The White House has a new memo on involving private cybersecurity companies in US defense against AI-driven hacks, vishing, and other attacks:
Transnational Criminal Organizations (TCOs) pose a growing threat to American citizens, businesses, and national security. These organizations conduct sustained cyber campaigns to perpetrate frauds that undermine American prosperity, security, and freedom. Through Executive Order 14390 of March 6, 2026 (Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens), I directed the Federal Government to take various actions to combat cyber‑enabled crime harming American citizens. This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector.
Chris Nyhuis, CEO of Vigilant, released the following comments that all organizations should follow:
It’s the right move. But it quietly changes the role of private cybersecurity companies in American national security. The biggest question isn’t whether America has the technical capability to fight back. It’s whether we establish the doctrine necessary to do it without making a cyber incident worse.
I support this. America has extraordinary cyber capability sitting in the private sector, and we should be putting some of that capability into the fight. But offensive capability without disciplined rules creates its own risk. Before America acts, we need to prove who we’re dealing with, contain the original intrusion, understand the escalation risk, and then decide what action actually accomplishes the mission.
The forthcoming federal operating rules need to establish a simple doctrine:
PROVE > CONTAIN > DECONFLICT > ACT > PROTECT
1. PROVE: “EVERYBODY WANTS TO KICK THE DOOR DOWN. SOMEBODY STILL HAS TO PROVE IT’S THE RIGHT DOOR.”
Cyber attribution has always been difficult. But the consequences of getting attribution wrong are about to become significantly greater.
“Cybersecurity companies use terms like ‘high confidence’ all the time. That’s one thing when the result is a threat-intelligence report. It’s something entirely different when that assessment becomes the basis for an operation against somebody else’s infrastructure.”
Attackers also understand how attribution works and can attempt to manipulate the evidence defenders rely upon. Infrastructure can be shared or compromised. Tools can be copied. Malware can be planted. Indicators can be manufactured. That creates a potentially dangerous scenario:
“Imagine you’re a foreign adversary and you can make America believe your enemy attacked us. If our attribution process isn’t strong enough, you don’t have to attack your enemy yourself. You try to manipulate us into doing it for you.”
Nyhuis believes the program should therefore establish one forensic attribution standard for every participating company.
“One company’s telemetry cannot become America’s definition of truth.”
Attribution should be independently corroborated and then subjected to an adversarial review in which another team actively attempts to prove the attribution wrong.
“Before you ask, ‘Why do we believe it’s them?’ put somebody in the room whose job is to prove that it isn’t.”
2. CONTAIN: “NEVER OPEN A SECOND FRONT WHILE THE ATTACKER IS STILL INSIDE YOUR PERIMETER.”
Correct attribution isn’t enough. Before an offensive operation begins, Nyhuis believes there is another question that has to be answered: Have we actually contained the original intrusion?
Removing malware, restoring a compromised server or blocking the attacker’s known access does not necessarily mean the attacker is gone. The adversary may still possess valid credentials, persistence mechanisms, undiscovered access paths or other footholds inside the victim’s environment.
“Before you start talking about going after somebody, you’d better know whether you’ve actually contained the original intrusion.”
Launching an offensive operation before containment has been established could turn one cyber incident into a two-front fight.
“Never open a second front while the attacker is still inside your perimeter.”
If the attacker retains access when their infrastructure is disrupted, they may already possess everything necessary to retaliate from inside the victim’s environment.
“Think about the position you’ve just created. You’re attacking outward while the adversary may still be operating inward. They don’t have to break back into your network to retaliate — they may already be there.”
The attacker could destroy evidence, steal additional information, establish new persistence, disrupt operations, or deploy destructive malware using access they already possess. That is why containment status and retaliation risk should be part of the government’s operational approval process.
“Offensive cyber doesn’t make incident response less important. It makes disciplined incident response more important.”
Containment also does not necessarily mean immediate eradication. There may be legitimate investigative or intelligence reasons to knowingly maintain visibility into an adversary. The critical distinction is whether continued adversary access is known and intentional or simply undiscovered.
“You can make a deliberate decision to observe an attacker who’s still inside. That’s very different from launching an offensive operation because everybody incorrectly assumed the attacker was gone.”
