Security firms hit back at Trump’s call to hack back against international crime gangs

"The United States will use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime."

Share
President Trump will allow vetted US security companies to launch offensive cyber operations against foreign criminal networks (Image: Igor Omilaev on Unsplash)
President Trump will allow vetted US security companies to launch offensive cyber operations against foreign criminal networks (Image: Igor Omilaev on Unsplash)

The Trump administration has given security companies the green light to launch offensive cyber operations against "criminal networks operating in cyberspace" in a dramatic expansion of America’s offensive digital capabilities.

Traditionally, only the military and government agencies were allowed to launch cyberattacks against enemies, with operations typically conducted deep in the shadows.

That's all about to change thanks to a presidential memorandum signed last week that creates a programme allowing vetted US companies to conduct government-authorised surveillance and disruptive cyber operations against Transnational Criminal Organizations (TCOs) that "pose a growing threat to American citizens, businesses, and national security".

Under the programme, private firms can be authorized to secretly break into critical systems and potentially manipulate, disrupt, or even destroy digital infrastructure.

But the plan to create "cyber privateers" has already raised concerns among cybersecurity experts over attribution, collateral damage, and the risks of outsourcing offensive cyber operations to private companies.

"The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States," the White House wrote. "Yet, American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace.

"Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime."

The new memo explicitly - and remarkably - permits "the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon."

However, it does not give security professionals a licence to kill and establishes safeguards around "Critical Outcomes" - operations likely to cause death or serious injury, or rise to the level of a use of force or armed attack under international law.

Companies must immediately alert the government if they believe their actions have crossed this threshold or discover an imminent cyberattack against US critical infrastructure.

"It's impossible to 'strike back' without taking out innocent bystanders"

One of the key risks of enabling security firms to hack back is the risk of taking out the wrong infrastructure.

Ben Bernstein, cybersecurity advisor at Huntress, said that green-lighting private offensive operations creates "two massive roadblocks": collateral damage and "bureaucratic lag".

He explained: "Threat actors don't launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network.

"That makes it practically impossible to 'strike back' without taking out innocent bystanders. Plus, adversary infrastructure is incredibly ephemeral, often burning down in a matter of hours. By the time a vetted firm submits a target, sits through the DOJ and DHS deconfliction reviews, and finally gets a green light, they’ll be shooting at ghosts. Expecting government bureaucracy to move at the speed of modern ransomware operators is wildly optimistic." 

READ MORE: Gunra ransomware gang is targeting critical infrastructure worldwide, CISA warns

Kyle Hanslovan, CEO and co-founder of Huntress, offered a positive assessment of the guidelines.

"I’m proud to see the US Government push the boundaries when it comes to denying, degrading, and disrupting these measurable threats to democracy," he said.

"If done correctly, I believe it will ultimately slow the illegal transfer of wealth and knowledge from Western civilization."

"Considering the rapidly accelerated sophistication of organised cybercrime and nation-state actors, close public and private collaboration is no longer an option. When you add the reality of AI-powered autonomous threats, the only viable solution is a stronger coalition of the willing, which we are eager to support."

AI vs AI

In an era when threat actors are hijacking legitimate, trusted infrastructure, attribution is clearly a very difficult job. That's a problem when firms are allowed to hack back, increasing the risk of friendly fire and potentially even the misguided targeting of allies.

Tim Mackey, head of software supply chain risk strategy at Black Duck set out several other risk associated with the new policy and said: "Endorsing private companies to conduct offensive cyberactivity is far more likely to increase criminal, and potentially nation-state, activity than deter it.

"Without careful governance and control, individuals with access to sophisticated surveillance technologies could easily abuse that access and engage in surveillance efforts for personal gain. Unfortunately, one message this memo does send to adversaries is – the US government needs private companies and their capabilities to defend against cyberattacks." 

Darren Williams, Founder and CEO at BlackFog, warned that offensive actions will not necessarily improve organisations' defensive posture because they will not eliminate the vulnerabilities attackers exploit.

He said: "Cybercrime is increasingly centered on monetising stolen information, making data exfiltration as important as operational disruption. Criminal groups can rebuild infrastructure, change tactics, and move across jurisdictions, so taking systems offline is unlikely to provide lasting protection on its own.

READ MORE: Anthropic's rogue agents launch "real-world" attacks, join OpenAI's models in the wild

"Organisations still need to focus on what they can control. That means detecting and blocking data exfiltration in real time, monitoring outbound traffic for unusual behaviour, enforcing least privilege, and segmenting sensitive information. Incident response should prioritize containing data, not simply restoring systems after an attack." 

Corey Brunkow, a former US Army Colonel and Director of Federal Operations at Horizon3.ai, said the threat landscape was now being transformed by AI, enabling attackers to discover vulnerabilities and chain attack paths at "machine speed" to render human-only defence "structurally insufficient".

He continued: “Public and private organisations can respond by continuously validating real attack paths, prioritising proven exploitability and mission impact. They should also nominate valid, proven attack paths that originate from transnational criminal organisations for counteraction by competent authorities, using the most sophisticated, commercially derived capabilities.”

Follow Machine on LinkedIn