Trump Signs Aug. 12 Memorandum Creating a DOJ- and DHS-Run Program for Vetted Private Firms to Conduct Offensive Cyber Operations Abroad
The memorandum sets up a contracting program in which approved companies may hack foreign criminal networks, with each operation requiring written government approval and a $1 million bond.
The 40-Word Company That Might Hack Iran
A company can now break into a foreign server, map a criminal gang's infrastructure, and knock it offline — all with the U.S. government's written sign-off. That is new. Until Aug. 12, 2026, that work belonged only to the FBI, the NSA and Cyber Command[3][5].
President Trump signed the change that day, in a National Security Presidential Memorandum called "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime." The White House released it the next day[1][2]. It sets up a program letting vetted private companies run offensive cyber operations against foreign criminal networks — the gangs behind ransomware, phishing scams, financial fraud and sextortion[1][6].
It is worth being precise about what this is not. It is not what the security industry calls "hack back," where a company that gets breached strikes at its attacker on its own[2]. A firm has to apply, get vetted, sign a contract with the Justice Department or the Department of Homeland Security, and then get written approval for every single operation before it can act[2][6]. The program lives inside the National Coordination Center of the Homeland Security Task Force, run by two executive directors — one picked by the Attorney General, one by the Homeland Security Secretary[2][6]. Officials have 60 days to write the detailed rules[13].
The Guardrails Are the Argument
Here is the number both sides keep repeating, for different reasons: $20.877 billion. That is what the FBI's Internet Crime Complaint Center says Americans lost to online crime in 2025, with $11.37 billion of it tied to cryptocurrency[13]. The White House says 73% of U.S. adults have been hit by some kind of online scam or attack[13]. Supporters treat that scale as the whole argument — a crime wave this size needs more hands than the government has[5][14].
The memo tries to answer the obvious worry — a private company breaking into computers overseas going wrong — with hard limits written into the text itself. Firms must post a bond or escrow of at least $1 million, which they lose if they break the rules[11]. Operations expected to cause what the memo calls "Critical Outcomes" are banned outright — that means any effect serious enough to count as a use of force or an armed attack under international law, like causing death or serious injury[8][15]. And if an operation's effects reach a U.S. person or a U.S.-based system, it has to stop immediately[15].
Those guardrails exist because the hardest technical problem here is figuring out, with certainty, whose computer you are actually touching. Criminal networks rent servers from ordinary hosting companies and route their traffic through other countries. Hit the wrong box and you could knock out a hospital that happens to share the same infrastructure as a scam operation[9]. That is not a hypothetical critics invented — it is the same risk the memo's own rules are built to contain[9][15].
Contractor or Privateer
This is where the real dispute sits, and it is not really about the crime numbers. Critics point to Article I, Section 8, Clause 11 of the Constitution, which gives Congress — not the president — the power to grant "letters of marque and reprisal." That is the old authority to license private ships or actors to attack an enemy on the government's behalf[7]. Trump issued this by memorandum, with no vote in Congress[7]. CNN's headline called the firms "cyber privateers," a phrase that carries that whole legal argument inside two words[3].
The administration's answer is that this isn't privateering at all. A privateer, historically, picked its own targets and kept its own spoils. Here, the government picks the target, approves each operation in writing, and can shut any of them down — which the administration says makes these firms contractors under federal control, not independent raiders[2][6]. No court has ruled on which reading is right[8].
One detail cuts against both easy stories. The memo grants participating companies no immunity from prosecution, at home or abroad[8]. A firm that gets this wrong doesn't just risk a diplomatic incident — it risks its own executives facing criminal or civil exposure, with the government's approval offering no legal shield.
Why the Industry Itself Is Split
The companies with the skills to actually do this work are not lining up on one side. Some cybersecurity firms want in: they already track ransomware infrastructure commercially, for paying clients, and argue that doing it under a signed federal contract with per-operation sign-off beats the legal gray zone they operate in now[2][5]. Others — including firms that spent years opposing "hack back" legislation — see the no-immunity clause and the attribution problem and conclude the risk isn't worth the contract[8][9].
