The U.S. government’s top cybersecurity official on Tuesday defended the Trump administration’s plan to let private companies hack foreign cybercrime gangs, saying the new program would help the U.S. prevent cybercrime schemes that defraud Americans.
“We're not talking about letters of marque. We're not talking about the Wild West,” National Cyber Director Sean Cairncross said at a USTelecom event in Washington. “This is a very specific program, overseen by the government, to engage industry and allow us to scale our efforts to take some of these actors on.”
Cairncross’s remarks were some of the first from a senior government official about the initiative that President Donald Trump announced in August. Through the program, the departments of Justice and Homeland Security will vet proposals by private companies to disrupt foreign gangs’ computer systems and then provide oversight during the operations, including deconflicting with military and intelligence activities and ensuring compliance with U.S. laws.
Cybersecurity experts say it remains unclear whether the program will significantly expand the U.S.’s ability to disrupt cybercrime. Some businesses could see participation as a way to boost their chances of winning future contracts, while others might steer clear of the program for fear of unintended consequences, including retaliation from foreign governments accidentally targeted in operations.
On Tuesday, Cairncross said the government was looking for creative new ways to punish malicious hackers whose attacks cost Americans tens of billions of dollars every year.
“We need to … make clear that we are imposing costs on bad actors in this space,” said Cairncross, a former Republican political operative who took over the Office of the National Cyber Director in August 2025.
“Deterrence is a tricky concept in cyber,” Cairncross added, “but at the end of the day, if a man or a woman is making a decision to do some sort of harm to the United States, then they will respond to incentives, and we have a lot of different ways to incentivize or disincentivize behavior.”
Other strategies include enlisting new partners’ help in arresting cybercriminals, dismantling their computer infrastructure and cutting off their cryptocurrency funding, Cairncross said.
He pointed out that many scam victims are elderly Americans. “It's insane, and we’re sick of it.”
Message to industry: Back to basics
Cairncross also discussed the Trump administration’s efforts to protect critical infrastructure, including by partnering with frontier AI labs to deploy their vulnerability-hunting technology into poorly defended but vital utility networks.
“We have been working closely — and I believe it is functioning well — to get models deployed throughout sectors as quickly as possible,” he said.
But while AI has grabbed headlines, Cairncross said it wasn’t where infrastructure operators and other businesses should be focusing their attention. “It's not necessarily the newest, shiniest object that is the sole fix here.”
Instead, he urged companies to double down on patching or replacing legacy technology, especially end-of-life edge devices that frequently serve as attackers’ entry point into networks.
“The resources need to be dedicated to fixing those problems,” he said. “The bill for that has come due, and the interest is going to continue to pile on it until people address that.”
Cairncross specifically called on telecommunications companies to fix the glaring weaknesses that allowed Chinese government hackers to breach major telecoms as part of the Salt Typhoon espionage campaign.
“What I would like to see,” he said, “is an increased hardening of telecom networks to fight what is an ongoing and persistent effort to use our networks to listen in on what policymakers are doing.”
Regulatory update
With the Cybersecurity and Infrastructure Security Agency still finalizing its cyber incident reporting rule, Cairncross said the government was committed to making regulatory compliance easier for businesses that sometimes struggle to report incidents while still responding to them.
"There is a lot of attention going into … providing clarity to industry and harmonizing the reporting structure,” Cairncross said.
Companies are sometimes reluctant to report attacks because of liability fears, he added, which is something the administration is trying to address.
“We want to hear from industry where friction points exist,” he said, “and then we will go about knocking them down.”
Cairncross celebrated the “enormous amount” of collaboration between government and infrastructure operators on cybersecurity, but he warned that those partnerships would falter if Congress failed to reauthorize the soon-to-expire Cybersecurity Information Sharing Act. The Trump administration, he said, is “continuing to push” lawmakers to preserve the program.