
US will let vetted private firms launch offensive cyberattacks on foreign criminals
A Trump memorandum signed August 12 lets vetted private companies run spyware surveillance and destructive operations against foreign criminal networks, subject to written sign-off from Justice and Homeland Security, $1 million in escrow, and a bar on touching Americans or US-based systems. That reverses the long-standing reading of federal hacking law that private firms may defend but never attack, and creates a government-supervised offensive-cyber program whose entry requirements guidance will define within two months. Hunter Strategy's Jake Williams calls the policy half-baked and warns that American operators could be classified as non-uniformed combatants while traveling abroad.
Source: techcrunch.com ↗
Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas.
Why this matters
- → Reverses 20+ years of policy banning private offensive cyber ops, creating new legal attack surface.
- → Exposes US employees abroad to foreign indictment as 'non-uniformed combatants' under cover of policy.
- → Signals escalating cyber warfare posture amid Iranian infrastructure attacks and AI-driven threats.