Generated by Codex with GPT 5.6 Sol XHigh
Techmeme surfaced TechCrunch’s August 13 report, “In a first, US will allow some private firms to carry out cyberattacks.” The article examines an August 12 presidential memorandum that creates a federal program for vetted American companies to conduct offensive cyber operations against foreign criminal organizations.
The distinction that matters is between private “hack back” and government-directed contracting. The memo does not give every breached company permission to retaliate. It puts participating firms under federal supervision, requires written approval for each operation, and says the companies act exclusively on behalf of the United States using government authority. Even with those limits, it is a substantial policy change: capabilities previously reserved to agencies and military or intelligence contractors can now be exercised operationally by private cybersecurity firms.
What the Program Actually Authorizes
The National Coordination Center will run the program, with one executive director from the Department of Justice and another from the Department of Homeland Security. Participating companies must sign a contract with one of those departments and satisfy standards for technical competence, operational history, secure facilities, personnel vetting, reliability, and other criteria that have yet to be written. The memo explicitly asks the program to accommodate both large companies with capacity and smaller firms suited to specialized missions.
Two kinds of activity are in scope. “Cyber Surveillance Operations” cover unauthorized access performed to collect intelligence while remaining undetected. “Cyber Effects Operations” can manipulate, disrupt, deny, degrade, or destroy data, systems, networks, or infrastructure. That range reaches well beyond tracing stolen funds or sharing threat indicators: an approved contractor could quietly implant access for a later mission or actively disable criminal infrastructure.
The intended targets are foreign cyber-enabled transnational criminal organizations attacking U.S. people, institutions, or interests. The definition excludes groups that are institutional parts of foreign governments or wholly directed by them. But the memo also says a group is presumed independent unless clear intelligence establishes the government connection. That presumption is operationally important because ransomware crews, fraud networks, intelligence services, and military units can share tools, hosting, personnel, or protection without fitting into clean categories.
Private firms may use threat information gathered by their commercial customers to propose operations. State, local, tribal, territorial, and federal agencies may also identify threats for proposals. This creates a path from ordinary incident-response data to a government-authorized offensive package, potentially shortening the distance between observing an attack and disrupting its infrastructure.
Guardrails Exist, but the Hard Rules Come Later
The memo requires DOJ and DHS to produce operating procedures within 60 days. Until those rules exist, no operation can be approved. Every package must receive written review and direction from both program leaders. Contractors may be required to keep at least \$1 million in bond or escrow, forfeitable for violating their agreements, and their eligibility must be reconsidered at least annually.
The planned procedures must prevent targeting U.S. people and systems without the necessary legal or judicial authorization. If an operation strays onto an American person, an American-controlled system, or infrastructure located in the United States, the company must stop, minimize what it collected or affected, and immediately alert the government. It must do the same if it uncovers an imminent attack on critical infrastructure or believes an operation could cause a “Critical Outcome.” The executive directors’ delegated approval authority does not extend to actions likely to cause death or serious injury, or to rise to the level of force or armed attack under international law.
These are meaningful controls on paper, but they leave the difficult part to implementation. A bond can punish noncompliance after the fact; it cannot restore an innocent server, reverse leaked intelligence, or undo escalation. Annual eligibility reviews do not reveal how targets will be attributed, how evidence will be independently challenged, or how contractors will be held accountable when an authorized action has effects outside its approved boundary. Much of that workflow sits in a classified annex, while the required annual status report goes to executive-branch officials rather than being expressly made public.
The Central Risk Is Misidentification
Cyber operations rarely land on a neatly labeled machine owned only by the intended adversary. Attackers routinely route traffic through compromised routers, cloud accounts, websites, and business networks belonging to victims. A server that appears to support a criminal group may be rented with a stolen identity, shared with unrelated customers, or located in a partner country whose laws still treat the American contractor’s access as a crime.
The Verge’s coverage highlights both attribution and collateral-damage risks. It notes that mixed relationships between criminal groups and foreign governments can be hard to classify, while infrastructure used by an attacker may actually belong to an innocent organization. TechCrunch also reports a more personal exposure: employees carrying out these operations could face foreign indictments, detention, or accusations that treat them as non-uniformed combatants. U.S. authorization does not automatically create immunity in every jurisdiction touched by an operation.
Incentives also deserve scrutiny. Contractors can receive valuable access, government work, and proprietary intelligence while proposing missions from data supplied by customers. A sound system therefore needs more than technical review. It needs disciplined separation between the company that identifies an opportunity, the officials who validate the target, and the authorities that measure results and investigate mistakes.
A New Market for State-Directed Cyber Power
The case for the program is straightforward. Criminal groups operate across borders, exploit infrastructure faster than traditional legal processes can seize it, and impose large costs on Americans. Private security companies often see attacker behavior first and employ specialists the government cannot easily recruit or retain. Putting that capacity inside a supervised federal process could make takedowns faster and more persistent than defense alone.
The test is not whether contractors can break into criminal systems; many firms already possess the technical ability. The test is whether the government can turn that ability into legitimate, discriminating operations with reliable attribution, tight boundaries, and consequences for mistakes. The most important details—target-evidence standards, conflict checks, escalation paths, auditability, and oversight—are precisely the details still being written.
This makes the memo consequential before the first operation launches. It establishes private offensive cyber work as an instrument of U.S. policy, not merely an exceptional workaround. If the program succeeds, it may become a durable model for fighting ransomware and transnational fraud. If it fails, the damage could include innocent systems, diplomatic conflict, contractor exposure, and weaker norms against privately executed cyberattacks. The next 60 days of implementation will determine which version of “cyber privateering” the United States is actually creating.