← BACK TO FEED
cybersecurityoffensive cyberUS policyhack-backCFAA

Trump Signs Off on Private Sector Hack-Back Operations Against Cybercriminals

President Trump has signed a memo authorising US government agencies to contract private cybersecurity firms to conduct offensive cyber operations — including surveillance and network disruption — against cyber-enabled transnational criminal organisations (CE-TCOs), excluding entities acting on behalf of foreign governments. Participating companies must undergo rigorous vetting, meet annual technical evaluations, maintain at least $1 million in bond or escrow, and are prohibited from operations that could cause loss of life or be considered an act of war. Legal experts have raised concerns about whether existing laws, particularly the Computer Fraud and Abuse Act, adequately cover private companies conducting such government-directed operations, though a key exemption may offer some protection.

The White House has formalised what many suspected was coming: private cybersecurity firms can now be contracted by US government agencies to run offensive operations against transnational criminal organisations with a cyber component. Trump signed the memo this week, making official a direction that had been telegraphed since March.

The scope is broad. Participating companies can carry out cyber surveillance and what the document calls 'Cyber Effects Operations,' defined as activities causing 'manipulation, disruption, denial, degradation, or destruction' of information systems and the infrastructure they control. In plain English: sanctioned hacking, with paperwork.

The memo does draw a line between pure surveillance missions and disruptive operations, though it concedes that even surveillance work will inevitably involve some degree of system manipulation. Covert intelligence gathering tends to be messy like that.

One notable carve-out: the programme targets foreign criminal groups, not entities operating directly on behalf of foreign governments. Nation-state actors remain the domain of official intelligence operations. This isn't a licence to poke at Chinese state infrastructure.

Companies wanting in will face vetting, annual capability evaluations, and strict operational procedures to be drafted within 60 days. There is also a financial skin-in-the-game requirement: a bond or escrow of at least $1 million, forfeited if a contractor steps out of line. The Justice Department gets a say on any operations touching US residents or triggering domestic legal concerns.

Certain outcomes are off limits entirely. Operations that could cause loss of life, serious injury, or qualify as an armed attack under international law are prohibited. Whether that line holds in practice is another matter.

The programme is designed to accommodate both large firms and smaller specialists brought in for targeted work. Which is a polite way of saying there will be room for boutique offensive security shops alongside the defence primes.

The legal position remains genuinely murky. The US Computer Fraud and Abuse Act does not obviously permit private companies to carry out offensive cyber operations abroad, and legal observers have been pointing this out since March. Some analysts argued the CFAA would need amending before any of this could be done cleanly.

There is, however, a potential escape hatch. Section 1030(f) of the CFAA exempts lawfully authorised investigative, protective, or intelligence activity conducted by or on behalf of a US government agency. If contractors operate under direct government direction and within formally authorised procedures, they might fall within that exemption. Might. No court has actually tested this, and lawyers at Jenner and Block were careful to note that the protection almost certainly would not extend to private firms acting independently.

The key word is 'direction.' The government is writing the procedures and calling the shots. That relationship may be what keeps participating firms on the right side of a statute that was never written with government-contracted hackers in mind.

Whether the legal scaffolding holds is something courts will eventually have to work out. For now, Washington is pressing ahead, and US allies are watching closely. If this model proves effective, or even just survivable legally, expect others to take notes.

READ NEXT
White House Outsources Cyber Offence to Private Firms in Unprecedented Anti-Crime PushObsidian Security Hits Unicorn Status With $85M Round Targeting AI Agent SprawlIsaac Asimov Knew What He Was Doing: Former US Cyber Chief Says Robot Laws Were Right All Along