Federal Cyber Hack-Back Plan Raises Attribution Risks
### Federal Cyber Hack-Back Enters a New Phase
Federal cyber hack-back policy is moving into a more formal phase as government agencies explore deeper collaboration with private cybersecurity firms. In this Techstrong TV interview, Mike Vizard talks with Chris Nyhuis, President and CEO of Vigilant, about what that shift could mean for offensive cyber operations.
Nyhuis explains that private companies have supported government cyber operations before. What is changing now is the push to formalize the process. Under the model discussed, approved U.S. contractors could work with the federal government after an organization submits evidence of an attack.
### Attribution Is the Hardest Problem
The biggest challenge is attribution. Nyhuis notes that separating criminal groups from nation-state activity can be difficult. The line has become even less clear as some hacking groups borrow tools, training and tactics from larger geopolitical actors.
Attackers can also mimic another group’s fingerprints. They may copy infrastructure, coding styles or attack patterns. That creates risk when evidence looks convincing but points in the wrong direction. A federal cyber hack-back program must account for that uncertainty before action is taken.
### Private Sector Speed Meets Government Oversight
The conversation also explores why the private sector is attractive to government leaders. Cybersecurity companies often move faster than federal agencies. They can develop new tools quickly and bring specialized expertise to complex investigations.
That speed still needs guardrails. Offensive cyber activity is not the same as simply returning fire. Actions taken against the wrong target could create legal, diplomatic or operational consequences. Nyhuis says governance, precision and authorization will be essential.
### AI Adds More Complexity
AI could make the model more powerful, but it also raises the stakes. If AI is used in offensive operations, poorly defined instructions or weak oversight could lead to unintended outcomes. That is especially concerning when attribution is already difficult.
For security leaders, the discussion highlights a central tradeoff. A federal cyber hack-back program may give defenders more options against organized cybercrime. It also requires a careful framework for evidence, oversight and accountability.
Transcript
Hey guys, thanks for the thrill. We're here with Chris Nyhuis, who's the CEO of Vigilant, and we're having a little chat about this new federal initiative that's going to recruit some folks to maybe pursue some more offensive tactics when it comes to defending our cybersecurity infrastructure and our interests anywhere in the world, probably. Chris, welcome to the show.
Thanks, Mike. It's great to be here. Some folks have applauded this.
Some people have raised some questions, and some people are like, "Well, is this the modern version of we're having a bunch of privateers that we're going to go send out and pull in some, I don't know, booty? " It's not clear what exactly is going to be collected here or what the process is going to be, but walk us through this program as you understand it. Yep.
So I'll say out of the bat, this is not new. So there have been private companies doing this for quite some time. They have direct relationships with agencies, US government, to carry out similar offensive, more hack back type approach.
Now, what's happening now is there's a lot more formalization put towards it. And it also, I think in a smart way, elicits the federal government going out to the private sector, which is much faster, much quicker at developing new technology, has a lot more resources, and to be part of this offensive fight. What basically this legislation or this policy does is it creates a centralized governing body that will create relationships with private sector organizations, cybersecurity companies.
Now, those cybersecurity companies have to be US contracted through this program so that an organization that gets hacked can submit the evidence of that hack, and then these contractor organizations will go out and, in conjunction with the US government, go after that entity that attacked them. Now, this doesn't mean nation states. So we're not talking about China, Russia, Iran.
These are non-nation state entities. The US government's going to keep Iran and Russia and all those to themselves. But these are more organized crime entities or factions or groups like that.
Well, there's a lot to unpack there, but how do I know what's a unaffiliated group versus something that is kind of attached to a nation state? Because it seems like that line's been pretty blurry over the last few years. Yeah, Mike, that is going to be, I think, the single most critical piece to this entire policy.
I think it could also potentially be the Achilles heel of it as well. And what you're talking about there is attribution. And it's, how do we attribute this attack to someone?
And a couple things made that harder. Back in 2020, when COVID hit, we had a lot of these middle-tier hacking groups. They had a lot of time on their hands, and they went and joined forces with a lot of these nation states.
They were given tools, training, education, funding, and basically with this, "Hey, we're going to help you out. We're going to give you information. We're going to give you technology and tools.
You can use it. Go do your thing. " So that's one thing.
So you're right. It blurred the lines. The second thing is this attribution thing, right?
It is very easy for anybody to mimic anyone else in an attack. If I wanted to attack someone and make it look like it was coming from your house, I could easily do that. I could go out, mimic your IP address.
I could mimic your system. I could do it from your office. I could learn your patterns, and I could make anyone think that you were the one that did it, and the evidence would be pretty credible.
The same thing goes for hackers from China or hackers from Iran, or even just individual groups, because all of them leave a fingerprint. They might write code a certain way, or they might attack from different places. And so when you're attributing, the big issue here is that the US government and the cybersecurity industry has made all of those findings about the attribution, what do people do, very public.
So anyone can go read these documents and then just do exactly that, and it would look like it came from China, or it would look like it came from Russia. So it's going to be an interesting thing when people start hacking the wrong people. Where's that fine line between a lawful act and what other people might consider unlawful in the sense that if you hack into something that is a server that sits in a foreign country, some people technically would consider that an act of war.
