dave Wilburn warns the private sector and infosec practitioners from trusting that the Trump administration will be able to attribute threat actor infrastructure correctly, or that it will protect them in case something goes wrong.

"You should also consider the unreliability of the Trump regime's designations for targeting. They've routinely designated civilian or even functionally nonexistent organizations as criminal or terrorist organizations. You cannot trust their assurances that the bad guys you're harming are actually bad guys."

Wilburn's post and others have raised the most important question regarding this program and its chances of success, namely that enough effort will be put in correctly identifying threat actor infrastructure and subsequent fallout before a cyber contractor is let loose.

Large paydays might entice contractors from raising objections when operations and attributions seem murky or put together in haste.

While initially the cybersecurity crowd was extremely happy about the possibility of hacking back the threat actors they hate, it is now dawning on many that they will just be a regular contractor with minimum input, working under strict government authority in operations where they might end up carrying some of the legal risks, such as damages or prosecution by foreign states. Having a proficient legal department might end up being one of the hidden requirements in the long run.

Now, the one complicating thing:

If you're a private firm who thinks you're going to, say, be immune from getting sued under the CFAA by any innocent parties you harm because this EO purports to grant you the power to act as the U.S. gov... you might want to be careful there.😏

— Brian in Pittsburgh (@arekfurt) August 13, 2026

Digital Letters of Marque and Reprisal...

I'm not sure if this is a good thing, but I'm also not sure how many businesses would want to sign onto this scheme anyway.

[image or embed]

— Nicholas Weaver ( @ncweaver.skerry-tech.com ) August 13, 2026 at 6:12 AM

I had to read this four times because the writing is so terrible.

Bottom line, it’s a perpetual motion machine for billable threats.

www.whitehouse.gov/briefings-st...

[image or embed]

— Jason Kikta ( @kikta.net ) August 13, 2026 at 2:38 AM

Countdown to a European law enforcement agency having a multi-year ransomware operation being upended by a US defence prime doing pew pews

— Jamie MacColl ( @jamiemaccoll.bsky.social ) August 13, 2026 at 10:53 AM

Risky Business Podcasts

The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, James, and special guest co-host Brad Arkin at the helm!

Breaches, hacks, and security incidents

China hackers use AI against Taiwan: Suspected Chinese hackers have used publicly available AI tools to breach Taiwanese government networks. The intrusion is part of a hacking wave that hit multiple governments networks across Asia. The breach of Thailand's Ministry of Finance with AI tools is part of the same campaign. According to Dream Security, the hackers used a framework of Hermes and OpenClaw agents to automate reconnaissance, breaking in, moving laterally, gathering and then exfiltrating data. [ Dream // Focus Taiwan // Financial Times ]

Colombia's Ministry of Justice hit by ransomware: A ransomware attack has hit Colombia's Ministry of Justice. The hack took down systems related to the Ministry's illicit-drug monitoring and legal processes. The incident took place five days before the country's presidential handover and the installment of a new government. [ DarkReading ]

Ransomware hits Guatemala Supreme Court: A cyberattack has taken down the internal systems of the Guatemala Supreme Court. [ Emisoras Unidas ]

Romania restores land registry after cyberattack: The Romania government has restored its land registry agency's database and apps, a full month after a ransomware attack forced authorities to cease all cadastre and real estate activity. [ Romania Insider ]

AnMed returns online: US non-profit healthcare provider AnMed says staff have access to its IT system again two weeks after a ransomware attack. The organization also took down several social media pages after members of The Gentlemen ransomware group posted some angry messages demanding payment and making threats to leak user data. [ AnMed ]

LawCare impacted by BeaconCRM hack: Hackers have stolen sensitive data from UK mental health charity LawCare. The charity is one of almost 1,000 organizations impacted by a breach at software provider BeaconCRM. The stolen data includes details on donors, supporters, volunteers, and fundraising contacts. Most of the data belongs to British lawyers, with which the charity has worked to connect to people in need. [ LawCare // The Law Society Gazette ]

Valid AWS credentials hard-coded into public JS file? Sounds like vibe coding to me.

