JAKARTA - The United States government will for the first time allow private companies that have passed the selection to carry out offensive cyber operations against international criminal groups and hackers.

TechCrunch quoted Thursday, August 13, saying the policy was contained in a memorandum by President Donald Trump. The US government wants to use the private sector's ability to fight ransomware, financial fraud, to sextortion or extortion using sexual material.

Ransomware is an attack that locks or takes control of the victim's data and systems, then usually followed by a ransom demand.

Companies that enter the program can conduct surveillance to collect information, including using spyware or spy software. They can also carry out operations to disrupt or destroy data and systems belonging to the criminal groups targeted.

The policy changes the US government's position so far. Under federal law on computer hacking, private companies are generally prohibited from carrying out cyber attacks or disruption operations without court-granted approval.

Previously, the private sector could defend its systems from attacks, but not run cyberattack operations itself.

Even though the new policy has been set, the program is still in the early stages. The government has not completed all the rules for its implementation.

Guidelines for participating companies will be published in two months. Both large and small companies can be considered, including companies that have special capabilities for certain operations.

Each participant is required to place 1 million US dollars in an escrow account or a holding account. The funds can be seized if the company violates government rules.

Each operation must also receive approval from representatives of the US Department of Justice and the Department of Homeland Security. Its implementation can only be carried out under the supervision of the federal government.

The memorandum also requests that procedures be made so that operations do not target US citizens or systems located in the United States.

Participating companies are required to report if they know of a cyber attack that immediately threatens critical US infrastructure, such as the electricity grid and water providers.

However, the policy does not give companies the freedom to hack back or attack hackers through their systems whenever they face cyber threats.

TechCrunch has asked the White House whether any private companies have joined the program. A White House spokesperson did not respond and only referred to the government fact sheet.

The policy is expected to face legal challenges. Critics have also warned that the involvement of private companies could trigger diplomatic problems if foreign governments consider their territory or systems to be the target of US companies.

Jake Williams, vice president of research and development at cybersecurity firm Hunter Strategy, said US citizens involved in such operations could also face risks when traveling abroad.

"Americans involved in these operations can easily be classified as non-uniformed combatants when traveling abroad," Williams told TechCrunch.

He called the policy "half-baked". Williams judged that the secret annex to the memorandum might answer some questions about the selection of targets, but had not convinced him that the program would not be abused.

The Trump administration said the new policy was created as cyber threats to US citizens and companies increased. At the same time, the government has also cut and laid off federal cybersecurity employees since January 2025.

A number of states, including Michigan, Minnesota, and Georgia, have recently reported intrusions into water provider systems. US intelligence officials are reportedly linking the attacks to hackers backed by the Iranian government.

Cyber threats are also evolving in terms of technology. Anthropic, OpenAI, Meta, and the UK AI Safety Institute reported that the advanced AI models they tested were able to penetrate technical restrictions and carry out cyber attacks.


The English, Chinese, Japanese, Arabic, and French versions are automatically generated by the AI. So there may still be inaccuracies in translating, please always see Indonesian as our main language. (system supported by DigitalSiber.id)

Add VOI as a Preferred Source
Follow VOI news updates across Google.
+