The Trump administration is launching a new program that will allow private firms to perform cyberattacks against foreign criminals, as reported earlier by Bloomberg. The private firms would operate “under the control and oversight” of the federal government, giving them permission to surveil and disrupt criminal networks, according to a presidential memorandum published on Wednesday.
The Department of Justice and Department of Homeland Security will oversee the private firms, which must meet requirements in “technical proficiency, proven performance of cyber operations, facility security,” and more. Companies in the program must hold a bond or escrow of at least $1 million that they’ll forfeit if they don’t comply with their contractual agreement. The memorandum also says private firms will only hack groups that are “not an institutional part of a foreign government or wholly operated under a foreign government’s direction.”
The memo describes private businesses as “underutilized” forces for fighting criminal networks. “It is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime,” it says.
But as pointed out by Cybersecurity Dive, it can be difficult to identify which criminal groups are affiliated with foreign governments, which could put cybersecurity firms at risk of stoking geopolitical or legal conflicts. Jason Healey, a senior cyber conflict researcher at Columbia University, tells Cybersecurity Dive that “Anyone conducting these operations is doing so at substantial personal legal risk.” Jake Williams, the vice president of research and development at Hunter Strategy, similarly tells TechCrunch that “Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas.”
Ben Bernstein, a manager for the cybersecurity advisors team at Huntress, also raises concerns about how this program will play out. “Threat actors don’t launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network,” Bernstein says. “That makes it practically impossible to ‘strike back’ without taking out innocent bystanders.”
The US government previously carried out its own cyber operations, rather than relying on third parties. President Donald Trump began making plans to get private cybersecurity companies involved last year, Bloomberg reported.
Read the full article here
