Trump administration to let private firms carry out cyberattacks abroad
The Trump administration has launched a program allowing private companies, under federal oversight, to conduct cyberattacks against foreign criminal networks. Experts warn of significant legal and geopolitical risks.

The Trump administration has launched a new program permitting private companies to carry out cyberattacks against foreign criminal groups, according to a presidential memorandum published Wednesday and first reported by Bloomberg.
Under the program, private firms will operate "under the control and oversight" of the federal government, granting them permission to surveil and disrupt criminal networks. The Department of Justice and the Department of Homeland Security will oversee participating companies, which must meet requirements covering technical proficiency, a proven track record in cyber operations, and facility security. Firms must also hold a bond or escrow of at least $1 million, which they forfeit if they fail to comply with their contractual obligations.
The memorandum specifies that private firms may only target groups that are not an official part of a foreign government or entirely directed by one. It describes the private sector as an "underutilized" resource in the fight against cybercrime, stating it is US policy to use all instruments of national power, including private-sector capabilities, to combat it.
Experts flag risks
As Cybersecurity Dive has pointed out, it can be difficult to determine whether a criminal group is affiliated with a foreign government, potentially exposing cybersecurity firms to geopolitical or legal disputes. Jason Healey, a senior cyber conflict researcher at Columbia University, said anyone conducting these operations faces substantial personal legal risk, while Jake Williams of Hunter Strategy noted that Americans involved could be classified as non-uniformed combatants while traveling overseas. Ben Bernstein of Huntress added that attackers rarely operate from clearly identifiable servers, often routing traffic through compromised innocent infrastructure such as small businesses or hospital networks, making retaliation without harming bystanders practically impossible.
The US government previously conducted its own cyber operations without relying on third parties. Trump began developing plans to involve private cybersecurity firms last year, Bloomberg reported.