There's a personal stake here too. A former Cyber Command official warned that employees of participating firms could become targets themselves — detained or questioned by foreign governments when they travel, simply for working at a company enrolled in the program[9]. That risk doesn't show up in the bond requirement or the contract terms. It falls on individual employees with offices or family overseas.
What the Rest of the World Sees
Outside the U.S., the loudest reaction so far has been a warning about precedent, not a formal objection. The Register, a British tech outlet, framed it as Washington granting "a license to hack back" — a description CyberScoop's more technical reporting says is actually wrong, since victims still can't retaliate on their own[2][10]. But the underlying point stands regardless of the label: if the U.S. can authorize private contractors to break into foreign computers, other governments gain a ready-made argument for doing the same through their own proxies[10]. Those governments won't necessarily copy the American guardrails — just the American precedent.
There's also a scenario nobody has fully answered yet. Some criminal gangs operate with the tacit tolerance, or even direction, of the states that host them. A contractor targeting what looks like a Russian or Iranian criminal crew could, in theory, actually be hitting an arm of that government — turning a fraud takedown into something closer to a state-on-state incident[9].
As of Aug. 15, 2026, no Chinese or Russian government has issued an on-the-record response to the memorandum, and most overseas coverage in the first 48 hours simply republished U.S. wire reporting rather than adding official reaction[4]. Nothing has happened operationally yet, either — no company has been named, no contract signed, no operation approved. The 60-day clock on writing the actual rules is still running[13].
Summary
President Trump signed a National Security Presidential Memorandum on Aug. 12, 2026, titled "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime"[1]. The White House released it the next day[2]. For the first time, the U.S. government will let vetted private companies run offensive cyber operations against foreign criminal networks — work that has been the job of the FBI, the NSA and Cyber Command[3][5]. The stated targets are transnational criminal organizations behind ransomware, phishing, financial fraud and sextortion[1][6].
The program is not a free-for-all, and it is not what the industry calls "hack back." A company that gets breached still may not strike back on its own[2]. Instead, a firm must be accepted into the program, sign a contract with the Justice Department or the Department of Homeland Security, and get written approval for each individual operation[2][6]. The program sits inside the National Coordination Center of the Homeland Security Task Force and is run by two executive directors, one picked by the Attorney General and one by the Homeland Security Secretary[2][6]. Firms must post a bond or escrow of at least $1 million, which they forfeit if they break the contract[11]. Operations expected to cause "Critical Outcomes" — harm serious enough to count as a use of force under international law — cannot be approved[8][15]. Anything that reaches a U.S. person or a U.S.-based system must stop right away[15].
Supporters point to the size of the problem. The FBI logged $20.877 billion in reported internet crime losses in 2025, of which $11.37 billion involved cryptocurrency[13]. The White House says 73% of U.S. adults have been hit by an online scam or attack[13]. The administration argues private security firms already see these networks up close and have been "underutilized"[5].
The sharpest genuine dispute is about legal authority. Critics say the Constitution gives Congress, not the president, the power to grant "letters of marque and reprisal" — the old authority to license private actors to attack a nation's enemies[7]. The administration issued this by memorandum, without a vote in Congress[7]. Defenders answer that this is not a letter of marque at all: the government picks the targets, approves each operation, and can cancel any of them, so the firms are contractors, not privateers[2]. No court has ruled on the question[8]. Separately, the memo grants participating companies no immunity from prosecution — at home or abroad[8].
The Event
On Aug. 12, 2026, President Trump signed a National Security Presidential Memorandum titled "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime"[1]. The White House published it on Aug. 13[2]. It directs the creation of a program, housed in the National Coordination Center of the Homeland Security Task Force and led by executive directors from the Justice Department and the Department of Homeland Security, under which vetted private companies may conduct surveillance and disruptive cyber operations against foreign criminal networks[2][6]. Officials have 60 days to write the operating procedures[13].
Undisputed Facts
- The memorandum is titled "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime" and was signed Aug. 12, 2026[1][13].
- Companies must be vetted, must sign a contract with DOJ or DHS, and must get written government approval before each operation[2][6].
- The memorandum does not let a breached company strike back on its own; it creates a government-run contracting program instead[2].
- Participating firms must maintain a bond or escrow of at least $1 million, forfeit if they violate the contract[11].
