The Trump administration will let private companies hack foreign criminal organizations as part of a new program that could expand the U.S. government’s ability to disrupt those groups’ cybercrime activities, while also introducing myriad legal challenges and perils.
President Donald Trump late Wednesday issued a memorandum directing the departments of Justice and Homeland Security to create a program allowing vetted companies to hack into criminal groups to spy on them or sabotage their operations. Trump said the program would help the U.S. combat cybercrime schemes that cost the nation tens of billions of dollars annually.
The new policy represents a dramatic expansion of the private sector’s role in offensive cyber operations against U.S. adversaries and significantly blurs the line between the government’s foreign policy activities and businesses’ commercial activities. And while the program focuses on criminal gangs, not nation-states, it marks the largest step that the U.S. government has ever taken toward a world of corporations “hacking back” against foreign governments on behalf of the U.S.
Many cybersecurity experts have sharply criticized the hack-back concept, saying it creates unacceptable escalation risks and could expose private companies to the kind of foreign military retaliation previously reserved for government personnel. But the Trump administration has embraced aggressive measures for confronting transnational criminal groups, evincing less concern about potential collateral damage.
When the topic of hacking back came up at the Black Hat USA cybersecurity conference in Las Vegas last week, a DHS official did not dismiss the concept. “Our long-term goal is to terrify those who would target Americans, such that they know we’re actually the worst target in the world, because we will mess you up,” said Joseph Alm, the assistant secretary of homeland security for cyber, infrastructure, risk and resilience.
The new program comes with several restrictions meant to limit the potential for unintended consequences. Co-executive directors from DOJ and DHS will review every proposed operation and provide written approval of the ones the government green-lights. Participating companies will have to meet certain requirements, such as technical competency and personnel vetting, and set aside bonds of at least $1 million that they would forfeit if they violated the program’s rules.
Trump’s memorandum also says that the program’s leaders cannot authorize surveillance or disruption operations that would kill or seriously injure people or constitute the use of force or an armed attack under international law.
The White House gave DHS and DOJ 60 days to establish operating procedures for the program, including standards for companies’ participation, procedures for deconflicting operations with the military and the intelligence community and requirements for participants to report useful information that they acquire about criminal gangs’ activities.
The memorandum says the program should ensure “participation by both large companies, which provide critical capacity, and smaller, more agile companies, which may be better suited for specialized or discrete tasks.”
“American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace,” Trump said in the memorandum. “By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter [transnational criminal organization] threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.”
Major legal question marks
The new private hacking program is rife with potential risks for participating businesses, the U.S. government and American society.
The memorandum requires the operating procedures to address some of those risks. Companies will be required to stop and alert the government if they accidentally target a U.S. person or information system, and DOJ must ensure that any hacking operations aimed at U.S. persons or otherwise raising constitutional or legal questions follow applicable laws, including judicial authorizations.
But other questions could remain unresolved until specific incidents raise them. Criminal organizations often steal data from U.S. businesses; it is unclear what would happen if a company participating in the hacking program came across that sensitive data during an operation against a criminal gang.
And while the memorandum addresses deconfliction with the military and the intelligence community, that coordination is likely to be difficult, given the classified nature of the government’s own hacking operations. Military and intelligence officials would be reluctant to share even limited information about their activities with private companies, even in the interest of warning them not to tread on the same ground.
In addition, it is unclear how rigorously the U.S. government will vet participating companies, a crucial question given the sensitivity of the information and authorities with which they will be entrusted. A select few defense contractors already assist the government with hacking operations, but the vast majority of businesses, even in the defense industry, have no direct experience with such activities.
It is also unclear how carefully the U.S. will vet companies’ targets, including to verify that they are truly unaffiliated with foreign governments. Some self-proclaimed independent hacker teams are widely considered to be fronts for their governments, including the Iran-linked Handala group, while others, such as the Russia-linked Evil Corp, have close ties to their countries’ governments and have occasionally received support from them. A poorly vetted operation that accidentally targets foreign government employees or infrastructure could create a geopolitical crisis and put the responsible company in the crosshairs of a powerful adversary.
The memorandum says companies can only hack a foreign criminal group that “is not an institutional part of a foreign government or wholly operated under a foreign government’s direction,” but it also says that a criminal group will be assumed not to meet those conditions “unless clear intelligence exists establishing such connection.”
It remains to be seen how many companies will be eager to participate in the program, despite its many risks. Given the secrecy of the operations, companies likely will not be able to advertise their work, meaning that the only benefit they receive will be a government payment for their services.