For roughly fifteen years, “hack back” has been the idea that would not die and would not happen. Every couple of years a bill would surface, a think tank would publish a paper invoking eighteenth-century letters of marque, and the security industry would line up almost unanimously against it — attribution is too hard, escalation is too easy, and the last thing a contested internet needs is a few hundred companies shooting into the dark. The idea always lost.
On August 12, 2026, it stopped losing. President Trump signed a National Security Presidential Memorandum titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” directing the Department of Justice and the Department of Homeland Security to build a formal program under which vetted private companies can conduct offensive cyber operations against foreign cyber-enabled criminal organizations. The departments have 60 days to produce operating procedures, vetting criteria, and an approval process.
It is not letters of marque. That distinction matters enormously, and most of the coverage has blurred it. But it is still the largest structural change in American cyber policy since the 2018 shift to “defend forward” — and unlike that change, this one reaches directly into the private sector.
What the Memo Actually Says
Strip away the commentary and the memorandum does five specific things.
It creates two categories of authorized activity. Cyber Surveillance Operations cover the access and reconnaissance work needed to observe adversary infrastructure — including, per the memo’s own language, manipulation or temporary disruption not intended to cause physical effects. Cyber Effects Operations go further: activity resulting in the “manipulation, disruption, denial, degradation or destruction” of systems or information. This is the part that would be plainly criminal under the Computer Fraud and Abuse Act absent federal authorization.
It requires express government approval for every operation. This is the hinge on which the whole thing turns, and it is why “hack back” is the wrong label. A letter of marque delegates authority — the privateer decides when and whom to raid. The memo does the opposite: participating companies propose operations, and every operations package requires review and approval by a designated executive director before anything runs. Companies are integrated into federal law enforcement and intelligence activity, not licensed to freelance alongside it.
It imposes a financial stake. Participants must post $1 million bonds. The memo does not fully specify what triggers forfeiture, which is one of several places where the document is a framework rather than a rulebook.
It sets escalation tripwires. Companies must notify authorities of imminent threats or the potential for what the memo calls “Critical Outcomes” — loss of life, or effects rising to the level of an armed attack. Someone in the government drew a line, and the line is meant to be reported before it’s crossed.
It builds an institutional home. A National Coordination Center oversees execution, with DOJ and DHS as the contracting parties. Companies must sign agreements with one of the two departments, undergo what the memo calls rigorous vetting, submit to ongoing evaluation of technical proficiency, and report regularly. The memo explicitly instructs that the program be designed so both small firms and large ones can participate.
What It Doesn’t Say
The gaps are as important as the text, and security leaders evaluating participation should hold them clearly in view.
Liability protection is incomplete. The memo routes around the CFAA by making operations government-approved, but it does not resolve what happens when an operation goes sideways — when infrastructure turns out to be shared, when a third party is damaged, when a foreign government objects. Practitioners advising on the memo have flagged indemnification, litigation support, and state-secrets protections as terms that companies would need to negotiate contractually, not assume.
Eligibility is undefined. Who qualifies as a vetted company? What clearances, what track record, what corporate structure? That is what the 60-day process is supposed to answer, and it is where the real policy will get made.
Foreign-law exposure is untouched. A U.S. government approval is not a defense in another jurisdiction. Operations against infrastructure that transits allied territory create legal exposure the memorandum has no power to waive.
“Transnational criminal organization” is a boundary that will be tested. The memo scopes to criminal groups, not nation-states. In practice the line between a ransomware crew and a state-tolerated or state-directed actor is frequently indistinguishable — which is precisely the ambiguity that makes the scoping so consequential.
The Reaction
The industry split roughly along the fault line you would expect. Josh Steinman, a former Trump White House cyber official now at Galvanick, backed the move. Chris Wysopal, Veracode’s co-founder, called it “a pretty big shift in US cyber policy” — an assessment nobody disputes. Jason Kitka, formerly of Cyber Command, criticized it, and the sharpest version of the skeptical case is that a market for authorized offense creates, as one critic put it, a perpetual motion machine for billable threats: the firms paid to disrupt threats also get to characterize how threatening they are.
That critique deserves to be taken seriously rather than dismissed as cynicism. It is a structural conflict, not a hypothetical one, and the memo’s oversight provisions — approval per operation, technical proficiency evaluation, regular reporting — read like an attempt to design against it. Whether the design holds depends entirely on the implementation details that don’t exist yet.
The escalation concern is the other durable objection. Private offensive capability operating under state approval is a model with international precedent, and not encouraging precedent. Other governments will observe that the United States has legitimized it, and will draw their own conclusions about what their own contractors may do.
