The US will allow approved private companies to hack foreign cybercriminal groups under government supervision, targeting ransomware and online fraud networks. The move has divided cybersecurity experts over its potential effectiveness, oversight and risks of retaliation and diplomatic disputes.