The DOJ's new policy green-lighting private security firms to hack foreign ransomware groups sounds pragmatic, but it's a dangerous leap. We're not deputizing accountable defenders; we're licensing for-profit companies to conduct offensive cyber warfare. These firms answer to shareholders, not citizens. Their incentives are to demonstrate effectiveness and secure future contracts, not to uphold legal standards or minimize harm. That's the definition of a mercenary army, and it's now operating in the most opaque domain we have.
There is zero oversight on tactics, targets, or collateral damage. A case-by-case approval letter is not a court order; it's a rubber stamp. If a contractor misidentifies an IP and takes down a hospital or power plant, there's no legal framework to hold them liable. Ransomware groups are thugs, yes, but replacing state action with profit-driven hit squads doesn't fix accountability. It eviscerates it. When a security firm decides that 'success' means escalating an attack to prove its worth, who stops them? Nobody.
Privatizing cyber combat also muddies attribution beyond repair. When a contractor strikes a server in Russia, the host government will retaliate against the corporate network, not the individual analyst. That's how international incidents start. More broadly, this normalizes the idea that offensive force is a commodity any company can buy. The next step isn't defense; it's a marketplace for vendettas. We're handing cyberweapons to the highest bidder and calling it progress. That's not defense; it's an abdication of state responsibility.