ELSEIF
Your brief EB
328 stories from 97 feeds 281 clusters Refreshed 10 minutes ago next pull 16:36

PLATFORMS Signal 399

US reportedly permits vetted private firms to conduct offensive cyber operations against foreign threats

A new US policy reverses long-standing prohibitions, allowing select private companies to launch government-supervised cyberattacks on international criminal groups.

WHY IT MATTERS

This shifts cybersecurity from purely defensive to offensive roles for private firms, introducing legal and operational risks. Engineers in security firms may now face new compliance requirements and potential international legal exposure.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Private companies can now conduct surveillance and disruptive cyberattacks under federal supervision.

02

Participating firms must deposit $1 million in escrow and comply with strict government oversight.

03

The policy excludes targeting Americans or US-based systems but may trigger diplomatic and legal challenges.

THE READ

What the cluster adds up to.

ORIGINAL ANALYSIS

The US government is breaking with decades of policy by permitting private companies to engage in offensive cyber operations. Previously, federal law prohibited private entities from conducting cyberattacks, limiting them to defensive measures. This change allows vetted firms to perform surveillance and disruptive attacks on international criminal groups, such as ransomware operators or state-backed hackers. The shift is framed as a response to growing cyber threats, but it introduces new operational and legal complexities for participating companies.

Adopting this policy comes with significant costs and constraints. Firms must deposit $1 million in escrow, which is forfeited if they violate program rules. Operations require approval from the Justice Department and Homeland Security, and all activities must be government-supervised. The policy also mandates that companies report imminent threats to critical infrastructure, adding a layer of compliance. Smaller firms may struggle with these financial and regulatory burdens, despite the memorandum’s suggestion that they could be better suited for specialized tasks.

The policy’s limitations are notable. It explicitly prohibits targeting Americans or US-based systems, and operations must be approved by multiple federal agencies. However, the potential for diplomatic fallout remains high. Foreign governments could retaliate by accusing US-based cybersecurity professionals of acting as non-uniformed combatants, exposing them to legal risks abroad. Critics argue the policy is underdeveloped, with concerns about abuse or unintended consequences, such as escalating cyber conflicts. The lack of clarity on target selection and the absence of public details about participating firms further amplify these risks.

The policy’s rollout is still in its early stages, with guidance for participating companies expected within two months. Legal challenges are likely, given the contentious nature of private entities conducting offensive cyber operations. The memorandum does not address whether any firms are already involved, leaving questions about the program’s immediate impact. For engineers, this means navigating a new landscape where offensive capabilities are no longer the sole domain of government agencies, but also a potential responsibility for private sector security teams.

Written by elseif from the cluster below · checked for specifics the sources never contained

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
TechCrunch In a first, US will allow some private firms to carry out cyberattacks Open ↗