Russia's blurred hacker lines challenge Trump's cyber carveout

Get the Geopolitics newsletter
Daily geopolitics — wars, elections, sanctions, the diplomatic moves that move markets. Free.
- Trump's White House memorandum allows vetted U.S. companies to conduct cyber surveillance and disruptive operations against foreign criminal groups under DOJ and DHS contracts, with each operation requiring written approval and targets excluding groups that are "an institutional part of a foreign government" or "wholly operated" by one.
- Russia's model complicates that carveout: Russian intelligence services have long tolerated, protected or intermittently recruited financially-motivated hackers without exercising full control — a dynamic that gives Moscow easier access to talent and makes the directive's government-actor exclusion nearly impossible to apply, experts said.
- Past prosecutions illustrate the blur: DOJ in 2017 charged two FSB officers with directing criminal hackers in the Yahoo breach, while Treasury linked Evil Corp leader Maksim Yakubets to the FSB even as his organization ran profit-driven attacks.
- The administration has already shown it can pull punches on Moscow: Defense Secretary Pete Hegseth ordered a brief pause in U.S. Cyber Command operations against Russia during Ukraine negotiations, Rep. Don Bacon confirmed, and the new memo requires State Department coordination before any operation.
- The program faces a 60-day development window for resolving how oversight, targeting criteria, and contractor liability will work when intelligence on a target proves wrong; much of the operational process is governed by a classified annex.
- Michael Daniel of the Cyber Threat Alliance argued the U.S. could "call Russia's bluff" by forcing Moscow to either acknowledge ties to a targeted hacker group or let it absorb the damage — but warned that hitting clandestine intelligence personnel by mistake could produce substantially greater consequences.
Why it matters: The directive's carveout for state-directed groups rests on attribution judgments the U.S. government often cannot make conclusively, meaning private contractors targeting Russian hackers risk either striking clandestine intelligence personnel or letting state-linked groups operate freely. With a prior Cyber Command pause during Russia-Ukraine talks already on record and the program to be developed within 60 days, the policy must resolve who bears responsibility when attribution is wrong — and how cyber operations are weighed against ongoing diplomacy with the Kremlin.
Ask SkimNews



