Trump has signed a memorandum letting vetted US companies conduct offensive cyber operations against foreign criminal networks, reversing decades of policy.

Trump Authorises US Private Companies to Launch Offensive Cyberattacks Against Foreign Criminal Networks

The420 Web Correspondent
5 Min Read

President Donald Trump has signed a National Security Presidential Memorandum authorising vetted private American companies to conduct offensive cyber operations, including hacking and sabotage, against foreign criminal networks responsible for ransomware, phishing and sextortion campaigns targeting US citizens. The memorandum, signed on August 12, marks the first formal US programme permitting private firms to engage in so-called hack-back operations, a practice that has been broadly prohibited under federal computer hacking laws for decades.

The policy shift represents a significant departure from the United States’ long-standing position that offensive cyber operations remain the exclusive domain of law enforcement, intelligence and military agencies. According to the White House, American consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025 alone, a figure officials cited as justification for expanding the government’s response beyond purely defensive measures.

A Formal Program, Not a Free Hand

The memorandum does not grant private companies a general right to retaliate against attackers on their own initiative. Instead, it establishes a structured programme in which vetted firms must receive written, per-operation approval from federal directors before undertaking any specific action against a specific target. Companies that conduct offensive operations without that explicit authorisation remain fully exposed to civil and criminal liability under the Computer Fraud and Abuse Act, the primary US statute governing unauthorised computer access.

The programme will be administered by the Homeland Security Task Force’s National Coordination Center, led jointly by executive directors designated by the Attorney General and the Secretary of Homeland Security. Participating companies are permitted to conduct surveillance of criminal networks, including the use of spyware to gather intelligence, as well as disruptive operations aimed at destroying criminal infrastructure or data. The memorandum requires immediate cessation of any operation upon direction, along with minimisation procedures to limit further exposure and mandatory notification to federal authorities.

Legal analysts have flagged several unresolved issues within the framework. Crowell and Moring’s examination of the policy for Lawfare noted that while the government-authorisation exception creates a narrow lawful pathway, the memorandum leaves open what civil or criminal consequences would apply if an authorised operation causes collateral damage to innocent third parties through imprecise execution. Employees of participating companies who conduct authorised operations also face a legal ambiguity the memorandum does not resolve, since they hold no recognised status as combatants under international law even while carrying out state-directed offensive actions abroad.

Cybersecurity researcher Robert Graham, writing on his Cybersect newsletter, characterised the memorandum as effectively directing law enforcement agencies to compile a list of permissible private-sector actions rather than establishing an entirely new legal regime, noting that any assets recovered during such operations would presumably revert to the government rather than the companies conducting them.

A Divided Response From the Security Community

Reaction from cybersecurity experts has been sharply mixed. Supporters argue the private sector possesses innovative capabilities and technical scale that outstrip current federal resources, particularly amid reported cuts to federal cybersecurity staffing since early 2025, and that empowering vetted firms could meaningfully disrupt ransomware and scam operations that have proven largely resistant to conventional law enforcement action.

Critics, however, have warned that the hack-back model creates serious escalation risks, potentially exposing American companies and their employees to retaliation from foreign states or criminal groups in a manner previously reserved for government personnel. Concerns about the potential for abuse were raised even before the memorandum’s formal signing, with a Department of Homeland Security official declining to dismiss the hack-back concept when questioned at the Black Hat USA cybersecurity conference in Las Vegas last week.

The memorandum builds on an earlier executive order Trump signed in March 2026 addressing cybercrime and fraud targeting American citizens, and follows a broader national cybersecurity strategy released the same month that had signalled, without explicitly confirming, an expanded private-sector role in offensive operations against foreign adversaries.

The policy’s international dimension is likely to draw close scrutiny from allied governments and cybersecurity agencies worldwide, given that authorised private-sector hacking operations could implicate infrastructure or networks located in third countries, raising questions about jurisdiction, diplomatic fallout and unintended escalation between private actors and foreign state or criminal entities.

Stay Connected