US will allow private companies to conduct cyberattacks

illustrative, hacker / Rohit Choudhari
Фото: illustrative, hacker / Rohit Choudhari

The administration of US President Donald Trump will allow selected private companies to participate in offensive cyber operations against foreign criminal groups. Companies will be able to act only with permission and under the control of the US government - the new policy does not provide for a general license for independent hacking attacks.

According to a presidential memorandum released this week, federal agencies should use the technological capabilities of the private sector to combat transnational criminal organizations. Vetted program participants may be allowed to conduct cyber surveillance, as well as operations to manipulate, block, disrupt, or destroy information systems and networks of designated targets.

The US Department of Homeland Security and the Department of Justice are to oversee such operations. Companies admitted to the program will have to post a bond or place at least $1 million in an escrow account. According to Financial Times, this money may be forfeited if a participant exceeds the authorities granted to them.

The program could open a new market for American technology and cybersecurity companies. Financial Times notes that the initiative was privately supported by representatives of the technology industry, while Google and Microsoft have previously expressed readiness to help US authorities combat cybercrime. Proponents of the approach expect that both large technology and AI companies, as well as smaller firms already working with the government in intelligence and cybersecurity, could join.

The new approach partly resembles historical privateering, when a state authorized private ship owners to attack enemy vessels. Supporters of so-called digital privateering in the US have long proposed adapting this principle to cyberspace. Last year, Utah Senator Mike Lee even introduced legislation to revive the practice of issuing "letters of marque," which historically gave private individuals the right to act against enemies of the state.

The decision also comes after the Trump administration reduced the size of the US Cybersecurity and Infrastructure Security Agency (CISA). According to Financial Times, part of the American intelligence community, against this backdrop, advocated for more active use of private sector capabilities, including AI companies, to counter foreign hacking groups.

At the same time, business involvement in offensive operations creates legal and security risks. Cybersecurity researcher Lukasz Olejnik told Financial Times that the memorandum does not give companies an unlimited right to attack. However, cyber operations could affect systems beyond the intended target, or infrastructure associated with other states, creating a risk of international escalation. The Guardian also notes that such proposals have previously been controversial due to possible unintended consequences and coordination problems between government structures and private contractors.

Based on: Financial Times, The Guardian

analytics