The Trump administration will let private companies hack foreign criminal organizations as part of a new program that could expand the U.S. government’s ability to disrupt those groups’ cybercrime activities while also introducing myriad legal challenges and perils.
President Donald Trump late Wednesday issued a memorandum directing the departments of Justice and Homeland Security to create a program allowing vetted companies to hack into criminal groups to spy on them or sabotage their operations. Trump said the program would help the U.S. combat cybercrime schemes that cost the nation tens of billions of dollars annually.
The new policy represents a dramatic expansion of the private sector’s role in offensive cyber operations against U.S. adversaries and significantly blurs the line between the government’s foreign policy activities and businesses’ commercial activities. And while the program focuses on criminal gangs, not nation-states, it marks the largest step that the U.S. government has ever taken toward a world of corporations “hacking back” against foreign governments on behalf of the U.S.
Many cybersecurity experts have sharply criticized the hack-back concept, saying it creates unacceptable escalation risks and could expose private companies to the kind of foreign military retaliation previously reserved for government personnel. But the Trump administration has embraced aggressive measures for confronting transnational criminal groups, evincing less concern about potential collateral damage.
When the topic of hacking back came up at the Black Hat USA cybersecurity conference in Las Vegas last week, a DHS official did not dismiss the concept. “Our long-term goal is to terrify those who would target Americans, such that they know we’re actually the worst target in the world because we will mess you up,” said Joseph Alm, the assistant secretary of homeland security for cyber, infrastructure, risk and resilience.
The new program comes with several restrictions meant to limit the potential for unintended consequences. Co-executive directors from DOJ and DHS will review every proposed operation and provide written approval of the ones that the government greenlights. Participating companies will have to meet certain requirements, such as technical competency and personnel vetting, and set aside bonds of at least $1 million that they would forfeit if they violated the program’s rules.
Trump’s memorandum also says that the program’s leaders cannot authorize surveillance or disruption operations that would kill or seriously injure people or constitute the use of force or an armed attack under international law.
The White House gave DHS and DOJ 60 days to establish operating procedures for the program, including standards for companies’ participation, procedures for deconflicting operations with the military and the intelligence community and requirements for participants to report useful information that they acquire about criminal gangs’ activities.
The memorandum says the program should ensure “participation by both large companies, which provide critical capacity, and smaller, more agile companies, which may be better suited for specialized or discrete tasks.”
“American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace,” Trump said in the memorandum. “By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter [transnational criminal organization] threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.”
Mixed reactions
Some cybersecurity experts said the program could be effective if properly designed and overseen.
“This administration action is a meaningful response to a growing problem and does have some guardrails in place,” said Scott Shackelford, a business law and ethics professor at Indiana University who leads its Center for Applied Cybersecurity Research. “But significant questions remain about unleashing the private sector in this way, and what accountability mechanisms will be in place for bad actors.”
Jason Healey, a senior cyber conflict researcher at Columbia University, said he “would have hated this idea ten or fifteen years ago” when the opportunity still existed to prioritize defense over offense. “But that horse left the barn a long time ago,” he said, “and we have to make decisions for the world we are in, not the one we prevented.”
“So, sure, let's try to allow the private sector to get into the counter-offense game as well,” he said, “but only with very specific criteria to know when it is working and when it is making things worse.”
Kyle Hanslovan, chief executive of the cybersecurity firm Huntress, said the growth of sophisticated adversaries and the threat of “AI-powered autonomous threats” meant that old models of public-private collaboration were no longer sufficient. “The only viable solution is a stronger coalition of the willing,” he said, “which we’ve been eager to support.”
Other experts were more critical.
“This is a bad idea,” said Paul Rosenzweig, a former deputy assistant secretary for policy at the Department of Homeland Security. “There are much better ways to revive what it seems to me is an essentially governmental function.”
Erica Lonergan, a professor and cyber conflict expert at Columbia, said “the devil will be in the details, but I have some significant concerns.” She pointed to uncertainties around vetting, goal setting, risk mitigation and oversight. “Is this a slippery slope to enable private-sector offensive cyber operations directly against nation-state adversaries?”
