A National Security Presidential Memorandum builds a private offensive-cyber contractor industry on a 1986 statutory exemption no appellate court has ever tested.
Intelligence Lead
President Donald Trump signed a National Security Presidential Memorandum on 12 August authorizing vetted private companies to conduct offensive hacking operations against foreign cyber-enabled transnational criminal organizations, operating under Justice Department and Homeland Security contract rather than under new congressional authority. The memorandum does not amend the Computer Fraud and Abuse Act; it threads a 1986 law-enforcement exemption to argue that contracted private firms inherit the same legal cover as federal investigators. The approach succeeds where a decade of "hack-back" legislation failed in Congress, but it does so by resting an entire offensive program on an interpretation the courts have not yet reviewed.
Situation Report
The memorandum directs the Homeland Security Task Force's National Coordination Center to stand up a two-category program. Cyber Surveillance Operations cover covert intelligence gathering from foreign networks, including unauthorized access intended to remain undetected. Cyber Effects Operations go further, permitting manipulation, disruption, denial, or destruction of targeted information systems. Two executive directors, one from DOJ and one from DHS, will jointly run the program.
Participating firms must sign federal contracts, pass vetting on technical proficiency, personnel security, and commercial ties, and post a forfeitable bond or escrow of at least one million dollars. Every operation requires written pre-approval before execution. If a firm inadvertently accesses a U.S. person or domestic system, the memorandum requires immediate cessation, data minimization, and notification to the National Coordination Center. The White House cited 2025 consumer losses exceeding twenty billion dollars to cyber-enabled crime, with seventy-three percent of U.S. adults reporting some form of online scam or attack, as the justification for the program.
Industry reaction split sharply. Former U.S. Cyber Command official Jason Kitka warned the structure risks becoming a "perpetual motion machine" for contractors financially incentivized to keep finding targets. Veracode co-founder Chris Wysopal called it a major policy shift while noting it stops short of granting firms independent operational authority, since every action still requires government pre-approval. Former Trump-administration cyber official Josh Steinman praised the framework as a workable middle path between inaction and unchecked private retaliation.
Background & Context
Congress rejected private offensive cyber authority twice, most notably through the Active Cyber Defense Certainty Act first introduced in 2017, amid warnings from the NSA and DOJ that uncoordinated private hacking could misattribute targets, disable innocent third-party infrastructure, or trigger unintended escalation with foreign states. Former NSA Deputy Director Rick Ledgett called the concept "an epically stupid idea" at the time. A parallel push for congressional "cyber letters of marque," reviving the mechanism once used to license privateers against enemy shipping, has similarly stalled in committee.
Wednesday's memorandum sidesteps that legislative deadlock entirely. Rather than seeking a statutory grant, it relies on Section 1030(f) of the CFAA, a clause written in 1986 to shield the government's own investigators from prosecution under the same law they enforce. By contracting private firms as extensions of DOJ and DHS authority, the administration argues those firms inherit the exemption. A July 2026 Columbia Business Law Review analysis found support for that reading in two recent federal district court decisions, but acknowledged no appellate court has settled the question. The memorandum builds on a March 2026 executive order and national cybersecurity strategy that first signaled this direction without formal authorization.
Analysis & Assessment
The program's legal architecture is its central vulnerability. Because the memorandum claims existing authority rather than creating new statute, any federal appellate ruling against the 1030(f) private-delegate theory would expose participating firms to retroactive criminal liability under the same law shielding them today. Firms weighing participation face a narrow calculation: substantial government contracts and expanded market access, against residual exposure under both U.S. and foreign computer-crime statutes that the memorandum does not, and cannot, override.
The oversight structure, written pre-approval, bonding, and mandatory reporting, is designed to prevent the scenario Congress feared twice: contractors escalating operations for revenue rather than security outcomes. Whether that check holds will depend on classified implementation procedures due within sixty days, details civil liberties observers are likely to scrutinize closely given the surveillance category's broad language.
Internationally, the program creates friction independent of its domestic legal footing. Operations against criminal infrastructure hosted in the United Kingdom, European Union states, or elsewhere expose U.S. contractors to prosecution under foreign hacking statutes the memorandum cannot touch, and allied governments may object to private American firms operating offensively inside their jurisdictions without bilateral coordination.
