In a first, US will allow some private firms to carry out cyberattacks
The US government will, for the first time, permit vetted private companies to conduct offensive cyber operations against overseas criminal gangs and hackers under federal supervision. The White House says the policy could help tackle ransomware, financial fraud and sextortion, but it represents a major departure from the previous rule that private firms could defend themselves but not launch cyberattacks.
Participating companies could use surveillance tools, including spyware, and disrupt or destroy criminals’ data or systems, subject to approval from the Justice Department and Homeland Security. Firms must place $1 million in escrow, operations must not target Americans or US-based systems, and guidance on eligibility is due within two months. The policy does not allow companies to independently “hack back”, and critics warn it could trigger legal, diplomatic and personal-security risks for private-sector staff.
- US may authorise private firms’ offensive cyber operations.
- Operations require federal approval and supervision.
- Critics warn of legal and diplomatic risks.
New here? Start with this
Cyberattacks are increasingly used by criminal groups to steal money, lock organisations out of their computer systems and demand payments. Ransomware is software that blocks access to files until a ransom is paid, while sextortion involves threats to share intimate material unless a victim complies.
Until now, US companies have generally been allowed to protect their own networks but not to enter or disrupt another party’s computer systems, even if they believe that party is attacking them. Offensive cyber operations mean actively gathering information from, interfering with or damaging an adversary’s digital systems.
The new approach would involve selected private firms working under federal oversight against groups based outside the United States. It raises questions about how such operations would be controlled, how other countries might respond, and what risks employees could face if criminal groups identify those involved.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Supporters argue that tightly supervised private participation can give the United States more capacity and specialised expertise against transnational cybercrime, particularly where ransomware, fraud and sextortion move faster than traditional investigations. They contend that requiring federal approval, vetting, financial safeguards and a ban on targeting Americans distinguishes this from unchecked “hack back”, while enabling proportionate disruption of criminal infrastructure that otherwise harms victims at scale.
The case against
Critics argue that authorising private firms to conduct offensive operations risks blurring the boundary between law enforcement, intelligence work and commercial activity, even with formal oversight. They warn that attribution errors, collateral damage and the use of intrusive tools such as spyware could violate foreign laws, provoke diplomatic retaliation or endanger employees, while creating incentives for companies to push beyond defensive security into escalation.