Published Invest3 min read
Washington Will Let You Hack Back for $1 Million and a Classified Rulebook
A National Security Presidential Memorandum dated Aug. 12 lets vetted U.S. firms run offensive cyber operations under DOJ and DHS direction.
Context for builders, not their beat.See today for builders

What happened
- President Trump signed a National Security Presidential Memorandum dated Aug. 12 creating a program for vetted U.S. private firms to disrupt foreign cybercriminal networks, directing the federal government to enlist them in offensive cyber operations against foreign criminal networks.
- A company applies, clears a vetting process, and posts a bond or escrow of at least $1 million, which is forfeited if it breaks the rules.
- The program is stood up inside the National Coordination Center of the Homeland Security Task Force.
- Two executive directors, one each from the Department of Justice and the Department of Homeland Security, would run the program.
- Private firms that contract with DOJ or DHS could propose and carry out operations to access, surveil, disrupt, or destroy systems tied to those networks operating abroad, including broader offensive action against the networks behind ransomware, phishing, financial fraud, and sextortion schemes.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
The White House has invited American companies to break into foreign computers on the government's behalf, and priced the entry ticket at a bond of at least $1 million [1][2]. President Trump signed a National Security Presidential Memorandum dated Aug. 12 standing up a program for vetted U.S. firms to disrupt foreign cybercriminal networks under Justice Department and Homeland Security direction [1], which converts a product decision at every threat intelligence vendor into a decision for its general counsel.
The plumbing is specific. The program sits inside the National Coordination Center of the Homeland Security Task Force [3] and is run by two executive directors, one from DOJ and one from DHS [4]. Firms that contract with either agency may propose and carry out operations to access, surveil, disrupt, or destroy systems tied to those networks abroad [5]. A participant applies, clears vetting, and posts a bond or escrow of at least $1 million that is forfeited if it breaks the rules [2]. It collects threat information from other businesses or from state and local agencies [6], submits a proposal to the NCC [7], and does nothing until the executive directors give written approval and direction [8]. The government keeps operational control [9]. Participation is reviewed annually [10].
What is authorized is not euphemistic. The memo permits "Cyber Surveillance Operations," which it defines as accessing systems without the owner's permission or by exceeding authorized access [11], plus broader offensive action against ransomware, phishing, financial fraud, and sextortion networks [5]. Operations that would cause "Critical Outcomes" are barred, and anything touching a U.S. person or U.S.-based system must stop immediately under minimization procedures [12].
Here is the part that matters commercially. Decrypt's account of the order is that participants act at their own legal risk [13], and the targeting rules live in a classified annex, leaving the public guardrails thin on detail [14]. So the document that makes a given intrusion lawful is a written approval a firm cannot show a customer, an auditor, a foreign court, or an underwriter. The bond is not insurance for the company; it is the government's collateral against the company. Anyone pricing this needs to assume the loss scenarios are third-party claims from abroad and follow-on customer indemnity demands, not the $1 million.
The scale argument is real but loose. The White House cited more than $20.8 billion in reported American losses to cyber-enabled crime in 2025 [15], while Decrypt separately put crypto scam losses alone at an estimated $80.7 billion for the same year [16] - roughly 3.9 times the reported total, which tells you the two figures are not measuring the same thing [17]. Against $20.8 billion, a $1 million bond is about 0.005 percent [18], and the more than $25 million in crypto already seized from investment and romance scams [19] is about 0.12 percent [20].
Implementation guidance is due within 60 days, which lands around Oct. 11 [21][22]. Watch whether that guidance says anything about indemnification or contractor liability, whether the $1 million floor moves once real firms model the downside, and which company is willing to be named first. A vendor that signs up without a written answer on indemnity is buying an operational capability and an uninsured tail at the same time.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
President Trump signed a National Security Presidential Memorandum dated Aug. 12 creating a program for vetted U.S. private firms to disrupt foreign cybercriminal networks, directing the federal government to enlist them in offensive cyber operations against foreign criminal networks.
ReportedView cited source - [2]
A company applies, clears a vetting process, and posts a bond or escrow of at least $1 million, which is forfeited if it breaks the rules.
ReportedView cited source - [3]
The program is stood up inside the National Coordination Center of the Homeland Security Task Force.
ReportedView cited source - [4]
Two executive directors, one each from the Department of Justice and the Department of Homeland Security, would run the program.
ReportedView cited source - [5]
Private firms that contract with DOJ or DHS could propose and carry out operations to access, surveil, disrupt, or destroy systems tied to those networks operating abroad, including broader offensive action against the networks behind ransomware, phishing, financial fraud, and sextortion schemes.
ReportedView cited source - [6]
A participating company gathers threat information from other businesses or from state and local agencies.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- decrypt.coJose Antonio LanzAug 13White House Lets Private Firms Hack Cybercriminals—At Their Own Legal Risk
Cited in this coverage: decrypt.co
Additional citations
- The White House


