Skip to Content
Join the Network with Us — Join Membership


US Moves to Let Private Firms Hack Foreign Cybercriminal Networks

August 17, 2026

The United States is preparing to allow selected private companies to conduct offensive cyber operations against foreign cybercriminal groups, under a new policy that would permit government-approved firms to infiltrate criminal networks, disable servers, and deploy spyware against overseas targets.

The Policy Behind the Shift

President Donald Trump signed a memorandum directing the Justice Department and Department of Homeland Security to develop this approach. The measure is specifically aimed at transnational criminal organisations blamed for ransomware, sextortion, and online fraud, which the White House said cost Americans more than 20 billion dollars in 2025 alone.

Under the plan, participating companies would need to obtain government approval before conducting any operations, and would also be required to post a bond of at least 1 million dollars. Notably, actions that could cause death or injury, or that cross the threshold of a "use of force" under international law, would be explicitly excluded from what's permitted.

What Private Firms Could Actually Do

Under the memorandum, participating companies could be authorised to take down hackers' servers or infiltrate their computers using spyware, effectively expanding the role of private cybersecurity companies well beyond simply defending their own networks and customers, into something closer to active offensive operations.

Ari Redbord, head of policy and government affairs at TRM Labs and a former federal prosecutor, described the model as combining private-sector access to data with public-sector legal authority. The policy has drawn comparisons to 18th-century privateering, when governments authorised privately owned ships to attack enemy vessels on their behalf. Redbord argued that modern digital operations, unlike their historical counterpart, could be subjected to continuous oversight in ways that privateering never could.

The administration has 60 days to finalise details of the programme, though some aspects are expected to remain classified even after that.

Experts Split on Whether This Is a Good Idea

The proposal has genuinely divided cybersecurity specialists. Alan Woodward, a cybersecurity professor at the University of Surrey, warned that granting authority doesn't necessarily guarantee compliance, arguing that privateering historically created more problems than it actually solved. He also cautioned that companies participating in government-sanctioned hacking could lose their status as neutral defenders, potentially turning them into targets themselves in the process.

Possible risks flagged include misidentified targets, foreign prosecutions, and diplomatic disputes arising from operations that inherently cross national borders. Jason Healey, a Columbia University researcher and former cybersecurity official under President George W. Bush, said the programme appears to contain legal safeguards, but raised concerns over whether government institutions responsible for oversight would actually be strong enough to supervise operations of this nature effectively.

A Notable Reversal From Earlier Positions

This move marks a genuine shift from the administration's earlier stance. A senior US official had reportedly indicated back in March that the government wasn't interested in using private actors to fight cybercriminals, and National Cyber Director Sean Cairncross had also previously ruled out this kind of approach entirely. Why the policy reversed within just five months remains unclear based on available information.

Major technology companies are already heavily involved in cybersecurity efforts to defend their own services, but this new programme would allow participating firms to go significantly further under direct government authorisation. Notably, the operations would reportedly function without judicial oversight, relying instead purely on government supervision. Microsoft declined to comment on the development, while Google did not respond to a request for comment.

Supporters of the policy argue that stronger offensive capabilities could genuinely disrupt cybercriminal infrastructure and improve the chances of recovering stolen money for victims. Critics, however, maintain that the strategy could create new legal, diplomatic, and cybersecurity risks if private offensive operations end up extending beyond their intended targets.

FAQs

Q1. What would the new US policy allow private companies to do?

Government-approved private companies would be authorised to take down cybercriminal servers and infiltrate their computers with spyware, targeting foreign transnational criminal organisations.

Q2. What safeguards are included in the policy?

Companies would need government approval before operations, must post a bond of at least 1 million dollars, and are barred from actions causing death, injury, or crossing the threshold of "use of force" under international law.

Q3. Why are cybersecurity experts concerned about this policy?

Experts worry about risks including misidentified targets, foreign prosecutions, diplomatic disputes, and participating companies losing their neutral status and becoming targets themselves.

in News
Share this post
Archive