White House authorizes private companies to conduct offensive cyber operations against criminal gangs

President Trump signed a national security presidential memorandum on August 12 authorizing vetted private US companies to conduct offensive cyber operations against foreign transnational criminal organizations, according to reporting from The Guardian, The Record, and multiple cybersecurity outlets. The move reverses decades of US policy that generally prohibited private entities from “hacking back” against attackers, citing escalation risks and legal complications.
How the program works
The memorandum directs the National Coordination Center (NCC) to stand up a formal program authorizing participating companies to conduct two categories of activity: “cyber surveillance operations” for intelligence gathering, and more aggressive “cyber effects operations” that can manipulate, disrupt, degrade, or destroy digital infrastructure belonging to targeted criminal groups. Every operation requires written pre-approval from officials at the Department of Justice and Department of Homeland Security, which jointly oversee the program.
Participation isn't open to any security firm that wants in. Companies must pass technical, personnel, and security vetting, sign contractual agreements with DOJ or DHS, and maintain a bond or escrow of at least $1 million. If a company's operation accidentally hits a US person or system, it must immediately halt and notify the NCC — a built-in circuit breaker meant to limit collateral damage from authorized offensive activity.
What's off-limits
The policy draws a hard line around what it calls “Critical Outcomes”: actions that could cause death or serious injury, or that would qualify as a use of force or armed attack under international law. Those cannot be authorized through the program's standard approval process, regardless of the target. The stated focus is transnational criminal organizations running ransomware campaigns, financial fraud schemes, and other cyber-enabled crimes against US interests — not state-linked espionage or geopolitical rivals, at least as the policy is currently scoped.
Why this is a significant shift
Cybersecurity policy in the US has historically treated offensive “hack back” activity by private actors as legally risky and diplomatically dangerous — an attack routed through infrastructure in a third country could look like an act of war regardless of the attacker's actual target or intent. Formalizing a vetted, government-supervised private-sector offensive capability is the White House's attempt to thread that needle: keep the legal authority and escalation control with DOJ and DHS while tapping private companies' technical capabilities against a category of threat — ransomware gangs and cybercrime networks — that has grown faster than government capacity to counter it.
The National Coordination Center has 60 days from the memorandum's signing to publish detailed operating procedures, meaning the program's practical scope, vetting bar, and first participants likely won't be public knowledge for several more weeks. Security researchers and civil liberties groups are expected to scrutinize those procedures closely, given the history of “hack back” proposals raising concerns about accountability when private companies are given authority normally reserved for intelligence and law enforcement agencies.
Originally reported by The Guardian. Read the original article for additional details.
View original source