- The memorandum bars operations expected to cause "Critical Outcomes" — effects likely to cause death or serious injury that could rise to a use of force or armed attack under international law[8][15].
- Operations that reach a U.S. person or a U.S.-based system must stop, and minimization procedures apply[15].
- The FBI's Internet Crime Complaint Center recorded $20.877 billion in reported losses for 2025, including $11.37 billion tied to cryptocurrency[13].
- The memorandum builds on a March 2026 executive order directing federal agencies to take a more aggressive posture against cybercrime[5].
- Article I, Section 8, Clause 11 of the Constitution assigns the power to grant letters of marque and reprisal to Congress[7].
- No court has ruled on the legal basis for the program, and the memorandum does not grant participating firms immunity from prosecution[8].
The Pressure
Strip away the moralizing and blame. What structural realities persist regardless of which narrative wins?
- Enforcement cannot reach the offenders
- Most of the money is stolen by people the U.S. cannot arrest. They sit in countries that will not extradite, and indictments against them pile up unserved. That gap — not ideology — is the force pushing the government toward disruption instead of prosecution[1][13].
- The expertise is already private
- The firms that map ransomware infrastructure do it commercially, for paying clients, every day. The government can hire that capacity in months or build it in years. Cost and speed favor hiring[5].
- Attribution is the technical bottleneck
- The hard part of any offensive operation is being certain whose machine you are on. Criminal networks rent servers from ordinary providers and route through third countries. This is why the same guardrails — U.S.-person stop rules, "Critical Outcomes" bans — appear in the memo and in critics' objections. Both sides know that is where it breaks[9][15].
- Precedent travels
- Whatever the U.S. authorizes for its own contractors becomes an argument other states can use for theirs. That cost is real and does not depend on whether the American program is well run[10].
Material realityNothing has happened operationally yet. The memorandum sets up a structure and gives officials 60 days to write operating procedures[13]. No company has been named, no contract signed and no operation approved. What is fixed is the shape: two executive directors from DOJ and DHS, per-operation written approval, a $1 million bond, a ban on effects severe enough to count as a use of force, and a hard stop on anything reaching U.S. persons or U.S.-based systems[2][6][11][15]. What is genuinely open is whether an executive memorandum can authorize this without Congress, since no court has ruled and the memo grants no immunity[7][8]. Underneath all of it sits a number nobody disputes: $20.877 billion in reported U.S. internet crime losses in 2025, against a prosecution rate for foreign-based offenders that is close to nil[13].
Narrative as a weaponThree groups are actively shaping how this reads. The White House wants you to see a victim-protection program — hence the lead with consumer losses and the words "vetted," "control" and "oversight," and the near-silence on which constitutional authority is being used[1]. Critics want you to see privateering, because the analogy carries the constitutional argument in a single word before any evidence is presented; "cyber privateers" appeared in headlines within a day[3][7]. The cybersecurity trade press is doing the most corrective work, mainly by insisting on a distinction the general press keeps collapsing — this is not victim hack-back, and the difference matters legally[2][8]. Two silences are worth noting on their own. Foreign governments had not responded on the record in the first 48 hours[4]. And the industry that stands to be paid has said very little in public, which is itself a position.
How Each Side Sees It
Each major actor’s view — how it frames things, its underlying incentive, and how it’s materially affected. Tap a side to read it.
Frames it asThe government says the enemy has already outgrown the government's capacity. Criminal gangs abroad steal from Americans daily and rarely face arrest, because they sit in countries that will not extradite. Private security firms already track these networks for their corporate clients. They see the infrastructure first and they move faster than a federal procurement cycle. The administration argues American business has "historically been underutilized" in disrupting these networks[5]. On the legal question, its position is that this is contracting, not privateering: the government selects the targets, signs off on every operation in writing, and can pull the plug — so the firms are hired hands under federal control, not independent raiders licensed to keep the spoils[2][6]. It also points to the guardrails written into the text: no "Critical Outcomes," a hard stop on anything touching Americans, and a $1 million bond that gives a company real money to lose[8][11][15].
WhyShow visible results against a crime category that costs Americans over $20 billion a year and touches most households[13]. It also fits a broader administration preference for using private capacity instead of growing federal headcount[5].
