US government to allow private companies to carry out cyberattacks on its behalf

← Back to the feed

US government to allow private companies to carry out cyberattacks on its behalf

Engadget · 2 hours ago

President Donald Trump has signed a national security memorandum allowing vetted private companies to conduct cyberattacks against transnational criminal organisations on the US government’s behalf. The move is intended to broaden the response to ransomware, sextortion, fraud and phishing, but it raises legal and operational questions because the practical rules and potential overseas consequences remain unclear.

The policy significantly expands beyond the Justice Department’s 2022 stance of generally not prosecuting good-faith security research under the Computer Fraud and Abuse Act. A Homeland Security Task Force must set vetting and operational standards within 60 days, while participating firms must post a $1 million bond that can be forfeited for failing to follow government direction. The memorandum followed cyberattacks on water facilities in Minnesota and Michigan linked to Iran, but does not address whether participating firms or employees could face charges in countries where targeted computers are located.

  • US firms may conduct government-authorised cyberattacks against criminal groups.
  • Rules for vetting and operations are due within 60 days.
  • Overseas legal risks for companies and staff remain unresolved.

Americas Cybersecurity Government Politics Technology World

Read the full article at the source →