3. DECONFLICT: “THE TECHNICALLY CORRECT ACTION CAN STILL BE THE OPERATIONALLY WRONG ACTION.”
A cyber target rarely exists in isolation. The same infrastructure could be part of a corporate incident response, federal criminal investigation, intelligence operation, foreign-partner investigation or an active case involving victims.
Before private operators act, they need to know who else may already be operating in that environment, and what could be damaged by taking action.
“Cyberspace doesn’t put up a sign telling you that somebody else is already working the case.”
Nyhuis believes government deconfliction should therefore be a mandatory gate before offensive action. That becomes particularly important when an investigation involves live victims.
“If taking down a server destroys an evidence chain, alerts an offender or puts a victim at greater risk, you’ve won the technical battle and potentially lost the actual mission.”
The question cannot simply be whether an operator can disrupt the target. It has to be whether disrupting the target at that moment advances the larger mission.
“The technically correct action can still be the operationally wrong action.”
4. ACT: “OFFENSE NEEDS AN OBJECTIVE, NOT JUST A TARGET.”
Once attribution, containment, and deconfliction have been established, there is still one more question before action: What exactly are we trying to accomplish? Surveillance, intelligence collection, disruption, denial, degradation and destruction can produce very different consequences.
“The objective can’t simply be, ‘We found the bad guy, now hit him.’ What outcome are we trying to create? What happens when they respond? And what does success actually look like?”
An operation designed to collect intelligence should be evaluated differently from one intended to disrupt infrastructure. An operation intended to temporarily deny capability is different from one intended to permanently destroy it. And every action creates the possibility of a reaction.
Nyhuis believes escalation therefore needs to be evaluated as part of the operational decision—not after the operation has already begun.
“America absolutely needs the capability to go after foreign cybercriminals. But capability needs doctrine. Prove who did it. Contain the original intrusion. Understand the escalation risk. Then decide whether and how to act.”
Offensive cyber capability is ultimately a tool. The mission should determine how—and whether—that tool is used.
5. PROTECT: “IF AMERICA AUTHORIZES PRIVATE CITIZENS TO ENTER THE FIGHT, WHAT HAPPENS WHEN THE FIGHT FOLLOWS THEM HOME?”
There is another side of this program that Nyhuis believes cannot be an afterthought: Who protects the private-sector people conducting these operations? The individuals carrying out authorized operations may be private-sector cybersecurity professionals—not military personnel, federal law-enforcement officers, or diplomats.
That distinction matters.
“If the United States authorizes a private cybersecurity professional to disrupt a foreign criminal organization on America’s behalf, we need to think seriously about what happens to that person afterward.”
The United States may view the individual as an authorized participant in a lawful government-directed operation. The organization being targeted may see something much simpler: The person who attacked them. And the risk may not end when the operation does.
“Cyber operations don’t necessarily end when somebody closes the laptop.”
An operator who helps disrupt a sophisticated foreign criminal organization could potentially become a target for retaliation, identification, doxxing, intimidation, or other threats.
International travel raises another set of questions. What happens when that private-sector operator travels overseas months or years later? Could a foreign jurisdiction investigate or seek to detain the operator based on its own laws? What assistance would the United States provide? What happens if the criminal organization identifies the operator or their family?
These are questions the program should answer before the first operation is authorized, not after something goes wrong.
“We shouldn’t discover the government’s responsibility to these people when the first American cyber operator gets detained at a foreign airport or targeted because of an operation our government asked them to conduct.”
Nyhuis believes the framework should explicitly address operator identity protection, operational security, physical-security risk, foreign legal exposure, international travel, threat monitoring, and government assistance if an authorized operator is threatened or detained.
This isn’t an argument against using private-sector operators. It’s an argument for recognizing what America is asking them to do.
“If America asks private citizens to accept personal risk while conducting a U.S.-authorized cyber operation, then America needs to define what protection follows that authorization.”
Because bringing private cybersecurity professionals into national-security operations creates responsibilities in both directions.
“We need rules protecting America from a bad operation. But we also need rules protecting the Americans we’re asking to conduct a good one.”
THE DOCTRINE
The framework Nyhuis believes should govern private-sector offensive cyber operations can be reduced to five principles:
- PROVE
Do we have forensic evidence that identifies the right adversary?