Impact on themOwns the outcome either way. A quiet, effective takedown campaign is a strong political story. A single operation that knocks out a foreign hospital, or a contractor employee detained overseas, lands on the White House[9].
Frames it asIndustry is split, and that split is the story. Firms that could win contracts argue they already have the visibility, the tooling and the talent, and that doing this under a signed federal contract with per-operation approval is far safer than the gray-market alternative. The other camp — which for years opposed "hack back" bills — argues the risk is not theirs to take. Attribution in cyberspace is genuinely hard: the server you hit is often a rented box in a third country running other people's traffic. Get it wrong and you have attacked an innocent business. And because the memo gives no immunity, the company, not the government, may carry the criminal and civil exposure[8]. A related worry is personal: foreign governments may treat employees of participating firms as fair targets for detention or questioning when they travel[9].
WhyNew federal revenue and a privileged seat at the table for some; protection of global staff, foreign offices and customer trust for others.
Impact on themDirect and financial. Entry costs at least $1 million in posted bond, plus vetting and compliance[11]. Firms with staff or data centers overseas weigh that against real legal and physical exposure[9].
Frames it asTheir core claim is constitutional, not tactical. Article I gives Congress the exclusive power to grant letters of marque and reprisal — the historical mechanism for licensing private actors to attack a nation's enemies[7]. Critics say a memorandum cannot substitute for that vote, and note that the old privateering system at least ran through prize courts, which created a public record; this program runs through an interagency center with no comparable judicial transparency[7]. Their second argument is operational: a former Cyber Command official said the memo sets out no clear process for protecting Americans' civil liberties, and that hacking a foreign data center to reach scammers could knock out a hospital sharing the same infrastructure[9]. Third, they argue the U.S. is surrendering a moral position it has spent a decade building. Washington has condemned China and Iran for using private contractors and criminal proxies to do state cyber work; one critic said using contractors this way "makes us no better" and "makes us look hypocritical"[9].
WhyKeep offensive state power inside institutions that can be sued, subpoenaed and voted on. Establish early that an untested executive authority does not become settled practice by default[8].
Impact on themLitigation is likely but slow, and standing is hard when operations are classified and the victims are abroad. Their nearer path is congressional pressure during the 60-day period while procedures are still being written[13].
Frames it asThe reciprocity argument is the strong one. If the United States may license private companies to break into computers in other countries, every other state gains a ready-made justification for doing the same through its own proxies — and those states will not copy the American guardrails, only the American precedent[10]. Analysts also flag an escalation trap: some criminal gangs are effectively tolerated or steered by the states they operate from. A contractor that hits what it believes is a Russian or Iranian criminal crew may in fact hit an arm of Moscow or Tehran, turning a fraud takedown into a state-on-state incident[9]. Third, the operators themselves face exposure: a private hacker acting under U.S. contract can still be prosecuted under the laws of the country whose systems were accessed, and existing cooperation frameworks like the Budapest Convention were not built for private enforcement[7].
WhySovereignty over networks inside their borders, and leverage to normalize their own proxy operations by pointing at Washington.
Impact on themAs of Aug. 15, 2026, no on-the-record Chinese or Russian government response to this memorandum had surfaced in searches; overseas coverage in the first 48 hours mainly republished U.S. reporting[4].
Like this article?
The Bias Ledger average rating 3.7
The same story, as framed by outlets across the spectrum, ordered least to most biased. The bias score (1 = straight, 10 = heavily spun) is an AI assessment of that framing — click an outlet to see its track record. The tell is the word choice or omission that reveals the angle.
