Pressure of Truth
Exposing the spin on all sides of the news.
U.S.

Trump Signs Aug. 12 Memorandum Creating a DOJ- and DHS-Run Program for Vetted Private Firms to Conduct Offensive Cyber Operations Abroad

The memorandum sets up a contracting program in which approved companies may hack foreign criminal networks, with each operation requiring written government approval and a $1 million bond.

How spun is the coverage?Coverage bias 3.7 / 10
4 sides analyzed15 sources cited

The 40-Word Company That Might Hack Iran

A company can now break into a foreign server, map a criminal gang's infrastructure, and knock it offline — all with the U.S. government's written sign-off. That is new. Until Aug. 12, 2026, that work belonged only to the FBI, the NSA and Cyber Command[3][5].

President Trump signed the change that day, in a National Security Presidential Memorandum called "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime." The White House released it the next day[1][2]. It sets up a program letting vetted private companies run offensive cyber operations against foreign criminal networks — the gangs behind ransomware, phishing scams, financial fraud and sextortion[1][6].

It is worth being precise about what this is not. It is not what the security industry calls "hack back," where a company that gets breached strikes at its attacker on its own[2]. A firm has to apply, get vetted, sign a contract with the Justice Department or the Department of Homeland Security, and then get written approval for every single operation before it can act[2][6]. The program lives inside the National Coordination Center of the Homeland Security Task Force, run by two executive directors — one picked by the Attorney General, one by the Homeland Security Secretary[2][6]. Officials have 60 days to write the detailed rules[13].

The Guardrails Are the Argument

Here is the number both sides keep repeating, for different reasons: $20.877 billion. That is what the FBI's Internet Crime Complaint Center says Americans lost to online crime in 2025, with $11.37 billion of it tied to cryptocurrency[13]. The White House says 73% of U.S. adults have been hit by some kind of online scam or attack[13]. Supporters treat that scale as the whole argument — a crime wave this size needs more hands than the government has[5][14].

The memo tries to answer the obvious worry — a private company breaking into computers overseas going wrong — with hard limits written into the text itself. Firms must post a bond or escrow of at least $1 million, which they lose if they break the rules[11]. Operations expected to cause what the memo calls "Critical Outcomes" are banned outright — that means any effect serious enough to count as a use of force or an armed attack under international law, like causing death or serious injury[8][15]. And if an operation's effects reach a U.S. person or a U.S.-based system, it has to stop immediately[15].

Those guardrails exist because the hardest technical problem here is figuring out, with certainty, whose computer you are actually touching. Criminal networks rent servers from ordinary hosting companies and route their traffic through other countries. Hit the wrong box and you could knock out a hospital that happens to share the same infrastructure as a scam operation[9]. That is not a hypothetical critics invented — it is the same risk the memo's own rules are built to contain[9][15].

Contractor or Privateer

This is where the real dispute sits, and it is not really about the crime numbers. Critics point to Article I, Section 8, Clause 11 of the Constitution, which gives Congress — not the president — the power to grant "letters of marque and reprisal." That is the old authority to license private ships or actors to attack an enemy on the government's behalf[7]. Trump issued this by memorandum, with no vote in Congress[7]. CNN's headline called the firms "cyber privateers," a phrase that carries that whole legal argument inside two words[3].

The administration's answer is that this isn't privateering at all. A privateer, historically, picked its own targets and kept its own spoils. Here, the government picks the target, approves each operation in writing, and can shut any of them down — which the administration says makes these firms contractors under federal control, not independent raiders[2][6]. No court has ruled on which reading is right[8].

One detail cuts against both easy stories. The memo grants participating companies no immunity from prosecution, at home or abroad[8]. A firm that gets this wrong doesn't just risk a diplomatic incident — it risks its own executives facing criminal or civil exposure, with the government's approval offering no legal shield.

Why the Industry Itself Is Split

The companies with the skills to actually do this work are not lining up on one side. Some cybersecurity firms want in: they already track ransomware infrastructure commercially, for paying clients, and argue that doing it under a signed federal contract with per-operation sign-off beats the legal gray zone they operate in now[2][5]. Others — including firms that spent years opposing "hack back" legislation — see the no-immunity clause and the attribution problem and conclude the risk isn't worth the contract[8][9].

There's a personal stake here too. A former Cyber Command official warned that employees of participating firms could become targets themselves — detained or questioned by foreign governments when they travel, simply for working at a company enrolled in the program[9]. That risk doesn't show up in the bond requirement or the contract terms. It falls on individual employees with offices or family overseas.

What the Rest of the World Sees

Outside the U.S., the loudest reaction so far has been a warning about precedent, not a formal objection. The Register, a British tech outlet, framed it as Washington granting "a license to hack back" — a description CyberScoop's more technical reporting says is actually wrong, since victims still can't retaliate on their own[2][10]. But the underlying point stands regardless of the label: if the U.S. can authorize private contractors to break into foreign computers, other governments gain a ready-made argument for doing the same through their own proxies[10]. Those governments won't necessarily copy the American guardrails — just the American precedent.

There's also a scenario nobody has fully answered yet. Some criminal gangs operate with the tacit tolerance, or even direction, of the states that host them. A contractor targeting what looks like a Russian or Iranian criminal crew could, in theory, actually be hitting an arm of that government — turning a fraud takedown into something closer to a state-on-state incident[9].

