The U.S. Will Let Private Companies Hack Back at Criminal Groups — Under Government Watch

The White House announced on August 13, 2026 that the U.S. government will, for the first time, allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers. The policy was set by a presidential memorandum from the Trump administration titled "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," published in August 2026 TechCrunch.
The memorandum authorizes private companies enrolled in a government program to conduct surveillance operations, including the use of spyware to collect intelligence, and to carry out disruptive attacks aimed at destroying criminals' data or systems. It stops short of permitting companies to "hack back" against any cyber threats. The policy breaks from the long-standing U.S. position under federal computer hacking laws, which broadly prohibited private companies from conducting cyberattacks or disruption operations without court-authorized approval.
Several guardrails shape the program's scope. Any operation requires sign-offs from representatives of the Justice Department and Homeland Security before approval, and all operations must be conducted exclusively under federal government supervision. The memorandum directs the federal government to create procedures preventing any operation from targeting Americans or U.S.-based systems. Participating companies must deposit $1 million in escrow, an amount forfeited if the government finds the company noncompliant with program rules. Companies are also required to notify the government if they discover an imminent cyberattack against critical U.S. infrastructure, such as power grids or water providers.
As of the announcement, the U.S. government had not fully established how the program will operate. The White House did not confirm whether any private companies were already participating. The government said it would issue guidance within two months outlining the requirements participating companies must meet to join the program, and indicated it would consider companies of all sizes, including smaller firms.
The August memorandum builds on a chain of administration cyber policy actions. On March 6, 2026, President Donald Trump signed Executive Order 14390, titled "Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens." That same month, the White House unveiled President Trump's Cyber Strategy for America, which communicated the administration's cyber vision to Congress, industry partners, and the public. A June 2026 White House fact sheet on AI innovation and security called for the development of a classified benchmarking process against which industry may assess their models for advanced AI cyber capabilities. The August fact sheet frames the new memorandum as expanding the fight against transnational criminal organizations by incorporating what it describes as the ingenuity of the private sector White House.
The policy arrives amid a sustained wave of cyberattacks targeting U.S. financial institutions. Reuters reported on August 5, 2026 that hackers had attempted a series of sophisticated attacks on major Wall Street financial services firms and money managers in recent days. The following day, Reuters reported that hackers targeted U.S. private equity and financial companies, including Blackstone and CME, using websites designed to steal employee credentials. On August 7, Reuters reported that U.S. companies face a rise in cyber attacks amid a worldwide surge in AI-driven cyberattacks and ransomware that steal sensitive data and disrupt operations.
The idea of expanding the private sector's role in offensive cyber operations had been under discussion earlier in the year. The New York Times reported in January 2026 that the U.S. was weighing expanding private companies' role in cyberwarfare, with General Moore stating that turning to the private sector would allow a rapid increase in scale, resulting in more cyberattacks.
To understand what this means for the cybersecurity industry, it helps to know that the government already works with private cybersecurity firms. But in those existing arrangements, companies build tools or provide services that government operators then deploy. Under this new memorandum, the private company itself would conduct the operation, though under federal supervision and with approval from two agencies.
The $1 million escrow requirement is modest for established cybersecurity firms but could serve as a meaningful barrier for smaller companies, despite the government's stated intent to consider firms of all sizes. The two-month window for issuing eligibility guidance means the operational details, including how supervision will be structured in practice, what constitutes sufficient Justice Department and Homeland Security review, and how compliance will be monitored on a per-operation basis, remain undefined.
One concern worth noting is the tension between the memorandum's prohibition on targeting Americans or U.S.-based systems and the reality that transnational criminal infrastructure frequently routes through or resides on compromised U.S. systems. Criminal groups often hijack ordinary computers or cloud accounts inside the United States and use them as relay points to hide their tracks. How the government's prevention procedures will handle those situations is not addressed in the announced policy. That operational question will need resolution before any private firm can conduct a disruptive attack without legal exposure.
The distinction the memorandum draws between authorized offensive operations and "hack back" is also worth noting. The term "hack back" in industry usage typically refers to a victim company taking matters into its own hands and striking back at its attackers. This program is narrower: it targets transnational criminal organizations specifically, under government supervision, rather than granting victim companies a general right of cyber-response. Think of it less like a self-defense law and more like deputizing private firms to act on the government's behalf.
Reuters reported on August 12 that President Trump signed the memo to allow use of cyber tools to target transnational criminal organizations Reuters.
The program's practical impact will depend on the forthcoming guidance, the speed of interagency approval processes, and whether private firms judge the legal and financial risk favorable enough to participate. For an industry that has spent decades playing defense, the memorandum opens a door that previous administrations kept closed.


