Published Product3 min read
Washington licenses private hacking, and leaves the liability where the vendor stands
A memorandum signed on 12 August lets contracted US firms attack foreign criminal networks. It excludes state-directed groups and is silent on prosecution abroad.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Donald Trump signed the national security presidential memorandum on 12 August and the White House published it that night.
- The memorandum runs to five sections. A National Coordination Center creates and manages the programme. Two Program Executive Directors oversee it; the Attorney General designates one and the Secretary of Homeland Security designates the other.
- The memorandum directs the National Coordination Center, which operates under the Homeland Security Task Force, to develop the programme; the Departments of Justice and Homeland Security will provide oversight.
- Section 4 defines a Cyber Surveillance Operation as collecting information or intelligence, involving accessing systems without authorisation, with the intent to remain undetected.
- A Cyber Effects Operation is activity resulting in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Donald Trump signed a national security presidential memorandum on 12 August authorising private US companies to run offensive cyber operations against foreign criminal groups, and the White House published it that night [1]. According to Ars Technica this is the first time the federal government will authorise private companies to conduct offensive cyber operations against overseas hackers [22], which converts a compliance problem security vendors have spent two decades avoiding into a procurement opportunity with an unpriced tail. The plumbing sits inside government. The memorandum runs to five sections, directs the National Coordination Center, which operates under the Homeland Security Task Force, to build and manage the programme, and puts the Departments of Justice and Homeland Security in oversight [2][28]. Two Program Executive Directors run it, one designated by the Attorney General and one by the Secretary of Homeland Security [2]. Section 4 defines the work in two buckets. A Cyber Surveillance Operation collects information or intelligence by accessing systems without authorisation, with the intent to remain undetected [3]. A Cyber Effects Operation produces "the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure" [4]. TechCrunch reports that surveillance may include spyware [11], and Ars Technica notes the memo does not rule out attacks that use encryption to lock targets out of their networks, or DDoS [23]. Targets are defined as any foreign group conducting cyber-enabled crime against the US government, a US person or US interests [5]. The definition then excludes any group that is an institutional part of a foreign government or wholly operated under a foreign government's direction [6]. That carve-out is where the operational risk lives. Politico reports that North Korean hackers work at state direction, that many Eastern European gangs are thought to operate with the tacit consent of the Russian government, and that Chinese and Iranian state hackers sometimes moonlight as criminals [7][8]. Engadget notes the memorandum was signed after a wave of cyberattacks on water facilities in Minnesota and Michigan now linked to Iran [27], the sort of case the exclusion appears to place outside the programme [6]. This is not hack-back. TechCrunch, whose security editor read the document, reports that it stops short of that: companies act under contract, against approved targets, supervised by the federal government [9], and the Program Executive Directors must review every cyber operations package and give written approval before anything happens [15]. The longstanding US position across administrations has been that private firms may defend against attacks but not launch them [10]. The obligations on vendors are thin where it matters. Companies must disclose all contractual relationships to the National Coordination Center and maintain a bond or escrow of not less than $1 million against non-compliance [14], with participation reviewed at least annually [15]. Operations may not produce Critical Outcomes, defined as actions likely to cause loss of life or serious injury, or anything rising to the level of use of force or armed attack under international law [16]. Activity aimed at a US person needs any necessary authorisation, judicial or otherwise, before approval [17], and a separate clause covers unintentional targeting of a US person or a system in the United States [18]. Engadget observes that the memorandum offers protection from US prosecution but does not explain what happens if companies or individual employees are criminally charged in the foreign countries housing the computers they attack, and that the US has itself charged foreign hackers [26]. Set against the $20.8 billion the administration's own fact sheet says American consumers lost to cyber-enabled crime in 2025 [19], the $1 million bond is about 0.005 percent [30]. What to watch: the Program Executive Directors have 60 days from signing to establish operating procedures, which falls on 11 October, and 180 days for an initial report, which falls on 8 February [12][31].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Donald Trump signed the national security presidential memorandum on 12 August and the White House published it that night.
ReportedView cited source - [2]
The memorandum runs to five sections. A National Coordination Center creates and manages the programme. Two Program Executive Directors oversee it; the Attorney General designates one and the Secretary of Homeland Security designates the other.
ReportedView cited source - [28]
The memorandum directs the National Coordination Center, which operates under the Homeland Security Task Force, to develop the programme; the Departments of Justice and Homeland Security will provide oversight.
ReportedView cited source - [3]
Section 4 defines a Cyber Surveillance Operation as collecting information or intelligence, involving accessing systems without authorisation, with the intent to remain undetected.
ReportedView cited source - [4]
A Cyber Effects Operation is activity resulting in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure.
ReportedView cited source - [11]
TechCrunch reports that surveillance under the programme may include the use of spyware.
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- arstechnica.comDan GoodinAug 13Private security firms will soon be allowed to hack overseas cybercriminals
- thenextweb.com



