Tech and AI
Private companies cleared to attack criminal networks abroad on the American government's behalf
By Staff Writer | 14 August 2026

A presidential memorandum signed on 12 August lets vetted firms surveil and disrupt foreign criminal groups. Federal hacking law has said the opposite for decades.
The American government will allow approved private companies to run offensive cyber operations against criminal groups based abroad, under a National Security Presidential Memorandum signed on 12 August. Firms accepted into the programme may gather intelligence on those groups, including by deploying spyware, and may carry out disruptive operations aimed at destroying their data or their systems.
That reverses a position successive administrations have held for years. Private companies sit under the same federal computer misuse statutes as everybody else, and the settled reading has been that a company may defend its own network but may not go on the offensive without a court order. The memorandum keeps the prohibition on companies acting alone: every operation runs under the direction, control and authority of the government, and requires sign-off from officials at the Department of Justice and the Department of Homeland Security before it proceeds.
Administration of the programme falls to the National Coordination Center of the Homeland Security Task Force, with two executive directors, one designated by the Attorney General and one by the Secretary of Homeland Security. The published fact sheet puts consumer losses to cyber-enabled crime in the United States at more than 20.8 billion dollars in 2025, and lists ransomware, phishing, financial fraud, sextortion and impersonation as the categories the programme is meant to reach.
Entry is not free. A participating company must hold a bond or escrow of at least 1 million dollars, forfeit if the government finds it has departed from the agreed rules of engagement, and its participation is reviewed annually.
The boundary the memorandum draws, and the one it does not
Targets are limited to foreign groups that are not an institutional part of a foreign government and are not wholly operated at a foreign government's direction. Anything aimed at an American person needs whatever authorisation the law requires, judicial or otherwise, before it is approved, and a company that finds it has strayed onto an American person or a system inside the United States must stop, minimise and notify at once. It must also report any imminent attack on critical national infrastructure it comes across. Guidance setting out what a company has to demonstrate before admission is due within 60 days, and is meant to accommodate smaller specialist firms as well as large ones.
The distinction between a criminal gang and a state-directed one is the weak joint, and the memorandum resolves it by presumption: a foreign group is taken not to be state-run unless clear intelligence establishes the connection. Practitioners have pointed out for years that the two overlap heavily, that the overlap is often deliberate, and that a company acting on a mistaken classification would be committing a hostile act against another state rather than disrupting a gang.
Threat actors don't launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network. That makes it practically impossible to 'strike back' without taking out innocent bystanders.
Ben Bernstein, Manager, cybersecurity advisers team, Huntress
What a contractor is being asked to carry
The exposure runs to the individuals, not only to the company. Cyber conflict researchers have warned that anyone conducting these operations does so at substantial personal legal risk, and that a foreign state need only allege participation to act on it. American prosecutors have charged named state hackers from several countries; the reverse is available to those countries, and an employee's travel plans become a matter for the general counsel rather than the diary.
Legal challenge looks likely, and the programme is at an early stage: the framework exists, the operating detail does not. For anyone drafting the agreements that will sit underneath it, the shape is already familiar. Two departments approve, one company executes, a third party's compromised equipment is in the path, and the memorandum's indemnity position, insurance requirements and liability for collateral damage are all left to the procedures still to be written.
Whoever signs first will be negotiating against a framework written entirely from the government's side of the table.