The Trump administration is launching a new program that will allow private firms to perform cyberattacks against foreign criminals, as reported earlier by Bloomberg. The private firms would operate âunder the control and oversightâ of the federal government, giving them permission to surveil and disrupt criminal networks, according to a presidential memorandum published on Wednesday.
The Department of Justice and Department of Homeland Security will oversee the private firms, which must meet requirements in âtechnical proficiency, proven performance of cyber operations, facility security,â and more. Companies in the program must hold a bond or escrow of at least $1 million that theyâll forfeit if they donât comply with their contractual agreement. The memorandum also says private firms will only hack groups that are ânot an institutional part of a foreign government or wholly operated under a foreign governmentâs direction.â
The memo describes private businesses as âunderutilizedâ forces for fighting criminal networks. âIt is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime,â it says.
But as pointed out by Cybersecurity Dive, it can be difficult to identify which criminal groups are affiliated with foreign governments, which could put cybersecurity firms at risk of stoking geopolitical or legal conflicts. Jason Healey, a senior cyber conflict researcher at Columbia University, tells Cybersecurity Dive that âAnyone conducting these operations is doing so at substantial personal legal risk.â Jake Williams, the vice president of research and development at Hunter Strategy, similarly tells TechCrunch that âAmericans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas.â
Ben Bernstein, a manager for the cybersecurity advisers team at Huntress, also raises concerns about how this program will play out. âThreat actors donât launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network,â Bernstein says. âThat makes it practically impossible to âstrike backâ without taking out innocent bystanders.â
The US government previously carried out its own cyber operations, rather than relying on third parties. President Donald Trump began making plans to get private cybersecurity companies involved last year, Bloomberg reported.
Read the full article here