August 12, 2026 · Executive Power & Institutional Control
· Official action
Confirmed
Trump Signs a Memo Letting Vetted Private Companies Hack Foreign Criminal Networks
President Trump signed a national security memorandum on Aug. 12 directing the creation of a federal program that will authorize vetted private companies to carry out offensive hacking against foreign cyber-enabled transnational criminal organizations. A federal coordination center will manage the program; participating companies must sign contracts with the Justice Department or the Department of Homeland Security and undergo what the document calls rigorous vetting. Approved firms may conduct "Cyber Surveillance Operations" and "Cyber Effects Operations," the latter defined to include disruption, denial, degradation or destruction of information systems, under federal control.
Offensive cyber operations have been reserved for the military and intelligence agencies across administrations, and much of the security industry has opposed "hack back" proposals on the grounds that private operators cannot reliably attribute attacks. Extending the authority to contractors raises unsettled questions about oversight, liability and the boundary between federal law enforcement and private action.
The memorandum states the program must operate within existing law, including the Computer Fraud and Abuse Act. Practitioners were divided: one former Cyber Command official called it "a perpetual motion machine for billable threats," while a former Trump White House cyber official welcomed it. No participating companies have been named.
Offensive cyber operations have been reserved for the military and intelligence agencies across administrations, and much of the security industry has opposed "hack back" proposals on the grounds that private operators cannot reliably attribute attacks. Extending the authority to contractors raises unsettled questions about oversight, liability and the boundary between federal law enforcement and private action.
The memorandum states the program must operate within existing law, including the Computer Fraud and Abuse Act. Practitioners were divided: one former Cyber Command official called it "a perpetual motion machine for billable threats," while a former Trump White House cyber official welcomed it. No participating companies have been named.
Sources
- Trump turns to private sector in offensive hacking operations memo — CyberScoop, 2026-08-13
- Early Edition: August 14, 2026 — Just Security, 2026-08-14 Supporting