Tag: offensive cyber operations

  • Hack-Back Memo Puts State Hackers Out of Scope, Despite Attacks on 45 Water Systems

    Hack-Back Memo Puts State Hackers Out of Scope, Despite Attacks on 45 Water Systems

    TL;DR · 30-second read

    The Short Version

    The American government will now let approved private companies break into, and even wreck, computers run by foreign criminal hacking gangs. In March, officials said they would not do this.

    Each company must set aside at least $1 million, which it loses if it breaks the rules. Every attack needs written approval from the Justice Department and Homeland Security.

    The catch: hackers working directly for a foreign government are off-limits. That matters because the order came after suspected Iranian attacks on water suppliers in 45 American towns.

    Tom’s Hardware reported that President Donald Trump signed a presidential memorandum on August 12 creating the first US program that lets vetted private companies conduct offensive cyber operations against foreign cybercrime organizations. These include operations that destroy data and systems. Participating firms must post at least $1 million in escrow, which they forfeit if they break program rules. Every operation needs written approval from Department of Justice and Department of Homeland Security officials.

    A National Coordination Center will run the program. Implementation guidance is due within 60 days. The policy reverses public statements administration officials made in March.

    Executive Summary

    The memorandum authorizes two kinds of activity. “Cyber Surveillance Operations” means getting into foreign systems without permission to gather intelligence while staying undetected. “Cyber Effects Operations” means disrupting or destroying those systems and their data. Both large firms and smaller specialists will be eligible. Participants may also sign commercial deals with other private firms and with state and local agencies to receive threat data and propose operations based on it.

    This matters for two reasons. First, it turns offensive cyber activity, long treated as a government monopoly in the US, into something a licensed private sector can do under supervision. Second, its target definition is narrow. A group qualifies as a target unless “clear intelligence exists” that it is part of a foreign government or wholly run at a government’s direction. So the program is aimed at criminal ransomware crews, not at the state-directed actors behind many attacks on physical infrastructure. For operators of water, power and data center infrastructure, that distinction shapes what the program can and cannot do for them.

    The Target Line Runs Straight Through Critical Infrastructure

    The memo arrived after suspected Iranian cyberattacks on water suppliers in 45 US municipalities. It also followed a CISA alert about Iranian hackers targeting programmable logic controllers (PLCs), the small industrial computers that open valves, run pumps and switch equipment at water and energy companies. Yet state-directed hackers fall outside the program’s own definition of a valid target. Private operators could go after a ransomware crew that encrypts a utility’s billing systems. They could not go after a government-run unit tampering with its treatment-plant controllers.

    The line is drawn deliberately. Ransomware crews that operate with a state’s tolerance but not under its formal control stay within scope, a description that fits much of the Russia-based ransomware ecosystem. Once an actor is clearly an arm of a foreign state, the matter stays with government. For utility and industrial security teams, the practical conclusion is that nothing changes for defending operational technology against nation-state intrusion. Segmentation, monitoring and incident response for control systems remain their responsibility. The new program targets the financially motivated threat, not the geopolitical one.

    There is also an ambiguity problem. Eligibility turns on whether “clear intelligence” ties a group to a government, and in practice attribution is often contested and slow. A group judged criminal today may later prove to have state links. That question will matter a great deal to any firm whose operation lands on the wrong side of the line.

    A $1 Million Bond on a Destructive Capability

    The escrow requirement is the program’s main economic control. A minimum of $1 million, forfeited for rule-breaking, is a meaningful commitment for a small specialist firm. Whether it is proportionate to the harm a destructive operation could cause is a separate question. Wiping servers that turn out to be shared with innocent third parties could produce losses well above that figure. The minimum works as a deterrent and an entry filter. It is not obviously a compensation fund.

    The commercial provisions may matter more for the market’s shape. Participants can contract with other private firms and with state and local agencies, receive threat data and propose operations based on it. That creates a potential new service line for security vendors: selling disruption, not just detection. Two background facts point the same way. Congress earmarked $1 billion for offensive cyber operations in last year’s spending bill. Google said in August last year that it was preparing to take part in disruptive actions against cybercriminals. Large platform companies with deep telemetry into criminal infrastructure look like natural participants. Smaller firms may compete on specialized tasks, as the eligibility rules anticipate.

    Escalation, Legal Exposure and a Classified Annex

    DOJ and DHS officials cannot approve operations likely to cause loss of life or amount to an armed attack under international law. The memo does not prohibit such operations outright, however. Approval authority for them sits in a classified annex. Companies weighing participation, and the public, therefore cannot see the full rulebook for the highest-risk cases.

    Personnel face exposure too. Jake Williams, vice president of research and development at Hunter Strategy, told TechCrunch that Americans involved in these operations “could easily be classified as non-uniformed combatants while traveling overseas.” That is a risk that falls on individual employees, not only on their employers, and firms will need to account for it in staffing, travel policy and insurance.

    The speed of the reversal adds uncertainty. In March, Thomas Lind, then a senior adviser at the Office of the National Cyber Director, said the administration had no plans to authorize private offensive operations: “We’re not interested in fighting pirates with pirates.” National Cyber Director Sean Cairncross said the same week that companies running offensive campaigns were not what the administration meant when it asked industry for help. A policy that changed direction within months could change again, which makes long-term investment in offensive capability a harder bet.

    Collateral Risk Is Written Into the Rules

    The memo requires any company that unintentionally hits a US person or a system on US soil to halt operations and notify the government immediately. That clause concedes that operations aimed abroad can land at home. Criminal groups commonly route activity through rented servers and compromised machines owned by unrelated parties. Hosting providers, cloud platforms and data center operators therefore have a direct interest in how approvals weigh that possibility, and in how quickly they would be told if their infrastructure were affected.

    Defenders more broadly face a quieter risk: retaliation. A criminal group whose systems are destroyed by a US firm may not distinguish between that firm and US targets generally. The memo’s safeguards govern how operations are approved. They do not change who absorbs the response.

    Background

    For decades, US law and policy have treated breaking into someone else’s computer as illegal, even when that someone is an attacker. Offensive cyber operations have been reserved for government agencies such as the military and intelligence community. Proposals to let private victims “hack back,” including the Active Cyber Defense Certainty Act introduced in Congress in 2017, never became law. Critics warned of misattribution, collateral damage and escalation.

    Pressure grew as ransomware crews, many operating from jurisdictions beyond the reach of US law enforcement, hit hospitals, pipelines and municipalities. Some large technology firms have already worked with authorities to take down criminal infrastructure, and Google said last year it was preparing to take part in disruptive actions. The August 12 memorandum is the first formal framework for private firms to go further, under federal supervision.

    Sources

    Source: White House authorizes private companies to launch ‘hack-back’ cyberattacks that destroy data and systems, targeting foreign cybercrime organizations. Tom’s Hardware on the August 12 presidential memorandum creating a supervised private offensive cyber program.