threat_intelligence1603 wordsRead on Arc Codex

White House Authorizes Private Companies to Conduct Offensive Cyber Operations

White House Authorizes Private Companies to Conduct Offensive Cyber Operations A new federal program will let vetted U.S. cybersecurity firms help investigate and disrupt foreign cybercrime groups under government direction. - Sarah Gooding The White House is creating a program that will allow vetted U.S. companies to conduct offensive cyber operations against foreign cybercrime groups under federal direction. The presidential memorandum creates a formal path for private companies to perform work usually associated with government cyber operators. Participating firms could covertly access criminal systems, collect intelligence, disrupt networks, manipulate infrastructure, or destroy data after receiving approval from the Department of Justice and Department of Homeland Security. Before you picture every company in America launching counterattacks against its hackers, the program comes with tight boundaries. Companies cannot act independently or retaliate on behalf of a customer whenever they detect an intrusion. They must be accepted into the federal program, operate under a DOJ or DHS contract, and receive written government approval for every operation. Cybersecurity companies have long helped law enforcement investigate attacks by supplying malware analysis, infrastructure data, telemetry, and attribution research. The new program allows private companies to execute government-approved surveillance and disruption operations themselves. That could give federal law enforcement access to a much larger pool of operators, infrastructure, commercial telemetry, and specialized expertise. What Companies Will Be Allowed to Do The memorandum creates two categories of authorized activity: cyber surveillance operations and cyber effects operations. A cyber surveillance operation involves secretly accessing a target's systems to collect intelligence. That intelligence could identify the people behind a criminal operation, expose its infrastructure, or support a later disruption. A cyber effects operation goes further. It can manipulate, disrupt, deny access to, degrade, or destroy systems, networks, infrastructure, and the information stored on them. Depending on the approved operation, that could mean disabling command-and-control servers, taking criminal services offline, interfering with malware infrastructure, or deleting information used to operate a campaign. The targets must be foreign cyber-enabled transnational criminal organizations attacking U.S. people, businesses, government agencies, or other U.S. interests. A White House fact sheet points to ransomware, phishing, financial fraud, sextortion, and impersonation scams as examples of the activity the program is intended to disrupt. This is broader than asking a private company to analyze a malware sample or help identify a server. Approved contractors will be able to enter and affect infrastructure controlled by criminal groups on behalf of the U.S. government. How an Operation Reaches Approval The program will be managed by the Homeland Security Task Force's National Coordination Center, with executive directors appointed by DOJ and DHS. A participating company will be able to receive threat information from businesses and government agencies, use it to develop a proposed operation, and submit an operation package to the center. Errata Security CEO Robert Graham described the change as a transfer of authority in his analysis of the memorandum: “That’s how I read this memo: instead of making them share data with us, let’s share authority with them, specifically, §1030(f).” To illustrate how that would work, Graham continued: “What that means in practice is that while CrowdStrike is tracking down a Chinese APT group, they can get permission to hack some computers of that specific group. It’s not blanket permission to hack all APT groups — law enforcement still maintains control, requiring written approval of every operations package — but it’s more hacking than they are allowed to do today.” In a March analysis for Lawfare, former DOJ cybercrime prosecutor Aaron Cooper and attorneys Philip Chertoff and Shoba Pillay noted that no court had addressed whether §1030(f) protects private companies conducting operations on behalf of the government. The new memorandum places participating companies under federal control and cites §1030, but it does not amend the law or explain what protection contractors would have under foreign computer-crime laws. The memorandum also requires participating companies to undergo technical, personnel, facility, and security vetting. DOJ and DHS may require a company to maintain a bond or escrow of at least $1 million that can be forfeited for violating its contract. Companies must stop and report an operation if they discover that it has moved beyond the approved target or scope. It also calls for operations to be coordinated across U.S. law enforcement, the State Department, the Treasury Department, the Department of War, DOJ, and the intelligence community. Coordination with foreign law enforcement is less clear in the public memorandum, even though cybercrime investigations regularly cross national borders. Jamie MacColl, a senior research fellow at the Royal United Services Institute who studies ransomware and cybercrime, captured the concern in a reply on Bluesky: “Countdown to a European law enforcement agency having a multi-year ransomware operation being upended by a US defence prime doing pew pews”. Investigators may spend months quietly monitoring infrastructure, collecting evidence, identifying victims, or preparing