The Trump administration is recruiting private
security firms to conduct federal government-authorized operations, including
cyberattacks, against overseas-based criminal organizations that commit hacks
on US persons, organizations, or government entities.
In a National Security Presidential Memorandum
issued, US President Donald Trump directed the National Coordination Center
(NCC), which operates under the Homeland Security Task Force, to develop a
program for conducting specific cyber operations that combat foreign
transnational criminal organizations (TCOs). The Departments of Justice and
Homeland Security will provide oversight. The lynchpin of that program is
bringing in private sector companies to participate.
A fact sheet that accompanied the memo listed
ransomware, sextortion schemes, phishing campaigns, financial fraud, and
impersonation scams as activities eligible for private-sector security firms to
target.
The memo said such firms could “conduct Cyber
Surveillance Operations and Cyber Effects Operations” against “cyber-enabled”
TCOs. Such groups are defined as “any foreign group that conducts cyber-enabled
crime against the United States Government, a United States person, or United
States interests, and that is not an institutional part of a foreign government
or wholly operated under a foreign government’s direction.”
The new program is the first time the federal
government will authorize private companies to conduct offensive cyber
operations against overseas hackers. The memo appears to permit companies
participating in the program to use spyware or launch offensive attacks
intended to destroy TCO data or systems.
The memo doesn’t rule out certain types of
offensive attacks, such as those that use encryption to lock targets out of
their networks or performing distributed denial-of-service attacks. Up until
now, the government has prohibited the private sector from taking such actions
without court-authorized approval.