Mobile

US Government Urges Corporations to Combat Cybercriminals with Offensive Hacking Techniques

Ryan Haines / Android Authority

Summary

  • The US government is initiating a program that permits approved private companies to carry out offensive cyber actions against international criminal entities.
  • Such operations will require federal oversight and the companies must deposit a minimum of $1 million in escrow.
  • This policy represents a significant shift from the previous US stance which restricted private companies to defensive measures only.

The US government’s latest approach to cybersecurity suggests that companies should not only act defensively but also take the fight to cybercriminals. A new presidential directive is set to allow select American firms to execute offensive cyber operations targeting foreign criminal organizations, with government oversight playing a crucial role.

According to sources, the directive from the Trump administration establishes a federal program enabling private entities to perform both surveillance and disruptive cyber actions against global cybercriminal groups. The intent is to combat threats such as ransomware, fraud, and various cybercrimes aimed at US citizens.

However, these companies will not have free rein. Every action must receive formal approval from authorities within the Justice Department and the Department of Homeland Security, all while functioning under federal supervision. Additionally, firms may be asked to place at least $1 million in a bond or escrow account that could be forfeited if they violate the established rules.

The directive grants substantial powers, permitting operations that can manipulate, impede, degrade, or destroy data and computer systems. Surveillance activities may even involve clandestine access to systems to gather information without the permission of the system owners.

There are safeguards in place. The initiative is designed to focus solely on foreign criminal entities, not government targets, and companies must cease any operations that inadvertently impact US persons or systems, reporting such incidents immediately. The complete set of operational rules is still in development, with officials tasked to finalize procedures within 60 days.

This strategy marks a dramatic shift from the US government’s long-held view that private entities are limited to defense against cyber threats. Cybersecurity expert Jake Williams characterized the plan as “half-baked,” cautioning it could lead to legal challenges or accusations for Americans engaged in such activities when traveling abroad.

Thank you for being part of our community. Please review our Comment Policy prior to engaging.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button