- CONTAIN
Is the original attacker still inside — and what could they do if we escalate?
- DECONFLICT
Who else is operating, investigating or potentially at risk if we act?
- ACT
What outcome are we trying to achieve, what response should we anticipate, and is offensive action the right tool?
- PROTECT
What responsibility does the United States assume for the private citizens it authorizes to conduct these operations?
“America absolutely needs the capability to go after foreign cybercriminals. But capability needs doctrine. Prove who did it. Contain the original intrusion. Understand the escalation risk. Then decide whether and how to act — and protect the Americans we authorize to do it.”
UPDATE: John Strand, Owner, Black Hills Information Security, Inc. had this comment:
“This article is both exciting and concerning at the exact same time. It genuinely feels like the cyber equivalent of letters of marque, where private industry is authorized to conduct specific, targeted operations on behalf of the United States government.
There are a number of questions that immediately come to mind. How will oversight work? What are the limits of these authorities? Who is responsible for ensuring those limits aren’t exceeded? How does this fit within international law? Those are all critical issues that need to be answered before a program like this reaches full maturity.
“That said, it’s also important to acknowledge the strategic reality. Our adversaries are already operating this way. We’ve seen multiple reports of China leveraging private cybersecurity companies to conduct offensive cyber operations. Russia has long relied on so-called private hackers who carry out activities that align with government objectives. When our adversaries embrace a model that we refuse to consider, it can leave the United States at a strategic disadvantage.
“For that reason, I think this is a positive step, particularly for strengthening U.S. offensive cyber capabilities. At the same time, it has to be implemented carefully. Strong oversight and clearly defined legal boundaries are essential if this model is going to be successful.
“There’s another issue that deserves attention as well. If private security companies are going to participate in these operations, what level of legal protection and indemnification will they receive? Before any company signs a contract to perform offensive cyber activities on behalf of the U.S. government, those questions need clear answers.
“There’s a lot to unpack here, and I expect the next 60 to 90 days will determine not only how this proposal evolves, but also how the relationship between government and private industry develops in the offensive cyber space.”
Jeremiah Fowler, Researcher for Black Hills Information Security, Inc.:
“I personally see this as a positive step in combating cybercrime because it recognizes that some of the best technical expertise is outside of the government.
“The private sector cybersecurity community brings a wide range of skill sets and many have dealt with the aftermath and active defense from these threats on a daily basis. Cybercriminals and state sponsored groups have been attacking US companies and assets for years causing billions of dollars in damages and it’s good to see the gloves come off. Cybercriminals have benefited for years from jurisdictional boundaries and the difficulty of pursuing threat actors operating overseas and this program could be a game changer.
“Speed important in terms of cybersecurity and the perception is that government processes can be slowed down by bureaucracy. Criminal infrastructure can appear, move, and disappear in hours so a public-private model could help bridge that gap of speed and efficiency. Another benefit is information sharing. Private companies often see pieces of an attack that government agencies may not see, while law enforcement and intelligence agencies possess information unavailable to the private sector.”
Donald McFarlane, Advisory Board Member, Xcape, Inc.:
“This is not cyber vigilantism. It connects private-sector visibility and capability to lawful federal authority and oversight.
“This is a significant evolution of the public-private cyber partnership. We’re moving beyond simply sharing threat intelligence to creating a pathway by which threat information acquired through normal business activities, along with threats identified by state and local government, can feed proposed operations for federal approval.
“Capability is not going to be the scarce resource. Target validation, competing intelligence equities and deconfliction will be. The NCC is going to be busy. The secret’s in the deconfliction.”
Corey Ham, Director of Continuous Pentesting, Black Hills Information Security, Inc.:
“My primary concern is the security of these contractors. Giving more entities access to sensitive information increases the likelihood that it can be compromised. Most of the information we have on Chinese state-sponsored hacking similar to this is from data leaks and breaches affecting contractors like I-Soon, for example. I worry that both nation states and crime groups will compromise the contractors who are targeting them, and access information they should not be able to access, like forensic data from other targets or classified data.”
