The Long Beach News

collapse
Home / Daily News Analysis / The US government wants private companies to start hacking the hackers

The US government wants private companies to start hacking the hackers

Aug 16, 2026  Twila Rosenbaum  4 views
The US government wants private companies to start hacking the hackers

The US government is shifting its cybersecurity strategy. Under a new presidential memorandum, vetted American companies will be allowed to carry out offensive cyber operations against foreign criminal groups, provided federal agencies approve and supervise each action. The policy marks a significant departure from the long-standing principle that private companies should defend against hackers but not attack them.

Key facts

  • The US is establishing a federal program that lets vetted private companies conduct offensive cyber operations against foreign criminal organizations.
  • Operations require written approval from program directors at the Justice Department and Department of Homeland Security.
  • Participating companies may have to put at least $1 million in a bond or escrow account.
  • Approved operations include surveillance, disruption, manipulation, degradation, or destruction of computer systems and data.
  • Accidental targeting of US persons or US-based systems must be halted and reported.
  • Federal agencies have 60 days to develop the operating rulebook.

A new role for private cybersecurity companies

For years, cybersecurity firms have operated in a reactive mode: monitor networks, identify vulnerabilities, block intrusions, clean up after breaches, and attribute attacks to specific actors. The idea of actively hacking back was considered too risky, legally ambiguous, and potentially escalatory. The new memorandum challenges that view by creating a formal pathway for private companies to go on offense, not just against individual attackers but against entire foreign criminal enterprises.

According to the memorandum, companies participating in the program could conduct both surveillance and disruptive cyber operations against foreign cyber-enabled criminal organizations. The stated goal is to reduce threats such as ransomware, fraud, and other cybercrimes that target Americans. That includes taking down infrastructure used by criminal gangs, disrupting their communications, and potentially destroying data or systems that support their illicit activities.

However, this is not a free hand. Every operation will require written approval from program directors at the Justice Department and the Department of Homeland Security. The companies would act under federal supervision, and could be required to post at least $1 million in a bond or escrow account, which might be forfeited if they violate the terms of the program.

What qualifies as offensive cyber operations?

The memorandum outlines authorities that go far beyond typical defensive measures. Companies may be allowed to manipulate, disrupt, degrade, or destroy computer systems and data belonging to foreign criminal groups. They may also conduct surveillance operations that involve secretly accessing systems without the owner's permission to gather intelligence. This is a significant expansion of what a private entity is normally permitted to do under US law.

The Computer Fraud and Abuse Act, for example, generally makes unauthorized access to computer systems a federal crime. The new program would presumably create a safe harbor for companies acting with federal approval and supervision. But the specifics of that legal protection remain unclear. The memorandum gives officials 60 days to establish precise operating procedures, including the process for approving operations, the rules of engagement, and the limits of liability for participating companies.

Guardrails and accountability

The program includes several guardrails intended to prevent abuse and minimize collateral damage. It is designed to target foreign criminal groups, not foreign governments. That distinction could be difficult to maintain in practice because many criminal groups operate with the tacit support of, or in complex relationships with, state security services. Russian-speaking ransomware syndicates, for example, have frequently been linked to intelligence agencies or permitted to operate within certain borders as long as they do not target domestic interests.

Another important safeguard requires companies to stop and report any operation that accidentally targets a US person or a US-based system. That acknowledges the reality of the internet: infrastructure is often shared, and a malicious command-and-control server could be hosted on a US cloud provider or use compromised systems located in the United States. The requirement to halt and report offers some transparency, but it does not eliminate the risk of collateral damage or the potential for legal consequences.

The escrow requirement adds a financial layer of accountability. Companies would need to put up at least $1 million as a bond to participate. If a firm breaks the rules, that money could be forfeited. The requirement also signals that the government intends to take compliance seriously, though critics note that a million-dollar bond is relatively small compared with the potential financial scale of large cyber operations and the possible costs of litigation.

A major policy reversal

Historically, the US government has maintained that private companies can defend their networks but should not launch offensive strikes. The reasoning was rooted in both law and policy. Offensive cyber activities are state-like functions that raise diplomatic, legal, and ethical questions. Allowing private firms to conduct them could lead to accountability problems, unintended escalation, and violations of sovereignty.

