United States • 🌿 Progressive

Trump wants private companies to hack foreign criminals — but who watches the contractors?

Trump wants private companies to hack foreign criminals — but who watches the contractors?

A Trump administration memo would allow vetted private companies to run offensive cyber operations against foreign criminals under federal contract, but offers…

The Trump administration moved Wednesday to let private businesses perform offensive cyber operations against foreign criminal targets selected by the government, handing corporate actors a role with consequences for workers, consumers and civil liberties that the presidential memorandum does not address. The framework favors speed over accountability. --- THE CONTEXT --- U.S. anti-hacking laws currently bar companies and individuals from penetrating digital infrastructure outside narrow law-enforcement exceptions. The memorandum preserves those laws but creates a federal contracting pathway that effectively shields participating companies from prosecution, extending state power through a corporate intermediary. --- THE FACTS --- Companies seeking to participate must contract with the Department of Justice or the Department of Homeland Security, pass rigorous vetting and deposit one million dollars the government can seize for non-compliance. Joshua Steinman, former senior director for cyber policy on the National Security Council during Trump's first term, said targets would likely include organized crime and money laundering networks. Arthur Tellis, a former Department of Defense staffer and fellow at the Institute for Progress, assessed that these firms would be more effective at surveillance than at disrupting criminal enterprises. Steinman also acknowledged that many companies would enter the program primarily to secure government contracts and expand their revenue base. --- THE POSITIONS --- Two Republican lawmakers have introduced separate legislation to create cyber privateers, invoking 16th-century naval warfare. The memo stops short of that grant of autonomy, though it generated enthusiastic online response from the legislation's supporters. No consumer protection body or civil liberties organization is cited in the memorandum's text. --- WHAT REMAINS UNKNOWN --- The memo provides no mechanism for affected third parties to seek redress if a contractor operation causes unintended harm. It also does not specify what transparency or reporting obligations companies will face once operational. --- UNANSWERED QUESTIONS --- • What protections exist for individuals or businesses that suffer collateral harm from a contractor's cyber operation? • Will workers employed by these firms have legal protections if asked to execute operations they consider unlawful? • How will the profit motive of venture-capital-backed startups be kept separate from target selection decisions? • Is there an independent judicial review mechanism for operations conducted under this program? --- EPM ANALYSIS --- The memorandum converts a public security function into a market opportunity, creating incentives that may not align with public interest. Steinman's own admission that companies see this primarily as a contracting opportunity underscores that tension. The winners are firms positioned to capture federal revenue; the potential losers are anyone caught in an operational error with no published redress mechanism. The decisive variable is whether Congress imposes transparency requirements before the program scales. 📌 📌 EPM Take: In EPM's view, outsourcing offensive cyber operations to profit-driven companies does not inherently make Americans safer — it shifts accountability away from institutions that are at least nominally subject to democratic oversight. The one-million-dollar deposit is a business risk calculation, not a substitute for civil liability or congressional review. EPM's broader reporting has shown repeatedly that when federal policy externalizes risk, ordinary people absorb the cost. This program is structured the same way.

El plan de Trump para privatizar el hackeo: ¿quién controla a las empresas que atacan en nombre del Estado?

El memorando de Trump autoriza a empresas privadas contratadas a realizar operaciones cibernéticas ofensivas contra delincuentes extranjeros, pero no establece…

El gobierno de Trump busca convertir a empresas privadas en brazos ofensivos del Estado en el ciberespacio, una decisión que desplaza hacia el sector corporativo funciones de alto riesgo que afectan directamente a trabajadores, consumidores y ciudadanos de todo el mundo. El memorando presidencial del miércoles abre esa puerta sin cerrar las ventanas de la supervisión. --- EL CONTEXTO --- Las leyes antipiratería en vigor en Estados Unidos prohíben ampliamente hackear infraestructura digital. El documento no cambia esas leyes, pero obliga a cualquier empresa participante a operar bajo contrato federal, lo que le otorga una cobertura legal que el sector privado ordinario no posee. --- LOS HECHOS --- Las empresas interesadas deberán firmar contratos con el Departamento de Justicia o el Departamento de Seguridad Nacional, pasar una verificación rigurosa y depositar un millón de dólares recuperables si incumplen obligaciones. Joshua Steinman, ex director senior del Consejo de Seguridad Nacional, indicó que los objetivos podrían incluir crimen organizado y lavado de dinero. Arthur Tellis, ex funcionario del Departamento de Defensa y fellow del Institute for Progress, advirtió que estas empresas serían probablemente más hábiles en vigilancia que en interrumpir estructuras criminales. Steinman también señaló que muchas verán esto como una oportunidad para acceder a recursos gubernamentales o incrementar su visibilidad. --- LAS POSICIONES --- Dos congresistas republicanos han propuesto legislación que va más lejos, invocando el concepto histórico de corsarios cibernéticos. El memorando no llega hasta ahí, pero despertó entusiasmo en línea entre sus defensores. Ni el Departamento de Justicia ni el Departamento de Seguridad Nacional han detallado públicamente los mecanismos de supervisión. --- LO QUE FALTA SABER --- No se conocen los criterios concretos para seleccionar objetivos, ni qué protecciones tendrán comunidades o individuos que pudieran verse afectados colateralmente. Tampoco está claro quién responde si una operación privada provoca daños involuntarios. --- PREGUNTAS SIN RESPUESTA --- • ¿Qué mecanismos protegerán a civiles o empresas inocentes de ser afectados por errores operativos de estas firmas contratistas? • ¿Tendrán los trabajadores de esas empresas algún recurso legal si se les pide ejecutar operaciones éticamente cuestionables? • ¿Cómo se garantizará que la lógica de lucro corporativo no influya en la selección de objetivos? • ¿Existirá revisión judicial independiente de las operaciones autorizadas? --- ANALISIS EPM --- El memorando transforma una función pública en un negocio con incentivos de mercado. Las startups respaldadas por capital de riesgo mencionadas por Steinman no tienen el mismo marco de rendición de cuentas que una agencia federal. Los perdedores potenciales son quienes sufran daños colaterales sin acceso a mecanismos de reparación. La variable decisiva es si el contrato federal impone obligaciones de transparencia equivalentes a las exigidas a los organismos del Estado. 📌 📌 Conclusion EPM: A juicio de EPM, la privatización de operaciones cibernéticas ofensivas plantea una pregunta que este memorando elude deliberadamente: ¿quién responde cuando una empresa comete un error que daña a terceros inocentes? La lógica del contrato gubernamental no sustituye la rendición de cuentas democrática. En un contexto donde EPM ha documentado cómo los costos de las políticas federales recaen siempre sobre trabajadores y consumidores ordinarios, este esquema merece vigilancia ciudadana, no solo tecnocrática.
📤 Share on Telegram

¿Te gustó este artículo? Recibe cobertura global en tu correo.

Suscríbete gratis / Subscribe free