Trump Memo Authorizes Private Firms to "Hack Back" at Foreign Cybercrime Gangs, $1M Bond
For the first time, the White House is letting vetted private firms go on the offensive against foreign cybercrime gangs — surveilling and disrupting criminal networks abroad under strict, government-approved rules, and a $1 million bond they forfeit if they break them.
The White House has, for the first time, told private American companies they may go on the offensive against foreign cybercrime gangs — surveilling and disrupting criminal networks abroad in operations the United States has until now reserved for its own military and intelligence agencies. President Trump signed the authorization on August 12, and it was made public the following day, according to reporting from The Register, TechCrunch, The Record, CyberScoop, Infosecurity Magazine and SecurityWeek. It arrives with an unusual price of admission: a bond of at least $1 million that a participating firm forfeits if it breaks the rules.
The move sweeps away decades of US cyber policy that treated private "hack back" as off-limits, and it reframes offensive operations against transnational criminals as something the government can license and direct rather than monopolize. The liftable fact: for the first time, vetted US firms can be authorized to conduct offensive cyber operations against foreign cybercrime gangs, gated by a $1 million bond and bound by strict, government-approved rules. One cybersecurity policy expert quoted in the coverage called it "a pretty big shift in US cyber policy."
A Memo, Not an Executive Order
The authorization takes the form of a national security presidential memorandum — a directive signed by the president — not an executive order, and not an act of Congress. That distinction matters for how durable it is: reporting describes a framework in which the executive branch, through agencies such as the Department of Justice and the Department of Homeland Security, vets companies, contracts with them, and approves the specific operations they may run. Firms that clear the vetting become, in the language of the reporting, "participating companies," and every operation is described as requiring written government approval and direction before any action is taken. The government is not stepping back from offensive cyber; it is deputizing a controlled set of private actors to carry parts of it out under contract.
Supporters of the approach, as reflected in the coverage, frame that government control as the point rather than a caveat. In their telling, the memorandum does not unleash corporate vigilantism; it channels private technical talent into a supervised system where the state still decides who acts, against whom, and how, and retains the ability to pull authorization. The counterargument, taken up below, is that supervision on paper and supervision in the fast-moving reality of a live operation are not the same thing.
What the $1 Million Bond Buys — and Costs
The most concrete new mechanism is financial. A participating firm must post a bond of at least $1 million — held in escrow, per reporting — as a condition of taking part, and it forfeits that money if it falls out of compliance with the terms of its contract. The bond is not a fee for access so much as a hostage: it gives the government a fast, non-judicial lever to punish a contractor that strays outside its authorized targets or methods, without waiting on a criminal case to run its course. Paired with the requirement that operations be pre-approved in writing, the bond is the enforcement half of a "strict rules" regime the administration is presenting as the guardrail that makes private offensive operations tolerable.
The structure of the authorization comes down to what it permits, what it demands in return, and what its critics fear it unleashes:
The Target: Foreign Cybercrime Gangs
The stated quarry is foreign and transnational cybercrime — the ransomware crews, extortion operations and fraud networks that run campaigns against Americans from outside US jurisdiction, where arrests and takedowns are slow and often depend on cooperation from countries that may not offer it. Reporting describes the memorandum as aimed at cyber-enabled transnational criminal organizations behind ransomware, phishing and extortion schemes. The logic the administration offers is one of reach: criminal infrastructure sits offshore, beyond the easy grasp of US law enforcement, and private firms with the talent and speed to act could disrupt it faster than the interagency process that governs government operations.
That framing places the memo alongside a run of aggressive, cross-border enforcement actions against criminal infrastructure. Coordinated takedowns like the German and US dismantling of the "Kratos" phishing-as-a-service platform, which reportedly seized more than 200 servers and produced an arrest in Indonesia, show what the existing government-to-government model can do. The memorandum's bet is that adding vetted private capacity to that mix expands what the United States can reach.
The enforcement gap the memo tries to close is real. When a ransomware crew operates from a jurisdiction that will not extradite or cooperate, the traditional toolkit — indictments, sanctions, and server seizures coordinated through mutual legal assistance — can take months and still leave the operators free to rebuild. The administration's wager is that vetted private firms, moving faster than that process allows, can raise the cost of doing business for criminals who have grown used to operating with near impunity from abroad. Critics do not dispute the gap; they dispute whether handing offensive authority to profit-driven companies is the right way to close it.
