In August 2026, the U.S. administration took a significant step in the evolution of its cyber policy. However, describing the move simply as giving American companies permission to “hack back” only partially captures what is actually happening.
On August 12, President Donald Trump signed the memorandum Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, establishing a framework for engaging private U.S. companies in Cyber Surveillance Operations and Cyber Effects Operations against foreign transnational criminal organizations.
The memorandum builds on Executive Order 14390 of March 6, 2026, which directed federal agencies to make greater use of the private sector’s technical capabilities to identify, track, and counter transnational cybercrime.
This Is Not a General Authorization for Hack Back
The first and most important clarification is that this is not a blanket legalization of hack back for private companies.
A U.S. organization hit by ransomware or another cyberattack still does not have the right to independently access the attacker’s infrastructure, delete stolen data, or disrupt the attacker’s servers.
Unauthorized access to computer systems remains subject to the restrictions of the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. §1030.
The new model works differently.
A private company may conduct an offensive operation only after being admitted to the government program, entering into a contract with the Department of Justice or Department of Homeland Security, and obtaining written authorization for the specific operation.
In other words, this is not a new right of digital self-defense. It is a model of state-delegated cyber operations, in which private-sector operators perform specific cyber operational functions on behalf of, and under the control of, the U.S. government.
From Defensive Cybersecurity to State-Controlled Cyber Offense
Historically, the boundary between defensive cybersecurity and offensive cyber operations in the U.S. private sector has been relatively clear.
A company could:
- defend its own infrastructure;
- conduct threat hunting within an environment it controls;
- collect threat intelligence;
- block malicious traffic;
- share indicators of compromise with partners and government agencies;
- cooperate with law enforcement.
Crossing the boundary of its own infrastructure and gaining unauthorized access to an adversary’s systems, however, created significant criminal and civil liability risks.
That barrier has long been central to the debate around hack back.
Proponents have argued that victims should be able not only to close the door after an intrusion, but also to pursue the attacker, destroy stolen data, or disrupt the attacker’s infrastructure.
Critics have consistently pointed to three fundamental problems:
- misattribution;
- collateral damage;
- risk of international escalation.
The new administration has not attempted to resolve these issues through a blanket exemption from the CFAA.
Instead, it is creating a narrower construct:
The private operator may act, but acts on behalf of and under the control of the state.
That distinction fundamentally changes the legal character of the operation.
What Types of Operations Are Now Permitted?
The memorandum identifies two primary categories of activity.
1. Cyber Surveillance Operations
These operations are focused on obtaining information and intelligence.
The memorandum defines them broadly enough to include unauthorized access to an adversary’s information systems, or access beyond granted authorization, when the purpose is to obtain information or intelligence — including intelligence intended to support subsequent Cyber Effects Operations.
In practical terms, a private operator could potentially perform activities historically associated primarily with government intelligence or law-enforcement organizations, including:
- gaining access to criminal infrastructure;
- analyzing its internal architecture;
- identifying operators and affiliates;
- discovering C2 infrastructure;
- mapping financial and technical relationships;
- collecting intelligence for subsequent disruption.
This represents a meaningful expansion of the role private-sector cyber operators may play in government-led operations.
2. Cyber Effects Operations
This is where the model moves beyond intelligence collection.
The memorandum defines Cyber Effects Operations as activities that result in:
- manipulation;
- disruption;
- denial;
- degradation;
- destruction
of information systems, networks, physical or virtual infrastructure controlled by information systems, or data residing within them.
In effect, the government is creating a mechanism through which private-sector technical capabilities can be used not merely to identify criminal actors, but to generate real cyber effects against their infrastructure.
That could include disrupting criminal infrastructure or degrading an adversary’s technical capabilities.
The critical distinction from traditional hack back, however, is that each operation must undergo government authorization and oversight.
This Is Not a Free Market for Offensive Cyber Operations
One of the most important elements of the memorandum is its control architecture.
The program is to be managed by the National Coordination Center, with oversight from two senior officials representing the Department of Justice and Department of Homeland Security.
Each operation must:
- be documented as a separate operational package;
- undergo government review;
- be coordinated against other government operations and interests;
- receive written authorization;
- be conducted under federal government oversight.
The memorandum also requires operational deconfliction with law enforcement, the Department of State, the Department of the Treasury, the Department of Defense, and the intelligence community.
This is a critical detail.
The same infrastructure may simultaneously be:
- an FBI investigative target;
- an intelligence collection point;
- part of a larger intelligence operation;
- monitored by allied governments;
- a technical resource used by multiple threat actors.
An independent private-sector attack could destroy evidence, expose an intelligence source, or compromise a much larger operation.
The architecture therefore is not based on the principle that a company receives a “license” and can then operate independently.
It is based on mission-by-mission authorization.
The Core Problem: Attribution
The most vulnerable part of the entire model is determining who or what actually constitutes the target.
The memorandum limits operations to foreign Cyber-Enabled Transnational Criminal Organizations. Such groups must not be institutional components of a foreign government or operate entirely at the direction of a foreign government.
