U.S. EDITIONTHEWEEKLYOBSERVER.COM

HOME  /  POLITICS  /  WASHINGTON

CYBERSECURITY

Trump Gives Private Companies the Green Light to Hack Back at Foreign Cybercriminals

A newly signed presidential memorandum creates the first formal U.S. program letting vetted firms conduct offensive cyber operations — including data-destroying attacks — against foreign criminal networks.

ON

BY OBSERVER NEWSDESK

The Weekly Observer

AUG 14, 2026 · 4 MIN READ
fXinEMAIL
Trump Gives Private Companies the Green Light to Hack Back at Foreign Cybercriminals
The White House in Washington, D.C. File photo by Kathleen Tyler Conklin (Flickr), CC BY 2.0.

President Trump has signed a memorandum authorizing certain private American companies, for the first time, to launch their own offensive cyberattacks against foreign criminal hacking networks — a dramatic shift in a debate over "hacking back" that Washington has resisted formalizing for decades.

The National Security Presidential Memorandum, signed Wednesday, creates a formal program under Justice Department and Department of Homeland Security oversight that lets vetted firms conduct surveillance — including deploying spyware to gather intelligence — and disruptive attacks aimed at destroying data or systems belonging to transnational criminal organizations, according to The Washington Post.

Crucially, the memo does not hand companies a blanket right to retaliate against attackers on their own initiative. Participating firms must receive written pre-approval from federal directors before taking any specific action against a specific target, according to CyberScoop. The White House says the program is meant to fight cyber-enabled fraud and other crimes from transnational criminal organizations by "incorporating the ingenuity of the private sector" into the government's offensive toolkit.

Untested Legal Ground

The move formalizes what cybersecurity circles have long called "hack-back" — private-sector retaliation against hackers — an idea that has circulated in policy debates for more than a decade without ever being authorized at this scale. Legal experts caution the program sits on largely untested legal footing; U.S. courts have never squarely ruled on the boundaries of privately conducted offensive cyber operations against foreign targets, and allowing companies to break into and disrupt systems abroad raises thorny questions about attribution errors, unintended escalation and international law, according to Tech Times.

"THIS MEMORANDUM EXPANDS THE FIGHT AGAINST TCO-PERPETRATED CYBERCRIME BY INCORPORATING THE INGENUITY OF THE PRIVATE SECTOR."

Supporters of the policy argue that government agencies alone can't keep pace with the volume and sophistication of ransomware gangs, romance-scam networks and other cyber-enabled fraud operations often based overseas and out of reach of U.S. law enforcement. Critics counter that outsourcing offensive operations to private firms — even under supervision — risks turning corporate security teams into quasi-intelligence operatives without the accountability structures that govern government hacking programs.

The authorization is notably narrow in scope: it applies only to transnational criminal organizations, not to nation-state hacking groups linked to adversary governments like Russia, China, Iran or North Korea, whose activities remain the exclusive purview of U.S. Cyber Command and other government agencies, according to TechCrunch.

What's Next

DOJ and DHS are expected to begin standing up the vetting process for companies seeking to participate, though officials have not detailed a timeline for when the first authorized operations might begin. Cybersecurity policy watchers say the program's real test will come the first time an authorized company's operation goes wrong — whether through misidentifying a target or triggering retaliation against U.S. infrastructure.

SHARE THIS STORY