Policy/ cybersecurity · white house · cybercrime · policy

White House Recruits Private Hackers to Fight Cybercrime

A new presidential memorandum lets vetted businesses conduct surveillance and offensive cyber operations against criminal networks, under federal oversight.

The federal government just outsourced part of its cybercrime fight to private companies.

A presidential memorandum signed Aug. 12 directs a new National Coordination Center to vet and authorize U.S. businesses to conduct cyber surveillance and, in some cases, offensive operations against transnational criminal organizations behind ransomware, phishing, financial fraud, and sextortion schemes. Approved companies would get contractual access to threat intelligence from federal, state, local, tribal, and territorial agencies, and each operation still needs sign-off from the Justice Department and Homeland Security before it can proceed. The National Coordination Center has 60 days to write the actual rules. The memo expands on a March 6 executive order that pushed federal agencies to get more aggressive about cybercrime targeting Americans.

This is a real shift from years of policy that kept private hacking off-limits without a court order. The rules officially still ban retaliatory hacking, so-called hacking back, under the Computer Fraud and Abuse Act. But handing vetted companies government threat data and blessing offensive operations against criminal networks blurs a line that used to be pretty firm.

Google already stood up its own disruption unit, and some conservative voices have floated reviving letters of marque for cybercriminals; this memo reads like the government formalizing a trend that was already underway, not starting one.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →