2026年8月13日,美国东部时间下午5:30 / CNN
作者:肖恩·林加斯
2026年8月6日,唐纳德·特朗普总统在白宫椭圆形办公室发表讲话。
吉姆·沃森/法新社/盖蒂图片社/档案照片
特朗普政府正招募私营企业对外国网络犯罪分子发动网络攻击,这一重大政策转变被专家指出可能会给企业带来法律风险。
此举让经过审核的企业在黑客行动中扮演重要角色,而这类行动历来是美国执法、情报和军事机构的专属领域。
根据特朗普总统周三发布的一份备忘录,在新联邦项目的“管控和监督”下,企业可以使用网络工具监视外国犯罪分子并破坏其网络。
该项目的目标是惩罚每年给美国造成数十亿美元损失的外国犯罪团伙。项目的管辖范围是外国犯罪团伙,而非外国政府。
备忘录中写道:“长期以来,美国企业的创新能力在识别和破坏网络犯罪团伙的行动中未得到充分利用。”
美国政府已经在针对外国目标开展大量黑客行动。一些前官员表示,新项目可能会导致“厨房做饭的人太多”,也就是权责重叠、协调混乱。
“真正的风险在于,最终会有一群网络私掠者四处行动,在联邦层面没有明确的协调或指挥方向,”美国网络司令部前军官安德鲁·绍卡说道。
绍卡在接受CNN采访时表示:“协调网络行动已经是联邦机构面临的一大挑战,但如今再加入能力更强、行动更快的私营企业,只会让情况更加复杂。”
新项目可以节省美国政府的资源。美国联邦调查局前局长克里斯托弗·雷称,中国政府支持的黑客数量是联邦调查局网络人员的50倍。
“获得私营部门的帮助来对抗网络犯罪分子,能够让美国破坏更多犯罪团伙,同时让联邦调查局和网络司令部等机构能够更专注于应对中国等国家支持的网络攻击,”前联邦调查局高级网络官员辛西娅·凯泽说道。
“但细节决定成败,”凯泽告诉CNN,“在签署协议之前,企业需要更明确的信息,包括责任保护、政府监督类型、外国犯罪分子对美国基础设施的使用情况,以及其他诸多担忧。”
近年来,针对各类美国民众的诈骗案件激增,促使一些普通民众发起反击,入侵诈骗者的网络。
网络安全公司Veracode联合创始人克里斯·“焊接池”·怀索帕尔表示,新的联邦项目将是解决该问题的一种更系统化的方式。但他也担心,由私营企业实施的政府批准的黑客行动如果出现差错,可能会造成潜在后果。例如,为了打击诈骗者而入侵外国的数据中心,可能会在无意间影响当地一家医院。
怀索帕尔表示,外国政府还可能将参与该新黑客项目的企业员工在海外旅行视为合法的拘留或讯问目标。
美国司法部和国土安全部的官员将监督这个新的黑客小组。备忘录称,任何针对“美国人员”的项目活动都必须接受额外的法律审查,包括司法部的审查。
但前网络司令部官员杰森·基克塔表示,新备忘录并未明确规定一套清晰的流程,以确保网络行动维护美国公民的公民自由。
“对于未具名政治任命官员做出的决定,没有明确的监督或审查程序,”基克塔说道,“该备忘录的支持者会说,这仍然要求活动受到司法部和国土安全部权限的约束。但这项行政令将责任推给了企业。”
‘Cyber privateers’: Trump issues order allowing US companies to hack overseas groups under certain conditions
Aug 13, 2026, 5:30 PM ET / CNN
By Sean Lyngaas
President Donald Trump speaks in the Oval Office of the White House on August 6, 2026.
Jim Watson/AFP/Getty Images/File
The Trump administration is enlisting private companies to conduct cyberattacks on foreign cybercriminals in a major policy shift that experts say could come with legal risk for the companies.
The move gives vetted companies a prominent role in hacking operations that have historically been the dominion of US law enforcement, spy and military agencies.
Companies can use cyber tools to surveil foreign criminals and disrupt their networks under the “control and oversight” of the new federal program, according to a memo issued Wednesday by President Donald Trump.
The program’s goal is to punish foreign criminal groups that cause Americans billions of dollars in annual losses. The program’s remit is foreign criminal groups, not governments.
“American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace,” the memo says.
The US government is already doing a lot of hacking on foreign targets. The new program risks having too many cooks in the kitchen, some former officials said.
“The real risk is that you end up with a bunch of cyber privateers running around without any clear coordination or direction at the federal level,” said Andrew Schoka, a former Army officer at US Cyber Command.
Deconflicting in cyber operations “is already a major challenge for federal agencies, but now you’re adding in the complexity of private sector firms with a lot more capability and speed,” Schoka told CNN.
The new program could free up US government resources. Chinese government-backed hackers outnumber FBI cyber personnel 50-to-1, according to former FBI director Christopher Wray.
“Having private sector help to counter cyber criminals allows the US to disrupt more groups and frees up agencies like FBI and Cyber Command to focus more on countering nation states like China,” said Cynthia Kaiser, a former senior FBI cyber official.
“But the devil is in the details,” Kaiser told CNN. “Before they sign up, companies will need more explicit information about liability protections, types of government oversight, and foreign criminal use of US infrastructure, among other concerns.”
An explosion of scams targeting every type of American in recent years has prompted some private citizens to hack back and compromise the networks of the scammers.
Chris “Weld Pond” Wysopal, co-founder of cybersecurity firm Veracode, said the new federal program would be a more organized way of dealing with the problem. But he also worried about the potential consequences of a government-sanctioned hacking operation carried out by a private firm that goes awry. Hacking a data center in a foreign country to target scammers could, for example, inadvertently affect a hospital, he said.
Foreign governments may also see employees of companies participating in the new hacking program who travel abroad as legitimate targets for detention or questioning, Wysopal said.
Officials from the departments of Justice and Homeland Security will oversee the new hacking group. Any program activity “directed at a United States person” must undergo extra legal scrutiny, including from the Justice Department, the memo says.
But Jason Kikta, a former Cyber Command official, said the new memo didn’t lay out a clear process for ensuring cyber operations uphold the civil liberties of American citizens.
“There is no clear oversight or review process on the determinations that will be made by unnamed political appointees,” Kikta said. “Defenders (of the memo) will say that it still requires activity to be constrained by DOJ and DHS authorities. But this order pushes liability on to the companies.”
发表回复