Trump Gives Green Light to U.S. Companies to Aim Hacks at Cybercriminals

The Trump administration is encouraging American companies to conduct their own cyberattacks against criminal hackers, a move that White House officials say will help address digital scourges like ransomware but that some former officials and security experts warn could lead to chaos.

Under a national security memorandum that President Trump signed late Wednesday, select companies would work with the Justice and Homeland Security Departments to strike foreign cybercriminal groups with hacks under certain conditions. The attacks would allow both surveillance of the criminal networks and specific types of hacking operations that could lead to disruption, manipulation or destruction of information systems and networks, including virtual and physical infrastructure.

It was not clear which companies, if any, would sign up, but the move is a sharp pivot from decades of cybersecurity policy across Republican and Democratic administrations that generally prioritized improving corporate defenses and confined offensive cyberoperations to the U.S. military and intelligence agencies. It adds detail to a shift that Trump officials had teased in general terms for months.

The concept of giving the private sector a more direct role in offensive cyberactions has been around for years. But it has never before been publicly endorsed by a presidential administration, in part because of concerns that doing so could provoke more cyberconflict, raise novel questions of liability and international legal exposure for U.S. firms, and have unforeseen — and potentially escalatory — consequences. The new memorandum does not directly address many of those concerns, though it states that the policy is meant to tap into the “ingenuity of the private sector” to stem the ever rising costs of cyberattacks.

Rather than permit a free-for-all on the digital battlefield, however, the conduct that U.S. companies can engage in is intended to be relatively circumscribed. Participating companies must first be vetted to be included in the program, sign a contract with the government that includes $1 million fines for violations, and receive written approval from officials at the Justice and Homeland Security Departments before proceeding with an attack. The policy will not authorize attacks that are likely to lead to loss of life, serious injury or “rise to the level of use of force or armed attack under international law,” though former officials and experts said precisely calibrating offensive cyberoperations is sometimes as much an art as a science.

The White House did not respond to questions about the memorandum other than to say operations would be “based on intelligence.” The Trump administration did not brief reporters on the order ahead of its release late Wednesday.

We are having trouble retrieving the article content.

Please enable JavaScript in your browser settings.


Thank you for your patience while we verify access. If you are in Reader mode please exit and log into your Times account, or subscribe for all of The Times.


Thank you for your patience while we verify access.

Already a subscriber? Log in.

Want all of The Times? Subscribe.

NYT

Related posts

Leave a Comment