The Trump administration has issued a directive encouraging American corporations to engage in proactive cyberattacks against criminal hackers. White House officials contend this strategy will help combat digital threats like ransomware, though former officials and security experts warn the move could trigger widespread instability.
A national security memorandum signed by President Trump late Wednesday outlines a framework where vetted companies work alongside the Department of Justice and the Department of Homeland Security to strike foreign cybercriminal syndicates. These operations are authorized to include surveillance of criminal networks and specific hacking maneuvers intended to disrupt, manipulate, or destroy information systems and networks, covering both physical and virtual infrastructure.
This policy represents a significant departure from decades of bipartisan cybersecurity doctrine, which typically focused on bolstering corporate defenses and restricting offensive cyber activities to military and intelligence agencies. The memorandum formalizes a shift that administration officials had previously signaled in general terms.
While the idea of involving the private sector in offensive cyber warfare has been discussed for years, it has never been officially endorsed by a U.S. president. Critics have long expressed concerns that such a policy could escalate cyber conflicts, create complex liability issues, and expose U.S. firms to international legal repercussions. The new memorandum does not fully resolve these concerns, though it asserts the policy aims to leverage “private sector ingenuity” to mitigate the escalating costs of cyberattacks.
To prevent unregulated digital warfare, the administration has established strict limitations. Participating companies must undergo a vetting process, enter into government contracts subject to $1 million fines for violations, and obtain written authorization from the Justice and Homeland Security Departments before launching any attack. The policy explicitly prohibits operations likely to cause loss of life, serious injury, or actions that constitute an “armed attack” under international law. However, experts note that precisely defining the boundaries of offensive cyber operations remains a significant challenge.
The White House declined to provide further details on the memorandum, stating only that all operations would be “based on intelligence.” No formal briefing was provided to the press prior to the order’s release.
Amanda Naylor, director of cyberpolicy at the National Security Council, noted in a LinkedIn post that the memorandum is designed to provide “new tools to protect Americans from cybercrime and fraud.”
Conversely, several former officials and security executives cautioned that the new approach could complicate the already volatile landscape of modern cyberwarfare. One former senior intelligence official suggested that approved private entities might eventually exercise authorities that exceed those of the government’s own security agencies.
The executive action includes a classified annex detailing procedures to ensure private-sector activities do not conflict with federal operations. The memorandum also specifies that targets must be transnational criminal organizations unaffiliated with foreign governments, unless intelligence proves otherwise.
Nick Carr, threat intelligence lead at Microsoft and a former cybersecurity official, expressed concerns regarding the difficulty of accurate attribution in criminal operations. While he noted that the order could potentially improve attribution efforts, he emphasized how few organizations—including government agencies—can consistently perform the task accurately.
The ambiguity of whether criminal groups, such as Russian-speaking syndicates, operate independently or as proxies for state intelligence services remains a major hurdle. Michael Garcia, former associate chief of policy at the Cybersecurity and Infrastructure Security Agency, noted that while attribution capabilities have grown, “obfuscation is still a hell of a tactic.”
Some former officials argued the order is a necessary response to an unsustainable surge in cyber threats, a problem expected to worsen with the advancement of artificial intelligence.
“The current pace of cyberoperations is unsustainable for just the military,” said Mieke Eoyang, a former Pentagon official who managed military cyberweaponry during the Biden administration.
Eoyang, currently a visiting professor at Carnegie Mellon University, suggested the policy’s effectiveness will depend on the rigor of the vetting and approval processes. She noted that existing military protocols, though “onerous,” were designed to carefully weigh collateral damage and deconfliction.
This directive moves the United States closer to the models used by adversaries like China and Russia, where state intelligence agencies frequently utilize private-sector contract hackers to maintain plausible deniability. While U.S. defense firms currently support the NSA and U.S. Cyber Command, their role is generally limited to providing tools and intelligence rather than direct operational engagement.
Dakota Cary, an expert on China’s hacking ecosystem, observed that while Beijing has historically adapted cybersecurity policies from the U.S., this new American policy represents a reversal of that trend.
“In many ways, China’s hacking prowess now stems from the fact that they copied our education system,” said Mr. Cary, an adviser at SentinelOne. “Now it seems the U.S. is interested in copying China’s system for deputizing private-sector hackers.”
Due to the inherent complexities, it remains unclear which companies will join the program, as legal experts warn of significant risks.
“This approach presents novel questions for publicly traded companies: Even if they engage in ‘hack back’ activities under government direction, how will they manage the increased operational risk to their business and customers, and how and when will they disclose it?” said Vanessa Le, a partner at Latham & Watkins specializing in geopolitical risk.
Also Read
- Key Analyst Moves of the Day: Upgrades and Reiterations for Microsoft, Cava, American Bitcoin, Sylvamo, Tesla, SpaceX, Union Pacific, Alvotech, AB InBev, Paychex, Rocket Pharmaceuticals, Meta, Creditcorp, Apple, Chevron, Similarweb, BP, Nvidia, Marvell, Broadcom and Micron
- Former Philippine President Returns to ICC for Historic In-Person Appearance
- UK Armed Forces Entry Medical and Employment Standards
- U.S. Officials Held Talks With Houthis in Oman as Red Sea Tensions Escalate, Sources Say

