Skip to main content
Geopolitics & DefenseGovernment & Policy

US Enlists Private Sector in Cybercrime Hacking Operations

Government officials seated around a table in a bright conference room, engaged in discussion.

“It’s an embarrassment to America,” Davi Ottenheimer told CyberScoop — a blunt summation that captures why reactions have ranged from cautious optimism to alarm after a newly signed presidential memorandum authorizing private-sector participation in federal cyber operations against transnational criminal organizations.

The memorandum and its 60‑day implementing timeline

The memo directs the creation of a coordination center and gives it 60 days to establish a program that would enlist participating companies in federal law-enforcement hacking operations. The document, sources told CyberScoop, contains a classified annex. The publicly described requirements include establishing legal and constitutional procedures for prior approval when targeting U.S. citizens and developing procedures to halt any unintentional targeting of U.S. people or systems.

Attribution, legal limits, and the risk of escalation — Michael Garcia’s concerns

Michael Garcia, formerly a top official at the Cybersecurity and Infrastructure Agency and now vice president of cybersecurity at Monument Advocacy, called the memo “a massive shift in the cyber policy community” and framed the debate around attribution and legal authority.

Garcia warned that pressure to attribute attacks more quickly could lower certainty about who is behind a crime and “lead to a private sector company accidentally attacking a foreign government.” He added that constitutional and statutory limits matter: “It’s in the Constitution — the federal government has the ability to wage war. And there are laws by which private citizens can’t take up arms.” Garcia said he wanted court oversight for the program, similar to what has been required for private-sector takedown operations, and questioned whether enough companies would accept the legal risk without clear protections from the government.

Historical parallels and ethical objections — Davi Ottenheimer’s warning

Security consultant Davi Ottenheimer, founder of Ottenheimer GmbH, drew a historical analogy to letters of marque, a practice that once authorized privateers to attack enemy ships, and noted why that practice “fell out of favor” in the 1800s. He warned that the memo could revive mercenary-like violence and create troubling incentives and defenses for those attacked.

Ottenheimer argued the policy’s operative definition of “criminals” could be weaponized, saying, “Left-wing opposition, liberals, anti-fascists —they’re all criminals to him,” and cautioning that the memo would allow private organizations to hack people the president designates as criminals. He also described procedural and ethical problems: there is “no notice for you being designated. There’s no prevention of you being designated. There’s no way for you to know you’re being designated,” and added sharply, “You can’t attack somebody and then say it’s your fault that you didn’t notify them you didn’t want to be attacked.”

Supporters’ rationale — Amanda Naylor, Joshua Steinman, Ari Redbord, and Robert Graham

Supporters argue the memo brings private-sector speed and innovation to bear against cybercrime. Amanda Naylor, director of cyber policy at the National Security Council who worked on the memo, wrote on LinkedIn that it was designed “to bring the capabilities, speed, and innovation of the American private sector into the fight against transnational cybercrime and fraud.”

Joshua Steinman, a former Trump White House cybersecurity official and founder of security firm Gavalnick, framed the memo as a move toward “parity,” noting that “the Chinese and the Russians do this at scale” and saying the policy “opens up an entire workforce that allows us to go out and achieve strategic objectives.” He emphasized that “the most sensitive things are going to continue to be done by the uniformed and authorized civilian workforces,” and described private-sector activity as “measured and reasoned,” likening it to “a Boy Scout in cyberspace.”

Ari Redbord, global head of policy at TRM Labs, called the effort “a huge step toward empowering the private sector at a critical moment,” arguing that “scammers are using AI to move with unprecedented speed and scale” and that “the private sector holds the data. The public sector holds the authorities.” Errata Security CEO Robert Graham noted the memo’s federal supervision elements and cautioned that, absent careful controls, law enforcement might eventually tell companies, “Stop bothering us, just do what you think is best.”

Operational questions: seized assets, foreign laws, and measuring success

Several experts flagged practical unanswered questions that the 60‑day process must resolve. Graham and Redbord both pointed out the memo is “quiet” about what happens to seized assets. Redbord asked a string of operational questions: what “government direction and control” looks like during live operations; how disruption turns into “actual dollars back in victims’ pockets”; whether the program can build a victim compensation fund; what happens when operations touch a third country with its own laws and interests; and how success will be measured “in money recovered and networks dismantled.”

Will Barker, cybersecurity adviser at Huntress, encapsulated the stakes: “The 60-day implementing guidance is where the real substance lives,” including “minimum standards, operational procedures, [and] the adjudicatory framework for target selection.”

How participating companies, foreign governments, and victims are positioned

  • Participating companies: Might be attracted by mission and data access, but face legal and reputational risk; Garcia said lawyers will ask whether the government will provide protections and warned some firms could be deterred.
  • Foreign governments: Could react negatively if operations accidentally engage their infrastructure or nationals; Garcia warned of the risk that a private-sector action could be perceived as an attack on a foreign government.
  • Victims of cybercrime: Supporters and critics alike raised the question of restitution — Redbord pressed whether disruption operations can be translated into dollars returned to victims and whether a formal victim compensation mechanism will be created.

The memo sets a hard, consequential clock. Within 60 days a coordination center must sketch operational rules, and a classified annex will shape what remains concealed from public view. The debate among voices quoted to CyberScoop turns on whether those procedural details — attribution standards, court oversight, asset disposition, and cross‑border legal safeguards — will restrain risk or leave a wide aperture for error. The answer, experts say, will determine whether the new policy is a bold new tactic or a dangerous precedent.

https://cyberscoop.com/private-sector-hacking-presidential-memo-cybersecurity/