💥Join UPSC 2027,2028 Mentorship (August Batch) + XFactor Notes & Microthemes PDF

Foreign Policy Watch: India-United States

US memorandum authorises vetted private firms to conduct offensive hacking against criminal networks

Why in the News

A US presidential memorandum allows vetted private companies to participate in government-authorised offensive cyber operations against overseas transnational criminal organisations (TCOs).

Note: Vetted private firms are privately owned companies that have passed thorough background checks by a client, usually a government agency, to prove they are safe, reliable, and qualified to do sensitive work

What does the memorandum allow?

  1. Private participation: Selected firms can conduct hacking operations under government supervision.
  2. Permitted actions: Operations may include entering, disabling or destroying criminal networks’ systems.
  3. Oversight: Firms require government contracts, security vetting and supervision.
  4. Targets: Criminal organisations attacking US persons or interests, excluding entities formally controlled by foreign governments.

Key Concepts

  • TCO: Criminal network operating across national borders.
  • Offensive cyber operation: Entering, disrupting or destroying another computer system.
  • Attribution: Identifying the actor responsible for a cyberattack.
  • Hacktivist: Non-state actor conducting cyber operations for political or ideological purposes.

Why is it controversial?

  • Misattribution: Attacks may hit innocent third-party systems.
  • Collateral damage: Destructive operations can affect infrastructure in other countries.
  • Escalation: Private hacking can trigger cross-border conflicts.
  • Accountability: Commercial actors may have weaker accountability than state agencies.
  • Proxy problem: It resembles the private or proxy cyber models the US has criticised in China and Russia.

Implications for India

  • India has no publicly declared offensive cyber doctrine.
  • Sections 43 and 66 of the IT Act, 2000 criminalise unauthorised access and damage.
  • Compromised Indian servers could become staging infrastructure for foreign cyber operations.
  • India continues to advocate state responsibility and opposition to cyber proxies at the UN.

Prelims Pointers

  • CERT-In: National agency for cyber incident response.
  • NCIIPC: Protects Critical Information Infrastructure.
  • I4C: Coordinates India’s response to cybercrime.
  • Defence Cyber Agency: Handles cyber operations for the armed forces.
  • Section 70B, IT Act: Provides the statutory basis for CERT-In.

[2022, GS3, 10 marks] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.”

[2017] In India, it is legally mandatory for which of the following to report on cyber security incidents?
1.Service providers
2.Intermediaries
3.Corporate bodies
Select the correct answer using the code given below:

[A] .1 and 2 only

[B] .2 and 3 only

[C] 1 and 3 only

[D] 1, 2 and 3 only


Join the Community

Join us across Social Media platforms.