The United States has moved from debating “hack back” in the abstract to building a controlled, government-run channel for it—authorizing vetted private companies to execute offensive cyber operations against foreign criminal networks under federal command.
At a Glance
- A presidential memorandum established a program for private firms to conduct government-directed cyber surveillance and disruption against foreign criminal groups.
- Operations occur under the direction, control, and authority of the U.S. government—not freelance corporate retaliation.
- Companies must be vetted, contracted by DOJ/DHS, follow strict procedures, and post financial guarantees to enforce compliance.
- The remit targets transnational criminal organizations, not foreign states, aiming to blunt cybercrime costing Americans billions annually.
What the program actually authorizes—and what it does not
On August 12, 2026, President Trump signed a presidential memorandum titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” creating a formal structure for private-sector participation in offensive cyber activity against foreign criminal groups that victimize Americans. The White House characterized this as bringing private-sector ingenuity to bear against transnational criminal organizations, while making plain that any operations occur “under the direction, control, and authority of the U.S. Government,” not on a company’s own initiative. In parallel, reporting describes two operational categories: cyber surveillance operations to collect intelligence, and cyber effects operations that can disrupt or destroy adversary systems or data to achieve lawful disruption objectives.
The mechanism matters. This is not a blanket permission slip. Companies that participate do so as government contractors, under Department of Justice and Department of Homeland Security oversight, after rigorous vetting and pursuant to contracts that specify procedures and limits. Offensive actions are executed exclusively on behalf of the federal government and require written authorization on a per-operation basis. Several accounts detail concrete guardrails: an approval workflow at DOJ/DHS, strict operational procedures, and escrow or bond requirements—at least $1 million posted and forfeitable for violations—to align incentives and enforce compliance.
Why the United States is doing this now
The policy is a direct response to the rise of cross-border cybercrime: ransomware syndicates, business email compromise crews, and infrastructure-targeting gangs that operate from permissive jurisdictions, inflict real-world harm in the United States, and move too quickly for traditional mutual legal assistance channels. The administration tied the initiative to the scale of annual losses borne by U.S. citizens and businesses—at the level of billions to tens of billions of dollars—arguing that stronger disruption capacity is warranted. The remit is explicitly criminal: foreign criminal groups, not governments, fall within scope, which aligns the program with law-enforcement authorities focused on transnational criminal organizations rather than state-on-state cyber conflict.
Strategically, the model attempts to reconcile two stubborn realities. First, unauthorized private retaliation across networks is largely prohibited under the Computer Fraud and Abuse Act and analogous statutes; U.S. cyber policy has long discouraged vigilante hacking by victims. Second, federal teams cannot scale to every compromised hospital or small business in real time. A government-directed, contractor-executed option is an institutional answer to that gap—expanding capacity without abandoning legal control.
How the government keeps operational control
Program architecture, as described in the memorandum and corroborating coverage, concentrates decision rights in government hands. Vetting gates who is eligible; contracts define scope; approvals are issued operation-by-operation; and federal oversight supervises execution. The operational categories—surveillance for intelligence and effects for disruption—are defined to match the objective of dismantling or degrading criminal infrastructure. The financial safeguard, including escrowed funds at a seven-figure floor, is a compliance backstop: it creates consequences if a contractor exceeds authorization or deviates from procedure.
Practically, this means the government can surge capacity while preserving chain-of-command clarity and evidentiary hygiene. Surveillance activity generates intelligence that can support arrests, seizures, or sanctions. Effects operations, when authorized, can neutralize staging servers, encryptors, or command-and-control nodes. The design choice to narrow scope to foreign criminal organizations reduces diplomatic entanglement, even as DOJ and DHS approvals ensure each action is legally grounded and risk-assessed against collateral impact standards common in cyber disruption work.
Where this fits in the arc of U.S. cyber policy
The United States has wrestled for years with whether and how to allow private contribution to offensive cyber operations. After waves of ransomware and systemic compromises, proposals repeatedly surfaced to deputize private capability under strict government authority. What distinguishes this memorandum is that it formalizes a pipeline: identification of qualified firms, vetted access, contract-based tasking, and defined operational categories under DOJ/DHS control. In that sense, it is a capacity-building measure inside the existing legal architecture rather than a free-market license to strike adversaries.
Historically, unauthorized “hack back” presented three show-stopping risks: misattribution in a technically deceptive environment; collateral damage on multi-tenant infrastructure; and escalation with foreign sovereigns. A government-run regime addresses those by centralizing attribution processes, applying standardized impact assessments, and bounding targets to criminal entities operating abroad. It also connects technical action to law-enforcement outcomes: seizures, arrests, sanctions designations, and infrastructure takedowns are more effective when intelligence and disruption are coordinated under prosecutorial oversight.
Program scope and likely use-cases
Based on the memorandum’s framing and subsequent briefings, the initial use-cases will likely center on criminal infrastructure that is both functionally essential to an illicit enterprise and jurisdictionally insulated from routine U.S. subpoenas. Examples include: botnet command servers used to deploy ransomware encryptors, bulletproof hosting nodes trafficking stolen financial data, and staging environments for business email compromise campaigns. Cyber surveillance operations can map networks, identify operators, and collect indicators for broader disruption; cyber effects operations can directly disable infrastructure that is actively harming American victims, when approved.
This division of labor mirrors counter-crime playbooks in other domains: intelligence first, effects when the legal and operational case is mature. For victims, the tangible upside is speed. Instead of waiting out cross-border paperwork while a ransomware crew reconstitutes, a government-authorized team could have legal cover to surveil, identify, and in certain circumstances disable the infrastructure mid-campaign, while preserving evidence for follow-on prosecutions or sanctions.
The Trump Administration's new "hacking back" program raises a lot of issues about the Computer Fraud and Abuse Act, the federal computer hacking statute. Here's an overview of those issues, new from me at Volokh. https://t.co/kNOgZnIvgP
— Orin Kerr (@OrinKerr) August 17, 2026
Safeguards, authorities, and implementation details
The White House, DOJ, and DHS anchored the program in a direction-and-control model that preserves federal authority. Reporting indicates that companies must pass rigorous vetting, operate only under written tasking, and adhere to strict procedures; they are financially bonded to deter and punish violations. The memorandum’s focus on criminal groups, not governments, keeps the program aligned with transnational crime authorities and avoids recasting it as a foreign policy instrument, which would entail a different legal and oversight regime.
As with any new operational model, details matter for durability: implementing guidance, approval hierarchies, and rules of engagement translate principle into practice. But the backbone is clear from the presidential memorandum and reputable reporting: the United States has created a structured, government-run path to employ private offensive cyber expertise against foreign criminal networks that target Americans, with federal officials deciding who acts, when, and how.
What to watch next
The proof point for any disruption program is effect. Because the initiative is framed as an anti-crime capability, the most consequential markers will be coordinated takedowns of infrastructure, arrests facilitated by shared intelligence, and measurable disruption of active criminal campaigns. Given the program’s design, look for DOJ and DHS to emphasize contractor vetting outcomes, approval discipline, and case studies where surveillance intelligence fed directly into effects operations and prosecutions. The narrative will be anchored not in slogans about “privateers,” but in whether the combined public-private team reduces the operational freedom of foreign cybercriminals who profit from attacking Americans.
Sources:
reason.com, federalnewsnetwork.com, theregister.com, whitehouse.gov, cnn.com, labs.cloudsecurityalliance.org, plainsec.com



