Technology

U.S. Greenlights Private Companies for Offensive Cyber Operations Against Criminal Groups

Martin HollowayPublished 22h ago7 min readBased on 11 sources
Reading level
U.S. Greenlights Private Companies for Offensive Cyber Operations Against Criminal Groups
Photo by Shealeah Craighead / Public domain

The White House announced on August 13, 2026 that the U.S. government will, for the first time, allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers. The policy was established by a presidential memorandum from the Trump administration titled "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," published in August 2026 TechCrunch.

The memorandum authorizes private companies enrolled in a government program to conduct surveillance operations, including the use of spyware to collect intelligence, and to carry out disruptive attacks aimed at destroying criminals' data or systems. It stops short of permitting companies to "hack back" against any cyber threats. The policy breaks from the long-standing U.S. position under federal computer hacking laws, which broadly prohibited private companies from conducting cyberattacks or disruption operations without court-authorized approval.

Several guardrails shape the program's scope. Any operation requires sign-offs from representatives of the Justice Department and Homeland Security before approval, and all operations must be conducted exclusively under federal government supervision. The memorandum directs the federal government to create procedures preventing any operation from targeting Americans or U.S.-based systems. Participating companies must deposit $1 million in escrow, forfeited if the government finds the company noncompliant with program rules. Companies are also required to notify the government if they discover an imminent cyberattack against critical U.S. infrastructure, such as power grids or water providers.

As of the announcement, the U.S. government had not fully established how the program will operate. The White House did not confirm whether any private companies were already participating. The government said it would issue guidance within two months outlining the requirements participating companies must meet to join the program, and indicated it would consider companies of all sizes, including smaller firms.

The August memorandum builds on a chain of administration cyber policy actions. On March 6, 2026, President Donald Trump signed Executive Order 14390, titled "Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens." That same month, the White House unveiled President Trump's Cyber Strategy for America, which communicated the administration's cyber vision to Congress, industry partners, and the public. A June 2026 White House fact sheet on AI innovation and security called for the development of a classified benchmarking process against which industry may assess their models for advanced AI cyber capabilities. The August fact sheet frames the new memorandum as expanding the fight against transnational criminal organizations by incorporating what it describes as the ingenuity of the private sector White House.

The policy arrives amid a sustained wave of cyberattacks targeting U.S. financial institutions. Reuters reported on August 5, 2026 that hackers had attempted a series of sophisticated attacks on major Wall Street financial services firms and money managers in recent days. The following day, Reuters reported that hackers targeted U.S. private equity and financial companies, including Blackstone and CME, using websites designed to steal employee credentials. On August 7, Reuters reported that U.S. companies face a rise in cyber attacks amid a worldwide surge in AI-driven cyberattacks and ransomware that steal sensitive data and disrupt operations.

The idea of expanding the private sector's role in offensive cyber operations had been under discussion earlier in the year. The New York Times reported in January 2026 that the U.S. was weighing expanding private companies' role in cyberwarfare, with General Moore stating that turning to the private sector would allow a rapid increase in scale, resulting in more cyberattacks.

For context on what this means for the cybersecurity industry, the program creates a new category of government-sanctioned offensive cyber contractor. This is distinct from the intelligence community's existing relationships with private firms, such as the In-Q-Tel model (a venture fund that invests in technologies relevant to intelligence agencies) or defense contracting for CYBERCOM support. Those arrangements typically involve companies building tools or providing services that government operators then deploy. Under this memorandum, the private company itself would conduct the operation, albeit under federal supervision and with dual-agency sign-off.

The $1 million escrow requirement is modest for established cybersecurity firms but could serve as a meaningful barrier for smaller companies, despite the government's stated intent to consider firms of all sizes. The two-month window for issuing eligibility guidance means the operational details, including how supervision will be structured in practice, what constitutes sufficient Justice Department and Homeland Security review, and how compliance will be monitored on a per-operation basis, remain undefined.

There is a notable tension between the memorandum's prohibition on targeting Americans or U.S.-based systems and the reality that transnational criminal infrastructure frequently routes through or resides on compromised U.S. systems. Criminal groups often use botnets, networks of hijacked computers, or compromised cloud servers located in the United States as relay points to mask their activities. How the government's prevention procedures will handle these situations is not addressed in the announced policy. That operational question will need resolution before any private firm can conduct a disruptive attack without legal exposure.

The distinction the memorandum draws between authorized offensive operations and "hack back" is also worth noting. In industry usage, "hack back" typically refers to retaliatory intrusions by victim companies against their attackers. This program is narrower: it targets transnational criminal organizations specifically, under government supervision, rather than granting victim companies a general right of cyber-response. The scope is closer to a deputized offensive capability than a self-defense doctrine for cyber.

Reuters reported on August 12 that President Trump signed the memo to allow use of cyber tools to target transnational criminal organizations Reuters.

The program's practical impact will depend on the forthcoming guidance, the speed of interagency approval processes, and whether private firms judge the legal and financial risk calculus favorable enough to participate. For an industry that has spent decades on the defensive side of the line, the memorandum opens a door that previous administrations kept closed.