TB Tech Bytes
SECURITY 2026-08-14 Source: Ars Technica

US Policy Shift Authorizes Private Security Firms to Launch Counter-Attacks Against Overseas Cybercriminals

US Policy Shift Authorizes Private Security Firms to Launch Counter-Attacks Against Overseas Cybercriminals

In a landmark policy reversal, the US government has issued updated rules of engagement granting vetted private cybersecurity firms legal authority to conduct active offensive counter-measures against verified overseas cybercriminal infrastructure and ransomware networks.

Legalizing 'Hack Back': From Passive Defense to Offensive Ransomware Infrastructure Takedowns

Under the new framework, participating firms can neutralize botnets, delete stolen corporate data from command-and-control servers, and disrupt criminal payment portals without violating the Computer Fraud and Abuse Act (CFAA).

Get Tech News In Your Inbox

Subscribe to the free Tech Bytes daily newsletter for high-signal technical breakdowns and industry analysis.

Stay Ahead

5 minutes of high-signal tech every weekday. Free.

No spam ยท Unsubscribe anytime

Escalation Risks, Collateral Damage, and International Sovereign Law Concerns

While corporate CISOs welcome aggressive deterrent capabilities, international legal experts warn that privatized offensive cyber operations increase the risk of misattribution, accidental collateral damage against civilian infrastructure, and geopolitical escalation.