Major legal question marks
The new private hacking program is rife with potential risks for participating businesses, the U.S. government and American society.
The memorandum requires the operating procedures to address some of those risks. Companies will be required to stop and alert the government if they accidentally target a U.S. person or information system, and DOJ must ensure that any hacking operations aimed at U.S. persons or otherwise raising constitutional or legal questions follow applicable laws, including judicial authorizations.
But other questions could remain unresolved until specific incidents raise them. Criminal organizations often steal data from U.S. businesses; it is unclear what would happen if a company participating in the hacking program came across that sensitive data during an operation against a criminal gang.
And while the memorandum addresses deconfliction with the military and the intelligence community, that coordination is likely to be difficult, given the classified nature of the government’s own hacking operations. Military and intelligence officials would be reluctant to share even limited information about their activities with private companies, even in the interest of warning them not to tread on the same ground.
“There's overlap between the kind of things that might fall into Cyber Command’s priorities and bailiwick, and what these entities would do,” said Gary Corn, a former staff judge advocate at U.S. Cyber Command. “Deconfliction has always been a challenge, even internal to the government, because you have different players in the space, and you don't want to be on the same box, so to speak, and one inadvertently disrupting the operations of the other. That'll become exponentially more challenging here with this.”
In addition, it is unclear how rigorously the U.S. government will vet participating companies, a crucial question given the sensitivity of the information and authorities with which they will be entrusted. A select few defense contractors already assist the government with hacking operations, but the vast majority of businesses, even in the defense industry, have no direct experience with such activities.
It is also unclear how carefully the U.S. will vet companies’ targets, including to verify that they are truly unaffiliated with foreign governments. Some self-proclaimed independent hacker teams are widely considered to be fronts for their governments, including the Iran-linked Handala group, while others, such as the Russia-linked Evil Corp, have close ties to their countries’ governments and have occasionally received support from them. A poorly vetted operation that accidentally targets foreign government employees or infrastructure could create a geopolitical crisis and put the responsible company in the crosshairs of a powerful adversary.
“Anyone conducting these operations is doing so at substantial personal legal risk,” Healey said.
The memorandum says companies can only hack a foreign criminal group that “is not an institutional part of a foreign government or wholly operated under a foreign government’s direction,” but it also says that a criminal group will be assumed not to meet those conditions “unless clear intelligence exists establishing such connection.”
That could be problematic. “A lot of the proxy actors don't operate wholly under a foreign government's direction,” said Corn, now the director of the Technology, Law & Security Program at American University’s Washington College of Law. “Foreign governments tap into these different non-state entities as they want.”
And under international law, Corn added, the U.S. government is accountable for any cyberattack that a private company conducts, even if it violates the program’s rules.
Even operations that only target criminal gangs might disrupt computer infrastructure in allied countries. “The internet is not a seamless, direct-from-us-to-Russia kind of thing,” Rosenzweig said. “To do whatever it is you're thinking you might do, you have to engage with systems that are subject to the jurisdiction of many, many other nations, each of whom would have something very negative to say about this prospect.”
The Trump administration, Rosenzweig added, has “misunderstood the interconnected nature of the world's cyber ecosystem.”
The prohibition against piracy is one of the oldest principles of international law, and Rosenzweig said it was “quite likely” that companies would be violating that prohibition if they participated in the new program.
The global consequences of the program could be significant. Even the Western countries that have followed the U.S.’s lead in stepping up their cyber engagements have not tapped private companies in this way, Shackelford said. “It could serve to further isolate the U.S. diplomatically and set back cyber norm-building efforts.”
It remains to be seen how many companies will be eager to participate in the program despite its many risks. Given the secrecy of the operations, companies likely will not be able to advertise their work, meaning that the only benefit they receive will be a government payment for their services.
Hanslovan, the Huntress CEO, said he was confident that the program’s leaders would figure out how to mitigate issues such as collateral damage.
“I’m proud to see the U.S. government push the boundaries when it comes to denying, degrading, and disrupting these measurable threats to democracy,” he said.
Editor’s note: This story has been updated with expert commentary.