RSS Amplifier

Borderline - (sometimes even overline) · Aug 15, 2026

The case against private-sector hacking (“back”)

0
Sign in to vote or save

Ivan · blog.kwiatkowski.fr

Disclaimer: The views expressed in this blog post are my own and only my own. They are based on my personal experiences and reflections.

Over the years, I’ve seen a number of debates in the infosec community about the concept of hacking back and I was slightly unsettled that there wasn’t a new one this week as hacking back actually became a thing. On August 12, the White House published a presidential memorandum titled “expanding capabilities to combat transnational cyber-enabled crime” which essentially delegates cyber-offensive capabilities to vetted US companies. 

I know there are many proponents of hacking back in the community who are already thinking: “well finally we can do something about those ransomware groups who steal our riches and hate our way of life”. We’re all well aware that threat intelligence vendors have been tiptoeing this line forever; he that has never fiddled with a C2 server, let him cast the first stone and all that. But it goes beyond this and I’ll have to dive into the text a little bit before explaining why I think it’s a bad idea. 

What is on the table

The memorandum details plans to develop a program managed by the National Coordination Center (NCC, a law-enforcement coordination body rather than a cyber agency) and overseen by the Department of Justice and the Department of Homeland Security. Selected companies will receive threat intelligence either from other public or private sector entities and propose operations to combat the corresponding threats. In terms of guardrails, the document makes it very clear that the program executive directors will establish standard operating procedures, while participating companies will undergo extensive vetting. DOJ or DHS may also require them to maintain a bond or escrow of at least $1M in case they go a little too crazy – although I have a very hard time picturing any form of audit framework that isn’t the honor system1. Crucially, it feels to me like a threat intelligence company proposing a cyber offensive operation based on its own data would be compatible with this framework: this is where we go from “hacking back” to plain “hacking”2

Sec. 4(b) states actions likely to cause critical outcomes such as serious injury or loss of human life cannot be authorized, while Sec. 4(c) addresses the very important question of criminal groups with suspected government ties. The memorandum explicitly forbids targets that are an “institutional part of a foreign government”, but assumes that a criminal group does not fall in this category unless there is clear intelligence to the contrary3. This places a high burden on the notoriously flaky attribution process, rewards ignorance, and has real escalation risks. There’s also a classified annex that deals with deconfliction and adjudication.

To recap, private companies would propose cyber operations to the NCC, which would greenlight them. From there, the memorandum is surprisingly non-specific about the expected outcomes of this program. What happens to data stolen by the program’s participants? Is it turned over to the NCC and the US intelligence community? Can the company use it to write a public or commercial report, doxing the criminals? Is sabotaging attacker infrastructure fair game (I assume yes)? It worries me to see a major shift in cyber policy that doesn’t even bother defining success.

The problem

When you’re paid handsomely to hack criminals, the last thing you want to do is solve cybercrime.

I’ll start by getting out of the way a philosophical objection that I imagine won’t get a lot of traction with US readers. I always wince when government prerogatives are offloaded to private entities: the state is (supposedly) in charge of the public good, and companies maximize profits. It’s rare for the two to overlap. The reason why we don’t privatize the police is that it’s quite easy to see what sort of incentives would come out of having a contractor with fining powers or billing the city per arrest. My experience working for big tech showed me plainly how an OKR-driven culture works against fixing systemic problems. When you’re paid handsomely to hack criminals, the last thing you want to do is solve cybercrime.

From a legal standpoint, it’s also worth noting that it’s not because an action is allowed by the US government that it automatically becomes legal worldwide. The memorandum insists that operations will comply with US international obligations, which I can’t imagine being possible since we’re talking about hacking stuff overseas. If a C2 server hosted in Europe was hacked with the NCC’s blessing, and the hosting provider was able to identify the source of the attack, it would make for an interesting day in court. The darker version is that some Monday in the future, someone won’t show up at work because they got arrested and extradited during their vacation overseas.

Another concern is that the document says little about the means. As I read the document I kept thinking back to this blog post from 2025 by Huntress4, where a bad actor installed a trial version of their EDR to test evasion techniques. They then proceeded to use the agent’s forensic acquisition capabilities to obtain, among other things, the bad actor’s historical browsing data. Huntress is skittish about exactly how they went about their investigation but I can tell you for a fact that it went way beyond routine endpoint telemetry consumption.

The Huntress case, I think, is the typical example of what the program attempts to achieve: the exact same thing, with an extra step to obtain government approval. Certainly an improvement over what took place, but I’m not sure I like that picture at scale. The companies best positioned for this type of work happen to be software vendors and defenders who will suddenly have a side business of hacking their own users. Worst case scenario, you can imagine threat intelligence teams over at Google or Microsoft participating in this program (I don’t think they would) and pushing malicious updates to targets to extract intelligence from them. I don’t imagine the list of vetted companies will be public and the mere existence of this possibility will be an argument in Europe to exclude US vendors.

Conclusion

To be clear, this is not about analysts going a little more aggressive than their contract mandates as they’re working on a report. That part is the grey area we’re all happy to live with. But paradoxically, making those individual activities safer makes the overall system a lot more dangerous. My concern is that US cyber policy is making a dramatic shift that will both create problematic incentives for and erode trust in US vendors, all for unclear gains.

Subsequent operating procedures must be drafted in the next 60 days, but may not be released publicly. If they are, I hope they will shed some light on how the US government intends this whole thing to play out. I doubt it will dispel my doubts that US cybersecurity vendors may from now on be used as a mercenary force on a voluntary basis. As it stands, my assessment is that the memorandum contains critical accountability gaps and will almost certainly suffer further scope creep over the next few years.


[1] Neither the procedures or the annual report are required to be public, there is no independent oversight, and I don’t see how NCC will have the technical ability to review the contractors’ actions, or even the expertise. In all likelihood this will devolve into a rubber-stamping exercise in the near term.

[2] The memorandum is ambiguous when it comes to who will actually conduct the offensive operations, as noted by Mayer Brown. Based on the spirit of the document, in this post I assume that it will be the private sector and not DHS/DOJ personnel. It’s kind of nuts that a directive introducing a new offensive capability doesn’t even clearly state who is pressing the button.

[3] In my opinion, this would mean any action against Lazarus, Bluenoroff, Kimsuki, etc. is off the table.

[4] For the record, in June it turned out that one of Huntress’s employees tipped off a ransomware operator about an FBI investigation, which the company covered up according to a former employee. While this probably makes them a poor candidate for offensive hijinks, it also provides a glimpse of a great many things that can go wrong with the new program.

Read the original on blog.kwiatkowski.fr

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.