Published Product3 min read
The $1 Million Bond: Washington Just Created a Licensed Offensive Cyber Product
A national security presidential memorandum lets vetted firms run surveillance and destructive operations abroad under DOJ or DHS contract.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- President Donald Trump signed a national security presidential memorandum on Wednesday titled "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," authorizing vetted private companies to carry out hacking operations against foreign criminal groups.
- The memorandum tells the Homeland Security Task Force's National Coordination Center to build the program, with executive directors from the Justice Department and Homeland Security running it.
- Approved firms may conduct cyber surveillance operations and cyber effects operations, which the memo defines as disrupting or destroying a target's systems.
- Companies do not get blanket authority; each has to sign a contract with the Justice Department or Homeland Security.
- Screening of participating firms covers technical proficiency, facility security and personnel background.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
A national security presidential memorandum signed Wednesday authorizes vetted private companies to carry out hacking operations against foreign criminal groups, each under contract with the Justice Department or the Department of Homeland Security [1][5]. For anyone selling security services, that is a product category that did not previously exist and a liability regime that opens with a forfeitable bond of at least $1 million [8][9].
The memorandum, titled "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," assigns the build to the Homeland Security Task Force's National Coordination Center, with two executive directors from Justice and Homeland Security running the program [1][2]. Two work types are on offer: cyber surveillance operations, and cyber effects operations, which the document defines as disrupting or destroying a target's systems [3]. There is no blanket authority. Screening covers technical proficiency, facility security and personnel background, and written sign-off is required before any operation runs [6][7]. Program directors have 60 days to publish operating procedures, including the adjudicatory framework for picking targets [10].
The constraints are where the vendor exposure sits. A firm that breaches its contract terms forfeits the bond [8][9]. Operations likely to kill or seriously injure people are barred, as is anything rising to a use of force under international law, and a firm that exceeds its approved parameters or hits a U.S. person or system by mistake has to stop at once [11][12][13]. The Computer Fraud and Abuse Act still applies [14]. Legalizing hack-back outright would take an act of Congress, and two attempts by then-Rep. Tom Graves of Georgia, the Active Cyber Defense Certainty Act of 2017 and its 2019 reintroduction, never reached a floor vote [15][16][17]. So this authority is contractual rather than statutory: the sign-off, the bond and the underlying criminal statute are the compliance surface [5][8][14].
That shapes who can sell it. "It's a government program, not a private-sector free-for-all," said Will Barker, a cybersecurity advisor at Huntress, who argues the 60-day guidance is the document to read because it sets the entry bar, and that a high bar sends the work to well-funded defense contractors [18][19]. Facility security and personnel vetting requirements point the same way [6]. Jason Kikta, a former U.S. Cyber Command official now chief technology officer at Automox, called the program "a perpetual motion machine for billable threats" [20].
The operational objections are unresolved. Ben Bernstein of Huntress said threat actors route traffic through compromised innocent infrastructure, "like a vulnerable router at an Ohio dental office or a hospital network," making it close to impossible to strike back without hitting bystanders [21][22]. He also said adversary infrastructure burns down within hours, so operators clearing deconfliction review will be "shooting at ghosts" [23]. Huntress co-founder and Chief Executive Kyle Hanslovan supports the program but names deconfliction as the risk: private activity that disrupts a long-running government access operation can cost arrests and diplomatic leverage [24][25].
The White House put 2025 consumer losses to cyber-enabled crime at $20.8 billion and said 73% of U.S. adults have been hit by an online scam or attack [26][27]. Set against that figure, the minimum bond is roughly one twenty-thousandth of a single year's stated losses [33]. The memo extends Executive Order 14390, signed March 6 [28]. It also reverses recent messaging: in March 2026, CyberScoop reported that then-Office of the National Cyber Director senior adviser Thomas Lind said the administration was "not interested in fighting pirates with pirates," and National Cyber Director Sean Cairncross said private offensive operations were "not what we're talking about" [29][30]. Gizmodo likens the arrangement to letters of marque [31].
No specific companies have been named as participants [32].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
President Donald Trump signed a national security presidential memorandum on Wednesday titled "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," authorizing vetted private companies to carry out hacking operations against foreign criminal groups.
- [2]
The memorandum tells the Homeland Security Task Force's National Coordination Center to build the program, with executive directors from the Justice Department and Homeland Security running it.
- [3]
Approved firms may conduct cyber surveillance operations and cyber effects operations, which the memo defines as disrupting or destroying a target's systems.
- [5]
Companies do not get blanket authority; each has to sign a contract with the Justice Department or Homeland Security.
- [6]
Screening of participating firms covers technical proficiency, facility security and personnel background.
- [7]
Written sign-off is required before any operation runs.
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- siliconangle.comDuncan RileyAug 13Trump memo lets vetted US firms run offensive cyber operations abroad
- gizmodo.comTom McKayAug 13Trump Admin Lets Loose the Cyber Pirates
Additional citations
- SiliconANGLE
- SiliconANGLE; NSPM fact sheet via Gizmodo
- Gizmodo, citing the NSPM fact sheet
- Will Barker, Huntress, via SiliconANGLE



