A recently signed presidential memorandum aims to enlist private sector companies in federal law enforcement hacking operations against transnational criminal organizations, a move that has sparked debate among cybersecurity experts regarding its legal, practical, and ethical implications. The directive, which sets a 60-day timeframe for establishing the program, represents a significant shift in U.S. cyber policy.
Supporters of the memo, including those within the former Trump administration, view it as an essential step to enhance the nation's capabilities in cyberspace. Amanda Naylor, former director of cyber policy at the National Security Council, stated that the memo is designed to leverage the private sector's speed and innovation in combating transnational cybercrime and fraud. Joshua Steinman, a former Trump White House cybersecurity official, suggested it would help the U.S. achieve parity with adversaries who operate with fewer restrictions in cyberspace, allowing for the pursuit of strategic objectives against criminal organizations.
However, critics express serious concerns, likening the memo to the historical practice of "letters of marque" that authorized privateers. Security consultant Davi Ottenheimer criticized the memo, highlighting that the practice of privateering was abandoned due to the violence and mercenarism it fostered. He also raised concerns about the targeting of individuals or groups designated as "criminals," fearing potential misuse of such broad authority.
The memo mandates the establishment of legal and constitutional procedures for approving the targeting of U.S. citizens and developing methods to prevent unintentional targeting of U.S. persons or systems. Despite these provisions, Ottenheimer argued that limiting operations to "criminals" could create perverse incentives for attackers and complicate defenses, potentially allowing targets to halt operations by claiming state affiliation. He also pointed out the lack of notification for individuals being designated as targets, raising ethical questions about due process.
Michael Garcia, a former CISA official, acknowledged some positive aspects of the memo but expressed significant worries about its execution, particularly regarding attribution. He cautioned that pressure for faster attribution could lead to lower certainty about targets, potentially resulting in private companies accidentally attacking foreign governments. Garcia also questioned the legality of private citizens engaging in such operations, noting that the Constitution grants the federal government the sole authority to wage war. He suggested that court oversight, similar to that required for private sector takedown operations, should be included.
Another point of contention is the willingness of companies to participate. Garcia wondered if the legal risks involved would deter a large pool of companies, especially given uncertainties about government protections. Robert Graham, CEO of Errata Security, noted that while the program involves federal supervision, there's a risk it could evolve into law enforcement delegating more autonomy to private companies.
The memo's classified annex and the fate of any seized assets remain unclear, according to both Graham and Ari Redbord, global head of policy at TRM Labs. Redbord, while generally supportive of the memo as a transformative step to combine private sector data with public sector authorities against rapidly evolving AI-driven scams, also raised questions about the specifics of government direction and control during live operations and how disruption efforts would unfold.
Ultimately, the success and implications of this new policy will largely depend on the details established within the 60-day implementation period, which will define the operational framework, legal safeguards, and oversight mechanisms for private sector involvement in offensive cyber operations.






