San Francisco Daily 360

collapse
Home / Daily News Analysis / The US government wants private companies to start hacking the hackers

The US government wants private companies to start hacking the hackers

Aug 15, 2026  Twila Rosenbaum 51 views
The US government wants private companies to start hacking the hackers

The United States government is preparing to rewrite the rules of cybersecurity engagement. Under a new presidential memorandum, the Trump administration will permit vetted private companies to carry out offensive cyber operations against foreign criminal groups. The program, which requires federal approval and supervision, gives private firms the power to hack back against hackers who target American citizens, businesses, and infrastructure.

A landmark shift in US cyber policy

For decades, the US government maintained a strict separation between defensive and offensive cyber activities. Private cybersecurity companies were allowed to build firewalls, monitor networks, and kick attackers out of compromised systems, but they were not permitted to launch their own attacks. That line has now been crossed. The memorandum establishes a formal program under which private companies can conduct both surveillance and disruptive cyber operations against foreign cybercriminal organizations, including those responsible for ransomware, fraud, and other digital crimes.

According to a report from TechCrunch, the program will be run jointly by the Department of Justice and the Department of Homeland Security. Every operation will require written approval from the program directors at those agencies. Companies will operate under federal supervision, meaning they are not getting a blank check to attack anyone they please. But the powers they are being granted are still extremely broad.

What the new program allows

The memorandum explicitly authorizes operations that can manipulate, disrupt, degrade, or destroy computer systems and data belonging to foreign criminal groups. That means private companies could potentially delete ransomware payloads, take down command-and-control servers, or cripple the infrastructure used by organized cybercrime rings.

In addition to these disruptive actions, the program allows surveillance operations. Companies may be permitted to secretly access computer systems without the owner's permission in order to gather intelligence. This kind of offensive spying was previously reserved for intelligence agencies like the NSA or CIA. Now, private firms might be doing the same, albeit under close government watch.

Rules and guardrails

Despite the sweeping authorities, there are some guardrails. The program is designed to target foreign criminal groups, not foreign governments. Companies are required to stop and report any operation that accidentally affects a US person or a system located on US soil. This is a critical limitation because cyber operations often involve infrastructure that spans multiple countries, and there is always a risk of collateral damage.

Another safeguard is financial in nature. Participating companies may be required to put up at least $1 million in a bond or escrow account. If the company violates the rules, that money could be forfeited. This is intended to create accountability and ensure that private firms do not overstep their authority.

The exact procedures and rulebook for the program have not yet been written. The memorandum gives government officials 60 days to establish the operating procedures. That means the program is still in its early stages, and there is likely to be significant debate over how it will be implemented.

Background: Why the US is taking this step

The move comes amid a surge in cybercrime, particularly ransomware attacks. In recent years, criminal groups operating out of Russia, North Korea, and other countries have targeted US hospitals, schools, energy companies, and even government agencies. These attacks have caused billions of dollars in damage and have occasionally threatened critical infrastructure.

The traditional US approach has been to rely on law enforcement and intelligence agencies to disrupt cybercrime operations. However, these efforts are often slow and face legal restrictions. Private companies, especially those with incident response teams, have long argued that they are in a better position to neutralize cyber threats quickly. Some have even admitted to conducting informal hack-back operations, despite the legal gray areas.

The Trump administration's new policy is an attempt to bring these activities out of the shadows and establish a legal framework for them. By allowing vetted companies to conduct offensive operations under federal supervision, the government hopes to strike a balance between speed and accountability.

Industry reactions and concerns

Not everyone is convinced the plan is prudent. Cybersecurity veteran Jake Williams described the plan as “half-baked” in comments to TechCrunch. He warned that Americans employed by participating firms could face legal trouble or accusations from foreign governments when traveling overseas. Because the operations would target systems located in foreign countries, those countries might choose to press charges against the individuals involved, even if the US government authorized the operation.

There are also concerns about the risk of escalation. If private companies start hacking criminal groups, those groups could respond by targeting the companies themselves. This could lead to an arms race in which cybersecurity firms become direct combatants rather than neutral defenders. Moreover, the line between criminal groups and state-sponsored actors is often blurred. Some criminal hacktivists work with intelligence agencies, so an operation intended to hit a criminal gang might inadvertently damage diplomatic relations.

