A hooded man is depicted gripping a laptop computer, with cyber code projected onto him in this illustrative image — Reuters
The U.S. is set to permit private companies to hack foreign cybercriminal groups, a move that’s sparking debate among experts. This initiative, seemingly without precedent, could either succeed or lead to chaos.
On Wednesday, President Donald Trump issued a memorandum instructing the Justice and Homeland Security departments to authorize certain American companies to monitor and target international criminal organizations.
The White House justified this stance by highlighting the substantial damage caused by ransomware, sextortion, and online fraud, which reportedly cost Americans over $20 billion in 2025.
The directive allows private entities to take actions such as dismantling hackers’ servers or deploying spyware to infiltrate their systems. All operations will require prior government approval, and companies must post a security bond of at least $1 million.
Activities that could result in death or injury are off-limits, as are any actions that would constitute “use of force” under international law.
This approach resembles 18th-century privateering, where governments authorized private ships and sailors to raid enemy vessels. Ari Redbord, a former federal prosecutor now working at TRM Labs, explains, “The private sector controls the data, and the government holds the authority. This memorandum combines both.”
Redbord sees a historical parallel in maritime privateering, noting, “Back then, once a ship left port, oversight was impossible. Today, technology allows continuous oversight from start to finish.”
However, some experts express skepticism. University of Surrey cybersecurity professor Alan Woodward notes, “You can grant a commission, but obedience isn’t guaranteed. Historically, privateering was eventually considered problematic because it became more trouble than it was worth.”
The memo marks a change in the White House’s stance. Previously, a senior U.S. official in March suggested the U.S. wasn’t interested in fighting cybercriminals with cybercriminals. Still, within five months, the administration reversed course.
Columbia University researcher and former cybersecurity official Jason Healey sees some safeguards, stating, “They’re supporting this under the rule of law, so I don’t see it as reckless.” Yet, he cautions, “The current administration has systematically weakened agencies like the Office of the Director of National Intelligence that are supposed to oversee such actions.”
Major U.S. tech companies already invest heavily in cybersecurity. The new program could extend their capabilities, enabling operations without judicial oversight, relying solely on government approval. Microsoft declined to comment, and Google did not respond to requests for comment.
Redbord warns that companies engaging in government-sanctioned hacking could lose their neutrality and become targets themselves.
The White House has 60 days to finalize the program’s specifics, though some details will remain classified. Its ultimate success or failure remains uncertain.
Over time, Washington will need to weigh the program’s costs against potential benefits, such as the risk of misattributions, foreign prosecutions, and diplomatic issues, as Woodward points out.
Cybercrimes continue to grow despite these efforts. Redbord emphasizes that, ultimately, unless victims recover their funds, most of the other concerns are secondary.





