Trump Admin Authorizes Private Firms for International Cyberattacks
The Trump administration has launched a new program allowing private firms to conduct international cyberattacks against foreign criminal networks under federal oversight. This marks a significant shift in U.S. cybersecurity strategy, aiming to leverage private sector capabilities. Experts, however, express concerns about the difficulty in identifying targets, the legal risks for operators, and the potential for collateral damage to innocent infrastructure.

The Trump administration has launched a groundbreaking new program that will empower private companies to conduct international cyberattacks against foreign criminal networks. This initiative, detailed in a presidential memorandum published Wednesday, marks a significant shift in U.S. cybersecurity strategy, which has historically reserved such operations for government entities. The move aims to leverage the private sector's "underutilized" capabilities in combating cybercrime, as reported earlier by Bloomberg.
Program Greenlights Private Cyber Operations
Under the new directive, private firms will operate "under the control and oversight" of the federal government, specifically the Department of Justice and Department of Homeland Security. These companies will be granted permission to surveil and disrupt criminal networks abroad. The memorandum emphasizes that this is part of a broader policy for the United States to utilize "all instruments of national power" to combat cybercrime.
Strict Oversight and Requirements
Participating firms must meet stringent requirements to qualify for the program. These include demonstrating "technical proficiency, proven performance of cyber operations, facility security," among others. A critical financial safeguard mandates that companies hold a bond or escrow of at least $1 million. This sum would be forfeited if the firm fails to comply with its contractual agreement.
The scope of targets is also carefully defined. Private firms will only be authorized to hack groups that are "not an institutional part of a foreign government or wholly operated under a foreign government’s direction." This stipulation aims to focus operations strictly on criminal elements rather than state-sponsored entities.
Uncharted Territory: Expert Concerns Emerge
Despite the administration's rationale, the initiative has quickly drawn scrutiny from cybersecurity experts regarding its potential pitfalls and legal complexities. Cybersecurity Dive pointed out the inherent difficulty in definitively distinguishing between independent criminal organizations and those with covert foreign government affiliations. This ambiguity could expose firms to substantial geopolitical or legal ramifications.
Jason Healey, a senior cyber conflict researcher at Columbia University, warned about the personal risks involved. He stated that "Anyone conducting these operations is doing so at substantial personal legal risk." Similarly, Jake Williams, vice president of research and development at Hunter Strategy, told TechCrunch that Americans participating in these operations could easily be classified as "non-uniformed combatants while traveling overseas," raising concerns about their legal status in foreign jurisdictions.
Potential for Geopolitical and Collateral Damage
Further concerns have been raised about the practical challenges and potential for collateral damage. Ben Bernstein, a manager for the cybersecurity advisers team at Huntress, highlighted the reality of cyberattack routing. He explained that "Threat actors don’t launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network."
Bernstein concluded that this complex routing makes it "practically impossible to ‘strike back’ without taking out innocent bystanders." This points to a significant challenge in ensuring precise targeting and avoiding unintended disruption to legitimate networks and services globally.
A Shift in U.S. Cyber Strategy
Historically, the U.S. government has directly conducted its own cyber operations without relying on third-party contractors. This new program represents a significant departure from established practices. President Donald Trump began laying the groundwork for private sector engagement in these critical operations last year, indicating a strategic pivot to incorporate external expertise into national security efforts.
FAQ
Q: What kind of oversight will private firms receive?
A: The Department of Justice and Department of Homeland Security will oversee private firms. These companies must also meet stringent technical, performance, and security requirements, and maintain a $1 million bond or escrow.
Q: What types of targets are private firms allowed to attack?
A: Private firms are permitted to target foreign criminal networks, specifically those "not an institutional part of a foreign government or wholly operated under a foreign government’s direction."
Q: What are some of the main concerns raised by experts about this program?
A: Experts are primarily concerned about the difficulty of accurately identifying government-unaffiliated groups, the potential for significant legal and geopolitical risks for operators, and the likelihood of inadvertently affecting innocent infrastructure during cyberattacks due to complex network routing.
Related articles
Kalshi Bans George Santos for Life Over Investigation Non-Compliance
Prediction market platform Kalshi has issued its first-ever lifetime ban to former Republican congressman George Santos. The move, announced Monday, comes after Santos reportedly failed to cooperate with an internal company investigation. This adds another chapter to the controversies surrounding the former House member, who was expelled from Congress in 2023.
Professor Murder Rides the Subway is a forgotten slice of dance punk
In a recent digital archaeology expedition, Terrence O'Brien, Weekend Editor at The Verge, unearthed and lauded Professor Murder's 2006 EP, "Professor Murder Rides the Subway," as a quintessential, yet largely
ai: Musk’s faster path to more gas turbines comes with pollution
Elon Musk's SpaceX is building a secret Texas foundry to produce gas turbine blades, aiming to accelerate AI data center power by 18 months. This addresses a critical energy bottleneck, but faces environmental backlash over pollution and health risks from gas turbines.
Robotaxis' Hidden Human Cost: Test Drivers Injured
An exclusive TechCrunch investigation reveals a hidden human cost in the robotaxi industry, with Waymo and Zoox test drivers suffering over two dozen injuries from sudden autonomous vehicle movements in 2024-2025. These incidents, including whiplash, sideline workers for months, challenging the industry's safety narrative. The report highlights occupational hazards for those at the forefront of AV development and raises questions about broader industry reporting as the sector expands.
Caterpillar Leverages Mining Automation Expertise for AI Deployment
Industrial giant Caterpillar is pioneering a pragmatic approach to artificial intelligence deployment, drawing upon decades of experience automating challenging physical environments like mining sites. The company's
Reimagining Classic IM: Exploring Open OSCAR Server in Go
Open OSCAR Server is an open-source, Go-based instant messaging server compatible with classic AIM and ICQ clients. It enables developers and enthusiasts to self-host a private IM server, reviving the functionality of these legacy platforms. The project boasts broad client compatibility, detailed protocol implementations, and a management API for administration.




