Foreign-Sponsored Cyber Theft, Restitution & State Accountability

FOREIGN-SPONSORED CYBER THEFT, RESTITUTION & STATE ACCOUNTABILITY

POSITION

A foreign government that directs, sponsors, materially assists, or knowingly protects cyber theft and fraud against Americans should bear the verified cost. Victims receive restitution first. Attribution must rest on evidence and independent review, not politics, rumor, or the fact that traffic passed through a country's network.

WHEN A COUNTRY IS RESPONSIBLE

A country may be held responsible when reliable evidence establishes that its government, military, intelligence service, public company, proxy, or controlled organization:

  1. directed, sponsored, financed, supplied, or materially assisted the operation;

  2. provided infrastructure, credentials, intelligence, safe harbor, laundering, or operational support with knowledge of the scheme;

  3. knowingly protected identified perpetrators after receiving credible evidence and a reasonable opportunity to investigate, cooperate, extradite, prosecute, or stop the activity.

Nationality, internet routing, rented infrastructure, or a criminal's physical location alone is not enough.

ATTRIBUTION & REVIEW

The Department of Justice, Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of the Treasury, Department of State, and intelligence community must produce a coordinated written attribution record. The record should identify the conduct, losses, evidence, confidence, competing explanations, foreign-government connection, cooperation requested, and response received.

A classified record receives independent review by a cleared court or review body. A public version must disclose as much evidence and reasoning as security permits. A materially affected country or asset owner receives notice and an opportunity to answer unless a temporary court-authorized delay is necessary to prevent flight, asset transfer, evidence destruction, or an immediate security threat.

VICTIM RESTITUTION & SOVEREIGN ASSESSMENT

  • Verified victims receive 100% restitution for direct financial loss, reasonable recovery expense, identity restoration, and other provable damage recognized by law.

  • The responsible country receives an additional sovereign assessment equal to 100% of verified losses.

  • For a repeated operation, refusal to stop identified perpetrators, material obstruction, or deliberate concealment, the additional assessment may rise to 200% of verified losses.

  • Victim restitution is paid before the additional assessment is used for government revenue.

COLLECTION TOOLS

Collection may use targeted sanctions, reciprocal tariffs, transaction restrictions, procurement bans, forfeited criminal proceeds, and legally reachable non-diplomatic commercial assets. Diplomatic property, humanitarian trade, and assets protected by law remain protected. A measure must identify the unpaid loss, affected actor, review date, and conditions for reduction or termination.

INDIVIDUAL ACCOUNTABILITY & COOPERATION

Sovereign accountability does not replace prosecution of the hackers, fraud organizers, money launderers, corrupt insiders, or companies that knowingly enabled the scheme. A country that promptly cooperates, preserves evidence, stops the operation, prosecutes responsible actors, and provides restitution receives credit when the response is set. A country that knowingly protects the operation receives stronger consequences.

WHAT WE WILL MEASURE

Public reporting should track verified victim losses, restitution ordered and paid, attribution confidence, review outcomes, foreign cooperation, perpetrators charged, infrastructure disrupted, assessments collected, sanctions and tariffs imposed, effects on lawful trade, repeat attacks, and false-attribution corrections.

Core MPA standard: Follow the evidence. Pay the victims first. Make state sponsors and knowing safe-harbor governments bear the verified cost. Do not punish a country merely because a criminal routed traffic through it.

Related policies: National Cybersecurity Standards & Trusted Personnel; Strategic Adversaries & Authoritarian States; Foreign Affairs; Investigations, Enforcement Deadlines & Due Process.

Status: Proposed / Draft, not yet formally adopted.

Originally published: September 29, 2026.

Last updated: September 29, 2026.

Version: Draft 0.1.

Next
Next

Fair Courts & Abuse of Process Reform