President Trump deploys Private US firms against overseas cybercrimes
Under a new executive order, a participating company could manipulate, disrupt, degrade, and even destroy an IT system in an effort to shut down overseas cybercrimes.
To crack down on hackers, the Trump administration is creating a program to enlist private US companies to conduct offensive hacking operations against cybercriminal groups.
President Trump on Tuesday signed an executive order to tap the private sector to help the US “combat transnational cyber-enabled crime,” even though US companies have typically focused on defense, including kicking hackers off their services.
Historically, the US has “underutilized” the innovative capabilities of the country’s tech industry to stop hackers, the Executive Order says. “Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime.”
The Trump administration defines the newly authorized activities as “Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations.” The Cyber Effects means a private company in the program could manipulate, disrupt, degrade, and even destroy IT systems, including industrial control systems, in an effort to stop hackers.

Under the surveillance component, a private company could also break into a computer or IT system “without authorization from the owner or operator or by exceeding authorized access.”
But it won’t be open season for private sector hacking. The Trump administration is requiring strict oversight of offensive operations by two officials from the Justice Department and the Department of Homeland Security, who must greenlight them.
Participating companies also need to sign a contract with the Justice Department or DHS that requires “rigorous vetting” to ensure compliance with the program’s rules. Companies can then propose an offensive cyber op to the Homeland Security Task Force’s National Coordination Center.
The White House’s program intends to recruit large and smaller “agile” companies, paving the way for startups and cybersecurity vendors to apply and join. A provision in the order also requires companies to steer clear of targeting foreign governments, although the line between cybercriminal and state-sponsored can be fuzzy.
‘A Really Terrible Idea’
The order signals that the age of US cyber privateering is here. Still, the White House’s order is already raising numerous questions about how the program will work in practice, and if the US will accidentally target the wrong groups. Microsoft’s threat intelligence director, Nick Carr, noted “how difficult attribution in criminal operations is, and how few organizations can repeatably do it right (including certain gov agencies). People are regularly and willingly wrong on pretty important incidents.”
Independent security researcher Lukasz Olejnik also points out that the executive order doesn’t completely rule out cyber operations that result in death or injury. It merely says the US officials overseeing the program “may not approve operations resulting in Critical Outcomes” involving lethal cyber ops. “The memo does not say whether higher approval is possible,” he tweeted. “This does not mean a general license for lethal cyberattacks. But attacks can spill across borders or hit state-linked systems, raising the risk of interstate escalation and conflict.”
Meanwhile, Marcus Hutchins, the cybersecurity researcher who helped stop the WannaCry ransomware attack, called the executive order a “really terrible idea.” He notes that the US government, particularly the FBI, has previously launched operations to shut down cybercriminal groups and arrest their members. “But the problem is, when you start involving private companies in that, they become fair game for retaliation,” he wrote on LinkedIn.
“The framework only provides companies immunity under US law; it can’t give them immunity against foreign nations,” he added. “Companies are going to go into this thinking the US government will have their backs, which they absolutely won’t, since it’s simply just a cheap way to outsource cyber risk to private companies.”
Hence, some tech companies, particularly larger ones, might avoid joining the program over concerns about blowback, especially in foreign markets where they operate.
Credit: PC Magazine