arrests. A contractor disrupting that infrastructure too early could alert suspects, destroy evidence, or interfere with another country's operation. The implementation rules will need a reliable way to check proposed actions against investigations outside the U.S. government. Operations that could cause death or serious injury, or rise to the level of armed force under international law, cannot be approved by the program's DOJ and DHS directors. Why the Government Wants Private-Sector Operators Federal agencies already conduct operations against cybercrime infrastructure. In 2023, for example, the FBI infiltrated the BlackCat ransomware group's systems, developed a decryption tool for victims, and seized websites used by the group. Private security companies, however, often encounter malicious activity before the government does. They operate endpoint products, cloud platforms, email services, payment systems, identity tools, package-security services, and global networks. Their systems generate enormous amounts of telemetry about malware, phishing, credential theft, malicious infrastructure, and attacker behavior. They also employ researchers and operators with highly specialized knowledge of particular malware families, criminal markets, infrastructure providers, and technical environments. Bringing those companies into government operations expands the available workforce without requiring every capability to be built inside a federal agency. The memorandum explicitly points to the private sector's “scale, speed, and capacity” as an offensive advantage that has historically been underused. The program gives the government a way to combine that capacity with federal legal authority and intelligence. The model could also shorten the distance between discovering a criminal operation and acting against it. A company that has already mapped infrastructure or followed a campaign across multiple customers may be well positioned to propose a targeted operation. Under the new framework, that proposal can move into a government approval process and potentially become an active disruption. New Work and New Incentives For participating cybersecurity companies, the most direct benefit is access to a new category of federal work. Both large firms and smaller specialists are expected to be eligible, according to the memorandum. Smaller companies could be selected for discrete operations that depend on expertise in a particular technology, actor, or criminal ecosystem. The program also gives security firms a larger operational role in campaigns they already investigate. A threat intelligence company may currently identify criminal infrastructure, notify providers, publish indicators, or pass evidence to law enforcement. Participation in the new program could allow the same company to propose and carry out a government-directed disruption. Private organizations, including companies hit by cybercrime, can enter commercial agreements with participating companies and supply threat information collected through their normal business activities. That creates another route for useful evidence to reach federal operators and potentially support action against the underlying criminal network. The government will choose the targets and approve each operation, but organizations may gain a clearer escalation path when they uncover foreign criminal infrastructure affecting multiple victims. That commercial structure has already prompted questions about incentives. Security researcher Kevin Beaumont sees merit in offensive action against ransomware groups, with an important qualification. He framed it this way in a three-post Mastodon thread: “There’s definitely merit in the idea of hacking ransomware groups and it does already in fact happen (don’t ask me how I know). But the correct incentives have gotta be there.” His support came with a warning about the industry being asked to carry out the work. Beaumont argued that private cyber companies have spent the past five years lobbying against change while making substantial money from ransomware. “Outsourcing the fight against ransomware to the companies that directly profit from it and giving them more profit seems potentially problematic,” Beaumont said. Jason Kikta, Automox CTO and a former commander of the U.S. Cyber National Mission Force, made a similar point, calling the proposal “a perpetual motion machine for billable threats”. A participating company could receive threat information from a customer, use it to propose an operation, and then be paid to help carry it out. The forthcoming rules will need to separate threat identification, operational recommendations, government approval, and payment so companies are rewarded for measurable disruption rather than a growing volume of operations. Building on the March Cybercrime Order The administration first signaled this direction in a March 2026 executive order. That order called for a National Coordination Center operational cell and directed agencies to use technical capabilities, threat intelligence, and operational insights from commercial cybersecurity firms to improve the attribution, tracking, and disruption of cybercriminals. The August memorandum turns that broader policy into a contractor program and explicitly authorizes private companies to conduct the operations. DOJ and DHS now have 60 days to establish the program's operating procedures, including eligibility requirements, targeting standards, reporting obligations, and the process for developing and approving operations. The first status report is due within 180 days, followed by annual reports to senior White House cybersecurity officials.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.