Legal and ethical questions

The program raises deep legal questions. Under the Computer Fraud and Abuse Act and similar laws, unauthorized access to computer systems is a crime. While the presidential memorandum may provide authorization for private companies, it is not clear that such document can exempt them from criminal liability under existing federal statues. Some legal scholars argue that a presidential memorandum is not sufficient to legalize acts that otherwise constitute hacking.

Additionally, there are international legal implications. Offensive cyber operations against targets in foreign countries could violate those countries' sovereignty. The United States has often criticized other nations for allowing cybercrime to flourish, but now the US itself is planning to authorize hacking operations across borders. Whether this is a violation of international law would depend on the specific circumstances and the level of state involvement.

Another concern is transparency. The program is likely to be classified or at least subject to secrecy. That means the public may not know which companies are involved or what operations they are conducting. This lack of oversight could lead to abuses, and it is unclear why the escrow requirement would be sufficient to prevent a company from going rogue.

Historical context: from defense to offense

The US government's stance on private-sector hacking has evolved over time. During the 1990s and 2000s, the FBI discouraged companies from hacking back, preferring to handle cybercrime investigations directly. In 2017, a bill introduced in Congress would have amended the Computer Fraud and Abuse Act to allow companies to take retaliatory actions, but it did not pass. The current memo goes much further than previous proposals.

Similarly, the Department of Defense has been experimenting with the idea of using private contractors for offensive cyber operations. The military has long relied on private firms for technology and intelligence support, but direct involvement in offensive hacking has been rare. This new program could open the door for companies like Palantir, Booz Allen Hamilton, and a host of smaller cybersecurity firms to take on roles that were once exclusively reserved for government operatives.

What could go wrong

The dangers are not merely theoretical. In 2018, a group of security researchers discovered a vulnerability that could have allowed them to take down a major ransomware group's infrastructure. Instead of doing so, they informed law enforcement, fearing legal consequences. Under the new policy, such an action might be legal—if the company were part of the program and received government approval.

But there is also the problem of attribution. Cybercrime groups often hide behind proxy services, stolen credentials, and pivots through multiple countries. A private company conducting an operation might accidentally hit the wrong target. The memorandum includes a requirement to stop and report any accidental targeting of US persons or systems, but what about accidentally targeting a hospital or power grid in another country? The consequences could be catastrophic.

The use of surveillance operations also raises privacy concerns. To gather intelligence, companies may need to collect personal data from systems that are used by innocent people. Even if the target is a criminal group, there is a risk that their communications could include protected information from American citizens. The program's safeguards may not be enough to prevent violations of privacy.

Potential benefits

Despite the risks, proponents argue that the policy is necessary. Ransomware attacks are becoming more severe and more common. In 2025, reports showed that ransomware payments surpassed $1 billion for the first time. Many of the most dangerous groups are based in jurisdictions where US law enforcement has no jurisdiction. Offensive cyber operations could disrupt these groups before they victimize more people.

Private companies also have expertise and agility that government agencies often lack. A skilled incident response team can understand the tactics, techniques, and procedures of a criminal group much faster than a large bureaucracy. By empowering these teams to go on the offense, the US government could potentially stop cybercrime networks before they grow too big.

The requirement of federal approval provides a layer of accountability. Companies cannot just act on their own. Every operation must be vetted by the Justice Department and the Department of Homeland Security. The escrow bond ensures that there are financial consequences for noncompliance. This could deter reckless behavior and give the government an oversight tool.

What happens next

Officials now have 60 days to establish the operating procedures. During this time, we can expect intense debate among lawmakers, cybersecurity experts, and civil liberties groups. The program will likely face legal challenges from organizations that believe it violates the law or the Constitution. Congress may also attempt to pass legislation that puts additional restrictions on the program or blocks it altogether.

In the meantime, cybersecurity firms are watching closely. Those interested in participating will need to prepare for a rigorous vetting process and be ready to wait for possible legal battles. The first operations under the new program could take place later this year or in 2027, depending on how quickly the rules are finalized.

The shift toward allowing private companies to hack the hackers is a significant moment in the history of cyber conflict. It reflects the growing severity of cybercrime and the limits of traditional law enforcement. However, it also represents a departure from long-established legal principles and carries substantial risks. Whether this program will make Americans safer or simply create new problems remains an open question.


Source:Android Authority News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy