Skip to main content
Geopolitics & DefenseNational Security

US Cyber Program Faces Russian Hurdle

Government briefing room with podium, chairs, and laptop screen near a window with natural daylight.

"The line between government control, government-affiliated and government-acknowledged is certainly blurry in Russia," Michael Daniel, president and CEO of the Cyber Threat Alliance, said — and that blur is the central operational problem at the heart of a White House effort to enlist private firms in offensive cyber operations overseas.

White House memorandum’s targeting rules

A White House memorandum now permits vetted U.S. companies, under contract with the Justice Department and Department of Homeland Security, to conduct cyber surveillance and operations that "manipulate, disrupt and destroy" systems used by foreign criminal groups — provided every operation receives written approval. The memo bars eligible targets that are "an institutional part of a foreign government" or "wholly operated under a foreign government’s direction," and instructs officials to assume a group is not government-directed unless "clear intelligence" proves otherwise.

Russia’s blurred state‑criminal boundary

Experts interviewed in the coverage argue that this bright-line wording collides with Russia’s intentionally opaque cyber ecosystem. Justin Sherman, CEO of Global Cyber Strategies, said "Russia’s cyber web is opaque and always shifting, blurring lines between government and cybercriminal, with no single rule for understanding each and every relationship." The article quotes multiple former officials who note Moscow's long practice of tolerating, protecting or intermittently recruiting financially motivated hackers without exercising full, continuous control — a dynamic that expands Kremlin access to talent while complicating the memo’s exclusion for state-directed groups.

Intelligence limits and attribution pitfalls

The memorandum envisions using classified intelligence from agencies such as the National Security Agency and CIA to help companies set targeting criteria. But Justin Sherman warned that private firms “have critical insights in some ways and limited in others,” and that federal agencies "can only share or declassify so much." Michael Daniel said determining the exact relationship between malicious actors and the Russian government "has long been a challenge and is often impossible." Simple indicators — a tie to the FSB, or use of tools developed by criminals — do not resolve attribution, Sherman added: those factors "do not by themselves prove that a criminal group is state-directed."

Past legal cases that illustrate the problem

The article cites concrete precedents that blur legal and practical lines. In 2017 the Department of Justice charged two FSB officers with directing and protecting criminal hackers involved in the Yahoo breach, while prosecutors said one of the hackers also committed separate intrusions for personal profit. The Treasury Department has said that Maksim Yakubets, the alleged leader of the Evil Corp organization, "worked for the FSB and was tasked with projects on behalf of the Russian state" even as his group carried out financially motivated attacks.

Operational oversight, liability and diplomatic consequences

Former officials flagged three operational risks. First, coordination and oversight remain undefined: much of the program’s process will be governed by a classified annex, and the public directive “does not explain how responsibility would be divided if a contractor followed an approved plan and the underlying intelligence proved wrong.” Second, real‑time coordination between government decision-makers and private-sector operators is untested; Michael Daniel said, “I don’t know of any analogous precedent.” Third, the prospect of targeting pro‑Russia cybercriminals carries diplomatic weight. The memorandum requires State Department coordination, and the article notes that President Donald Trump and President Vladimir Putin agreed in July to maintain contact and speak again — while Rep. Don Bacon confirmed that the administration previously paused U.S. Cyber Command operations against Russia during Ukraine talks. Chris Painter, a former State Department cyber coordinator, warned that companies could "paint the target on themselves" and face Russian retaliation if their role became public.

What this means for private companies, DOJ/DHS, and Moscow

  • Private companies: Firms may be asked to provide intelligence and to execute operations under written government approval, but they will have limited access to the classified context officials use to decide whether a group is government‑directed — and the memorandum leaves open who bears responsibility if intelligence proves wrong.
  • Justice Department and Department of Homeland Security: Agencies will approve contracts and individual operations and coordinate with the State Department. A DHS spokesperson declined to answer questions about how Russian groups would be distinguished from state-linked actors, and said the department "looks forward to implementing President Trump’s directive."
  • Moscow (the Kremlin and Russian services): The United States' assumption rule — that a group is not state-directed absent clear intelligence — could be used to "call the Russians’ bluff," Michael Daniel suggested: Moscow could either acknowledge ties or let operations proceed, but an inadvertent strike on clandestine personnel would carry "substantially greater consequences."

Officials and experts agree the program will require decisions in short order: Chris Painter noted "that’s all supposed to be decided in 60 days," referring to the timeline within which implementation details must be worked out. The directive frames an ambitious new relationship between government and the private sector, but the Russian example exposed in this reporting shows why strategic clarity, robust oversight and tightly defined liability rules will determine whether the initiative deters criminals without escalating into a diplomatic or operational misstep.

https://www.defenseone.com/policy/2026/08/russian-hurdle-trumps-new-offensive-cyber-program/415520/