BlackTree Security · Infrastructure · Automation · AI

America Is Hiring Private Cyber Firms to Hack Back! (Under Government Control)

A new White House programme will let vetted U.S. companies conduct offensive cyber operations against foreign criminal groups. The policy is a sharp change in who may act on America’s behalf online—but it is not a licence for private vigilantism.

On 12 August 2026, the White House signed a presidential memorandum titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.” It directs the National Coordination Center to build a programme through which vetted American companies can conduct cyber surveillance and cyber effects operations against foreign cyber-enabled transnational criminal organisations.

The target set includes organisations behind ransomware, phishing, financial fraud, sextortion and impersonation scams. The stated aim is to use the speed and technical capacity of the private sector to disrupt criminal networks that operate beyond the reach of conventional domestic enforcement.

This is not permission to hack anyone back

The memorandum does not give security vendors or victim companies a general right to attack suspected criminals. Participating companies must contract with the Department of Justice or Department of Homeland Security, pass technical and personnel vetting, and operate under federal direction.

Every proposed operation must be reviewed and approved in writing before action begins. The government will define the target, coordinate the operation across relevant agencies and retain operational control. Companies may be required to hold a bond or escrow of at least $1 million, which can be forfeited for contractual non-compliance.

The rules also draw hard limits around consequences. Officials may not approve an operation expected to cause death or serious injury, or one that would rise to the level of armed attack under international law. If an operation unintentionally touches a U.S. person, a U.S.-based system or a system controlled by a U.S. person, the company must stop, minimise the impact and notify the government immediately.

Why the policy matters

Private security companies already collect threat intelligence, dismantle malicious infrastructure with court approval and support law-enforcement operations. The new programme moves the boundary further. It creates a standing mechanism for companies to access systems without the owner’s authorisation and, where approved, manipulate, disrupt, degrade or destroy criminal infrastructure on behalf of the United States.

That could accelerate operations against ransomware panels, command-and-control servers, stolen-data repositories and scam infrastructure. A specialist company may understand a criminal platform better than any government team and may already have the telemetry needed to identify weak points. Shorter decision cycles could make disruption more effective against groups that routinely move domains, servers and cryptocurrency.

The same advantages create risk. Criminal infrastructure is often hosted on compromised third-party systems. Several groups share hosting providers, access brokers and malware services. Attribution can be incomplete, while the people running a ransomware affiliate programme may also have links to a foreign intelligence service. A mistaken target or an operation that spreads beyond its intended boundary could affect innocent organisations or create diplomatic consequences.

The state-connection problem

The programme is intended for foreign criminal groups, not institutional parts of foreign governments. However, the memorandum says a group will be assumed not to be controlled by a foreign government unless clear intelligence establishes that connection.

That is an important operational choice. The cybercrime ecosystem contains groups that are tolerated by states, occasionally tasked by intelligence services or staffed by people who move between criminal and government work. The distinction may be obvious in policy language but difficult to prove at the moment an operation is proposed.

Participating companies will therefore need more than offensive expertise. They will need defensible attribution, evidence handling, strict target validation, real-time monitoring and a reliable ability to stop. Insurers, legal teams and corporate boards will also want clarity about liability when an approved operation produces an unexpected result.

What happens next

The Justice and Homeland Security departments have 60 days to establish operating procedures and minimum standards. Those rules must cover company eligibility, target identification, deconfliction, reporting, legal review and the approval workflow. The first programme status report is due within 180 days, followed by annual reports.

The implementation details will determine whether this becomes a narrowly controlled extension of government capability or a much broader offensive market. Five questions deserve particular attention:

  1. Who qualifies? Technical skill is not the same as operational discipline, and smaller firms may face different governance pressures than established defence contractors.
  2. How are targets verified? Shared and compromised infrastructure makes positive attribution essential.
  3. What is disclosed? The public will need enough transparency to evaluate effectiveness without exposing sensitive methods.
  4. Who carries liability? Contracts and a $1 million bond do not resolve every consequence of an error across borders.
  5. How is success measured? Server takedowns are easy to count; durable reductions in victimisation are harder.

The practical lesson

This policy does not replace basic defence, incident response or international law-enforcement work. Nor does it authorise ordinary companies to retaliate after a breach. It creates a government-controlled channel through which selected private firms may perform offensive work using federal authority.

That distinction is the centre of the story. America is not simply legalising hack back; it is building a procurement and oversight framework for private cyber operators. If the programme works, it could make transnational criminal infrastructure more expensive and less reliable. If its attribution, controls or accountability fail, the consequences will travel far beyond the targeted server.

Sources and further reading

Leave a Reply

Your email address will not be published. Required fields are marked *