So how do I kind of navigate that? It's a hard one, right? Right now, Biden had put this in place, in policy.
Anyone that hacks the United States, it's an act of war. And that was a pretty bold statement because it meant we have to respond. Now, before this policy, and it's still being designed, and over the next 60 days, we'll get more information on it.
But prior to this, if you were not sanctioned by the US government, it was illegal and a felony to hack back. So that's what, again, what this does is it allows more people to be part of this already designed program. But when it comes to that is, any type of hack back to a nation state, and that's why they're really clear in the policy, this does not affect- ...
countries, right? So in this policy, in no way, shape, or form should it be ever focused at a country. It should only be focused at hacking groups or factions or organized crime.
The question comes in here is, well, what happens if they're organized crimes in the United States? Or what happens if they're organized crimes in Russia, or it's in China, and Russia says anything you hack in the entire region of Russia is an act of war, right? Then it pretty much nullifies this unless we decide we don't care, and we're just going to do it anyway.
And if they want to make it an act of war, they can. Is there a reason why this program seems to be organized under the DOJ rather than, say, the DOD? And to that effect, I couldn't help but wonder, is this more of a privateer model, or is it really more like, "Hey, we got a posse.
" So it's more around the different government entities are separated on purpose around legality, jurisdiction. I would even say, what legally could come back at them in an international court. So I think it was really, really smart for it to be under DOJ for a couple of reasons.
One, not being under the Pentagon is pretty important because if the Pentagon is saying, "Yes, go hack," and then they do, and the Pentagon's involved or general's involved or whoever, then it immediately becomes an act of war because our War Department went ahead and did it. But then when you look at the Pentagon, the Pentagon doesn't have the ability to prosecute offenses, and the DOJ does. So only the DOJ can go to a judge, and only the DOJ can decide, is this a state crime?
Is it a federal crime? So, that's really why they did that. It's really around what's their jurisdiction, what can they do, how do we streamline things, and how do we also separate the War Department from a lot of this activity that's taking place?
Now, we know the War Department's going to be involved in it. In part of it, we've seen that in the policy. However, it is heavily DOJ and Homeland Security.
This is all happening against the backdrop where we're kind of involved in an AI arms race in security these days, and that all happens at machine speed. So how do you think this is going to play out in that kind of a landscape where the attacks are increasing in volume and sophistication, and theoretically at least, we are going to get- Yeah ... better at responding at the same rate, but there may be a little gap between those two events.
But how will this play out at that level of interaction? Yeah. So I think one thing is, I think we have to step back a little bit from what AI's really doing.
We just saw recently, AI at OpenAI, and had an instance where they hacked another organization. And then all of a sudden, Anthropic's like, "Me too. " And so you have these organizations that said, "Oh," and it was rogue, right?
Well, it wasn't rogue. AI, it's not going rogue. It's operating off the training that we give it, and it's operating off of the instructions that were given.
And if you look back at those two attacks, they were given instructions that they took full awareness and access to. But in both of those cases, it took instruction and did something unintended, right? And so one of the things that we have to be really careful of here is if we're using AI to hack back, it could possibly do something unintended if we're not as precise around the instructions.
So that's one of the big things. And this policy doesn't actually speak to AI directly. It talks about automation.
And so I would assume that they're going to allow AI inside of this hacking back, but I think we have to be really, really careful and, I would say, more deterministic around how we're choosing who actually did it and how we're hacking back. " Right? And even in those two attacks by OpenAI and Anthropic, it didn't do some novel new type of attack.
It used regular, everyday things that were already open and vulnerable there. But the thing around AI is it always takes time to learn, right? And now it can learn faster than a human can, if you're feeding it information.
But when you're hacking someone offensively, it's not just this thing where you just return fire. You have to be low and slow. You have to be intentional.
You have to learn about the person you're attacking. You have to teach your AI how you're going to attack, and then eventually you carry that attack out. We do a lot of recon, and then we turn that recon into decisions, and then we turn those decisions into actions, and then we have to see if those actions actually did what we intended, right?
And we go back through that. So I think what a lot of people see in their brain is that this is going to be this thing where someone attacks us, and all of a sudden, we're just going to unleash AI, and that would be very sloppy if we did that. But the other part is that the attack back might take six months to do, right?
It might take eight months to do. It's not going to be this immediate thing because AI doesn't work like that. It may very well have a lot of collateral damage that's also unintended, right?
Oh, the faster you do it without identifying and teaching and training and learning with AI, you will have the more collateral damage, the faster you are on the trigger pull for AI. Yeah So how is all this being funded? Because, in the days of yore, the privateers would get a cut of the booty, and that's why they were all signing up during the American Revolution.
Yeah. And they went out and they made a boatload of money. But who's paying for all this, and how will it all come together?
So, that's a great question. They haven't put that out into anything yet. My assumption on the way this will play out is in the private sector, one of the currencies in the cyber industry is access, right?