Sweeping Away Decades of 'No Private Hack Back'
For as long as the modern internet has had a security industry, US policy has drawn a hard line against private companies retaliating in kind against attackers. The Computer Fraud and Abuse Act broadly criminalizes unauthorized access to computers, and it makes no general exception for a victim that wants to break into an attacker's systems to claw back data or disrupt an operation. Proposals to create a limited private "hack back" right have surfaced in Congress before and never became law, precisely because of the risks the new memorandum now has to manage. Authorizing even a vetted, contract-bound subset of firms to conduct offensive operations abroad is, as the expert quoted in the coverage put it, "a pretty big shift in US cyber policy" — a reversal of the default rather than a tweak to it.
The Concerns: Escalation and Attribution
The reversal has drawn immediate caution, and two risks dominate the criticism reported so far. The first is escalation. Offensive operations against criminal infrastructure hosted abroad can land on servers inside other countries, and a disruptive action that a US firm views as narrowly targeted can look, from the other side of a border, like a state-sanctioned intrusion. Critics warn that private operators — even under government direction — could provoke retaliation or diplomatic friction, and that the presence of a profit motive changes the incentives in ways a purely governmental program does not.
The second is attribution, the perennial hard problem of offensive cyber. Naming who is behind an attack is difficult and error-prone, and the consequences of getting it wrong grow with the aggressiveness of the response. The affiliate structure of modern criminal operations makes this harder: as The CyberSignal noted in coverage of the attribution of SonicWall SMA zero-day exploitation to the INC Ransomware operation, tying activity to a named group is not the same as tying it to a specific set of hands, and criminals routinely route their operations through compromised third-party systems. A firm authorized to disrupt "foreign cybercrime gangs" is one attribution error away from disrupting an innocent network that a criminal merely borrowed.
Whether the memorandum's guardrails answer those risks is the crux of the debate. The administration's framework leans on pre-approval and the bond to keep operators inside their lane; skeptics counter that written approval cannot anticipate how a live operation unfolds once it touches infrastructure the government did not foresee, and that a forfeited bond compensates the government for a breach without undoing damage to a third party. Both positions turn on rules that have not been made public, which is why the reaction so far has been less a verdict than a demand to see the fine print.
What Is Not Yet Known
Key details remain unconfirmed at publication, and they are the details that will determine how consequential the memo turns out to be. It is not public which firms have applied or been approved, nor how many the program intends to admit. The full list of "strict rules," the categories of targets that are off-limits, and the precise thresholds an operation must clear for written approval have not been released. It is unclear whether and how allied governments are notified before an operation touches infrastructure on their soil, whether Congress will move to ratify, constrain or defund the framework, and what redress exists for an innocent party whose systems are damaged by a misfire. The exact text of the memorandum has not been published in full. The CyberSignal will update this piece as those documents surface.
What It Means for Defenders
For CISOs and enterprise security teams, this is a governance and awareness story before it is an operational one, and the exposure runs through shared infrastructure. Criminal operations frequently live on the same hosting providers, cloud tenants and content networks as legitimate businesses. A disruptive action aimed at a criminal host can carry collateral effects for other tenants of that infrastructure, which means an organization could feel the downstream of an operation it has no part in. Security teams should track how these authorizations are scoped and whether the providers they depend on could be caught in the blast radius of a sanctioned disruption.
The second watch item is attribution disputes. If offensive operations expand, so will arguments over who was actually behind a given piece of activity — and an enterprise whose systems were compromised and reused by a criminal group could find its own network implicated in someone else's attribution fight. Keeping clean logs, clear records of infrastructure ownership, and defensible incident timelines is the kind of unglamorous preparation that matters if a network is ever mistaken for part of a criminal operation.
My Read
My read: the $1 million bond is the tell. It signals that the administration understands the central danger of private offensive operations is not capability but accountability, and it is trying to buy accountability with a forfeitable deposit and pre-approval paperwork. Whether that holds depends entirely on the unpublished specifics — the off-limits targets, the notification rules, the redress for mistakes — none of which are public yet. A $1 million bond is a meaningful deterrent to a mid-sized contractor and a rounding error to a well-funded one, and the escalation and attribution risks that critics raise are real regardless of how carefully the rules are drafted, because they are properties of offensive cyber itself and not of any one contractor's diligence. This is a genuine reversal of a long-standing default, and the honest way to read it is neither as a green light for corporate vigilantism nor as a routine contracting update, but as an experiment whose guardrails have not yet been shown to the public that will live with the results.
Primary Documents
- The Register — Trump wants to grant private cyber firms a license to hack back
- TechCrunch — In a first, US will allow some private firms to carry out cyberattacks
- The Record — Trump authorizes offensive cyber operations against foreign cybercrime
- CyberScoop — Trump memo opens the door to private-sector offensive hacking
- Infosecurity Magazine — Trump authorizes private-sector offensive cyber operations
- SecurityWeek — White House mobilizes security firms for operations against foreign cybercrime gangs