President Barack Obama ordered a new sanctions program Wednesday which could block assets of US and foreign hackers and of companies that seek to profit from cyberattacks.
Obama said the threat from cyberattacks was a "national emergency" and the new sanctions could help strike back against those involved in attacks on US targets.
"Starting today, we're giving notice to those who pose significant threats to our security or economy by damaging our critical infrastructure, disrupting or hijacking our computer networks, or stealing the trade secrets of American companies or the personal information of American citizens for profit," Obama said in a blog post released by the White House.
He added that cyber threats "pose one of the most serious economic and national security challenges to the United States," and that the sanctions will take aim both at hackers and "against companies that knowingly use stolen trade secrets to undermine our nation's economic health."
Obama said in his statement that hackers in China, Russia and Iran were among those attacking US targets and added that "it's often hard to go after bad actors, in part because of weak or poorly enforced foreign laws, or because some governments are either unwilling or unable to crack down on those responsible."
The announcement comes amid an epidemic of incidents reported in recent months, including a devastating attack against Sony Pictures, and data breaches that stole credit card or health data on tens of millions of Americans.
Under the order, the US Treasury would be able to freeze or block assets of those involved in attacks on "critical" US computer networks, such as banking systems or electic power, or the theft of data such as credit card information, and of companies that profit from such attacks.
"Cyber intrusions and attacks -- many of them originating overseas -- are targeting our businesses, stealing trade secrets, and costing American jobs. Iranian hackers have targeted American banks," Obama said.
- Countering the threat -
"The North Korean cyber attack on Sony Pictures destroyed data and disabled thousands of computers. In other recent breaches that have made headlines, more than 100 million Americans had their personal data compromised, including credit card and medical information."
Obama said he would "employ the authorities of my office and this administration, including diplomatic engagement, trade policy tools, and law enforcement mechanisms, to counter the threat posed by malicious cyber actors."
The executive order allows the Treasury and Attorney General's office to impose sanctions on hackers posing "a significant threat to the national security, foreign policy, or economic health or financial stability of the United States."
This could respond to so-called distributed denial-of-service attacks, theft of trade secrets or credit card numbers or other "sensitive information," according to a White House statement.
Sanctions could also be imposed on companies that use trade secrets or other stolen data or assist hackers in their efforts.
Officials said there were no immediate plans to use these sanctions but that the additional tool would bolster US efforts using law enforcement, diplomacy or military actions.
"We intend to use this tool judiciously and in extraordinary circumstances," said John Smith of the Treasury's Office of Foreign Assets Control, which administers sanctions.
Obama said the new sanctions would "in no way target the unwitting victims of cyberattacks," such as people whose computers are hijacked, and that the program would not be used against cybersecurity researchers or to curb freedom of online expression.
The sanctions are "not a tool that we will use every day," US national security adviser Lisa Monaco said, adding that "law-abiding companies have absolutely nothing to worry about."
Under the program, a company or individual who claims to be unfairly targeted could file an administrative appeal or challenge the designation in court, officials said.