A new White House memorandum allows selected American companies to hack transnational criminal organisations, sparking debate over oversight, attribution and escalation risks.
WASHINGTON, UNITED STATES — WEB DESK: US President Donald Trump has signed a memorandum directing federal authorities to allow selected American private companies to conduct cyber operations against certain foreign criminal organisations, marking a significant expansion of the private sector’s role in combating transnational cybercrime.
The initiative is aimed at organisations involved in crimes including ransomware, online fraud and sextortion, which the White House said cost Americans more than $20 billion in 2025.
Private firms could hack criminal infrastructure
Under the memorandum, authorised private-sector partners could take action against foreign cybercriminal groups, including taking down hackers’ servers or infiltrating their systems with spyware.
However, companies will not have unrestricted authority to launch cyber operations.
Each operation will require prior government approval, while participating companies must post a bond of at least $1 million. Actions that could cause death or injury, or that would constitute a use of force under international law, are excluded.
The Trump administration has been given 60 days to finalise the programme’s details, although some elements are expected to remain classified.
Cyber operations compared with privateering
The policy has drawn comparisons with 18th-century privateering, when governments authorised privately owned ships to conduct raids against enemy vessels.
Ari Redbord, a former federal prosecutor and policy executive at TRM Labs, told AFP that the concept could work differently in the digital era because government oversight can potentially continue throughout a cyber operation rather than ending once an authorised actor leaves port.
The comparison has nevertheless raised concerns among cybersecurity experts.
University of Surrey cybersecurity professor Alan Woodward warned that granting private companies official authority does not necessarily guarantee that operations will remain within intended limits.
Experts warn of escalation risks
Some experts believe the programme could help US authorities respond more aggressively to cybercriminal networks, while others question whether private companies can be trusted with such sensitive capabilities.
Jason Healey, a cybersecurity researcher at Columbia University and former US government cybersecurity official, said the programme appeared to contain legal safeguards but expressed concern about the weakening of institutions that could provide independent oversight.
Another concern is attribution.
Cybercriminal groups can operate through complex networks, proxies and compromised infrastructure, creating the possibility that a private company could mistakenly target the wrong system.
Woodward warned that companies participating in government-authorised hacking operations could themselves become targets of retaliation.
Policy reverses earlier White House position
The move also represents a notable change from the administration’s earlier position.
According to AFP, a senior US official said in March that the White House was not interested in “fighting pirates with pirates.” National Cyber Director Sean Cairncross had also previously ruled out using private companies for such operations.
It remains unclear what prompted the policy reversal within a period of several months.
The change comes as cybercrime continues to expand globally, with ransomware groups, online fraud networks and other criminal organisations increasingly operating across national borders.
Companies face new legal and security risks
The new programme could give US technology and cybersecurity companies capabilities beyond traditional defensive operations.
However, participating firms could face significant legal, diplomatic and security consequences if an operation is misdirected or triggers retaliation from foreign governments or criminal groups.
Microsoft declined to comment on the programme, while Google did not respond to an AFP request for comment.
The effectiveness of the policy will ultimately depend on how the administration implements its approval process, safeguards and oversight mechanisms.