| Outlet | Vantage | Bias | How they frame it | The tell |
|---|---|---|---|---|
| CyberScoop | U.S. cybersecurity trade press | 2 | "Trump turns to private sector in offensive hacking operations memo"[2] | The most precise framing found: it explicitly corrects the common error that this is victim "hack back," and describes the contracting-and-approval structure. Neutral verb, no adjective. Some unease shows in the choice of expert critics quoted, but the description is straight. |
| Bloomberg | U.S. center, business | 3 | "Trump Enlists Private Sector to Boost Cyber-Offensive Arsenal"[5] | "Enlists" and "boost" read as the administration's own verbs — capability-building rather than authority-expanding. The framing is institutional and untroubled; the constitutional objection is not in the headline. |
| Decrypt | U.S. crypto-industry trade press | 3 | "White House Lets Private Firms Hack Cybercriminals—At Their Own Legal Risk"[8] | Surfaces the detail most outlets buried: no immunity is granted, and the legal basis is untested in court. The em-dash clause is the analysis, but it is a sourced and checkable one. |
| CNN | U.S. center-left | 4 | "'Cyber privateers': Trump issues order allowing US companies to hack overseas groups under certain conditions"[3] | "Cyber privateers" leads in scare quotes, which flags it as someone else's word while still making it the frame. The phrase imports a contested legal claim — that this is a letter of marque — into the headline. The qualifier "under certain conditions" is accurate but vague where the memo is specific. |
| The Washington Post | U.S. center-left | 4 | "Trump signs memo authorizing private sector to launch cyberattacks"[4] | Drops the foreign-criminal-target limit and the per-operation approval requirement from the headline. "Launch cyberattacks" is technically right and reads far broader than what the memo permits. |
| Florida's Voice | U.S. right, Florida-based conservative outlet | 4 | "Trump signs memo authorizing private firms to conduct cyber operations against foreign crime groups"[14] | "Against foreign crime groups" is placed in the headline, which keeps the target narrow and the action justified. The letters-of-marque and civil-liberties objections do not drive the piece. |
| The Register | British technology press, skeptical house style | 6 | "Trump wants to grant private cyber firms a license to hack back"[10] | "License to hack back" is the one phrase specialist reporting says is wrong — the memo does not authorize victim retaliation[2]. "Wants to" also softens a signed instrument into an aspiration. |
References
- Expanding Capabilities to Combat Transnational Cyber-Enabled Crime — The White House · U.S. executive branch — the party issuing the action
- Trump turns to private sector in offensive hacking operations memo — CyberScoop · U.S. cybersecurity trade publication, ad- and event-funded; policy-focused newsroom
- 'Cyber privateers': Trump issues order allowing US companies to hack overseas groups under certain conditions — CNN · U.S. center-left cable and digital news, Warner Bros. Discovery-owned
- Trump signs memo authorizing private sector to launch cyberattacks — The Washington Post · U.S. center-left daily, owned by Jeff Bezos
- Trump Enlists Private Sector to Boost Cyber-Offensive Arsenal — Bloomberg · U.S. business wire, owned by Michael Bloomberg; market-oriented
- Trump taps cyber firms to go on offensive against criminals — The Record · Published by Recorded Future, a threat-intelligence company — a vendor in the sector it covers
- Trump resurrects digital privateers, bypassing Congress to let corporate militias wage cyberwar — NJ Today · U.S. left-leaning regional outlet; strongly opinionated framing
- White House Lets Private Firms Hack Cybercriminals—At Their Own Legal Risk — Decrypt · U.S. crypto-industry trade press; funded by and sympathetic to the digital-asset sector
- Trump's move to 'unleash' private sector hackers raises novel oversight, liability questions — Federal News Network · U.S. trade outlet covering federal agencies and contracting; advertiser-supported, government-workforce audience
- Trump wants to grant private cyber firms a license to hack back — The Register · British technology publication with a deliberately skeptical, irreverent house voice
- Trump signs memo calling for cyber privateers to conduct cyberattacks abroad — but they have to escrow $1 million to join — TechRadar · UK-based consumer and business technology site, Future plc; affiliate-revenue model
- In a first, US will allow some private firms to carry out cyberattacks — TechCrunch · U.S. technology trade press, owned by Regent; startup- and industry-facing
- Trump memo lets vetted US firms run offensive cyber operations abroad — SiliconANGLE · U.S. enterprise-technology trade site; sponsorship- and event-funded
- Trump signs memo authorizing private firms to conduct cyber operations against foreign crime groups — Florida's Voice · U.S. right-leaning Florida news outlet, aligned with state Republican politics
- White House authorizes private US companies to hack foreign criminal networks — Help Net Security · Independent cybersecurity trade publication, vendor-advertising funded