BeaconCRM powers over 1,000 charities (I've had emails from 2 charities now saying my details have been compromised)

[image or embed]

— Mark Williams-Cook ( @markwilliamscook.com ) August 13, 2026 at 12:33 PM

ICO reprimands ACRO over breaches: The UK's data protection agency has reprimanded the country's criminal records office for getting hacked three times in two years. The breaches took place between 2021 and 2023 and impacted ACRO's customer portal website. The ICO said the breaches allowed hackers to steal the data of almost 11,000 individuals who requested criminal records via the site. The ICO says the agency had failed to patch the portal for known vulnerabilities for years on end, with the last patch being applied in 2019. [ UK ICO ]

Uber Freight had a breach: Uber is investigating a breach at its freight transport business after hackers posted internal data on the dark web. The Helix group leaked the data after a failed extortion attempt. Helix is a new group that started hacking and extorting companies this month. [ WHTC ]

RingCentral discloses breach: The ShinyHunters hacking group has leaked the data of 1.6 million customers of AI company RingCentral. The files were stolen during a social engineering attack that took place last month. RingCentral has since notified all affected customers. The company claims to power AI voice assistants for more than 600,000 businesses. [ RingCentral // HIBP ]

New Trezor hack: Hardware crypto-wallet maker Trezor says hackers stole the data on 14,000 customers after breaching ShipMonk, one of its shipping partners. [ Trezor ]

Bybit sues North Korea over hack: Cryptocurrency exchange Bybit has sued the North Korean government in a DC court in an attempt to recover $1.5 billion worth of crypto assets stolen in February of last year. The lawsuit accuses the government and its intelligence service of the hack. Bybit has recovered only $48 million of the stolen funds and has another $30 million frozen at other exchanges. This is the first legal case filed against an entire country over a hack. [ Bybit // Risky Bulletin ]

Coinsbuy crypto-heist: Hackers have stolen $8 million worth of crypto from the Coinsbuy crypto exchange. [ FinanceFeeds ]

Ravencoin to roll back blockchain after hack: The Ravencoin project is preparing to roll back its blockchain to a state before August 7, when the platform was hacked and lost tens of millions of tokens. The token also crashed 20% in value. [ CoinDesk ]

Clop lists 43 victims: The Clop data extortion group has listed more than 40 new victims on its dark web leak site. Among the new victims are some large corporations like Shell, Philips, and General Electric. The recent batch of victims were likely hacked using a vulnerability in PTC Windchill and FlexPLM, two software packages for managing factories and production lines. [ BNR // Team Cymru ]

AI, general tech, and privacy

Blockchain crowd requests frontier AI access: An industry group for the blockchain and cryptocurrency community has sent an open-letter to frontier AI companies requesting access to their recent models to help defend their infrastructure and the funds it stores. [ Bitcoin Policy Institute ]

CBP workers abused their access: Internal CBP documents obtained by WIRED through a FOIA request have found that the agency's employees abused their access to government tracking tools to search for data on love interests, girlfriends, co-workers, and more. [ WIRED ]

"In one case, a CBP officer allegedly used government databases to contact a flight attendant. In another, an officer was accused of pulling information from trusted-traveler applications to ask people out."

This story is free to read because of FOIA, and disturbing as hell:

[image or embed]

— Katie Drummond ( @katie-drummond.bsky.social ) August 13, 2026 at 4:33 PM

Twitch to use live streams to train its AI: Game streaming platform Twitch will use live streams to train its AI models. The training is on by default and streamers will have to disable it in their account settings. [ Insider Gaming // Twitch Support ]

Non-profit sues Meta over spying glasses: A German privacy non-profit has filed a lawsuit against Meta for breaking the country's strict privacy laws and asking the court to ban the company's spyware glasses. [ Politico Europe ]

Brave adds anti-GPU fingerprinting protection: The Brave browser has added a new feature in v1.39 that will block GPU fingerprinting attempts via the WebGL and WebGPU APIs. [ Brave ]

Chrome blocks 7b notifications/day: Google says its Chrome web browser is blocking on average around 7 billion spam and malicious notifications each day. The number is staggering even if Chrome automatically revokes notification permissions for sites with which users haven't recently engaged. Google also rolled out rate limits for the servers that handle Chrome's notifications to combat the rising abuse. No site is allowed to send more than 1,000 notifications per minute. [ Google ]

OpenSSL releases Windows installer: The OpenSSL project has released a Windows installer for its library for the first time ever. [ OpenSSL ]

WhatsApp Scam Alert feature: Meta is adding an optional feature to WhatsApp that deploys a local LLM to detect possible scam messages. The new Scam Alert feature will not share any WhatsApp messages with Meta but only alert the user. The feature is being rolled out in a limited Beta this week. [ Meta ]