The new policy does not fully privatize offensive cyber operations. Federal agencies still authorize and supervise each operation, and companies are not being turned into independent vigilantes. But the change is still significant. It creates a formal, legal channel for private-sector entities to engage in actions that were previously reserved for nation-state actors or authorized military and intelligence activities.

This is not the first time the idea has been floated. For years, some cybersecurity experts and lawmakers have advocated for hacking back legislation, including proposed bills that would give companies legal immunity for certain defensive measures that go beyond their own networks. The Active Cyber Defense Certainty Act, introduced multiple times in Congress, would have allowed victims of cyberattacks to access hijacked computers, disrupt attackers, and recover data under certain conditions. Those proposals were controversial and never passed into law. The new presidential memorandum bypasses that legislative impasse through executive action, at least for companies that are admitted to the federal program.

Industry and legal concerns

The plan has been met with skepticism from within the cybersecurity community. A cybersecurity veteran described the plan as 'half-baked.' He warned that Americans involved in such operations could face legal trouble or accusations from foreign governments when traveling overseas. This is a real concern because cyber operations can cross national boundaries in ways that make it difficult to determine which country's laws apply.

A US-approved operation targeting a criminal group in a foreign country could violate that country's domestic law, even if the group is engaged in illegal activity. Many nations retain computer crime statutes that criminalize unauthorized access to computer systems. If a private company carries out an operation from within the US against servers located abroad, the host country might claim that its sovereignty has been violated. Even if the company never sets foot in that country, the foreign government could issue an arrest warrant, seek extradition, or pursue diplomatic retaliation.

There are also questions about the rules of engagement. What exactly constitutes a foreign criminal group? How does a company verify its targets? What if the target is actually state-sponsored? The memorandum says the program is not intended to target governments, but state-sponsored cybercriminals blur that line. A group might operate with state protection while engaging in ransomware, fraud, and theft for both personal and official benefit. Determining whether such a group qualifies as a criminal organization or an extension of the state could be extremely difficult.

Potential effects on the cybersecurity ecosystem

If successful, the program could create a new niche for cybersecurity firms that are willing to accept high risk and high responsibility. Companies might develop specialized teams for offensive operations, including threat hunters, forensic analysts, and software engineers. The requirement for federal approval suggests that only companies with strong compliance records and mature internal governance are likely to apply.

The program could also affect the broader security landscape. Allowing private companies to disrupt ransomware groups may reduce the cost of cybercrime and protect victims. If criminal groups fear that their infrastructure will be destroyed, they may think twice before attacking US targets. That deterrent effect, if real, could benefit businesses, hospitals, schools, and government agencies that are frequent ransomware victims.

On the other hand, there is a risk of unintended consequences. Offensive operations can be noisy, and a failed operation might provide attackers with a propaganda victory or lead to retaliation against the company or its clients. Disrupting an entire criminal ecosystem could also force attackers to adapt, using more resilient infrastructure, better operational security, and more destructive tactics. The long-term impact on the global cybercrime economy is uncertain.

What comes next

Federal officials now have 60 days to translate the memorandum into detailed procedures. That includes writing the rulebook for how companies apply, how operations are reviewed, and what kinds of safeguards will be mandatory. The public and industry stakeholders will likely have an opportunity to comment, although the timeline may be driven by presidential direction rather than notice-and-comment rulemaking.

The success of the program will depend on the quality of those rules and the effectiveness of federal supervision. If the process is slow and bureaucratic, few companies may participate. If it is too loose and permissive, the risk of diplomatic incidents and legal liability could be high. The middle ground, if found, could represent a meaningful shift in how the United States fights cybercrime, acknowledging that the scale of online criminal activity has outpaced the ability of government agencies to respond alone.

For now, the memorandum stands as a signal: the US government wants private companies to start hacking the hackers. But the details, and the dangers, are still being written. The next few months will determine whether this ambitious policy becomes a carefully controlled weapon against cybercriminals or a legal and diplomatic minefield for the companies that dare to participate.


Source: Android Authority News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy