HomeMalware & ThreatsUncle Sam Calls on Private Hackers to Disrupt Criminal Networks

Uncle Sam Calls on Private Hackers to Disrupt Criminal Networks

Published on

spot_img

White House Launches Program to Engage Private Sector in Cyber Surveillance and Operations

In a significant shift in U.S. cyber policy, the White House has announced a new initiative that allows private cybersecurity firms to join the fight against foreign cybercrime. Under this program, contractors will engage in cyber reconnaissance and conduct disruptive hack attacks on behalf of the U.S. government. This arrangement aims to combat the increasing sophistication of cyber-enabled crimes perpetrated by international criminal organizations.

On August 13, 2026, President Donald Trump issued a memorandum that establishes a program designed to empower private sector companies to "identify and disrupt criminal networks operating in cyberspace." The program specifically targets foreign groups engaged in various cybercrimes, including ransomware attacks, phishing schemes, financial fraud, sextortion, and complex social engineering scams. The White House underscored that this initiative would leverage the innovative capabilities found in the private sector to address these pressing issues.

Experts have taken note of the implications of this policy change. Chris Wysopal, chief security evangelist at application security firm Veracode, noted on social media that while the initiative does not explicitly resemble aggressive "hack-back" operations, it nonetheless represents a substantial expansion of the private sector’s role in offensive cyber operations. This development comes on the heels of alarming statistics released by the FBI, which reported that U.S. consumers suffered losses exceeding $20.8 billion due to cyber-enabled crimes in the previous year.

The memorandum, entitled "Expanding Capabilities To Combat Transnational Cyber-Enabled Crime," clarifies that the objective of this initiative is to utilize all available instruments of national power to counteract Transnational Criminal Organizations (TCOs). This also builds upon Executive Order 14390, issued back in March, which directed government bodies to allocate more resources toward preventing foreign cybercrime.

In a detailed outline of the program, the White House stated that by establishing partnerships with vetted U.S. companies, the government aims to enhance its capabilities in countering TCO threats and overall cybercrime impacting American citizens. The newly established framework allows these vetted companies to engage cooperatively with various levels of government—federal, state, local, tribal, and territorial—so they can gather intelligence on criminal networks and propose specific operations to counter them.

Under the program’s guidelines, participants must enter into contractual agreements with government agencies and undergo thorough vetting procedures. They will also be required to adhere to operational protocols established by the federal government. To further ensure compliance, participants may need to maintain a bond or escrow funds of at least $1 million, which could be forfeited in the event of any violations.

The program notably includes provisions for targeting criminal groups that have apparent state affiliations. The memorandum specifies that any foreign, cyber-enabled transnational criminal organization (CE-TCO) that aims its operations at the U.S. and its interests can be targeted. However, allegations regarding connections between these groups and foreign governments will require substantiation through credible intelligence.

The scope of permitted cyber operations is expansive and includes the targeting and surveillance of an array of IT infrastructure elements. This can cover internet and telecommunications networks, computers, and embedded systems, aiming to manipulate, disrupt, or even destroy information systems. Importantly, the guidelines expressly allow for certain forms of unauthorized access to these systems, leading to concerns about the implications of such permissions. Casey Ellis, founder of the bug bounty program Bugcrowd, highlighted this development as a departure from previous legal expectations surrounding cyber operations.

The White House’s decision to allow private contractors to engage in proactive cyber measures appears to be influenced by advocacy from industry experts pushing for legislative change. Last year, both the House and Senate considered bills to authorize "letters of marque," enabling private cybersecurity professionals to seize cryptocurrency wallets filled with proceeds from cyberattacks against Americans. This historical term refers to a practice used centuries ago, allowing privateers to capture vessels belonging to enemies of the state.

As the initiative roll out unfolds, it will be overseen by the Homeland Security Task Force’s National Coordination Center, which was established by Trump a year prior. Each of the co-executive directors from the departments of Justice and Homeland Security will supervise the program and approve participant selection. The framework ensures that participants follow strict legal obligations, and any operations deemed to pose a significant risk to human life or violate international law will be strictly prohibited.

Despite the groundbreaking nature of the program, the White House has stressed that it will operate in accordance with all relevant U.S. laws, and participants are expected to comply with existing regulations a well. Lessons from the past will guide how operations are conducted to avoid missteps that could raise ethical or legal concerns.

In conclusion, the White House’s newly launched program signifies a pivotal moment in the landscape of cybersecurity. By formally involving private contractors in offensive operations against foreign cybercriminals, the U.S. aims to bolster its defenses and reduce the risks posed to its citizens. However, this initiative also raises critical questions about oversight, accountability, and the potential consequences of granting private entities a role in cyber warfare. As the program matures, its efficacy and ethical considerations will undoubtedly be scrutinized by industry stakeholders and the public alike.

Source link

Latest articles

AI Agents Launch Near-Autonomous Cyberattack on Asian Government Networks

New Phase in Cybersecurity: Autonomous AI Agents Breach Taiwanese Government Systems In a significant development...

Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and Remote Code Execution

Microsoft has recently announced critical security updates aimed at addressing six distinct vulnerabilities found...

Akira Affiliate Disrupted Ransomware Operation Following EDR Evasion Attempt

A recent investigation by Huntress has spotlighted a fascinating misstep made by a ransomware...

Researcher Bypasses Microsoft Defender Patch to Seize Control

Urgent Cybersecurity Alert: New Exploit Threatens System Integrity Through Antivirus Software In a recent security...

More like this

AI Agents Launch Near-Autonomous Cyberattack on Asian Government Networks

New Phase in Cybersecurity: Autonomous AI Agents Breach Taiwanese Government Systems In a significant development...

Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and Remote Code Execution

Microsoft has recently announced critical security updates aimed at addressing six distinct vulnerabilities found...

Akira Affiliate Disrupted Ransomware Operation Following EDR Evasion Attempt

A recent investigation by Huntress has spotlighted a fascinating misstep made by a ransomware...