Page 1 of 1

US government will let private companies hack criminal gangs

Posted: 13 Aug 2026, 17:17
by Mexico_b
The new program, meant to aggressively disrupt costly cybercrime schemes, carries numerous legal and security risks.


The Trump administration will let private companies hack foreign criminal organizations as part of a new program that could expand the U.S. government’s ability to disrupt those groups’ cybercrime activities, while also introducing myriad legal challenges and perils.

President Donald Trump late Wednesday issued a memorandum directing the departments of Justice and Homeland Security to create a program allowing vetted companies to hack into criminal groups to spy on them or sabotage their operations. Trump said the program would help the U.S. combat cybercrime schemes that cost the nation tens of billions of dollars annually.The new policy represents a dramatic expansion of the private sector’s role in offensive cyber operations against U.S. adversaries and significantly blurs the line between the government’s foreign policy activities and businesses’ commercial activities. And while the program focuses on criminal gangs, not nation-states, it marks the largest step that the U.S. government has ever taken toward a world of corporations “hacking back” against foreign governments on behalf of the U.S.

Many cybersecurity experts have sharply criticized the hack-back concept, saying it creates unacceptable escalation risks and could expose private companies to the kind of foreign military retaliation previously reserved for government personnel. But the Trump administration has embraced aggressive measures for confronting transnational criminal groups, evincing less concern about potential collateral damage.

When the topic of hacking back came up at the Black Hat USA cybersecurity conference in Las Vegas last week, a DHS official did not dismiss the concept. “Our long-term goal is to terrify those who would target Americans, such that they know we’re actually the worst target in the world, because we will mess you up,” said Joseph Alm, the assistant secretary of homeland security for cyber, infrastructure, risk and resilience.

The new program comes with several restrictions meant to limit the potential for unintended consequences. Co-executive directors from DOJ and DHS will review every proposed operation and provide written approval of the ones the government green-lights. Participating companies will have to meet certain requirements, such as technical competency and personnel vetting, and set aside bonds of at least $1 million that they would forfeit if they violated the program’s rules.

Trump’s memorandum also says that the program’s leaders cannot authorize surveillance or disruption operations that would kill or seriously injure people or constitute the use of force or an armed attack under international law.

The White House gave DHS and DOJ 60 days to establish operating procedures for the program, including standards for companies’ participation, procedures for deconflicting operations with the military and the intelligence community and requirements for participants to report useful information that they acquire about criminal gangs’ activities.

The memorandum says the program should ensure “participation by both large companies, which provide critical capacity, and smaller, more agile companies, which may be better suited for specialized or discrete tasks.”

“American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace,” Trump said in the memorandum. “By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter [transnational criminal organization] threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.”

Major legal question marks
The new private hacking program is rife with potential risks for participating businesses, the U.S. government and American society.

The memorandum requires the operating procedures to address some of those risks. Companies will be required to stop and alert the government if they accidentally target a U.S. person or information system, and DOJ must ensure that any hacking operations aimed at U.S. persons or otherwise raising constitutional or legal questions follow applicable laws, including judicial authorizations.

source: https://www.cybersecuritydive.com/news/ ... ns/827805/