US memo recruits vetted companies to hit foreign cybercrime networks

A new White House program would let private firms run offensive operations under federal oversight.

CSBadmin
2 Min Read

The White House has opened the door for vetted private firms to carry out offensive hacking against foreign cybercrime groups, via a national security memorandum signed by President Donald Trump. The August 12 memo directs the National Coordination Center to build a program authorizing participating companies to run surveillance and cyber effects operations against cyber-enabled transnational criminal organizations.

Companies must contract with the Justice Department or Department of Homeland Security and pass rigorous vetting. Officials have 60 days to establish operating procedures, and every proposed operation requires written approval. The memo says actions will be conducted on behalf of and under the supervision of the federal government, and must comply with existing law, including the Computer Fraud and Abuse Act.

Reaction is mixed. Chris Wysopal, who co-founded Veracode, welcomed the memorandum as a genuine policy pivot. He said it stops well short of the broader hack-back proposals that have circulated for years. Critics point to collateral damage dangers, since criminals operate from inside legitimate networks, and note that participating firms receive neither immunity nor indemnity. The memo does require companies to stop and notify the center if a U.S. person is hit by accident.

Jason Kitka, a former Cyber Command official, argued in a social post that the program chiefly exists to bill for threats.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.