US to allow private companies to conduct offensive cyber operations for the first time

The US government will for the first time allow vetted private companies to conduct offensive cyber operations against international criminal groups and hackers, the White House announced on Wednesday.

This step, detailed in a newly published presidential memorandum from the Trump administration, will allow the federal government to use “innovative private sector capabilities” to combat cybercrime and threats targeting Americans. Such threats include ransomware attacks, financial fraud, and sextortion.

The memorandum permits private companies participating in the government program to conduct surveillance, including using spyware to gather intelligence, as well as destructive operations aimed at deleting criminals’ data or systems.

Change of long-standing policy

This policy change marks a significant departure from the US government’s long-held position on federal computer hacking laws, which generally prohibit private companies from conducting cyberattacks or operations to disable systems without court sanction. Until now, the US government’s position across several administrations has been that the private sector can defend against cyberattacks but cannot carry them out independently.

Although the presidential memorandum establishes a new policy, it is in its early stages, and the government has not yet determined all the details of the program’s operation. Over the next two months, the government is to issue guidance that will define the requirements for participating companies. The memorandum provides that companies of various sizes, including small private firms that may be better suited to conducting specialized operations, will be able to join the program.

Requirements for participants and risks

Participating companies must deposit 1 million dollars into an escrow account. These funds may be confiscated if the government determines that the company is not complying with the rules for conducting operations. The memorandum requires the federal government to establish procedures that will prevent operations from being conducted against Americans or systems located in the United States. Each operation will require approval from representatives of the Department of Justice and the Department of Homeland Security and must be conducted exclusively under federal government supervision. The policy also requires participating companies to notify the government if they detect an imminent cyberattack on US critical infrastructure, such as power grids or water supply systems.

Critics have long argued that private companies should not be involved in government hacking operations, and the new policy is likely to face legal challenges and opposition. The memorandum does not allow companies to conduct “hack-back” (retaliatory cyberattacks). Critics note that involving the private sector in government operations could have diplomatic and international consequences, for example, if a foreign government claims to be the victim of an attack by an American company.

According to cybersecurity veteran Jake Williams, vice president of research and development at Hunter Strategy, this policy could put Americans working in private cybersecurity companies at risk of harassment or detention by foreign governments. “Americans participating in these operations can easily be classified as unofficial combatants when traveling abroad,” Williams said. He added that “claims about an American’s involvement in these operations do not necessarily have to be true,” noting that the administration’s policy itself creates the possibility for foreign governments to make such accusations.

Context of growing threats

The Trump administration did not specify the reasons for this decision, only stating that the government is combating a “growing threat” to Americans and businesses. The United States faces a range of international cyber threats amid massive cuts and layoffs of federal cybersecurity personnel since the start of the second Trump administration in January 2025.

Several US states are currently reporting cyberattacks on their water infrastructure, which intelligence officials have privately attributed to hackers supported by the Iranian government, according to reports. Officials in more than a dozen states, including Michigan, Minnesota, and Georgia, have reported intrusions into local water supply systems, but no water safety warnings have been issued.

The intelligence community’s assessment of these threats came after months of protracted war between the United States, Israel, and Iran. After the start of the US-led war in February, which resulted in the death of Iran’s supreme leader, Iranian military forces responded with rocket attacks on data centers owned by Western companies, as well as cyberattacks that actively disrupt American businesses and critical infrastructure.

The Trump administration’s cyber memorandum emerged as the United States and other governments grapple with a surge in autonomous cyberattacks driven by artificial intelligence (AI) targeting companies and organizations worldwide. Companies Anthropic, OpenAI, Meta, and the UK AI Security Institute have reported that advanced AI models they tested bypassed their technical safeguards to carry out cyberattacks.

Source: TechCrunch