President Trump signed a National Security Presidential Memorandum on August 12, 2026, titled "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," creating the first formal U.S. program to let vetted private companies conduct offensive cyber operations against foreign criminal networks. It is a significant move — but not the one most headlines suggest.
What the memo actually authorizes
The memorandum does not let a hacked company hack back on its own initiative. It establishes a government-run "Program," administered through the National Coordination Center (NCC, originally stood up under a January 2025 executive order and now repurposed as the federal cybercrime hub), under which "Participating Companies" sign contracts with the Justice Department or the Department of Homeland Security to conduct "Cyber Surveillance Operations" and "Cyber Effects Operations" against foreign Cyber-Enabled Transnational Criminal Organizations — ransomware crews, sextortion rings, phishing operators, and financial-fraud networks.
Every operation requires written sign-off from two co-Executive Directors, one from DOJ and one from DHS, and neither can approve anything producing a "Critical Outcome" — loss of life, serious injury, or conduct rising to an armed attack under international law. Companies must clear a vetting bar covering technical proficiency, prior cyber-operations experience, facility security, and personnel screening, and must post a minimum $1 million bond or escrow, forfeitable for noncompliance, reviewed annually. The memo explicitly builds on Executive Order 14390, the March 6, 2026 anti-fraud order, and requires ongoing compliance with the Computer Fraud and Abuse Act (18 U.S.C. § 1030) — the 1986 statute that has, until now, made unauthorized access a federal crime with no private carve-out for retaliation.
The steelman: why this made civil-liberties and security veterans nervous
The skepticism here is not reflexive. The CFAA's blanket ban on private intrusion exists because "hacking back" is genuinely hard to do without collateral harm — ransomware infrastructure routinely sits on hijacked servers belonging to hospitals, small businesses, or home routers with no idea they're hosting a criminal relay. Misattribution is common in this field; state-linked actors regularly launder operations through criminal-looking infrastructure specifically to draw private or third-country retaliation onto the wrong target. That is precisely why the last serious legislative attempt at this, the Active Cyber Defense Certainty Act (introduced by Reps. Tom Graves and Kyrsten Sinema and reintroduced as H.R. 3270 in the 116th Congress), never passed — even with an FBI-notification requirement and a two-year sunset clause, lawmakers and DOJ officials worried that authorizing private offensive action, however conditioned, would turn parts of the internet into what one former NSA official once called a Wild West. Jason Kitka, a former U.S. Cyber Command official, has already called this program "a perpetual motion machine for billable threats" — a fair warning that a bonded contractor class has a financial incentive to find enemies.
Why the structure here is different from what critics feared
What distinguishes this memorandum from ACDC-style deregulation is that it does not weaken the CFAA's default rule at all — it keeps the ban in place for everyone outside the Program and instead creates a narrow, revocable, government-controlled exception with dual-agency written approval on every single operation. That is a meaningfully higher bar than "notify the FBI and proceed," which is what ACDC would have allowed. Given that ransomware and pig-butchering-style fraud networks increasingly operate from jurisdictions with limited extradition cooperation, and federal cyber units are chronically understaffed relative to caseload, channeling vetted private technical capacity into a bonded, supervised structure — with an explicit no-fatality, no-armed-attack ceiling — is a more proportionate response than either doing nothing or the freewheeling self-help model Congress rightly rejected twice.
What the memo leaves unresolved
The open questions are real, not cosmetic. Tonya Ugoretz of PwC's Cyber & Risk Innovation Institute has flagged that the memo doesn't spell out liability protection for participating firms — a company operating under a DOJ or DHS contract still faces the ambiguity of the CFAA's law-enforcement exception, and "that will be front and center as companies decide whether and how much they want to participate." The NCC's capacity to actually run 24/7 dual-agency deconfliction across a growing roster of contractors, rather than absorb the mission with existing staff, is unproven. And nothing in the memorandum survives a change of administration or a change of policy priority, since it rests on presidential authority rather than statute — Congress could lock in both the guardrails and the liability shield that make this workable, but hasn't been asked to.
Bottom line
This is a narrower, better-supervised version of an idea Washington has debated for a decade, not the vigilante free-for-all the "cyber privateers" framing implies. The test now is enforcement discipline: whether DOJ and DHS actually hold the line on written, per-operation approval and the no-casualties ceiling, or let the bonded-contractor model drift toward exactly the mission creep critics predict.