On August 12, 2026, President Trump signed a National Security Presidential Memorandum, Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, directing the Department of Justice and Department of Homeland Security to jointly stand up a program letting vetted "Participating Companies" run offensive cyber operations against foreign criminal networks (White House, Aug. 12, 2026). It is the most significant American move toward legalized private-sector "hack-back" activity to date, and it deserves scrutiny proportionate to that fact.
What the Memorandum Actually Authorizes
The program, run through DHS's National Coordination Center (NCC), permits two categories of activity. Cyber Surveillance Operations let approved firms access foreign systems without authorization for intelligence collection. Cyber Effects Operations go further, permitting the "manipulation, disruption, denial, degradation, or destruction" of an adversary's infrastructure (White House presidential action text). Neither category is unbounded: co-executive directors from DOJ and DHS must jointly approve each operation in writing before it runs, and they explicitly lack authority to approve anything producing a "Critical Outcome" — death, serious injury, or effects that would qualify as an armed attack under international law.
Participating firms must sign contracts with DOJ or DHS, pass a vetting process covering technical proficiency and personnel reliability, and post a bond or escrow of at least $1 million, forfeitable for contractual noncompliance (Debevoise Data Blog, Aug. 17, 2026). DOJ and DHS have until October 12, 2026 to finalize the detailed operating procedures. Legally, the government leans on the Computer Fraud and Abuse Act's existing carve-out for "lawfully authorized investigative, protective, or intelligence activity" of a law enforcement or intelligence agency — 18 U.S.C. § 1030(f) — treating Participating Companies as instruments of that authorized government activity rather than granting them a freestanding hacking license (18 U.S.C. § 1030).
The Case for It
The rationale is not manufactured. The FBI's IC3 unit reported $20.8 billion in consumer losses to cyber-enabled crime in 2025, and the White House's own fact sheet leans on that figure to justify the program (White House fact sheet). Ransomware crews, romance-scam operations, and pig-butchering networks overwhelmingly operate from jurisdictions — parts of Southeast Asia, West Africa, Eastern Europe — where U.S. law enforcement has no reach and local authorities have no incentive to cooperate. Government cyber units are chronically understaffed relative to the scale of the problem, while private threat-intelligence and incident-response firms often have better real-time visibility into criminal infrastructure than the agencies chasing it. Chris Wysopal, the Veracode co-founder, called the move "a pretty big shift in US cyber policy" — but noted it stops well short of the far more permissive hack-back bills Congress has previously rejected (CyberScoop, Aug. 2026). Channeling private capability through a chartered, government-approved program — rather than tolerating ad hoc vigilantism that already happens quietly and illegally — is a defensible way to close that gap without abandoning the rule of law.
Why the Guardrails Are Thinner Than They Look
The steelman only holds if the approval and liability structure actually functions as designed, and there's real reason to doubt that at scale. A $1 million forfeitable bond is a rounding error for the well-capitalized cybersecurity contractors likely to dominate this program, and it says nothing about compensating a foreign victim of a misattributed strike — the memo's remedy runs to the U.S. government, not to anyone harmed by an operational error. Attribution in cyberspace is notoriously unreliable; criminal infrastructure routinely sits on shared hosting, compromised third-party servers, or cloud instances used by unrelated parties. A "disruption" operation aimed at a ransomware server can spill onto adjacent systems with no criminal connection at all, and the memo's own text concedes this risk by requiring firms to immediately notify the NCC if U.S. persons or systems are unintentionally affected — an acknowledgment that scope creep is expected, not hypothetical.
Former Cyber Command official Jason Kitka was blunter, describing the program as "a perpetual motion machine for billable threats" — a structural worry that firms paid to find and neutralize threats have an incentive to keep finding them (CyberScoop). Industry itself has historically opposed hack-back legislation for a related reason: authorized retaliation by one firm can trigger unpredictable counter-retaliation that lands on everyone else's networks, not just the aggressor's.
The Right Fix Is Narrower Scope, Not Abandonment
None of this argues for reflexive opposition to the concept. Coordinated, government-directed private offensive action is a legitimate response to a genuine enforcement gap, and DOJ/DHS joint sign-off before every operation is a real check, not a rubber stamp. But Congress, not a memorandum alone, should eventually codify liability rules for collateral damage to innocent third parties, and the October 12 operating procedures should publish measurable criteria — not just "rigorous vetting" — for what disqualifies a firm from Cyber Effects authority specifically, as distinct from the lower-risk surveillance track. A program this consequential should not rest on a bond sized for a fender-bender.