As of Aug. 15, 2026, no Chinese or Russian government has issued an on-the-record response to the memorandum, and most overseas coverage in the first 48 hours simply republished U.S. wire reporting rather than adding official reaction[4]. Nothing has happened operationally yet, either — no company has been named, no contract signed, no operation approved. The 60-day clock on writing the actual rules is still running[13].

Like this article?

Share this article

The Bias Ledger average rating 3.7

The same story, as framed by outlets across the spectrum, ordered least to most biased. The bias score (1 = straight, 10 = heavily spun) is an AI assessment of that framing — click an outlet to see its track record. The tell is the word choice or omission that reveals the angle.

OutletVantageBiasHow they frame itThe tell
CyberScoopU.S. cybersecurity trade press2"Trump turns to private sector in offensive hacking operations memo"[2]The most precise framing found: it explicitly corrects the common error that this is victim "hack back," and describes the contracting-and-approval structure. Neutral verb, no adjective. Some unease shows in the choice of expert critics quoted, but the description is straight.
BloombergU.S. center, business3"Trump Enlists Private Sector to Boost Cyber-Offensive Arsenal"[5]"Enlists" and "boost" read as the administration's own verbs — capability-building rather than authority-expanding. The framing is institutional and untroubled; the constitutional objection is not in the headline.
DecryptU.S. crypto-industry trade press3"White House Lets Private Firms Hack Cybercriminals—At Their Own Legal Risk"[8]Surfaces the detail most outlets buried: no immunity is granted, and the legal basis is untested in court. The em-dash clause is the analysis, but it is a sourced and checkable one.
CNNU.S. center-left4"'Cyber privateers': Trump issues order allowing US companies to hack overseas groups under certain conditions"[3]"Cyber privateers" leads in scare quotes, which flags it as someone else's word while still making it the frame. The phrase imports a contested legal claim — that this is a letter of marque — into the headline. The qualifier "under certain conditions" is accurate but vague where the memo is specific.
The Washington PostU.S. center-left4"Trump signs memo authorizing private sector to launch cyberattacks"[4]Drops the foreign-criminal-target limit and the per-operation approval requirement from the headline. "Launch cyberattacks" is technically right and reads far broader than what the memo permits.
Florida's VoiceU.S. right, Florida-based conservative outlet4"Trump signs memo authorizing private firms to conduct cyber operations against foreign crime groups"[14]"Against foreign crime groups" is placed in the headline, which keeps the target narrow and the action justified. The letters-of-marque and civil-liberties objections do not drive the piece.
The RegisterBritish technology press, skeptical house style6"Trump wants to grant private cyber firms a license to hack back"[10]"License to hack back" is the one phrase specialist reporting says is wrong — the memo does not authorize victim retaliation[2]. "Wants to" also softens a signed instrument into an aspiration.

References

  1. Expanding Capabilities to Combat Transnational Cyber-Enabled Crime — The White House · U.S. executive branch — the party issuing the action
  2. Trump turns to private sector in offensive hacking operations memo — CyberScoop · U.S. cybersecurity trade publication, ad- and event-funded; policy-focused newsroom
  3. 'Cyber privateers': Trump issues order allowing US companies to hack overseas groups under certain conditions — CNN · U.S. center-left cable and digital news, Warner Bros. Discovery-owned
  4. Trump signs memo authorizing private sector to launch cyberattacks — The Washington Post · U.S. center-left daily, owned by Jeff Bezos
  5. Trump Enlists Private Sector to Boost Cyber-Offensive Arsenal — Bloomberg · U.S. business wire, owned by Michael Bloomberg; market-oriented
  6. Trump taps cyber firms to go on offensive against criminals — The Record · Published by Recorded Future, a threat-intelligence company — a vendor in the sector it covers
  7. Trump resurrects digital privateers, bypassing Congress to let corporate militias wage cyberwar — NJ Today · U.S. left-leaning regional outlet; strongly opinionated framing
  8. White House Lets Private Firms Hack Cybercriminals—At Their Own Legal Risk — Decrypt · U.S. crypto-industry trade press; funded by and sympathetic to the digital-asset sector
  9. Trump's move to 'unleash' private sector hackers raises novel oversight, liability questions — Federal News Network · U.S. trade outlet covering federal agencies and contracting; advertiser-supported, government-workforce audience
  10. Trump wants to grant private cyber firms a license to hack back — The Register · British technology publication with a deliberately skeptical, irreverent house voice
  11. Trump signs memo calling for cyber privateers to conduct cyberattacks abroad — but they have to escrow $1 million to join — TechRadar · UK-based consumer and business technology site, Future plc; affiliate-revenue model
  12. In a first, US will allow some private firms to carry out cyberattacks — TechCrunch · U.S. technology trade press, owned by Regent; startup- and industry-facing
  13. Trump memo lets vetted US firms run offensive cyber operations abroad — SiliconANGLE · U.S. enterprise-technology trade site; sponsorship- and event-funded
  14. Trump signs memo authorizing private firms to conduct cyber operations against foreign crime groups — Florida's Voice · U.S. right-leaning Florida news outlet, aligned with state Republican politics
  15. White House authorizes private US companies to hack foreign criminal networks — Help Net Security · Independent cybersecurity trade publication, vendor-advertising funded