Spike News

Trump authorizes private companies for cyberattacks on foreign hackers

According to a report by The Washington Post on August 14th, U.S. President Donald Trump signed an order on Wednesday, authorizing some private companies to carry out cyberattacks against foreign hacker groups with government support. Previously, such actions were the exclusive domain of the U.S. National Security Agency.

This memorandum allows the U.S. government to contract with U.S. companies to infiltrate and disrupt the overseas digital networks belonging to “transnational criminal organizations that use computer technology to commit crimes”.

The memorandum stipulates that under the supervision of the federal government, these companies may infiltrate computer systems for monitoring purposes, and may manipulate or destroy digital or physical infrastructure that is controlled by information systems. However, they are not allowed to target foreign governments, nor should they take actions that result in “death” or “serious injury”.

This measure marks a significant change in the U.S. government's previous more cautious approach. Due to concerns about triggering geopolitical backlash, previous administrations had always prohibited companies that had been cyber-attacked from engaging in “hacker counterattacks” against the attackers’ systems. Now, the Trump administration wishes to mobilize the private sector to shift the battle to the side of criminal hackers.

The White House stated in a statement accompanying the memo: “President Trump is using all available tools to stop those organized criminal groups based abroad that harm Americans in the cyber space.”

Some analysts and industry executives have welcomed this move, believing it should help the U.S. government weaken the ability of foreign criminals to launch cyberattacks against Americans. Joe Lin, co-founder and CEO of a startup in northern Virginia that provides cyberattack software for the U.S. government, said, “Cyberattacks are cheap to launch, but defending against them is costly. The more we can use carefully selected commercial partners to disrupt our adversaries on a large scale, the weaker their ability to attack the United States becomes.”

Other experts have expressed concern that this approach may pose legal and geopolitical risks to both the US federal government and the companies involved.

Matt Curtis, who served as the Senior Director for White House Cyber Policy under the Biden administration, said, "What happens if a company takes action against targets it believes to be operated by Iranian or Russian criminal groups, but these groups are actually controlled, influenced, or protected by Tehran or Moscow?"

He said, “In this way, actions originally aimed at criminals could suddenly be seen as cyber operations authorized by the United States against a particular national entity… This could lead to retaliation or an escalation of the situation.”

This order also raises a question: whether companies involved may be held legally liable under the Computer Fraud and Abuse Act. This law defines unauthorized access to networked computers as a federal crime. Some analysts believe that if companies act as agents of the U.S. government, they may not be bound by this law. However, if they intend to infiltrate U.S. domestic computer systems, they must still comply with the protections provided by the Fourth Amendment of the U.S. Constitution, which requires a search warrant. This order does not address this issue directly.

Reporting has accused China and Russia of polluting water with their own allegations that the two countries often employ private enterprises for cyberattacks.

FBI Network Division Assistant Director Brett Leatherman cited a 2024 alleged cyber espionage attack supported by China referred to as "Salt Typhoon." The operation infiltrated several of the largest U.S. telecom companies and targeted the cellphones of American political figures as objectives.

Littman continued to accuse, saying, “It’s the people in the industry in China who do these things. If we don’t fix these loopholes… we will continue to fall behind.”

China's Foreign Ministry spokesman Lin Jian once pointed out that the real purpose of the United States in creating false narratives about online traceability is to frame and accuse China. Relevant reports clearly show who the greatest threat to global cyber security is.

China advises the US side to stop all irresponsible actions such as 'calling out thieves while they are still running away', to cease cyber attacks worldwide, and to stop using cybersecurity issues to slander and discredit China.