ELSEIF
Your brief EB
251 stories from 105 feeds 330 clusters Refreshed 8 minutes ago next pull 15:10

TECH Signal 408

U.S. government reportedly authorizes vetted private firms to conduct destructive cyberattacks on foreign cybercrime groups

A new U.S. program permits vetted private companies to launch offensive cyber operations, including data destruction, against foreign cybercriminal organizations under government oversight.

WHY IT MATTERS

This shifts cybersecurity from purely defensive postures to proactive, offensive measures by private entities. It introduces legal and operational risks for participating firms, including financial penalties and potential classification as non-uniformed combatants. The policy reversal may also escalate tensions with foreign states harboring cybercriminals.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Vetted private companies can now conduct offensive cyber operations, including data destruction, against foreign cybercrime groups.

02

Participating firms must post $1 million in escrow and obtain written approval from DOJ and DHS for each operation.

03

Operations targeting state-directed hackers are excluded, but ransomware groups with state tolerance remain valid targets.

THE READ

What the cluster adds up to.

ORIGINAL ANALYSIS

The U.S. government has authorized a new program allowing private companies to conduct offensive cyber operations against foreign cybercriminal organizations. This marks a significant departure from previous policy, which explicitly ruled out such private-sector involvement. The program permits two types of operations: intelligence-gathering through unauthorized access and disruptive or destructive actions against systems and data. Companies must meet strict eligibility criteria and obtain approval for each operation, ensuring government oversight remains central to the process.

Participation in the program carries substantial financial and operational risks. Firms must deposit at least $1 million in escrow, which is forfeited if they violate program rules. Any unintended impact on U.S. persons or systems requires immediate cessation of operations and government notification. The program’s structure suggests a preference for specialized firms, as both large and smaller companies can qualify. However, the requirement for written approval from DOJ and DHS officials may slow response times, potentially limiting the program’s effectiveness against fast-moving threats.

The policy targets foreign cybercrime groups that operate independently of foreign governments, such as ransomware crews tolerated by states like Russia. State-directed hackers are explicitly excluded, though the memo leaves room for classified exceptions. This distinction may prove difficult to enforce in practice, as many cybercriminal groups operate in gray areas with varying degrees of state involvement. The program’s focus on non-state actors aligns with recent U.S. concerns, such as Iranian cyberattacks on water suppliers, but risks misclassification or unintended escalation.

Legal and geopolitical implications loom large for participating firms. Individuals involved in these operations could be classified as non-uniformed combatants if traveling abroad, exposing them to legal jeopardy. The program also raises questions about accountability, as private companies may lack the diplomatic protections afforded to government actors. While the policy aims to disrupt cybercriminal ecosystems, its success hinges on precise targeting and adherence to international norms, which may be challenging to maintain in offensive operations.

Written by elseif from the cluster below · checked for specifics the sources never contained

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Tomshardware White House authorizes private companies to launch 'hack-back' cyberattacks that destroy data and systems, targeting foreign cybercrime organizations — vetted organizations can now conduct offensive cyber operations Open ↗