The White House issued a presidential memorandum allowing vetted private companies to conduct offensive cyber operations, including surveillance via spyware and disruptive attacks against criminals' data and systems, targeting international cybercrime such as ransomware and sextortion. This reverses decades of policy that restricted private firms to defensive cybersecurity. Participating companies must deposit $1 million in escrow, get sign-off from the Justice Department and Homeland Security, and operate under federal supervision, with guidance on program requirements expected within two months. Critics, including cybersecurity veteran Jake Williams, warn the policy is 'half-baked' and could expose American participants to being charged as combatants by foreign governments. The change comes amid ongoing Iranian-linked cyberattacks on U.S. water infrastructure and broader concerns about autonomous AI-driven cyberattacks reported by Anthropic, OpenAI, and Meta.
Questions this post answers
what does the new US presidential memorandum on offensive cyber operations allow private companies to do
It allows vetted private companies to conduct surveillance, including spyware-based intelligence collection, and disruptive attacks aimed at destroying criminals' data or systems, when combating international cybercrime like ransomware and sextortion. Companies must deposit $1 million in escrow, get sign-off from the Justice Department and Homeland Security, and operate under federal supervision. It stops short of allowing companies to conduct 'hack back' attacks. Security teams weighing offensive cyber policy shifts can follow developments like this on daily.dev.
what are the risks for Americans working at private companies participating in US offensive cyber operations
They risk being classified as non-uniformed combatants while traveling overseas and could be indicted or detained by foreign governments, according to cybersecurity veteran Jake Williams, vice president of research and development at Hunter Strategy. He notes that allegations of American involvement in these operations need not even be true for a foreign government to use them as justification for action. Professionals assessing career risk in offensive cybersecurity work can track this story on daily.dev.