// ARS TECHNICA — CYBERSECURITY
Private security firms will soon be allowed to hack overseas cybercriminals
Trump memo is first time gov’t has authorized private sector to perform cyberattacks.
The Trump administration is recruiting private security firms to conduct federal government-authorized operations, including cyberattacks, against overseas-based criminal organizations that commit hacks on US persons, organizations, or government entities.
In a National Security Presidential Memorandum issued Thursday, US President Donald Trump directed the National Coordination Center (NCC), which operates under the Homeland Security Task Force, to develop a program for conducting specific cyber operations that combat foreign transnational criminal organizations (TCOs). The Departments of Justice and Homeland Security will provide oversight. The lynchpin of that program is bringing in private sector companies to participate.
A fact sheet that accompanied Thursday’s memo listed ransomware, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams as activities eligible for private-sector security firms to target. The memo said such firms could “conduct Cyber Surveillance Operations and Cyber Effects Operations” against “cyber-enabled” TCOs. Such groups are defined as “any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government’s direction.”
The new program is the first time the federal government will authorize private companies to conduct offensive cyber operations against overseas hackers. The memo appears to permit companies participating in the program to use spyware or launch offensive attacks intended to destroy TCO data or systems. The memo doesn’t rule out certain types of offensive attacks, such as those that use encryption to lock targets out of their networks or performing distributed denial-of-service attacks. Up until now, the government has prohibited the private sector from taking such actions without court-authorized approval.
“There’s definitely merit in the idea of hacking ransomware groups and it does already in fact happen (don’t ask me how I know),” independent security researcher Kevin Beamont said in response to the memo. “But the correct incentives have gotta be there.”
He added: “The biggest problem I’ve had with fighting ransomware over the past 5 years is private cyber companies basically lobbying for nothing to change. A lot of companies have made a lot of money, so putting them in charge of stopping it seems optimistic.”
The memo placed specific limits on the scope of the new program. Private companies must first be approved after vetting by the Departments of Justice and Homeland Security. Cyber Effects Operations and Cyber Surveillance Operations may not result in “Critical Outcomes,” meaning those that result in the loss of life or serious injury or “rise to the level of use of force or armed attack under international law.” The memo also notes:
[M]inimum standards that Participating Companies must meet in order to take part in the Program, which shall include appropriate levels of technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors that the Program Executive Directors, in coordination with the Homeland Security Council, determine are relevant or necessary for guaranteeing high confidence in a Participating Company’s ability to perform successfully.
Participating companies must also deposit $1 million in an escrow account. The deposit will be forfeited “should the Participating Company enter non‑compliance with its contractual agreement described” in the memo.