US offensive cyber policy

Trump's Cyber-Privateer Memo Bets Federal Vetting Can Contain Private-Sector Hacking Risk

A new NSPM lets vetted US firms hack foreign cybercriminals under DOJ/DHS oversight — but core CFAA liability questions remain unresolved.

The Private-Sector Cyber Offense Program People of Internet Research · US $20.8B 2025 cybercrime losses Americans lost this much to cyber-… 73% US adults hit by scams Share of US adults who experienced… $1M Required bond for vetted firms Participating companies must post … peopleofinternet.com
The Private-Sector Cyber Offense Progr… People of Internet Research · US $20.8B 2025 cybercrime losses 73% US adults hit by scams $1M Required bond for vetted firms peopleofinternet.com

Key Takeaways

President Trump's August 12, 2026 national security presidential memorandum, "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," does something the US government has never formally done: it opens a lane for private American companies to conduct offensive cyber operations — surveillance and "cyber effects" attacks alike — against foreign criminal networks, under federal contract. It builds on a fraud-focused executive order Trump signed in March 2026, which the administration now describes as only the first step.

What the memo actually authorizes

The program sits inside a new National Coordination Center, co-directed by the Justice and Homeland Security departments, with mandatory coordination across State, Treasury, Defense, and the intelligence community. Companies don't get a blank check. To become a "Participating Company," a firm must clear vetting on technical proficiency, facility and personnel security, and "competence and reliability," post a $1 million bond or escrow account, submit to annual performance review, and disclose every contractual relationship to the NCC. The memo defines "cyber effects operations" broadly — manipulation, disruption, denial, degradation, or destruction of information systems or the data on them — but carves out a harder line: any operation touching US persons or domestic systems, or risking loss of life or serious injury, cannot be approved by program directors alone and needs separate authorization. Critically, per the White House fact sheet, the underlying legal framework — the Constitution, US statutes, and international agreements — still applies to every operation.

The steelman: this fills a real capability gap

The case for the memo starts with scale. The same fact sheet cites $20.8 billion lost by Americans to cyber-enabled crime in 2025, with 73% of US adults reporting they'd experienced some form of online scam or attack and 98% calling scams a threat. These aren't nation-state APTs; they're transnational fraud operations — pig-butchering scam compounds, sextortion rings, romance-scam networks — that federal law enforcement has struggled to reach because they sit behind foreign hosting, mixers, and jurisdictions with no extradition appetite. Private threat-intelligence and incident-response firms already map this infrastructure daily for clients; the memo's actual innovation is letting that mapping convert into disruption under government sign-off, rather than sitting in a report nobody acts on. As Chris Wysopal of Veracode put it, this is "a pretty big shift in US cyber policy" — but notably a more conservative one than the "hack back" bills Congress has floated since 2017, precisely because it routes everything through DOJ/DHS contracting rather than letting victims retaliate unilaterally.

Where the framework is thinner than it looks

The honest problem is legal, not rhetorical. The Computer Fraud and Abuse Act still criminalizes unauthorized access to computer systems, and as Lawfare's analysis points out, no court has ever ruled on whether a government-contractor exception shields a private firm operating on the US government's behalf abroad. A memorandum can direct agencies to build a vetting program; it cannot itself immunize a contractor from CFAA liability, from a foreign state's own hacking statutes, or from a lawsuit if an operation misidentifies infrastructure and hits an innocent third party's server. That's not a hypothetical edge case — attribution in cybercrime investigations is routinely wrong at the infrastructure level (shared hosting, compromised proxies, spoofed C2), and a disruption operation launched against the wrong target doesn't just fail, it creates a new victim with a real claim.

The escalation risk compounds this. Some of the criminal infrastructure US firms would be authorized to disrupt sits on servers with loose or deliberate ties to state intelligence services — Lawfare flags the danger of a participating company becoming "the center of an escalating geopolitical situation" it has no diplomatic tools to manage. Congress has debated this exact tradeoff before: when the Active Cyber Defense Certainty Act was introduced in 2017, NSA and DOJ officials themselves were skeptical of private offensive operations, for reasons that haven't disappeared just because the 2026 version routes through federal vetting.

The right frame going forward

The $1 million bond, the NCC disclosure requirement, and the carve-out barring operations against domestic systems or those risking bodily harm are real guardrails, not window dressing — this is a meaningfully narrower design than an open "hack back" regime. But guardrails inside an executive memorandum don't answer a statutory liability question that only Congress or the courts can settle. The administration should pair this rollout with legislation that explicitly defines the CFAA safe harbor for vetted contractors — not leave firms discovering the boundaries of their legal exposure in the first enforcement action or lawsuit that tests it. Proportionate regulation here means matching the ambition of the capability to the clarity of the liability rules protecting the people who'll actually run it.

Sources & Citations

  1. White House: Expanding Capabilities to Combat Transnational Cyber-Enabled Crime (memorandum)
  2. White House Fact Sheet on the memorandum
  3. Lawfare: Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations
  4. CyberScoop: Trump turns to private sector in offensive hacking operations memo