White House Private Cyber Program Tests Hackback Limits Against Foreign Crime Groups
Ars Technica reported that a Trump memorandum directs federal officials to build a program allowing vetted private security firms to conduct authorized cyber operations against foreign criminal hacking groups under Justice and Homeland Security oversight.

A new White House memorandum would let vetted private security companies conduct government-approved cyber operations against foreign criminal hacking groups, moving those firms beyond defense and into state-authorized offense.
A National Security Presidential Memorandum issued Thursday directs the National Coordination Center under the Homeland Security Task Force to build the program.
The Justice and Homeland Security departments are assigned oversight, while the targets are foreign transnational criminal organizations accused of cyber-enabled crime against US people, organizations, government entities or interests.
The program is aimed at the online crime economy rather than at state agencies.
A fact sheet tied to the memo named ransomware, sextortion, phishing, financial fraud and impersonation scams as activities that could fall inside the approved target set.
The memo frames the work around surveillance of covered groups and operations meant to produce effects against their computer systems.
Ars Technica reported that the plan would mark the first federal authorization for private companies to carry out offensive cyber operations against overseas hackers and that the memo appears broad enough to permit spyware or attacks designed to damage criminal data or systems.
The eventual operating rules have not yet been published.
The guardrails are also part of the story.
Firms would need approval after vetting by Justice and Homeland Security officials, and the memo bars operations that cause Critical Outcomes such as death, serious injury or effects that cross into armed-force territory under international law.
Participating companies would also have to meet standards covering technical proficiency, prior cyber-operations performance, facility security, personnel vetting, competence and reliability.
The memo requires a $1 million escrow deposit, which can be forfeited if a firm falls out of compliance with its contract.
The structure could give Washington another way to pressure overseas ransomware and fraud groups, but it also creates an incentive problem for the same industry that sells response services after attacks.
Beaumont backed action against ransomware crews in principle, while warning that the incentives have to be correct after five years in which some private cyber companies benefited from little changing.
The memo gives Justice and Homeland Security 60 days to define the approval process, permitted techniques, oversight mechanics and consequences for mistakes.




















