US to Allow Vetted Private Firms to Launch Offensive Cyberattacks Against Foreign Criminal Groups

The White House announced in August 2026 that vetted private companies will, for the first time, be permitted to conduct offensive cyber operations against international criminal gangs and hackers targeting Americans. The policy was established through a presidential memorandum published by the Trump administration on Wednesday, August 13, 2026.

The memorandum marks a significant departure from decades of U.S. cybersecurity policy. Under existing federal computer hacking laws, private companies have been prohibited from launching cyberattacks or disruption operations without court-authorized approval. The new policy allows participating firms to conduct surveillance — including the use of spyware to collect intelligence — as well as carry out disruptive attacks aimed at destroying criminals’ data or systems. The memorandum stops short of authorizing companies to “hack back” directly against cyber threats.

Participating companies must deposit $1 million in escrow, which will be forfeited for non-compliance. All operations require sign-offs from representatives of both the Justice Department and the Department of Homeland Security, and must be conducted under federal supervision. The government will issue detailed program requirements within two months. Procedures will also be established to prevent any operation from targeting Americans or U.S.-based systems.

The Trump administration cited a “growing threat” against Americans and businesses as the reason for the change, pointing to ransomware attacks, financial scams, and sextortion. The policy arrives amid ongoing cyberattacks on U.S. water infrastructure in over a dozen states — including Michigan, Minnesota, and Georgia — which intelligence officials have privately attributed to Iranian government-backed hackers, as well as a broader wave of AI-driven cyberattacks reported by Anthropic, OpenAI, Meta, and the U.K.’s AI Safety Institute.

Critics have raised concerns about the program’s risks. Cybersecurity veteran Jake Williams, vice president of research and development at Hunter Strategy, warned that Americans participating in these operations could be classified as “non-uniformed combatants” while traveling abroad, leaving them vulnerable to indictment or detention by foreign governments. Williams described the policy as “half-baked” and said he was not convinced the program would not be abused. The new policy is also expected to face legal challenges.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top