Skip to content

The US has allowed private firms to carry out cyberattacks abroad: a one million dollar deposit is the entire guarantee they will not go too far

1 min read
Share
The US has allowed private firms to carry out cyberattacks abroad: a one million dollar deposit is the entire guarantee they will not go too far

For the first time the US government will allow vetted private companies to carry out offensive cyber operations - spying, planting spyware and destroying other people's data and systems. The targets are international criminal groups and hackers. The decision was published in a presidential memorandum on Wednesday.

The US position until now, across several administrations, was simple: the private sector may defend but may not attack. American computer crime laws apply to companies exactly as they do to any citizen, and attacking without a court order is a criminal offence. With one signature, that wall came down.

A million dollar deposit as a guarantee of good behaviour

The mechanism is as interesting as the decision. A company wanting to take part must post a one million dollar deposit, forfeited if the government finds it is not following the rules. Every operation requires a sign-off from the Justice Department and from Homeland Security. Americans and systems inside the US must not be targets. If a firm discovers that an attack on American critical infrastructure is coming - the power grid, the water supply - it is obliged to notify the government.

The guidelines on who is allowed in will come out in the next two months. The memorandum explicitly says firms of all sizes will be considered, including small ones - they are supposedly better suited to specialised operations. Read that again: a small private firm, with a million dollar deposit, licensed to break into foreign systems.

Who answers when it goes wrong

Jake Williams, an industry veteran and vice president for research and development at the cybersecurity firm Hunter Strategy, called the policy „half-baked”. His main objection is not technical but far more down to earth: „Americans participating in these operations could easily be classified as unlawful combatants while travelling abroad.”

And he adds something sharper still - the accusation does not even have to be true. The policy itself creates cover for any foreign government to accuse any American security specialist who falls into its hands. Precisely what American prosecutors have done for years with Chinese, Iranian and Russian state hackers can now come back the other way - only this time the person in the firing line will be an employee of a private company.

The memorandum does not permit „hacking back” on one's own initiative. But critics have warned for years about the same thing: when a private firm carries out an attack under state supervision, the foreign government hit by it does not see a firm - it sees a state. And it responds accordingly.

The context that explains the hurry

The administration gave no reason, mentioning only a „growing threat”. The reason is visible without an official explanation. More than ten American states, among them Michigan, Minnesota and Georgia, are reporting breaches of local water systems, which intelligence services unofficially attribute to hackers backed by the Iranian government. So far there has been no need to issue a water safety warning.

All of this comes after months of war between the US and Israel on one side and Iran on the other, in which Iran's supreme leader was killed. The Iranian military responded with missiles against Western-owned data centres and with cyberattacks actively disrupting American companies and infrastructure. At the same time, American federal cybersecurity agencies went through a wave of layoffs.

So: a state that cut its own security apparatus and is now opening it up to the private market. In the Balkans we know that model under a different name - when an institution has no capacity, the work is put „out”, and responsibility disperses until nobody can find it any more. The only difference is that here the external contractor gets a licence to break into systems in other countries.