But the memorandum then introduces an important qualification: a foreign group is presumed not to be state-affiliated unless there is clear intelligence establishing such a relationship.
This creates one of the most significant operational and geopolitical risks in the framework.
Modern cyber threats rarely fit into clean categories.
Between an independent criminal organization and a state-sponsored APT there is a broad spectrum of relationships, including:
- state tolerance;
- informal patronage;
- tasking of criminal actors for specific operations;
- access and infrastructure sharing;
- financial or personnel relationships;
- temporary cooperation;
- use of common contractors;
- movement of operators between criminal and state-sponsored ecosystems.
A group may not formally belong to a foreign government while still operating under its protection.
A group that operates purely for financial gain today may perform an intelligence or disruption task for a state actor tomorrow.
Attribution therefore has at least two distinct dimensions.
Technical attribution
Did we correctly identify the specific operator or threat actor?
Political and legal attribution
How should that actor be classified from an international-relations and legal perspective?
The second type of error may be considerably more consequential than the first.
If a private U.S. company, operating under government control, conducts a disruptive or destructive operation against infrastructure that is later determined to be connected to a foreign government, the incident may no longer be viewed simply as counter-cybercrime activity.
It could acquire an entirely different geopolitical and legal character.
Criminal Infrastructure Does Not Necessarily Belong to the Criminals
There is also a more practical — but equally serious — problem.
Cybercriminal organizations rarely operate exclusively from infrastructure they own.
They routinely use:
- compromised servers;
- compromised routers;
- cloud infrastructure;
- VPS providers;
- bulletproof hosting;
- proxy networks;
- botnets;
- shared hosting;
- infrastructure belonging to other victims.
Consequently, the technical endpoint from which an attack originates is not necessarily owned or controlled by the attacker.
This creates an inherent collateral-damage risk.
An attempt to take down C2 infrastructure may affect systems belonging to unrelated third parties.
Misattribution can turn a legitimate defensive actor — or an innocent infrastructure provider — into an unintended victim of the operation.
This has long been one of the central arguments against private-sector hack back.
The major concerns are well known:
- attribution error;
- collateral damage;
- interference with government operations;
- international escalation.
The new U.S. framework attempts to mitigate these risks through mandatory government review and target validation.
But authorization alone does not eliminate the underlying problem.
In cyberspace, technical confidence rarely translates into absolute identification of the ultimate responsible entity.
Why a $1 Million Escrow Is Not a Security Guarantee
Participants in the program may be required to maintain a bond or escrow arrangement of at least $1 million, potentially subject to forfeiture if the terms of the agreement are violated.
Symbolically, this is important.
The government is attempting to establish a direct financial accountability mechanism for private operators.
From an enterprise risk-management perspective, however, $1 million looks more like an entry-level discipline mechanism than meaningful coverage for the potential downside.
A single operation could:
- affect critical infrastructure;
- disrupt third-party commercial operations;
- destroy substantial volumes of data;
- trigger an international dispute;
- provoke retaliatory activity against the contractor itself.
The resulting exposure could easily exceed the escrow amount by orders of magnitude.
For prospective participants, the critical issues will therefore extend well beyond technical capability:
- indemnification;
- allocation of liability between the operator and the government;
- insurance coverage;
- personnel protection;
- disclosure obligations;
- export controls;
- operational-data retention;
- consequences of tool or exploit disclosure;
- liability for subcontractor actions.
This could ultimately create a new market segment: not simply offensive cybersecurity, but state-authorized cyber operations contracting.
The Private Sector Becomes Part of the Government Operational Chain
The most significant strategic effect of the program may not be that the government gains access to more “hackers.”
The deeper change is the potential transformation of how cyber operations are produced and executed.
Traditionally, governments bring:
- legal authorities;
- intelligence;
- diplomatic channels;
- coordination capabilities;
- authority to impose certain forms of state action.
The private sector brings:
- development speed;
- specialized technical expertise;
- commercial threat-intelligence datasets;
- experience analyzing real-world attacks;
- telemetry from large numbers of enterprise environments;
- flexibility;
- the ability to rapidly develop specialized tooling.
The new model attempts to combine these capabilities.
A private company may propose or execute an operation based on intelligence obtained through its commercial activities.
The government evaluates the target, legal basis, strategic implications, and operational risks, and then authorizes the operation.
Conceptually, this resembles a transition from government-owned capability to a government-controlled capability ecosystem.
For government, the model offers a way to scale offensive cyber capacity without having to build every technology stack and specialist team internally.
For industry, it creates a new market.
At the same time, it raises a fundamental question:
How deeply is the U.S. government prepared to integrate commercial threat intelligence, exploitation capabilities, and private offensive expertise into the national security apparatus?
Why This Is Not a Return to Digital Privateering
Discussions around the policy frequently invoke the historical analogy of privateers — privately operated vessels authorized by governments to act against adversaries.
The analogy is useful, but imperfect.
A classical privateer operated with substantially greater autonomy.
The new U.S. model is instead built around:
- vetting;
- contractual control;
- prior authorization;
- written approval;
- government operational oversight;
- deconfliction;
- continuous reporting.
