Published Product3 min read
Offensive hacking becomes a procurable service, gated by a $1 million forfeitable bond
A presidential memorandum lets vetted private firms surveil and disrupt foreign criminal networks under Justice and Homeland Security oversight. The entry price is a $1 million bond.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- The Trump administration is launching a program that will allow private firms to perform cyberattacks against foreign criminals, as reported earlier by Bloomberg.
- According to a presidential memorandum published on Wednesday, private firms would operate "under the control and oversight" of the federal government, with permission to surveil and disrupt criminal networks.
- President Donald Trump began making plans to get private cybersecurity companies involved last year, Bloomberg reported.
- The Department of Justice and Department of Homeland Security will oversee the private firms, which must meet requirements in "technical proficiency, proven performance of cyber operations, facility security," and more.
- Companies in the program must hold a bond or escrow of at least $1 million that they will forfeit if they do not comply with their contractual agreement.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
A presidential memorandum published Wednesday authorises private firms to conduct cyberattacks against foreign criminal groups while operating "under the control and oversight" of the federal government, including permission to surveil and disrupt those networks [2]. The program was first reported by Bloomberg [1], and it converts something that used to be a government function into a line item a vendor can bid on [12][2].
The gating criteria are worth reading closely. The Department of Justice and the Department of Homeland Security will oversee participating firms, which must satisfy requirements in "technical proficiency, proven performance of cyber operations, facility security," and more [5]. Participants must also hold a bond or escrow of at least $1 million, forfeited if they breach their contractual agreement [6]. Of the qualifications described in the source material, the bond is the only one expressed as a number [1]. Everything else is judgement exercised by two departments, which means the real qualification bar is discretionary and unpublished.
The scope limit is a single sentence doing a great deal of work: firms may only hack groups that are "not an institutional part of a foreign government or wholly operated under a foreign government's direction" [7]. Cybersecurity Dive has noted that identifying which criminal groups are affiliated with foreign governments is difficult, and that getting it wrong could pull security firms into geopolitical or legal conflicts [10]. Jason Healey, a senior cyber conflict researcher at Columbia University, told Cybersecurity Dive that "Anyone conducting these operations is doing so at substantial personal legal risk" [11]. Jake Williams, vice president of research and development at Hunter Strategy, told TechCrunch that "Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas" [13]. That is an employment risk, not just a corporate one.
For anyone running infrastructure, the more immediate change is to the threat model. Ben Bernstein of Huntress puts the problem concretely: attackers do not operate from labelled servers in Moscow but route traffic through compromised third-party infrastructure such as a vulnerable router at an Ohio dental office or a hospital network, which he says makes it "practically impossible to 'strike back' without taking out innocent bystanders" [14]. If your firewall, VPN appliance or clinic router is being used as a relay, you are now a potential waypoint in a sanctioned disruption operation as well as a criminal one. Incident response playbooks that assume hostile traffic is criminal and friendly traffic is law enforcement no longer cover the field.
The memorandum's framing is that private businesses are an "underutilized" force against criminal networks [8], and that United States policy is to use "all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime" [9]. Trump began planning private-sector involvement last year, according to Bloomberg [4].
Watch three things. Whether the list of qualified firms and the terms of their contracts are made public, since oversight by DOJ and DHS [5] is only auditable if the awards are visible. Whether the $1 million bond [6] is the ceiling on a firm's exposure when a disruption operation damages an uninvolved third party, or merely the government's remedy for contractual non-compliance. And whether any firm publicly declines to participate, given the personal legal exposure described by Healey [11] and Williams [13].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The Trump administration is launching a program that will allow private firms to perform cyberattacks against foreign criminals, as reported earlier by Bloomberg.
- [2]
According to a presidential memorandum published on Wednesday, private firms would operate "under the control and oversight" of the federal government, with permission to surveil and disrupt criminal networks.
- [4]
President Donald Trump began making plans to get private cybersecurity companies involved last year, Bloomberg reported.
- [5]
The Department of Justice and Department of Homeland Security will oversee the private firms, which must meet requirements in "technical proficiency, proven performance of cyber operations, facility security," and more.
- [6]
Companies in the program must hold a bond or escrow of at least $1 million that they will forfeit if they do not comply with their contractual agreement.
- [7]
The memorandum says private firms will only hack groups that are "not an institutional part of a foreign government or wholly operated under a foreign government's direction."
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- theverge.comEmma RothAug 13The Trump admin will start letting private firms launch international cyberattacks
Additional citations
- The Verge, citing Bloomberg
- presidential memorandum, via The Verge
- Bloomberg, via The Verge
- Cybersecurity Dive, via The Verge
- Jason Healey, Columbia University, to Cybersecurity Dive
- The Verge
- Jake Williams, Hunter Strategy, to TechCrunch
- Ben Bernstein, Huntress, via The Verge



