Private security firms will soon be allowed to hack overseas cybercriminals





GOT DETAILS?

Private security firms will soon be allowed to hack overseas cybercriminals

Trump memo is first time gov’t has authorized private sector to perform cyber attacks.


Dan Goodin




|

8



Illustration of a skull on a digital background to represent a cyber attack


Credit:

Getty Images | cokada


Credit:

Getty Images | cokada




Story text








The Trump administration is recruiting private security firms to conduct federal government-authorized operations, including cyber attacks, against overseas-based criminal organizations that commit hacks on US persons, organizations, or government entities.

In a National Security Presidential Memorandum issued Thursday, US President Donald Trump directed the National Coordination Center (NCC), which operates under the Homeland Security Task Force, to develop a program for conducting specific cyber operations that combat foreign transnational criminal organizations (TCOs). The Departments of Justice and Homeland Security will provide oversight. The lynchpin of that program is bringing in private sector companies to participate.

Devil will be in the still-undefined details

A fact sheet that accompanied Thursday’s memo listed ransomware, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams as activities eligible for private-sector security firms to target. The memo said such firms could “conduct Cyber Surveillance Operations and Cyber Effects Operations” against “cyber-enabled” TCOs. Such groups are defined as “any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government’s direction.”

The new program is the first time the federal government will authorize private companies to conduct offensive cyber operations against overseas hackers. The memo appears to permit companies participating in the program to use spyware or launch offensive attacks intended to destroy TCO data or systems. The memo doesn’t rule out certain types of offensive attacks, such as those that use encryption to lock targets out of their networks or performing DDoSes. Up until now, the government has prohibited the private sector from taking such actions without court-authorized approval.

“There’s definitely merit in the idea of hacking ransomware groups and it does already in fact happen (don’t ask me how I know),” independent security researcher Kevin Beamont said in response to the memo. “But the correct incentives have gotta be there.”

He added: “The biggest problem I’ve had with fighting ransomware over the past 5 years is private cyber companies basically lobbying for nothing to change. A lot of companies have made a lot of money, so putting them in charge of stopping it seems optimistic.”

The memo placed specific limits on the scope of the new program. Private companies must first be approved after vetting by the Departments of Justice and Homeland Security. Cyber Effects Operations and Cyber Surveillance Operations may not result in “Critical Outcomes,” meaning those that result in the loss of life or serious injury or “rise to the level of use of force or armed attack under international law.” The memo also notes:

[M]inimum standards that Participating Companies must meet in order to take part in the Program, which shall include appropriate levels of technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors that the Program Executive Directors, in coordination with the Homeland Security Council, determine are relevant or necessary for guaranteeing high confidence in a Participating Company’s ability to perform successfully.

Participating companies must also deposit $1 million in an escrow account. The deposit will be forfeited “should the Participating Company enter non‑compliance with its contractual agreement described” in the memo.

Many of the specifics of the policy remain undefined. These details will be crucial to determining how effective and judicious the program will be. The memo directs the Justice and Homeland Security departments to deliver the particulars in the next 60 days.

Photo of Dan Goodin


Dan Goodin

Senior Security Editor
Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82.


8 Comments

Leer artículo original en Ars Technica