720-891-1663

Feds Allow Private Companies to Hack Hackers

The U.S. government just took its biggest step yet toward letting private companies fight cybercrime with cyberattacks of their own. A presidential memorandum directs the Justice and Homeland Security departments to create a program letting vetted companies hack into criminal groups to spy on them or sabotage their operations, aimed at cybercrime schemes that cost the U.S. tens of billions of dollars a year. cybersecuritydive

This isn’t about nation-state hacking — the program targets criminal gangs, not governments — but it still represents the biggest move the U.S. has made toward a world where corporations “hack back” against foreign actors on behalf of the government. cybersecuritydivecybersecuritydive

How it’s supposed to work

The plan comes with some guardrails. Co-executive directors from DOJ and DHS must review and approve every proposed operation, participating companies have to meet technical and personnel-vetting standards, and they’ll need to post a bond of at least $1 million that they forfeit if they break the rules. Operations that could kill or seriously injure someone, or that amount to a use of force under international law, are off the table. Agencies have 60 days to work out the operating procedures, including how these private operations get “deconflicted” with military and intelligence activity already underway in the same digital space. cybersecuritydivecybersecuritydive

Why some experts are worried

Reaction has been split. Some, like Indiana University’s Scott Shackelford, called it “a meaningful response to a growing problem” while flagging open questions about accountability. Others are blunter — former DHS official Paul Rosenzweig called it “a bad idea” and argued there are better ways to handle what he sees as an inherently governmental job. cybersecuritydivecybersecuritydive

The legal risks are real. The article lays out several: companies could stumble onto U.S. persons’ data while chasing a criminal group; poorly vetted targets could turn out to have quiet ties to a foreign government, potentially triggering a geopolitical incident; and cross-border internet infrastructure means a hack aimed at one country’s criminals could easily disrupt systems in an allied nation. As one former Cyber Command lawyer put it, deconfliction is already hard inside government — adding private actors makes it exponentially harder.

The bigger picture

Even companies willing to take the risk won’t get much public credit for it — the secrecy of the work means participants can’t advertise their involvement, so the payoff is essentially a government contract, not reputation. Whether this expands into a durable public-private hacking apparatus, or becomes a cautionary tale about outsourcing offensive cyber operations, will depend heavily on how strictly DOJ and DHS actually vet who gets in — and who they’re allowed to target.

Since this is all being done in secret we really won’t know how big or how successful – or not successful this program will be. Credit: Cybersecurity Dive

Facebooktwitterredditlinkedinmailby feather

Leave a Reply

Your email address will not be published. Required fields are marked *