Washington is taking a controversial new approach to fighting cybercrime by allowing selected private companies to carry out government-approved operations against foreign cybercriminal organisations. The move has divided cybersecurity experts, with some seeing potential benefits and others warning that it could create new risks.
President Donald Trump signed a memorandum directing the Justice and Homeland Security departments to allow certain U.S. companies to spy on and attack transnational criminal organisations. The White House cited ransomware, “sextortion” and online fraud, which it said cost Americans more than $20 billion in 2025.
Under the plan, private partners could take down hackers’ servers or infiltrate their systems with spyware. Each operation would require government approval, while participating companies would need to post a bond of at least $1 million. Actions that could cause death or injury, or qualify as “use of force” under international law, would be prohibited.
The approach has been compared with 18th-century “privateering”, when governments authorised private vessels to attack enemy ships.
“The private sector holds the data. The public sector holds the authorities,” Ari Redbord said, adding that the memorandum “puts them together,”. Redbord, a former federal prosecutor and current policy and government affairs chief at an analytics firm, supports the comparison, saying modern oversight can continue throughout an operation.
Other experts remain cautious. University of Surrey cybersecurity professor Alan Woodward said, “You can hand out a commission. You can’t hand out obedience,” and warned that privateering historically became more trouble than it was worth.
The policy reverses an earlier position from the White House, which had indicated it was “not interested in fighting pirates with pirates”. National Cyber Director Sean Cairncross had also previously ruled out such private-sector operations. The reason for the change remains unclear.
Jason Healey, a Columbia University researcher and former cybersecurity official, said the programme has safeguards because it is backed by the rule of law. However, he raised concerns about weakened oversight bodies.
Major U.S. technology companies already defend their products against cyber threats. Under the new programme, they could conduct government-approved hacking operations without judicial oversight. Microsoft declined to comment, while Google did not respond.
Woodward warned that participating companies could “stops being a neutral defender and becomes a target” themselves. The administration has 60 days to finalise the programme, with some details remaining classified.
Whether the approach succeeds remains uncertain. Potential costs include misidentified targets, foreign prosecutions and diplomatic tensions. Redbord said, “Short of victims getting funds back, none of the rest counts for much.”
Also read: Viksit Workforce for a Viksit Bharat
Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter
About us:
The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.