This is therefore less a model of “digital pirates with letters of marque” and more a model of private contractors embedded in a government operational framework.
For that reason, describing the memorandum as a law “legalizing hack back” is legally misleading.
A more accurate description is that it creates a mechanism under which activities that could otherwise expose a private company to CFAA liability may be conducted by a private entity within a federal government-authorized and controlled operational framework.
The Most Serious Risk: Escalation Through a Private Intermediary
The memorandum explicitly identifies a category of Critical Outcomes.
This includes operations that could:
- result in death or serious bodily injury;
- rise to the level of use of force or an armed attack under international law.
Such operations cannot proceed through the standard authorization mechanism.
The existence of this limitation is significant in itself.
It demonstrates that the administration recognizes how thin the line can be between cyber disruption and cyber conflict.
This becomes particularly important where IT infrastructure controls physical systems, including:
- energy;
- industrial production;
- transportation;
- medical equipment;
- telecommunications.
The fundamental question is therefore:
If a private company conducts an operation under full government control and at the direction of the U.S. government, to what extent can that operation realistically be perceived as “private” by the affected state?
Practically speaking, the answer may be:
very little.
A foreign government whose infrastructure is affected by such an operation is likely to interpret the activity as attributable to the United States, regardless of who physically executed the operation.
Delegating technical execution to the private sector therefore does not necessarily mean delegating political responsibility.
What Will Determine Whether the Program Succeeds?
The key measure of success will not be the number of operations conducted.
The real test will involve at least five factors.
1. Target Attribution Quality
The system must reliably distinguish between:
- the actual criminal actor;
- the actor’s infrastructure;
- third-party infrastructure that has been compromised;
- state and quasi-state entities.
This is the foundation of the entire model.
2. Approval Process and Operational Tempo
If authorization takes weeks, the principal advantage of private-sector participation — speed — may disappear.
If authorization becomes too fast, the probability of erroneous decisions increases.
The system will need to balance operational tempo against legal and strategic control.
3. Deconfliction
Private operations must not interfere with:
- FBI investigations;
- intelligence operations;
- allied activities;
- diplomatic initiatives;
- sanctions enforcement.
4. Tooling and Capability Control
A particularly difficult issue concerns the use of:
- zero-day exploits;
- persistence mechanisms;
- custom malware;
- destructive tooling.
Any capability deployed against criminal infrastructure may eventually be discovered, reverse-engineered, copied, or repurposed against the United States or its allies.
5. Accountability
The most difficult question remains unresolved:
Where does contractor liability end, and government responsibility begin?
A $1 million escrow arrangement does not answer that question.
The actual liability architecture will depend on operational procedures, contractual arrangements, and potentially the first major incidents arising from the program.
What This Means for the Cybersecurity Market
For the cybersecurity industry, the policy could mark the emergence of an entirely new class of companies.
Not simply an MSSP.
Not simply a threat-intelligence provider.
And not a traditional defense contractor.
Instead, potentially a private cyber operator capable of combining:
- high-confidence threat intelligence;
- attribution;
- malware analysis;
- infrastructure mapping;
- exploitation;
- covert access;
- disruption;
- rigorous operational security;
- legal and compliance support for government operations.
The memorandum specifically contemplates participation by smaller specialized companies, rather than limiting the program exclusively to large defense primes.
This could allow the United States to build a broader ecosystem of specialized cyber capabilities.
However, the barriers to entry for smaller companies will still be substantial.
In addition to technical competence, participants are likely to require:
- demonstrated cyber-operations performance;
- facility security;
- personnel vetting;
- organizational trustworthiness;
- the ability to operate within a highly controlled government framework.
Consequently, the defining asset of such a company will no longer be simply its exploit capability or red-team expertise.
The critical competitive advantage will be government trust in the company’s ability to execute offensive cyber operations without creating uncontrolled downstream consequences.
Conclusion
The new U.S. policy represents a deeper change than simply expanding cooperation between government and the cybersecurity industry.
The United States is effectively testing a model of privatized execution, centralized authority.
The government retains legal authority, target selection, strategic oversight, and ultimately political responsibility, while part of the technical execution is delegated to private-sector operators.
The memorandum does not give businesses a general right to “hack back.”
Quite the opposite: it emphasizes that operations must remain under federal government control and that each operational package requires separate written authorization.
The central tension in the model is straightforward.
The U.S. government is attempting to capture the private sector’s primary advantages — speed, specialization, and technological flexibility — while retaining the state-level control necessary to manage legal, intelligence, and geopolitical risk.
But the more tightly the government controls the operation, the more the private operator becomes an extension of the state apparatus.
Conversely, the more autonomy the private company receives, the greater the risk of misattribution, collateral damage, and uncontrolled escalation.
The real significance of the August memorandum will therefore not be determined by headlines claiming that private companies have been “allowed to hack hackers.”
It will become clear only when the operational procedures are established and begin defining the actual mechanics of the program.
That is where the meaningful boundary will ultimately be drawn between cyber defense, law-enforcement activity, and a partially privatized offensive cyber capability operating on behalf of the state.












