Published Product3 min read
The US just licensed private offensive hacking, and left the mechanics for later
A presidential memorandum lets vetted companies run spyware and destructive operations against criminal infrastructure. The rules that would make that safe do not exist yet.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- The White House said on Wednesday, in a newly published presidential memorandum, that the US government will for the first time allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers.
- The Trump administration said the move will let the federal government use the "innovative capabilities of the private sector" to combat cybercrime and threats targeting Americans, such as ransomware attacks, financial scams and sextortion.
- The memorandum allows participating private companies to conduct surveillance, such as using spyware to collect intelligence, and to make disruptive attacks aimed at the destruction of criminals' data or systems.
- US federal computer hacking laws broadly prohibit private companies from conducting cyberattacks or disruption operations without court-authorized approval, and private companies are regulated under the same computer hacking laws as anyone else in the United States.
- The US government's position to date, through multiple administrations, has been that the private sector can defend against incoming cyberattacks but not launch or operate them.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
The White House published a presidential memorandum on Wednesday authorising vetted private companies to conduct offensive cyber operations against international criminal gangs and hackers, the first time the US government has permitted this [1]. It inverts a position held across multiple administrations, that the private sector may defend against incoming attacks but may not launch or operate them [5], and it does so by policy while the federal computer crime statutes that broadly prohibit private cyberattacks without court authorisation remain on the books [4].
The permitted activity is not narrow. Participating firms may conduct surveillance, including using spyware to collect intelligence, and may carry out disruptive attacks aimed at destroying criminals' data or systems [3]. The stated targets are ransomware, financial scams and sextortion, which the administration says calls for the "innovative capabilities of the private sector" [2]. The administration gave no reason for the change beyond a reference to a growing threat [16].
The controls are thinner than the authority. Each operation needs sign-offs from Justice Department and Homeland Security representatives, and operations are to run exclusively under federal supervision [9]. The memorandum directs the government to build procedures that stop any operation from targeting Americans or US-based systems [8], which means those procedures do not exist yet; the government has not fully established how the program will operate [6]. Participating firms must deposit $1 million in escrow, forfeited if the government finds non-compliance with its rules of engagement [7]. In TechCrunch's account of the memorandum, that forfeiture is the enumerated consequence, with no other penalty described [17]. For a firm large enough to field an offensive team, $1 million is a licence fee, not a deterrent.
Guidance setting out entry requirements is due within two months [10], which puts it around mid-October [18]. That guidance is explicitly meant to consider companies of all sizes, including smaller firms said to be better suited to specialised operations [11]. So the applicant pool is not limited to the handful of contractors with existing classified relationships.
Two exposures land on people rather than institutions. Jake Williams, vice president of research and development at Hunter Strategy, told TechCrunch that Americans participating in these operations could be classified as non-uniformed combatants while travelling overseas, and that the allegation need not be true for a foreign government to make it, because the policy itself supplies the cover [13][14]. He called the policy half-baked, said a classified addendum likely explains how targets are chosen, and said he was not convinced the program would not be abused [15]. The second exposure runs the other way: critics have argued for years that private involvement in government hacking invites diplomatic consequences when a foreign state claims a US company attacked it [12]. The memorandum stops short of authorising companies to hack back threats [19], and participating firms must notify the government if they discover an imminent attack on critical US infrastructure such as power grids or water providers [20].
Watch the October guidance for the vetting bar and the definition of a criminal target. Watch whether any firm confirms participation; a White House spokesperson would not say whether any already had, and pointed to the fact sheet [21]. And watch the first legal challenge, which TechCrunch reports is likely, since the memorandum does not amend the statute it sits against [6][4].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The White House said on Wednesday, in a newly published presidential memorandum, that the US government will for the first time allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers.
- [2]
The Trump administration said the move will let the federal government use the "innovative capabilities of the private sector" to combat cybercrime and threats targeting Americans, such as ransomware attacks, financial scams and sextortion.
ReportedView cited source - [3]
The memorandum allows participating private companies to conduct surveillance, such as using spyware to collect intelligence, and to make disruptive attacks aimed at the destruction of criminals' data or systems.
ReportedView cited source - [4]
US federal computer hacking laws broadly prohibit private companies from conducting cyberattacks or disruption operations without court-authorized approval, and private companies are regulated under the same computer hacking laws as anyone else in the United States.
ReportedView cited source - [5]
The US government's position to date, through multiple administrations, has been that the private sector can defend against incoming cyberattacks but not launch or operate them.
ReportedView cited source - [6]
The program is in its early days, the government has not yet fully established how it will operate, and the new policy is likely to face legal challenges and opposition from critics who have argued for years that private companies should not get involved in government hacking operations.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- techcrunch.comZack WhittakerAug 13In a first, US will allow some private firms to carry out cyberattacks
Additional citations
- TechCrunch, citing the White House
- Jake Williams, Hunter Strategy, to TechCrunch
- TechCrunch report



