Trump gives private firms green light for cyberattacks | #cybercrime | #infosec


Donald Trump has signed a presidential memo that permits private US companies to carry out offensive cyber-attacks on foreign criminal organisations. 

The major policy shift directs federal agencies to unleash “the ingenuity of the private sector” and arrives as experts are warning of an escalation in attacks by cybercrime gangs linked to Russia. “Deputised” companies would be given permission to destroy hostile cyber networks and asked to post a $1m bond that would be forfeited if they went rogue.

“The US government is basically saying that there’s a protest outside the warehouse and it’s going to formally approve warehouse guards to act on behalf of the state to stop criminals and go after them in the street and attack them,” says Joseph Jarnecki, a research fellow at the Royal United Services Institute.

One Russian-speaking gang known as “Clop” claimed this week to have stolen large quantities of data from 50 multinational companies, including Shell and Philips. Both companies confirmed that they were investigating incidents, but played down the threat of large data theft.

A British defence and aerospace manufacturer that recently won a $62m (£46m) contract with Elon Musk’s SpaceX was also targeted by Russian cybercriminals.

Filtronic, a Sedgefield-based firm listed on London’s Aim index, was hit just over a week ago by hacker group Qilin. The group has previously claimed responsibility for an attack on the medical services provider Synnovis, leading to widespread disruption at NHS hospitals in June 2024.

A spokesperson for Filtronic confirmed the breach but said: “To date, no evidence has been identified that company, third party or employee data has been accessed, compromised or exfiltrated, and the business remains fully operational.”

On Friday shares in the company were up 43% year-to-date, buoyed by a renewed partnership with SpaceX and contracts with Airbus and Leonardo. Its latest earnings showed operating profit of £4m (down from £13.4m).

After attacks last year on major UK companies, including the Co-op Group and Jaguar Land Rover, firms are bolstering their cyber defences. Providers are benefitting handsomely: one basket of cybersecurity stocks has beaten the S&P 500 by roughly double since February. Trump’s memo could be a further boon, while also easing the capacity of federal agencies to neutralise threats. But it also comes with significant risks.

A recent report from security thinkthank the Royal United Services Institute that weighs the possibility of copying this “privateering” approach in the UK notes that “a clear distinction between organised cybercriminals and state actors does not always exist. This means that if a UK firm is deputised, there is a non-zero risk it could inadvertently impact a foreign state’s interests and become embroiled in geopolitical tension.”

Newsletters

Choose the newsletters you want to receive

For information about how The Observer protects your data, read our Privacy Policy

As boards and executives at larger firms tool up, hacker groups are targeting smaller firms in their supply chains. Manufacturers such as Filtronic are attractive targets due to the “downtime” caused by an attack.

“As soon as that production line stops, so does the revenue,” explains Matt Hull, vice-president of Cyber Intelligence and Response at NCC Group. “It’s useful for these threat actors to target that type of physical industry because they can leverage that quite powerfully.” 

Last week a report from Make UK, the manufacturing trade body, found 30% of members had experienced a cyber incident in the past 12 months.

Qilin has emerged this year as the most prolific “ransomware as a service” (RaaS) group on the dark web, claiming 1,454 attacks since July last year, double that of any other group. Fifty-five were in the UK.

Qilin charges an 85% commission for affiliated hacker groups to use its technology, which Hull notes “has likely attracted major gangs that were targeted by law enforcement”, such as Scattered Spider, the group that hacked M&S and Co-op. He notes Qilin has “primarily targeted organisations operating in Critical National Infrastructure and business services.” 

Incidents that appear on co-called leak sites are “the tip of the iceberg” says Aiden Sinnott, principal threat researcher at Sophos. “We can’t really know how many other companies out there have just paid the ransom and not been listed,” he says, adding that paying a ransom can often open up companies to further exploitation.

To what extent ransomware attacks are motivated purely by profit, as opposed to direction by hostile states, is hard to gauge. TRM Labs estimated that Russian-speaking ransomware groups accounted for 69% of all ransomware proceeds in 2024.

Photograph by Richard Baker/In Pictures via Getty Images



Click Here For The Original Source.

——————————————————–

..........

.

.