Private security firms will soon be allowed to hack overseas cybercriminals

← Back to the feed

Private security firms will soon be allowed to hack overseas cybercriminals

Ars Technica · 2 hours ago

The Trump administration plans to let vetted private cybersecurity firms carry out government-authorised operations against overseas criminal groups that target US people, organisations and government bodies. The initiative would mark the first formal US programme allowing private companies to conduct offensive cyber activity abroad, raising questions about oversight, incentives and the still-undefined limits of such powers.

Eligible targets include groups involved in ransomware, sextortion, phishing, financial fraud and impersonation scams, while possible actions could include surveillance, spyware or attacks that disrupt or destroy criminal systems. Justice and Homeland Security departments will oversee the programme; participating firms must pass vetting, avoid operations causing death, serious injury or an armed attack under international law, and place $1 million in escrow to be forfeited for contractual non-compliance.

  • US firms may be authorised to disrupt overseas cybercriminals.
  • The programme targets ransomware, phishing and online fraud groups.
  • Key operational safeguards and details remain unclear.

Cybersecurity Technology

Read the full article at the source →