Hackers claim medical data breach affecting nearly 19 million people in Poland
Posted in Commentary with tags Hacked on August 14, 2026 by itnerdPolish healthcare platform MyDr has confirmed (translation here) a cyberattack after hackers claimed to have stolen data belonging to 18.8 million people, roughly half of Poland’s population.
The attackers claim to possess more than 2.5 terabytes of data, while MyDr said the affected information likely dates from 2024 and earlier and that it is still conducting a forensic investigation to determine the scope of the breach.
MyDr processes information including PESEL national identification numbers, prescriptions, medical appointments and other personally identifiable information. As evidence of the breach, the attackers reportedly provided journalists with a prominent Polish politician’s PESEL number, two phone numbers and 25 prescriptions.
“We are dealing with one of the largest data leaks in history,” Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski said.
Denis Calderone, CTO, Suzu Labs:
“This is Poland’s third major cyber incident in as many months, and this one is the worst. Water treatment and energy infrastructure attacks are disruptive, but they’re largely recoverable. In this case we’re talking about a major EMR vendor servicing over 12,000 clinics nationwide. It’s reported that PESEL numbers (national identity numbers), prescriptions, and diagnoses for 18.8 million people were exposed. That’s roughly half the country who just had their personal identification numbers compromised. Ouch!
“MyDr processes roughly three million medical consultations and 2.7 million prescriptions every month. PM Tusk was quick to frame this as a private company, not a state institution. But when a single private vendor is holding that volume of clinical data and national identity numbers, the line between private vendor and public infrastructure is gone. The US learned this lesson with Change Healthcare in 2024. Change was a payments clearinghouse, not an EMR, but the architectural failure was the same: one vendor became the single point of failure for a national healthcare ecosystem. Change hit 192 million Americans. MyDr reportedly hit 18.8 million Poles. Similar proportional impact.
“The Polish government is advising citizens to lock their PESEL numbers through the mObywatel app, and that’s a good first step. But PESEL locking covers specific financial transactions and doesn’t extend to every context where an identity number can be misused. And then there’s the medical data. Prescriptions and diagnoses aren’t just PII, they’re blackmail material. A politician’s 25 prescriptions were already used as proof of the breach. Scale that across 18.8 million people and you have a dataset that will fuel identity fraud, targeted phishing, and extortion for years.
“The full details of how the attackers got in haven’t been disclosed yet. Healthcare organizations and third-party EMR vendors everywhere should be attentive to the revelations from this incident and shore up their own defenses accordingly. The regulatory timing is worth noting. Poland implemented the EU’s NIS2 directive into law on April 3 of this year, 17 months past the EU deadline, and healthcare is a covered sector. But entity registration isn’t due until October, mandatory ISMS implementation until April 2027, and the first cybersecurity audits until 2028. This breach landed in the exact gap between the law existing on paper and anyone having to prove they comply. Countries also need to stop treating national identity numbers as secrets. PESEL, Social Security numbers, and their equivalents were designed as indexes, not authentication factors.”
Damon Small, Board of Directors, Xcape, Inc.:
“Centralizing health records creates immense systemic liability, especially when exfiltration compromises half a nation’s population. While the threat actor identity and precise initial access vector remain unknown, the theft of 2.5 terabytes of medical data from Polish aggregator MyDr exposes 18.8 million people to extortion, targeted medical insurance fraud, and identity theft. Medical records remain among the most valuable assets on the black market, yet exfiltrating terabytes of sensitive files unnoticed highlights a glaring absence of basic network egress monitoring. Security leaders must recognize that protecting health data requires more than perimeter defense. Organizations must deploy strict data loss prevention controls, implement rate-limiting and anomaly detection on database queries, and establish real-time egress monitoring to flag massive data movements before records leave for the public Internet.
“Critical Takeaways
“We may not know who stole the data or how they got in, but we certainly know nobody was watching the exit.”
Seemant Sehgal, Founder & CEO, BreachLock:
“Half a population’s medical records exposed in a single incident, and the story almost always becomes about the attacker, when the conversation needs to focus on the years leading up to the attack. 2.5 terabytes does not leave a network quietly. That kind of exfiltration takes time, and time means signals. The decisions that shape an incident like this are made long before anyone finds a way in, and that is where the most valuable reflection has to start.”
Leave a comment »