Trump signs order letting vetted U.S. firms target foreign cybercrime groups
President Donald Trump approved a National Security Presidential Memorandum that authorizes selected private companies to conduct government-directed cyber operations against foreign criminal organizations.
In August, President Donald Trump signed a National Security Presidential Memorandum establishing a framework for private U.S. firms to carry out cyber missions on behalf of the federal government. The directive outlines two types of activities: secret surveillance of targeted computers to harvest intelligence, and "Cyber Effects" actions that can manipulate, block, degrade or destroy systems controlled by foreign criminal groups.
Companies must be approved by the Department of Justice or the Department of Homeland Security, meet strict vetting standards, and operate under written federal authorization. The program focuses on foreign transnational criminal organizations that conduct ransomware, phishing, fraud and impersonation attacks against Americans, while barring any groups tied to a foreign government. Safeguards require immediate cessation and reporting if an operation inadvertently affects a U.S. person or system, and prohibit actions that could cause loss of life or serious injury. Detailed operating rules are to be drafted within 60 days, with annual reviews and reporting requirements.
Why it matters
It gives the U.S. government a new tool to disrupt overseas cybercriminal networks, raising both security potential and oversight concerns.
In this story
