Delegating Hacking Back: PMC-Style, Facility-Cleared Cyber Contractors Under CFAA § 1030(F)
Main Article Content
Abstract
Ransomware attacks on American organizations threaten the U.S.’s national security and economic stability. Under the Computer Fraud and Abuse Act (CFAA), private organizations are prohibited from taking self-help measures, such as “hacking back,” to defend against attacks. Instead, American organizations must rely on law enforcement, which is under-resourced and over burdened, to respond to an attack. Twice, Congress has declined to amend the CFAA to allow organizations to hack back under the Active Cyber Defense Certainty Act (ACDC Act), citing concerns over attribution, foreign policy implications, and immunity. This Note proposes a new framework for enabling organizations to hack back that would not require amending the CFAA.
This Note proposes that the federal government create a regulated industry of private “hack back contractors” that may conduct active cyber defense operations on behalf of victim organizations while remaining under the oversight of federal entities like the Federal Bureau of Investigation (FBI) or Department of Homeland Security (DHS). This Note argues that: (i) the law enforcement exception of the CFAA provides private organizations the legal authorization to hack back when delegated to do so by U.S. law enforcement and points to two recent federal district court cases that support this reading of the statute; and (ii) this proposal is congruent with the U.S.’s existing policy on private military contractors (PMCs) and granting of facility security clearances (FCLs).
Article Details

This work is licensed under a Creative Commons Attribution 4.0 International License.