US President Donald Trump signed a national security presidential memorandum on Wednesday, August 12, authorizing federal law enforcement to use cyber tools against transnational criminal organisations operating in foreign jurisdictions that attack Americans.
The White House cited ransomware attacks, financial frauds, and other crimes run by foreign-based criminal organisations in a fact sheet about the memo. The directive aims to leverage private sector capability and innovation to conduct cyber operations under the direction, control, and authority of the US Government.
Public-private framework
The memo creates a framework encouraging private sector companies to enter agreements with other private entities, as well as federal, state, local, tribal, and territorial agencies. These partnerships are designed to gather threat information on transnational criminal organisations and propose cyber operations.
Participating companies must maintain a bond or escrow of at least US$1 million. Under US federal government supervision, participating companies that have been vetted will conduct 'cyber surveillance operations' and 'cyber effects operations' against specified targets.
Operational oversight
The memo directs the US Department of Homeland Security (DHS), through the Homeland Security Task Force's National Coordination Center, to create a program to conduct specific cyber operations that disrupt foreign transnational criminal organisations (TCOs). This program will be overseen by the DHS and the US Department of Justice.
The memo defines 'cyber effects' as including the potential manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon.
The US Department of Homeland Security (DHS) and the White House did not immediately respond to requests for additional details about the program.