Access to the DoD, access to agencies, access to intel. And so I would... They're talking about using private sector organizations, and it's going to be very exclusive, right?
Not everyone's going to be able to be part of it. There's going to be certain criteria you have to meet to be part of it. They're allowing small organizations and large, but you have to be a US-based company.
So that, I think what will probably happen, if I'm guessing right now, is that some organizations will get a government contract, but most organizations will do it voluntarily. And they'll do it voluntarily because they'll want access. And I think that would be the currency in this whole thing.
" Because ultimately, in a ransomware attack, for instance, a hacker steals a bunch of money. They might steal $2 million from 25 different companies. When the DOJ gets that money back, they distribute that back out to the companies that got hacked, right?
So that's the thing. The other thing I think that we'll see, alongside of that, who gets me involved is I think you're also going to see where a lot of cyber companies are going to be pushed out of it because they're not US-based. I think that's actually a good thing, because we have to realize that US citizens are always going to protect the United States better than a non-US citizen will.
We see that around the world, right? Whenever we show up and if someone doesn't agree with what we're doing, they just walk away, right? " Do you have any sense of which attacks are going to warrant this level of response?
If I'm an organization, is there somebody I call, and then there's a pool of these things, and there's X amount of resources? What's the triage there? Yeah, so there's basically, an organization will have to submit a document around the attack they experienced.
They'll have to then give that to this new entity, these entities. There's a director that will have to sign off on any action that's taken place. So I think that's going to take time as well.
And now, your question around what warrants an attack back, they haven't released that. And if I'm them, I would never release that. Because what you would basically be doing is giving this bar that people that are hackers will know what that bar is, and they'll just either operate underneath it or they'll know when you're going to respond.
And it's one of those things, it's you never want to show your opponent your tactics or your strategy, right? You can show them your tactics, but not strategy. And I think if they do release what that bar is, I think this entire thing will fall apart.
And I think hackers will manipulate it in big ways. Should we be concerned about where this kind of bleeds into cyber espionage? Because to be honest, the United States gives as good as it gets, but we'll have other countries out there that might take that as a cybercrime and launch their own similar program, and then it all becomes a series of escalations.
Yeah. So other countries actually do have these types of programs already. The differences are usually these countries have these directly attached to a military unit.
So like in China, they have hackers that are part of... But they bring them into their military to do it, and they give them all the protection of the military, right? In this case, organizations that are part of this, they're not going to get all the protection of the US government.
So if they do something wrong, the US government will protect them for up to a million dollars, right? Which is not very much at all. They're not going to protect their employees either, right?
So if their employee does something, they might get held accountable. Or say you're hacking Russia and you travel to Europe, and Russia knows that you're part of this hacking group, and they just track you and then you disappear, right? So, there's that kind of thing that takes place as well.
But when it comes to just overall, there's so much in this that hasn't really been thought completely through yet. And there's a lot of loose, I would say, loose shoestrings that we can really get tripped up on. But when it comes to these cyber espionage, where I'm more concerned about this is that there's a lot of cyber companies out there that are actually not secure themselves.
We just saw recently, just in the news this week, one of them got hit, right? And it's not unheard of. You have businesses that are not secure out there.
So where the espionage, I think, will take place is you'll have these organizations that are less secure than maybe the center core that's working with US government and another country's going to hack them to learn about- the communications that are happening within this platform, right? And so I think there's a lot to think about when it comes to how do we protect the organizations better that are part of it, how do we protect the individuals, and how do we stop cyber espionage from coming through those entities. All right.
That's a great question, by the way. What are we not thinking through enough here? There's been a lot of chatter, but the question is, I'm sure there's something that people are overlooking.
Yeah, so much. I think the biggest things we have to answer are how do we protect the businesses and the people that are involved in this, right? I think that's the first thing.
I think another one there is how do we vet the organizations? There's cybersecurity companies here in the US that have foreign nationals working for them that I know that along the way, through the last few decades of my career, there's been instances where they've been infiltrated by Russian agents or Chinese agents, and they've worked at those companies, and they've gained intelligence. And so we have to be really careful that we vet the entire organization.
So I think one thing that I personally would do is I wouldn't bring larger cyber companies into this program off the bat because they're going to be a lot more bureaucratic. You're going to find a lot more red tape. I think if you work with smaller cyber firms that have the capabilities, I think you're going to be able to vet people better.
You're going to be able to have information loop back really quickly so you can make quick changes to it. And then bring in those larger organizations once you get those policies in place. But the number one thing is going to be attribution.
The number one is how do we determine who actually really did it? And I'll say most cyber technology that's out there today doesn't have the capabilities in the way it detects the threat to actually be able to attribute to who the threat actor is. There's very few cyber companies that actually collect the right data continuously in an organization to attribute even potentially of who it might be.
All right. Well, folks, you heard it here. Hey, the Cybersecurity Sheriff has a new deputy in town, or multiple deputies is one way to think about this.
Yeah. And better or worse, we're all about to see what's going to happen firsthand. Hey, Chris, thanks for being on the show.
Oh, my pleasure, Mike. It was great. Great questions.
It was awesome. And as always, back to you guys in the studio.