US to let private hackers launch offensive cyberattacks worldwide — and critics are alarmed

The White House will allow private cybersecurity companies to conduct offensive cyber operations aimed at disrupting criminal organizations around the globe, according to Bloomberg. Until now, only government agencies could carry out such attacks in the name of US national security.
The initiative has already sparked sharp divisions. Opponents fear the move could lead to unintended consequences and escalation, while supporters argue that bringing more professionals into the fold will expand the country's ability to counter cyber threats.
Ari Redbord, head of government affairs at blockchain analytics firm TRM Labs, likened the policy to issuing "cyber privateering licenses" — a reference to 19th-century government permits that allowed private vessels to attack pirates and enemy ships. "This is about handing out cyber letters of marque," he said.
As Gizmodo notes, cyber policy experts have previously called this "the worst idea in cybersecurity," pointing to the difficulty of accurately identifying attackers and the potential for clashes between government and private actors. The plan raises questions about accountability, oversight, and the blurring line between state-sanctioned action and freelance hacking. While proponents see it as a way to harness private-sector talent against increasingly sophisticated criminal networks, critics warn that authorizing private firms to strike targets worldwide could provoke diplomatic incidents and make it harder to attribute attacks. The exact scope of the operations and the level of government oversight remain unclear, but the policy marks a significant shift in how the US approaches cyber defense and offense.


