The U.S. government has for the first time allowed some private companies to take part in offensive cyber operations targeting international criminal groups and hackers. TechCrunch reported on Aug. 13 that the White House, in a presidential message, said it would use private-sector capabilities to respond to cyber threats aimed at Americans, including ransomware, financial fraud and sextortion.
The White House said participating companies would be allowed to conduct surveillance activities such as collecting intelligence using spyware. They would also be able to carry out disruption attacks that destroy criminal groups' data or systems. It did not allow companies to conduct retaliation hacking on their own. All operations will be carried out under federal government oversight and require approval from representatives of the Department of Justice and the Department of Homeland Security.
The move reverses the previous approach. U.S. federal laws related to computer hacking have broadly prohibited private companies from conducting cyber attacks or disruption operations, and past administrations have maintained that the private sector can defend against attacks but cannot carry them out directly.
The policy is still in its early stages. The government plans to issue detailed guidelines within the next two months setting out participation requirements, and it decided to include not only large companies but also smaller private firms that may be better suited to specific operations.
Participating companies must place $1 million in escrow and will forfeit the amount if they violate the rules. They must also establish procedures to ensure Americans or systems in the United States are not targeted.
If a participating company discovers an imminent cyber attack targeting U.S. critical infrastructure such as the power grid or water supply facilities, it must notify the government. The White House did not immediately answer a question about whether any private companies are already taking part in the programme.