U.S. Department of Justice to Treat Ransomware Hacks Like Terrorism Now: Here’s the Full Memo

U.S. Department of Justice to Treat Ransomware Hacks Like Terrorism Now: Here’s the Full Memo

The U.S. Department of Justice plans to take a much harsher tack when pursuing cybercriminals involved in ransomware attacks — and will investigate them using similar strategies to the ones currently employed against foreign and domestic terrorists.

The new internal guidelines, first reported by Reuters, were passed down to U.S. attorney’s offices throughout the country on Thursday, outlining a more coordinated approach to investigating attacks. The new guidance includes a stipulation that such investigations be “centrally coordinated” with the newly created task force on ransomware run by the Justice Department in Washington, DC. That task force, formed in April, is currently developing a “strategy that targets the entire criminal ecosystem around ransomware,” including “prosecutions, disruptions of ongoing attacks and curbs on services that support the attacks, such as online forums that advertise the sale of ransomware or hosting services that facilitate ransomware campaigns,” the Wall Street Journal previously reported.

“To ensure we can make necessary connections across national and global cases and investigations, and to allow us to develop a comprehensive picture of the national and economic security threats we face, we must enhance and centralize our internal tracking,” says the guidance, which runs just over three pages.

In response to a request for comment, the Justice Department provided the memo in full.

Screenshot: Gizmodo/DOJ
Screenshot: Gizmodo/DOJ

“It’s a specialised process to ensure we track all ransomware cases regardless of where it may be referred in this country, so you can make the connections between actors and work your way up to disrupt the whole chain,” John Carlin, acting deputy attorney general at the Justice Department, told Reuters. “We’ve used this model around terrorism before but never with ransomware,” he added.

The announcement follows an ongoing and ever-intensifying cybercrime spree — in which larger and larger commercial and governmental entities have been hamstrung by cybercrime groups. The last several weeks have seen large companies — including JBS and Colonial Pipeline — paralysed by hackers, throwing large industrial supply chains that millions of Americans rely on into chaos.

Read the full DOJ memo below: