Top Stories

US moves to allow private companies to hack cybercriminals in novel policy shift

The US signed a memorandum to allow private companies to hack cybercriminals, creating a government-supervised framework to disrupt global ransomware groups

avatar-icon

News Desk

The News Desk provides timely and factual coverage of national and international events, with an emphasis on accuracy and clarity.

US moves to allow private companies to hack cybercriminals in novel policy shift
Donald Trump, Marco Rubio and Pete Hegseth attend a cabinet meeting at the White House on May 27, 2026.
Reuters

U.S. President Donald Trump signed a memorandum on Wednesday authorizing private companies to hack cybercriminals who target American citizens.

The White House authorized vetted tech firms to infiltrate foreign servers and disable offensive infrastructure following 2025 cybercrime damages exceeding $20 billion. The measure establishes government-supervised privateering to combat ransomware, online fraud, and extortion.

Why did the US decide to allow private companies to hack cybercriminals?

The United States authorized offensive private-sector operations to merge corporate threat intelligence with federal law-enforcement authority against foreign ransomware networks. Participating firms must obtain prior written approval for every operation, maintain a minimum $1 million financial bond, and avoid lethal force or actions violating international law. This initiative aims to disrupt transnational syndicates systematically.

The program draws direct comparisons to eighteenth-century maritime privateering, when sovereign governments issued letters of marque authorizing private captains to raid enemy vessels. TRM Labs policy director Ari Redbord explained that modern digital oversight continuously tracks corporate hacking activities, whereas historical governments lost sight of privateer ships once they sailed from port. Federal authorities maintain that public and private integration will strengthen national defense efforts.

However, several cybersecurity analysts expressed strong reservations regarding corporate discipline and potential diplomatic escalation. University of Surrey professor Alan Woodward warned that delegating offensive actions historically created major administrative headaches without guaranteeing long-term compliance. As detailed by The Economic Times, participating companies could forfeit their status as neutral defenders and become primary targets for foreign military retaliation.

What guardrails exist for government-sanctioned corporate hacking?

The policy shift marks a significant reversal after senior administration officials previously stated that the federal government would not use private hackers to fight digital piracy.

National Cyber Director Sean Cairncross previously rejected enlisting private sector firms for offensive operations just five months ago. Columbia University researcher Jason Healey noted that while legal rules exist, recent administrative restructuring has weakened federal intelligence oversight bodies.

Major technology companies maintain extensive defensive security operations but face new strategic risks if they choose to conduct offensive operations under federal oversight. Analysis from TechCrunch reveals that major platforms like Microsoft declined to comment, while Google did not respond to official inquiries regarding program participation. Federal officials now have 60 days to finalize operational rules before participating contractors begin supervised hacking operations against foreign syndicates.

Comments

See what people are discussing