A White House memorandum published on August 13 says vetted private companies will, for the first time, be allowed to run offensive cyber operations against international criminal groups. The stated targets are ransomware crews, financial-scam rings, and similar gangs that hit people and businesses. TechCrunch reported the change on the same day.
Until now, U.S. computer-crime law treated private firms like everyone else: they could defend their own networks, not break into someone else’s. The memo does not create a free-for-all “hack back.” Firms in the program would work only under federal supervision. Each operation would need sign-off from the Justice Department and the Department of Homeland Security. The text also says procedures must block operations against Americans or systems inside the United States. Participants would have to tell the government if they find an imminent attack on critical infrastructure such as power or water.
Entry is not cheap. A participating company must put $1 million in escrow and forfeit it if it breaks the rules. The government says it will publish the actual entry requirements within two months, and that smaller specialist shops as well as large vendors could apply.
The policy is still on paper. TechCrunch noted that no public list of participating firms exists yet, and that the change is likely to face legal challenges. Industry voices also warned that staff at those companies could be treated as combatants if another country objects. Guidance, not a live roster, is what exists today.
