The US government has taken a significant step in its cybersecurity strategy by permitting private companies to execute cyberattacks on “transnational criminal organizations”. This move, formalized in a presidential memorandum signed by President Donald Trump, aims to harness the “capability and innovation of the private sector” to combat various cyber threats, including ransomware, sextortion, financial fraud, and phishing.
Legal Framework and Implications
Traditionally, the Computer Fraud and Abuse Act (CFAA) has governed the legal landscape surrounding hacking and unauthorized computer access. This law applies to both individuals and private companies. However, the new memorandum expands the Department of Justice’s (DOJ) discretion regarding prosecution. In 2022, the DOJ announced it would no longer pursue cases against white-hat hackers engaged in security research. The current memorandum broadens this leniency to include a wider range of cyber activities.
Operational Details Still Unclear
While the memorandum outlines the intent to leverage private sector capabilities, it lacks specific operational details. It instructs the Homeland Security Task Force to establish vetting standards for companies wishing to participate and to outline procedures for conducting cyberattacks. These details are expected to be finalized within the next 60 days.
Financial Requirements for Participation
Companies interested in engaging in this initiative must pay a $1 million bond, which will be forfeited if they fail to adhere to government directives. This requirement creates a financial incentive for compliance, but the memorandum does not clarify the legal ramifications for companies or their employees if they face criminal charges in the countries targeted by these cyberattacks.
Context of the Memorandum
The memorandum comes in response to a series of cyberattacks on water facilities in Minnesota and Michigan, which have been attributed to Iranian hackers. The US has previously charged foreign hackers, raising concerns about potential retaliatory legal actions against US-directed cyber operations.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








