US Government Authorizes Private Firms to Fight Cybercriminals
New program allows private companies to launch offensive cyber operations against overseas criminal groups under federal oversight.
🕒 生成時間: (台北時間)
Summary · 摘要
The Trump administration has launched a new program allowing private security firms to conduct cyberattacks against foreign criminal organizations. These companies will operate under the strict supervision of the Department of Justice and the Department of Homeland Security. The initiative aims to combat threats like ransomware and financial fraud by using private-sector expertise. However, experts have raised concerns about the legal risks and the difficulty of identifying targets correctly. Critics warn that these operations could accidentally harm innocent people or create international conflicts.
川普政府已啟動一項新計畫,允許民間資安公司對外國犯罪組織進行網路攻擊。這些公司將在司法部與國土安全部的嚴格監督下運作。該倡議旨在透過運用民間部門的專業知識,打擊勒索軟體與金融詐騙等威脅。然而,專家已對法律風險及正確辨識目標的困難度提出擔憂。批評者警告,這些行動可能會意外傷害無辜民眾或引發國際衝突。
Ongoing story · 追蹤中的新聞
This article follows earlier coverage on the same developing story.
- US Government to Allow Private Companies to Conduct Cyberattacks
· 2026年8月14日
The Trump administration has announced a new program allowing private security firms to carry out cyberattacks against overseas criminal groups. These companies will work under the supervision of the Departments of Justice and Homeland Security. The initiative targets groups involved in ransomware, fraud, and other cybercrimes. However, experts warn that the plan carries significant legal and safety risks. Critics also worry that these operations could accidentally harm innocent people or create international tension.
The United States government has officially launched a new program that allows private security firms to carry out cyberattacks against overseas criminal groups. According to a presidential memorandum issued by the Trump administration, these private companies will work under the control and oversight of federal agencies. This move marks a major change in how the US handles cybercrime, as it is the first time the government has authorized private businesses to perform offensive cyber operations against hackers based in other countries.
This initiative follows plans that were first reported last year. The goal is to use the skills of the private sector to fight groups that commit crimes such as ransomware—a type of software that locks a user's files until they pay money—as well as financial fraud and phishing campaigns. The Department of Justice and the Department of Homeland Security will be responsible for managing these firms. To participate, companies must prove they have high technical skills and must hold a bond of at least $1 million, which they will lose if they break their agreement with the government.
Ars Technica reports that the program targets "cyber-enabled" criminal organizations. These are defined as foreign groups that attack US interests but are not part of an official foreign government. The memo suggests that private firms could use various methods to disrupt these criminals, including spyware or attacks that lock the criminals out of their own computer systems. Previously, the government did not allow private companies to take such actions without special permission from a court.
While the government describes private businesses as an "underutilized" force in the fight against crime, the plan has faced significant criticism from experts. One major concern is the difficulty of identifying who is truly behind a cyberattack. Ben Bernstein, a manager at Huntress, explained to The Verge that criminals often hide their activities by using innocent networks, such as those at hospitals or small businesses. Because of this, Bernstein warned that it is "practically impossible" to strike back at the real criminals without accidentally damaging the systems of innocent people.
There are also serious legal and safety concerns for the people working at these private firms. Jason Healey, a researcher at Columbia University, told Cybersecurity Dive that anyone participating in these operations faces "substantial personal legal risk." Furthermore, Jake Williams, a vice president at Hunter Strategy, noted in a report by TechCrunch that Americans involved in these cyberattacks could be seen as "non-uniformed combatants" if they travel to other countries. This could put them in danger of being treated like soldiers in a war rather than private citizens.
Another challenge is the risk of accidental conflict with foreign nations. As Cybersecurity Dive pointed out, it is often very hard to tell if a criminal group is acting alone or if they have ties to a foreign government. If a private firm accidentally attacks a group that is actually supported by a foreign state, it could lead to serious legal or political problems for the United States. Despite these warnings, the administration maintains that it is necessary to use all available tools to protect the country from growing digital threats.
As the program begins, the government will need to carefully manage the balance between fighting crime and avoiding international trouble. The success of this policy will depend on how well the federal agencies oversee these companies and how accurately they can identify targets. For now, the cybersecurity industry and legal experts are watching closely to see how these private operations will affect global security and the safety of those involved.
選擇題練習 · Quiz
共 4 題
- 細節 Detail
1.What requirement must private companies meet to participate in the government's new cyberattack program?
- 推論 Inference
2.Why might the new program lead to unintended international political tensions?
- 單字情境 Vocabulary
3.In the fourth paragraph, what does the word 'underutilized' imply about the government's view of private businesses?
- 主旨 Main Idea
4.What is the central message of the article regarding the new US cyberattack initiative?
易誤解詞彙 · Words to watch
這些字字面意思和文中用法不同,或是不常見的詞性/片語。
- carry out phrasal verb
- To perform or complete a task or activity.
- 執行、實施。
- 💡 常見於日常對話,此處指執行任務。文中:The United States government has officially launched a new program that allows private security firms to carry out cyberattacks against overseas criminal groups.
- bond noun
- A sum of money held as a guarantee that someone will fulfill an agreement.
- 保證金、擔保金。
- 💡 常見作名詞(連結、關係),此處指財務上的保證金。文中:To participate, companies must prove they have high technical skills and must hold a bond of at least $1 million, which they will lose if they break their agreement with the government.
- strike back phrasal verb
- To attack someone in return for an attack they made on you.
- 反擊。
- 💡 由 strike(打擊)與 back(回)組成,指報復性攻擊。文中:Because of this, Bernstein warned that it is "practically impossible" to strike back at the real criminals without accidentally damaging the systems of innocent people.
- ties noun (plural)
- Connections or relationships between people or groups.
- 關聯、連結。
- 💡 常見作動詞(繫鞋帶),此處作名詞指組織間的關係。文中:As Cybersecurity Dive pointed out, it is often very hard to tell if a criminal group is acting alone or if they have ties to a foreign government.
原始來源 · Sources
本文內容由 AI 從以下來源綜合改寫。事實請以原始來源為準。
gemini/gemini-3.1-flash-lite