Meta bans 750k kids accounts in Australia: Meta says it banned more than 750,000 Facebook and Instagram accounts for kids under 16 in Australia to comply with the country's new children social media laws. [ Meta ]

Signal Automatic Key Verification: Signal has released a new security feature to verify and confirm that you're having a conversation with the intended party. The new Automatic Key Verification ensures the proper association between a phone number, username, and its public encryption key. All verifications are done in the background, without any user interaction. The Automatic Key Verification feature is designed to stop MitM attacks. [ Signal // Automatic Key Verification ]

Government, politics, and policy

Germany approves new surveillance powers: The German cabinet has approved new surveillance and hacking powers for the country's intelligence agencies. The draft bill now goes to the Parliament. [ The Guardian // Risky Bulletin ]

Germany wants to hack Russian drone makers: Some German officials want to grant the country's intelligence agencies the power to hack Russian drone makers. Marc Henrichmann, chairman of the Bundestag Parliamentary Control Committee, argues agencies should be allowed to act before Russia launches drone attacks or sabotage operations. A Russian drone loaded with semtex was intercepted at the Leipzig Airport this month before it could hit an Ukrainian plane. [ Die Welt // United24 ]

Kenya orders internet cafes to store logs: Kenya's communications watchdog has ordered all internet cafes to store logs of customer activity. Logs must be kept for the past three years. The Communications Authority of Kenya says the new rule is designed to prevent the abuse of public computers to carry out cybercrime activity. The new rules enter into effect on August 14. [ Citizen Digital ]

Brazil orders Discord to suspend live streaming: Brazil's data protection agency has ordered Discord to suspend its live streaming feature. Discord is currently under an investigation after it failed to flag a live stream where a 13-year-old girl was harrassed and encouraged to commit suicide. The girl took her life shortly after the stream. Officials believe Discord failed to factor in child safety when rolling out recent features. [ ANPD ]

Overseas Koreans Agency sees huge spike in attacks: The South Korean government says cyberattacks targeting its Overseas Koreans Agency rose twelve times compared to last year. [ The Korea Herald ]

Russia to test AI models for "traditional values": The Russian Ministry of Digital Development will test AI models distributed in Russia for compliance with "traditional values." [ Vedomosti ]

US ends beneficial ownership rule: The US Treasury has ended the requirement for US businesses to report their beneficial owners. Companies are still required to report their beneficial owners if they are foreigners. The Treasury has also deleted the information of all US citizens from the FinCEN beneficial owners database. The decision will hinder investigations into citizens who run networks of shell companies and engage in money laundering and other illegal activities. [ US Treasury ]

We passed this law - and make no mistake, it is a law, not just an option for the Treasury department to interpret - to ensure people wouldn't hide their identities in nests of LLCs to launder money. Treasury is protecting criminals with this action. home.treasury.gov/news/press-r...

[image or embed]

— Sean Casten ( @seancasten.bsky.social ) August 12, 2026 at 2:08 PM

I helped pass this law in 2020. It's purpose is to prevent drug traffickers, Russian & Chinese kleptocrats, and other international criminals from setting up anonymously owned companies to hide their money in the US. Trump's Treasury Dept. is doing this to help criminals. 1/ https://t.co/k7zRPDlwoH

— Tom Malinowski (@Malinowski) August 12, 2026

Sponsor section

In this Risky Business sponsor interview , Catalin Cimpanu talks with Michael Leland, Field CTO of Island, about the company's seamless expansion into SASE and enterprise AI.

Arrests, cybercrime, and threat intel

Montenegro arrests 50 foreigners for high-tech crime: Montenegrin police have arrested 50 foreign nationals on suspicion of "high-tech crime." Most of the suspects were Ukrainian nationals. They were arrested this week in a large house near the capital of Podgorica. Authorities said they seized so many digital devices they needed a cargo vehicle for transport. [ Vlada Crne Gore // Balkan Insight ]

Ukraine disrupts 94 scam call centers: Ukraine's cyber police force has disrupted 94 call centers involved in cyber scams. The call centers posed as bankers, brokers, and law enforcement officers to trick victims into investing funds or paying non-existent fines. Authorities notified 26 suspects of charges, seized $2 million, and more than 3,300 computers. [ Ukraine Cyber Police ]

Spain arrests AI face-swapping scammer: Spanish authorities have arrested a man in the city of Murcia for attempted…

Text extracted automatically; images, tables and formatting may be missing. Original: https://news.risky.biz/risky-bulletin-white-house-lets-private-companies-carry-out-offensive-cyber-ops/