White House recruits security firms to hack overseas cybercriminals
| Source: Ars Technica AI
Tags: cybersecurity, White House, Trump, ransomware, offensive cyber, DOJ, DHS
Trump's National Security Presidential Memorandum authorizes vetted private security firms to conduct offensive cyber operations — including attacks on systems and data — against overseas criminal organizations for the first time, with DOJ and DHS oversight.
Details
A National Security Presidential Memorandum issued Thursday by the Trump administration authorizes vetted private sector cybersecurity firms to conduct offensive cyber operations against foreign transnational criminal organizations (TCOs) that target US persons, organizations, or government entities. The National Coordination Center (NCC), under the Homeland Security Task Force, will develop and oversee the program with DOJ and DHS oversight. Authorized operations include Cyber Surveillance Operations and Cyber Effects Operations against groups engaged in ransomware, sextortion, phishing, financial fraud, and impersonation scams. The memo permits use of spyware and offensive attacks designed to destroy TCO data or systems, though it prohibits operations resulting in loss of life, serious injury, or damage to critical infrastructure. Private firms must pass vetting by DOJ and DHS to participate. The program marks the first time the federal government has officially authorized private companies to conduct offensive cyber operations. Security researcher Kevin Beamont was skeptical: 'The biggest problem I've had with fighting ransomware over the past 5 years is private cyber companies basically lobbying for nothing to change. A lot of companies have made a lot of money, so putting them in charge of stopping it seems optimistic.' Questions about accountability, rules of engagement, and conflict-of-interest incentives remain unresolved.