Published Build3 min read
White House opens a contracted lane for private firms to hack back, with DOJ and DHS holding the pen
A presidential memorandum lets vetted US companies run surveillance and disruption operations against foreign cybercrime groups, but only under contract and with written approval for each one.
Written for builders.See today for builders

What happened
- The White House is creating a program, established by presidential memorandum, that will allow vetted U.S. cybersecurity companies to conduct offensive cyber operations against foreign cybercrime groups under federal direction.
- The memorandum creates two categories of authorized activity: cyber surveillance operations and cyber effects operations.
- A cyber surveillance operation involves secretly accessing a target's systems to collect intelligence that could identify the people behind a criminal operation, expose its infrastructure, or support a later disruption.
- A cyber effects operation can manipulate, disrupt, deny access to, degrade, or destroy systems, networks, infrastructure and the information stored on them, which could mean disabling command-and-control servers, taking criminal services offline, interfering with malware infrastructure, or deleting information used to operate a campaign.
- Companies cannot act independently or retaliate on behalf of a customer whenever they detect an intrusion; they must be accepted into the federal program, operate under a DOJ or DHS contract, and receive written government approval for every operation.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
A presidential memorandum creates a federal program under which vetted US cybersecurity firms can conduct offensive cyber operations against foreign cybercrime groups under government direction [1]. For security leaders who have spent years telling their boards that active defense stops at their own edge, the boundary has been redrawn, though not where most people will assume.
The memorandum defines two classes of authorized work [2]. A cyber surveillance operation means secretly accessing a target's systems to collect intelligence, which could identify the people behind a criminal operation, expose its infrastructure, or support a later disruption [3]. A cyber effects operation can manipulate, disrupt, deny access to, degrade, or destroy systems, networks, infrastructure, and the data on them, which in practice covers disabling command-and-control servers, taking criminal services offline, interfering with malware infrastructure, or deleting information used to run a campaign [4].
The constraints matter more than the capability. Firms cannot act on their own or retaliate for a customer whenever they spot an intrusion; they must be admitted to the program, work under a DOJ or DHS contract, and obtain written government approval for every operation [5]. Targets are limited to foreign cyber-enabled transnational criminal organizations attacking US people, businesses, government agencies, or other US interests [6], and a White House fact sheet cites ransomware, phishing, financial fraud, sextortion, and impersonation scams as the intended subject matter [7]. Read together, the authority attaches to an approved operation package rather than to a company [8]. This is not a licence to hack back; it is a procurement channel.
The plumbing sits with the Homeland Security Task Force's National Coordination Center, with executive directors appointed by DOJ and DHS [9]. A participating firm can take in threat information from businesses and government agencies, build a proposed operation from it, and submit an operation package to the center [10]. That is a different posture from the existing arrangement, in which vendors supply malware analysis, infrastructure data, telemetry, and attribution research to law enforcement [11]; under the program the vendor executes the surveillance or disruption itself [12].
Errata Security CEO Robert Graham reads the memorandum as a transfer of authority rather than a data-sharing push, writing that instead of making companies share data with the government, the government is sharing authority with them, specifically section 1030(f) [13]. His illustration: while CrowdStrike is tracking a Chinese APT group, it could get permission to hack computers belonging to that specific group, not blanket permission against all such groups, with law enforcement still requiring written approval of every operations package [14].
The unresolved part is liability. In a March analysis for Lawfare, former DOJ cybercrime prosecutor Aaron Cooper and attorneys Philip Chertoff and Shoba Pillay noted that no court has addressed whether section 1030(f) protects private companies conducting operations on behalf of the government [15]. The memorandum places participating firms under federal control and cites section 1030, but it does not amend the statute and does not explain what protection contractors would have under foreign computer-crime laws [16].
What to watch: the contract language, specifically indemnification and any treatment of exposure abroad, since that is where an untested reading of section 1030(f) [15] meets employees who travel. Watch also who is admitted, and whether the per-operation approval requirement [5] survives contact with operational tempo.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The White House is creating a program, established by presidential memorandum, that will allow vetted U.S. cybersecurity companies to conduct offensive cyber operations against foreign cybercrime groups under federal direction.
- [2]
The memorandum creates two categories of authorized activity: cyber surveillance operations and cyber effects operations.
- [3]
A cyber surveillance operation involves secretly accessing a target's systems to collect intelligence that could identify the people behind a criminal operation, expose its infrastructure, or support a later disruption.
- [4]
A cyber effects operation can manipulate, disrupt, deny access to, degrade, or destroy systems, networks, infrastructure and the information stored on them, which could mean disabling command-and-control servers, taking criminal services offline, interfering with malware infrastructure, or deleting information used to operate a campaign.
- [5]
Companies cannot act independently or retaliate on behalf of a customer whenever they detect an intrusion; they must be accepted into the federal program, operate under a DOJ or DHS contract, and receive written government approval for every operation.
- [6]
Targets must be foreign cyber-enabled transnational criminal organizations attacking U.S. people, businesses, government agencies, or other U.S. interests.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- socket.devSarah GoodingAug 13White House Authorizes Private Companies to Conduct Offensive Cyber Operations
Additional citations
- Socket (Sarah Gooding)
- Socket
- White House fact sheet, via Socket
- Robert Graham, Errata Security, quoted by Socket
- Cooper, Chertoff and Pillay writing in Lawfare, via Socket

