mimile
Back to feed

Trump cyber directive runs into Russia's blurred state-criminal hacker boundary

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Trump cyber directive runs into Russia's blurred state-criminal hacker boundary

President Donald Trump's August 2026 memorandum lets vetted U.S. companies conduct cyber operations against foreign criminal groups, but it excludes targets that are part of or directed by a foreign government. Current and former U.S. officials say that exclusion is hard to apply in Russia, where intelligence services have long tolerated, protected or recruited financially motivated hackers without full control, blurring the line between crime and state activity.

Key Facts

  • Russian intelligence services have long tolerated, protected or intermittently recruited financially motivated hackers without exercising full control over them.
  • Trump's August 2026 White House memorandum lets vetted U.S. companies conduct cyber surveillance and operations that manipulate, disrupt and destroy systems used by foreign criminal groups.
  • The directive excludes targets that are an institutional part of a foreign government or wholly operated under a foreign government's direction.
  • Michael Daniel, a former White House cyber coordinator under Barack Obama, said determining the exact relationship between Russian malicious actors and the Russian government is often impossible.
  • Justin Sherman, CEO of Global Cyber Strategies, said the ambiguity is intentional and lets the Kremlin expand the pool of hackers it can covertly draw upon.

The Russia Hurdle

President Donald Trump's August 2026 memorandum lets vetted U.S. companies conduct cyber surveillance and operations that manipulate, disrupt and destroy systems used by foreign criminal groups. Operations would run under contracts with the Justice Department and the Department of Homeland Security, and every operation would require written approval. The directive bars targets that are an institutional part of a foreign government or wholly operated under a foreign government's direction. Current and former U.S. officials say that line is especially difficult to draw with Russia, where intelligence services have long tolerated, protected or intermittently recruited financially motivated hackers without full control.

Russia's Blurred Cyber Ecosystem

Russian intelligence services have long tolerated, protected or intermittently recruited financially motivated hackers without exercising full control over them. Michael Daniel, president of the Cyber Threat Alliance and a former White House cyber coordinator under Barack Obama, identified three categories — government control, government-affiliated and government-acknowledged — and said the line between them is blurry in Russia. Daniel said determining the exact relationship between Russian malicious actors and the Russian government has long been a challenge and is often impossible. Justin Sherman, CEO of Global Cyber Strategies, said Russia's cyber web is opaque and always shifting, with no single rule for understanding each relationship. Sherman said some of that ambiguity is intentional and allows the Kremlin to expand the pool of hackers it can covertly draw upon.

Private Firms' Information Gaps

U.S. companies have insights about Russian criminal groups but lack the broader intelligence available to the government, Justin Sherman said. Federal agencies can only share or declassify so much of what two spy agencies — the National Security Agency and CIA — collect, he added. Such intelligence collection can help firms determine targeting criteria, though it may not be enough for Russia's ever-evolving cyber landscape. With an incomplete picture, Sherman said, 'you're bound to get it wrong some of the time.'

1 source

Trump cyber directive runs into Russia's blurred state-criminal hacker boundary