President Donald Trump has ordered the federal government to build a program under which private firms hack cybercriminals, with one important asterisk: the companies would be contractors acting for, and under the supervision of, the US government. The August 12 memorandum directs the National Coordination Center to create the program. It does not give security vendors a general-purpose license to strike back at anyone who compromises a customer.
The administration says it wants to use private-sector capabilities against cybercrime that harms Americans. The policy targets foreign cyber-enabled transnational criminal organizations, defined in the memorandum as foreign groups conducting cyber-enabled crime against the US government, US people, or US interests. Groups that are part of a foreign government, or wholly directed by one, are outside this program’s definition.
Can private firms hack cybercriminals on their own?
No. The memorandum requires participating companies to contract with the Justice Department or Department of Homeland Security, pass rigorous vetting, and follow procedures that have not yet been written. DOJ and DHS co-executive directors must coordinate on approvals, and every authorized action is to be conducted on behalf of and under federal supervision.
Those operating procedures are due within 60 days of the memorandum. The White House text says no operation can be approved until it complies with them. A classified annex will govern the operational workflow and the framework for deciding whether a proposed target qualifies, so some of the details that would determine how this works remain nonpublic.
What operations could the program authorize?
The memo creates two buckets. Cyber surveillance operations mean covert access to collect intelligence, including intelligence that could support a later operation, according to Help Net Security’s account of the memorandum. Cyber effects operations can manipulate, disrupt, deny, degrade, or destroy systems, networks, infrastructure, or data, The Register reported.
That is a substantial role for a contractor, but it remains a government-controlled operation rather than ordinary private defense. The White House says the program must comply with the Constitution, applicable law, and US international obligations, including the federal computer-hacking statute.
What limits will apply?
- Program leaders cannot approve an operation expected to cause death or serious injury, or one that amounts to use of force or an armed attack under international law.
- Companies must meet standards covering technical skill, prior cyber-operations performance, facility security, personnel vetting, competence, and reliability.
- DOJ and DHS may require a bond or escrow of at least $1 million, forfeitable for contractual noncompliance.
- Help Net Security reports that firms which accidentally target a US person or US-connected system must stop, apply minimization procedures, and notify the National Coordination Center.
The legal position is still unsettled. The Register cited legal analysis suggesting a Computer Fraud and Abuse Act exception for lawfully authorized government activity could limit contractor exposure. No court, however, has decided whether that provision protects private companies carrying out this kind of work. The policy is a directive to build a supervised program, not evidence that the difficult statutory questions have been settled.
This story draws on original reporting from Ars Technica.