What This Means for Security Leaders
Most CISOs will never sign one of these contracts. The memo still changes your world in four concrete ways.
Your threat model now includes authorized offense against infrastructure you may share. Criminal groups rent the same clouds, CDNs, and hosting providers legitimate businesses do. An approved operation against a criminal cluster is an operation inside a shared environment. Ask your cloud and hosting providers directly whether they intend to participate in the program, and what their notification posture is if their infrastructure is touched by one. You want that conversation on the record now, not during an incident.
Your threat-intelligence relationships are about to get more complicated. The memo explicitly encourages commercial threat-sharing agreements between participating companies and with federal, state, local, tribal, and territorial agencies. If a vendor in your intel stack becomes a program participant, the data you share with them may feed operational targeting. Review your intel-sharing agreements for language governing downstream operational use. This is a contract question, not a philosophical one, and it should be resolved before your next renewal.
Retaliation risk shifts from theoretical to concrete. If a firm in your sector — or your own vendor — participates in disrupting a criminal group, that group’s response will not be carefully targeted. Sector-wide retaliation against a peer’s action is a scenario worth tabletopping this quarter, because it is a category of exposure your organization cannot mitigate through its own controls.
Board conversations will start whether you initiate them or not. Directors read the same headlines. Some will ask whether the company should participate; a few will ask why you aren’t already. Have a written position — most likely “we are monitoring, we are not pursuing participation, here is why” — before the question arrives cold in a meeting. The worst version of this conversation is the improvised one.
What This Means for Careers
For anyone building a career in security, the memo is a genuine signal, and worth reading carefully rather than enthusiastically.
Offensive skills gain a new, credentialed employer class. A vetted-company program creates demand for people who can operate at government standard: exploitation, access operations, infrastructure tradecraft, and the discipline to work inside a legal approval chain. This is not “red teaming with a bigger budget.” It is closer to the profile of the NSA’s revived Tailored Access Operations mission and the corporate offensive units that firms like Google have already stood up — and it will hire from the same shrinking pool of people who hold both the technical depth and the clearances.
Clearance-holding offensive operators just got scarcer and more valuable. The population that can pass this vetting is small, and the government competes for it directly. Expect compensation pressure at the senior end and aggressive recruiting out of the intelligence community and Cyber Command — a dynamic already visible in the broader shift toward offensive cyber strategy.
Cyber law and policy expertise becomes a hiring line, not a footnote. Every participating company needs people who can navigate CFAA authorization, international law exposure, and government contracting simultaneously. That skill combination is rare and, for the next few years, extremely well paid.
Think hard before you sign up. A career move into authorized offense is not neutral. The legal protections are incompletely defined, the program’s durability across administrations is unknown, and the reputational calculus of the work is genuinely contested within the profession. Those are legitimate reasons to want clarity before committing — and the 60-day implementation window is when that clarity either arrives or doesn’t.
The Bigger Picture
The most honest reading of this memorandum is that it is an admission. Law enforcement and the intelligence community have not been able to keep pace with transnational cybercrime at the scale it now operates, and the government has concluded that the capability it needs already exists — inside private companies. Rather than build it internally, it is renting it, under supervision.
That is a coherent argument. It is also a boundary that, once moved, is very hard to move back. The safeguards in the memo — express approval, bonded participation, escalation reporting, per-operation review — are the difference between a controlled program and the free-for-all the industry has spent fifteen years warning about. They exist on paper today. Whether they exist in practice is a question the next sixty days begin to answer, and the next several years will actually settle.
Security leaders should watch the implementation documents far more closely than they watched the memo. The memo set a direction. The procedures will set the reality.
Sources: CyberScoop — “Trump turns to private sector in offensive hacking operations memo” (August 2026); Wiley — “Navigating the New Presidential Memorandum on Transnational Cyber-Enabled Crime” (August 2026); NPR — “Trump administration wants to allow companies to hack foreign cybercriminals” (August 15, 2026); Lawfare — analysis of the administration’s cyber strategy and private-sector offensive operations; Gizmodo and GovTech commentary on the memorandum. Quotes attributed to Josh Steinman, Chris Wysopal, and Jason Kitka as reported by CyberScoop.
This article is provided for informational purposes only and reflects reporting available as of mid-August 2026. The memorandum’s implementing procedures had not been published at the time of writing; eligibility criteria, liability protections, and program scope are subject to change. Nothing here constitutes legal advice — organizations considering participation should consult counsel experienced in CFAA and government contracting matters.



