A new presidential memorandum ends decades of prohibition on private-sector hacking, formalizing a federal program of vetted "cyber privateers."
Intelligence Lead
President Trump has signed a National Security Presidential Memorandum formally authorizing vetted American companies to conduct offensive cyber operations against foreign criminal networks, ending a policy line that has held since the origins of US cyber doctrine: private entities do not hack back. The order creates the first federal program of its kind, placing surveillance and disruptive "cyber effects operations" under government contract rather than confining them to intelligence and law enforcement agencies. Former officials and industry analysts assess the shift risks diffusing accountability for state-adjacent cyber activity at a moment when attribution and escalation control are already strained by sustained nation-state intrusion campaigns.
Situation Report
The White House confirmed the memorandum, titled "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," was signed this week and published to whitehouse.gov, with reporting from the Washington Post, CNN, NPR, and TechCrunch corroborating its contents and timing. The document establishes a federal coordination center tasked with creating, managing, and maintaining a program to authorize "Participating Companies" to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations, under the stated control and oversight of the federal government.
Under the framework, companies seeking authorization must contract directly with the Department of Justice or the Department of Homeland Security and undergo what officials describe as rigorous vetting before conducting operations. Authorized activity spans intelligence collection through spyware deployment to disruptive attacks aimed at destroying or degrading criminal infrastructure and data. The memorandum does not alter underlying federal computer-crime statutes; it instead creates a contractual mechanism through which the government can extend legal cover to private actors performing functions historically reserved for state agencies.
The NSPM operationalizes Executive Order 14390, signed 6 March 2026, which directed federal agencies to develop action plans against cyber-enabled crime targeting Americans. Officials familiar with the program have not detailed which companies are under consideration for initial contracts or which criminal networks will constitute first targets, leaving the program's practical scope assessed rather than confirmed at this stage.
Background & Context
For decades, the Computer Fraud and Abuse Act and successive administrations' policy guidance have barred private "hacking back," reflecting concern over miscalculation, collateral damage to third-country infrastructure, and diplomatic blowback from unsanctioned cross-border intrusions. Legislative proposals to loosen this restriction, including the long-stalled Active Cyber Defense Certainty Act, have circulated in Congress for close to a decade without passage, underscoring how contested this policy terrain has remained.
The new program's structure echoes the historical model of privateering, in which states licensed private actors to conduct hostile operations under official sanction, a practice international maritime law eventually abolished over its propensity for abuse and diplomatic entanglement. Its revival in cyberspace arrives amid mounting frustration in Washington over the scale of cybercrime losses, cited by industry estimates in the tens of billions of dollars annually, and a perceived inadequacy of law-enforcement-only responses to ransomware groups and criminal networks operating with tacit protection from adversary states.
Analysis & Assessment
It is assessed with high confidence that the memorandum formalizes rather than creates offensive capability: vetted firms with red-team and threat-intelligence skillsets already exist across the private sector, and the change here is legal and organizational rather than technical. The most probable near-term application is action against ransomware infrastructure and cryptocurrency-laundering networks tied to non-state criminal actors, where attribution carries comparatively lower political sensitivity than operations against state-linked advanced persistent threat groups.
The program is assessed as carrying moderate-to-high risk of scope creep. The line between a "foreign criminal network" and a state-tolerated or state-directed proxy is frequently blurred by design, as seen in North Korea's Lazarus Group and Russia-based ransomware crews operating under tacit state protection. Authorizing private companies to operate against such targets raises the probability of unintended escalation with a nation-state and complicates the diplomatic deniability that purely government-run covert cyber operations have traditionally afforded. The program also sets a precedent other governments may invoke to justify their own patriotic-hacker or privateer arrangements, a development that would further erode the international norm against non-state actors conducting offensive cross-border network operations.