Hacking Back Is Back: White House to Enable Cyber Privateers | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


It’s happened: After many years of debating the pros and cons of whether “hacking back” would become the law of the land, we now have a decision and a new, formal direction.

Specifically, whitehouse.gov announced that President Donald J. Trump Expands Capabilities to Combat Transnational Cyber-Enabled Crime:

“THWARTING CYBER CRIMES: Today, President Donald J. Trump signed a National Security Presidential Memorandum (NSPM) empowering U.S. Federal law enforcement to use cyber tools to disrupt transnational criminal organizations (TCOs) that operate in foreign jurisdictions to attack Americans. 

  • The NSPM directs the Homeland Security Task Force’s National Coordination Center (NCC) to create a program to conduct specific cyber operations that disrupt foreign TCOs, with two Executive Directors from the Department of Justice and the Department of Homeland Security.   
  • The NSPM directs the NCC to leverage the capability and innovation of the private sector to help conduct these cyber operations under the direction, control, and authority of the U.S. Government.
  • The NSPM establishes a framework where private sector companies that willingly participate in the program are encouraged to enter into agreements with other private entities as well Federal, State, Local, Tribal, and Territorial agencies to gather TCO threat information and propose cyber operations that address those threats.
  • The NSPM directs the Program’s Executive Directors and the Homeland Security Council to create rigorous procedures for the review and conduct of these limited cyber operations at the direction of the U.S. Government, ensuring strict compliance with the U.S. Constitution and laws, as well as applicable international agreements.”

HISTORY OF THE HACK-BACK DEBATE

For some context, this blog has been covering this “hack back” debate for more than a decade, when it became a hot topic before the first Trump administration. Policymakers and international experts have been exploring this decision for more than two decades.

Here is some of my earlier coverage:

2016: Can ‘Hacking Back’ Be An Effective Cyber Answer? — With the exponential growth in data breaches over the past few years, the concept of “hacking back” is growing in popularity. Proponents ask: If I can use a gun for self-defense in my home, why can’t I similarly “hack back” against attackers who invade my cyberspace? Let’s examine that premise from different perspectives.

2017: Hack Back Law: Why the Future May Be Like the Legalization of Marijuana — Hacking back has been in the news a lot in 2017, with new proposed legislation that would legalize forms of a more “active defense” for companies. When added to the flurry of ‘hack back’ activity that is below the public radar right now, it seems likely that some form of legalization is inevitable.

2020: Should Government IT Be Hiring Hackers — and Pirates? — When filling out cybersecurity teams, character, passion and diversity top experience, and hiring a technologist who thinks outside the box could be a better move than opting for a government security veteran.

2025: Cyber Privateers: The Return of the Hack-Back Debate — Is the second Trump administration open to private-sector companies — or nonmilitary or other government agencies — using offensive security against cyber threats?

In that last article from 2025, I also highlighted a quote that told me (and many other cyber experts) that this was coming soon when the industry was ready. Several media sources reported headlines like this one:

“Google is getting ready to ‘hack back’ as US considers shifting from cyber defense to offense.” Here’s an excerpt:

“Google Threat Intelligence Group vice president Sandra Joyce recently revealed that the company is planning to form a ‘disruption unit’ in the coming months. ‘What we’re doing in the Google Threat Intelligence Group is intelligence-led proactive identification of opportunities where we can actually take down some type of campaign or operation,’ Joyce said. ‘We have to get from a reactive position to a proactive one … if we’re going to make a difference right now.”

THE CURRENT POLICY ANNOUNCEMENT

So what is the wider cyber and technology media world saying about this? Here are some helpful examples. (I urge you to go and read the full articles.)

Gizmodo: Trump Admin Lets the Cyber Pirates Loose

“‘The White House will give cybersecurity firms permission to conduct “offensive cyber operations aimed at disrupting criminal organizations,’ Bloomberg reported on Thursday.

“Trump’s administration has spent months waffling on the idea, which is substantially similar to the centuries-old practice of issuing letters of marque. That’s a type of document from the Age of Sail which extended official protections to private vessels to attack pirates and enemy vessels, a legal (depending on who you ask) and regulated form of piracy known as privateering.”

CNN: ‘Cyber privateers’: Trump issues order allowing US companies to hack overseas groups under certain conditions

“The Trump administration is enlisting private companies to conduct cyberattacks on foreign cybercriminals in a major policy shift that experts say could come with legal risk for the companies.

“The move gives vetted companies a prominent role in hacking operations that have historically been the dominion of US law enforcement, spy and military agencies.

“Companies can use cyber tools to surveil foreign criminals and disrupt their networks under the ‘control and oversight’ of the new federal program, according to a memo issued Wednesday by President Donald Trump.

“The program’s goal is to punish foreign criminal groups that cause Americans billions of dollars in annual losses. The program’s remit is foreign criminal groups, not governments.”

FINAL THOUGHTS

More than a decade ago I wrote: “I believe that new approaches will emerge over the coming decade, which may change the playing field in cyberspace. I’m not exactly sure how we will solve the difficulties, but I have a strong feeling that this ‘hacking back’ topic is just beginning to heat up.”

In my opinion, this decision was inevitable, especially with the challenge of being “outgunned 50-to-1” on cyber by China. Why? Because the U.S. needs to get more experts into the game using new AI tools to help fight cybercrime. Those resources are available now in the private sector and want to help.

To be clear, this new policy forbids the private sector from hacking nation-states, and this only includes offensive hacking against cyber criminals. The details are still being worked out, but we must understand that these attribution lines can get blurry, especially when nation-state actors like North Korea engage in scams and deepfakes. Whether this new approach will work or not (or cause even more cyber issues) remains to be seen.

Nevertheless, I encourage you to read my previous articles on the topic to understand the numerous benefits as well as serious concerns that arise with taking this policy step. There will be difficulty with attribution and “opening Pandora’s box” regarding authorization, management, command and control, and more.

I am sure we will be revisiting this topic in the months and years ahead.





Click Here For The Original Source.

——————————————————–

..........

.

.