The Trump administration is poised to authorize private security firms to conduct federal-authorized cyberattacks against overseas criminal organizations that target US entities. The directive, through the National Coordination Center, will see companies like those in the cybersecurity sector involved in offensive operations targeting ransomware, sextortion and phishing schemes.
While the memo allows for 'Cyber Surveillance Operations' and 'Cyber Effects Operations', it's still unclear exactly how these firms can or cannot operate. The exact nature of what constitutes legitimate cyber-attack authorization remains to be defined.
The move marks a significant shift in US policy, allowing private companies to conduct offensive cyber operations without the need for court approval. This could mean anything from using spyware to launching distributed denial-of-service attacks, provided they target 'cyber-enabled' transnational criminal organizations.
For now, the devil is indeed in the details – and the legal and ethical implications of this new power remain to be seen.







