Trump opens the door for US companies to hack back at foreign cybercriminals; experts warn of legal risks.

Trump has issued a new executive order allowing selected private companies to conduct cyber operations to monitor and disrupt foreign criminal networks. Experts are concerned that these companies could face mishaps and legal liability.
On August 14, 2569 at 05.15:XNUMX p.m., CNN reported that The Trump administration is moving forward with a major shift in cybersecurity policy, allowing selected private companies to conduct cyber operations against foreign criminal groups under federal government conditions and oversight. This marks a step in bringing the private sector into missions that were historically largely the responsibility of law enforcement agencies, intelligence units, and the U.S. military.
According to an order issued by President Trump on Wednesday, vetted and licensed companies will be able to use cyber tools to monitor foreign criminals and disrupt their networks under the control and oversight of a new federal government program.
The primary goal of the project is to address foreign criminal groups that cause billions of dollars in damage to American citizens annually. The scope of the project focuses on foreign criminal organizations, not foreign governments.
The order states that the innovative capabilities of the American business sector have not been fully utilized in past efforts to discover and disrupt criminal networks operating in cyberspace.
This approach represents a significant shift, as the U.S. already has government agencies conducting cyber operations against foreign targets. Adding private companies could therefore enhance its ability to combat the rapidly expanding cybercrime landscape.
Cynthia Kaiser, a former senior cyber officer of the FBI. The view is that allowing the private sector to help deal with cybercriminals would enable the U.S. to better contain these groups, while simultaneously allowing agencies like the FBI and US Cyber Command to dedicate resources to threats from foreign states, such as China.
before Christopher Wray, former director of the FBI. It has been stated that the number of hackers supported by the Chinese government far exceeds the number of FBI cyber personnel by a ratio of 50 to 1.
However, Kaiser cautioned that the details of the program will be a key factor, with interested companies needing clarity on legal liability protections, forms of government oversight, and how foreign criminals might use infrastructure based in the United States.
While the program will empower the U.S. government, some experts worry that allowing private companies to conduct proactive operations could further complicate cyber coordination.
Andrew Schoka, a former US Cyber Command officer. Warnings have been issued about the risk of the emergence of numerous "Cyber Privateers," or private forces operating in cyberspace, conducting operations without coordination or clear direction from the federal government.
He stated that avoiding overlapping or interfering with cyber operations across different agencies is already a challenge for governments, and adding private companies with their superior capabilities and speed could further complicate the situation.
Another significant risk is damage to individuals or systems unrelated to the target.
Chris “Weld Pond” Wysopal, co-founder of cybersecurity company Veracode. I think that Government projects might be a more systematic way to deal with "hackback" problems than letting individuals or organizations do it themselves, but there are concerns about the consequences if government-approved operations go wrong.
For example, if a private company attacks a data center overseas to dismantle a criminal network, other systems using the same data center, such as hospitals, could be unintentionally affected.
Furthermore, foreign governments may view employees of companies participating in the program as being involved in U.S. cyber operations and could become targets of detention or investigation when traveling abroad.
The concern is that the legal burden will fall on the company.
The U.S. Department of Justice (DOJ) and the Department of Homeland Security (DHS) will oversee the program. Any operation targeting a United States person will be subject to additional legal review, including by the Department of Justice.
however Jason Kikta, a former US Cyber Command officer. It should be noted that the memorandum of understanding does not yet establish sufficiently clear oversight and verification processes to ensure that cyber operations do not violate the civil liberties of American citizens.
Kikta states that there are no clear oversight or review procedures for political officials' decisions, even though its operations remain under the authority of the DOJ and DHS.
The key issue, therefore, is who will be held responsible if the operation goes wrong, as experts believe this new order may directly shift a significant amount of legal liability to the private companies participating in the project.
refer : edition.cnn.com
































