US to Let Private Companies Launch Cyberattacks on Foreign Criminals Under New Policy

The United States government is preparing a framework that will permit vetted private companies to conduct offensive cyber operations against foreign criminal syndicates, according to recent policy disclosures. Under a presidential memorandum, participating firms will have the authority to conduct both surveillance and disruptive cyber operations against foreign cyber-enabled criminal organizations, provided federal authorities maintain direct oversight and approval.

This policy marks a shift from the US stance that private companies can defend against hackers but not attack them. Instead, the initiative seeks to enlist commercial technical talent to actively disrupt ransomware, fraud, and other cybercrimes targeting Americans.

According to reporting from TechCrunch, the program requires rigorous vetting for any private firm wishing to participate. Interested companies may be required to post at least $1 million in escrow as part of the compliance and security checks governing these state-supervised offensive engagements.

Federal Oversight and the Escrow Mandate

To mitigate risks, the newly structured federal framework ensures that no commercial entity acts unilaterally. Every surveillance effort or disruptive action must receive explicit government approval and remain under active federal supervision.

Financial accountability is equally central to the design of the program. By evaluating proposals that involve participating firms putting up at least $1 million in escrow, the federal government aims to filter out underprepared contractors and ensure that commercial participants maintain sufficient capital resources and accountability throughout high-stakes digital operations.

A Broader Landscape of Sophisticated State and Commercial Threats

For instance, a sophisticated supply chain attack involving Austin-based software provider SolarWinds compromised numerous corporate and government clients, prompting emergency directives from the U.S.

US to Let Private Companies Launch Cyberattacks on Foreign Criminals Under New Policy
Photo: nbcnews.com

While the SolarWinds incident highlighted the vulnerability of trusted IT software supply chains to foreign intelligence operations—such as those attributed by officials to Russia’s Foreign Intelligence Service (SVR)—the new offensive private-sector initiative focuses explicitly on criminal enterprises.

Cybersecurity companies like FireEye, which experienced its own high-profile breach involving tools used by its Red Team, have long navigated this tense ecosystem.

Stakeholder Impact and Next Steps

From Instagram — related to private companies cyberattacks foreign, Let Private Companies Launch Cyberattacks

Leave a Comment