Trump Signs Off on Private Sector Hack-Back Operations Against Cybercriminals
The White House has formalised what many suspected was coming: private cybersecurity firms can now be contracted by US government agencies to run offensive operations against transnational criminal organisations with a cyber component. Trump signed the memo this week, making official a direction that had been telegraphed since March.
The scope is broad. Participating companies can carry out cyber surveillance and what the document calls 'Cyber Effects Operations,' defined as activities causing 'manipulation, disruption, denial, degradation, or destruction' of information systems and the infrastructure they control. In plain English: sanctioned hacking, with paperwork.
The memo does draw a line between pure surveillance missions and disruptive operations, though it concedes that even surveillance work will inevitably involve some degree of system manipulation. Covert intelligence gathering tends to be messy like that.
One notable carve-out: the programme targets foreign criminal groups, not entities operating directly on behalf of foreign governments. Nation-state actors remain the domain of official intelligence operations. This isn't a licence to poke at Chinese state infrastructure.
Companies wanting in will face vetting, annual capability evaluations, and strict operational procedures to be drafted within 60 days. There is also a financial skin-in-the-game requirement: a bond or escrow of at least $1 million, forfeited if a contractor steps out of line. The Justice Department gets a say on any operations touching US residents or triggering domestic legal concerns.
Certain outcomes are off limits entirely. Operations that could cause loss of life, serious injury, or qualify as an armed attack under international law are prohibited. Whether that line holds in practice is another matter.
The programme is designed to accommodate both large firms and smaller specialists brought in for targeted work. Which is a polite way of saying there will be room for boutique offensive security shops alongside the defence primes.
The legal position remains genuinely murky. The US Computer Fraud and Abuse Act does not obviously permit private companies to carry out offensive cyber operations abroad, and legal observers have been pointing this out since March. Some analysts argued the CFAA would need amending before any of this could be done cleanly.
There is, however, a potential escape hatch. Section 1030(f) of the CFAA exempts lawfully authorised investigative, protective, or intelligence activity conducted by or on behalf of a US government agency. If contractors operate under direct government direction and within formally authorised procedures, they might fall within that exemption. Might. No court has actually tested this, and lawyers at Jenner and Block were careful to note that the protection almost certainly would not extend to private firms acting independently.
The key word is 'direction.' The government is writing the procedures and calling the shots. That relationship may be what keeps participating firms on the right side of a statute that was never written with government-contracted hackers in mind.
Whether the legal scaffolding holds is something courts will eventually have to work out. For now, Washington is pressing ahead, and US allies are watching closely. If this model proves effective, or even just survivable legally, expect others to take notes.