In the U.S., deploying a counterattack on a threat actor is **illegal** because of laws like the *Computer Fraud and Abuse Act of 1986* and the *Cybersecurity Information Sharing Act of 2015*, among others. You can only defend.
The act of counterattacking in the U.S. is perceived as an act of *vigilantism*. A vigilante is a person who is not a member of law enforcement who decides to stop a crime on their own. And because threat actors are criminals, counterattacks can lead to further escalation of the attack, which can cause even more damage and harm.
Lastly, if the threat actor in question is a state-sponsored [[Threat Actor#^hacktivist|hacktivist]] , a counterattack can lead to serious international implications.
### International standpoint on counterattacks
**The International Court of Justice** (ICJ), which updates its guidance regularly, states that a person or group can counterattack if:
- The counterattack will only affect the party that attacked first.
- The counterattack is a direct communication asking the initial attacker to stop.
- The counterattack does not escalate the situation.
- The counterattack effects can be reversed.
Organizations typically do not counterattack because the above scenarios and parameters are hard to measure. There is a lot of uncertainty dictating what is and is not lawful, and at times negative outcomes are very difficult to control. Counterattack actions generally lead to a worse outcome, especially when you are not an experienced professional in the field.