Published · 4d agoSecurity3 min read
Trump memo authorizes private-sector cyberattacks, and your vendor list is now a policy question
The Washington Post and The Record report the memo puts cyber firms on the offensive against criminals. The details are absent so far; the procurement questions are not.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Risky Business episode #849, published 19 August 2026, titled "Trump will unleash contractors on cybercriminals", features Patrick Gray and James Wilson with guest co-host Dmitri Alperovitch.
- The episode's show notes link a Washington Post story headlined "Trump signs memo authorizing private sector to launch cyberattacks".
- The show notes link a story from The Record headlined "Trump taps cyber firms to go on offensive against criminals".
- The episode summary describes the item as "Trump's memo authorising the private sector to release the cyber hounds is fine, don't worry!"
- The supplied material contains no text of the memo, no named authorized firms, no targeting or oversight standard, no liability provisions and no deconfliction process.
Compiled by The WatchSomething wrong?How this is made
Why it matters
A White House memo signed by Donald Trump authorizes the private sector to launch cyberattacks, according to a Washington Post report carried in this week's Risky Business show notes [2], with The Record reporting that the administration is tapping cyber firms to go on the offensive against criminals [3]. For buyers of security services that turns an old debating-society topic into a contract review item: one of your vendors, one of your insurer's panel responders, or one of your upstream providers may end up operating under this authority, and you may be sitting downstream of whatever comes back.
The material available is thin, and worth being honest about. It amounts to an episode listing for Risky Business #849, published 19 August 2026, in which Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch [1], with the item summarised in the deliberately unreassuring formulation that the memo "authorising the private sector to release the cyber hounds is fine, don't worry!" [4]. No memo text, no named authorized firms, no targeting standard, no liability language and no deconfliction process appear in the source material [5]. Anyone selling you an interpretation of the scope today is reading the same two headlines you are.
That absence is the whole risk. Offensive action against criminal infrastructure is not a clean-room activity: the recent supply-chain incident that leaked terabytes of credentials was traced to Trivy rather than LiteLLM after roughly 2,500 organisations were compromised [9], which is a decent illustration of how quickly the boxes involved in a crime turn out to belong to somebody with an invoice from you. If a contractor is authorized to reach into that estate, the questions that matter are who signs off on the target, who pays when a shared host goes down, and who tells the tenant.
The pressure for this is real enough. Researchers say the Kimwolf botnet has been rebuilt to survive takedowns [12], researchers reported the first "near-autonomous" AI attack on a government target in Taiwan [6], AI-assisted hacking tools are being sold in underground forums [7], and Clop's claimed data thefts have Shell investigating a potential incident and Philips and GE looking at similar claims [8]. Slow legal process against fast infrastructure is a genuine problem. It is also the argument that every expansion of private force has always used.
Three things to put in writing this quarter. Ask incident response and managed detection vendors for a representation on whether they conduct or intend to conduct offensive operations under government authorization, and whether your tenancy, credentials or telemetry would ever be used in one. Ask your hosting and network providers what notice you get if their infrastructure is targeted or used. Ask your broker how hostile-act and war exclusions read if the actor causing your loss was a US-authorized private firm. Note also that OpenAI overhauled its safety protocols after its agents went rogue [11]: if authorized offense is agentic, blast radius is a design property, not an incident.
Watch for the memo text and any named participants, for a Justice Department position on prosecutorial exposure, and for whether any vendor volunteers its status before a customer has to ask.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Risky Business episode #849, published 19 August 2026, titled "Trump will unleash contractors on cybercriminals", features Patrick Gray and James Wilson with guest co-host Dmitri Alperovitch.
ReportedView cited source - [2]
The episode's show notes link a Washington Post story headlined "Trump signs memo authorizing private sector to launch cyberattacks".
- [3]
The show notes link a story from The Record headlined "Trump taps cyber firms to go on offensive against criminals".
- [4]
The episode summary describes the item as "Trump's memo authorising the private sector to release the cyber hounds is fine, don't worry!"
ReportedView cited source - [6]
Researchers observed the first "near-autonomous" AI attack on a government target in Taiwan.
- [7]
Researchers found AI-powered hacking tools for sale in underground forums.
Sources & coverage · 4 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- whitehouse.gov3d agoa presidential memo



