4 min read

Cyber Privateers: What Trump's Hack-Back Memo Actually Changes

Cyber Privateers: What Trump's Hack-Back Memo Actually Changes

On August 13, 2026, President Trump signed a national security memorandum directing the Department of Homeland Security and Department of Justice to stand up a formal program allowing vetted private companies to conduct offensive cyber operations against foreign criminal networks. The White House is framing it as a response to the scale of ransomware, romance scams, and fraud schemes run by transnational criminal organizations against American victims. Coverage has settled on the label "cyber privateers," a nod to the eighteenth-century practice of licensing private ships to raid an enemy's commerce. The comparison is apt, and not entirely flattering to the policy's prospects.

What the memo actually does

The memo does not deputize companies to hack whoever they want. It directs DHS's Homeland Security Task Force, through its National Coordination Center, to jointly stand up a program with DOJ that vets "Participating Companies," which can then gather intelligence on foreign cyber-enabled transnational criminal organizations and propose specific operations — described in the memo as Cyber Surveillance Operations and Cyber Effects Operations — for government review and approval. Nothing proceeds without sign-off. Companies must post at least a $1 million bond or escrow, undergo vetting on technical proficiency, and report regularly to federal overseers. The memo also states the program must operate within existing law, including the Computer Fraud and Abuse Act, the same statute that criminalizes unauthorized access to computer systems and that has been the central legal obstacle to any private hack-back scheme for over a decade.

That last point matters more than the headlines suggest. This is authorization by delegation, not deregulation. The government is still the one pulling the trigger; it is simply outsourcing the reconnaissance and operational planning to companies with deeper visibility into criminal infrastructure than an under-resourced DOJ or DHS can maintain on its own. It is closer to how the government already uses contractors for signals intelligence work than to Rep. Tom Graves' 2017 Active Cyber Defense Certainty Act, which would have let companies act unilaterally. It is also narrower than the "letters of marque" legislation some conservatives have floated, most recently Rep. David Schweikert's Scam Farms Marque and Reprisal Authorization Act, which would let the president license private individuals to seize the property of people tied to cybercrime enterprises abroad — an idea still parked in the House Foreign Affairs Committee.

Why now

The memo builds on groundwork the administration laid in March, when it released a five-page National Cybersecurity Strategy built around "shaping adversary behavior" and enlisting private-sector help to "disrupt adversary networks." That strategy stopped short of explicit authorization; this memo is the implementing step. It also follows a string of embarrassments that make the timing legible: a reported breach of FBI wiretap and surveillance systems attributed to Salt Typhoon-linked actors, a roughly one-third reduction in CISA's workforce, and a budget picture in which Congress funded a billion dollars for offensive military cyber operations while cutting more than a billion from civilian defensive cybersecurity. Put together, the administration is betting that offense — armed with private-sector talent it can no longer fully retain in government — is cheaper and more visible than shoring up defense.

The reaction from the field splits along a predictable line. Veracode co-founder Chris Wysopal called it "a pretty big shift in U.S. cyber policy," while still noting it stops short of the more permissive hack-back proposals floated over the years. Former Cyber Command official Jason Kitka was blunter, describing it on social media as "a perpetual motion machine for billable threats" — a jab at the incentive structure the memo creates for contractors to keep finding operations worth proposing. Others with ties to the first Trump administration's cyber team welcomed it as overdue.

The case for it

Proponents argue the status quo has failed. Ransomware groups and romance-scam compounds operate with near-total impunity from jurisdictions that will not extradite, and attribution has improved enough since the "hack back" debates of the early 2010s that the old fear of hitting the wrong target is less disqualifying than it once was. Private cybersecurity firms already run active-defense operations — sinkholing botnets, running honeypots, taking down criminal infrastructure through civil litigation — and already possess more real-time visibility into criminal networks than most government agencies. Formalizing a channel for the government to direct and approve that expertise, rather than leaving it in a gray zone, is a legitimate way to close a capability gap without changing what is legally permissible for private actors.

The case against it

The unresolved risk is not really legal — the CFAA carve-out for actions taken by, or genuinely on behalf of, law enforcement is well-trodden ground — it is operational and diplomatic. Misattribution is still possible even with better tools, and an operation against the wrong server, hosted on infrastructure a company doesn't realize is a genuine third party, creates liability and diplomatic friction regardless of good intentions. More importantly, once private companies are executing operations abroad under a government license, the United States owns the escalation risk those operations create, even though it does not fully control the judgment of the people executing them day to day. A retaliatory response from a criminal group's state patrons, or a diplomatic protest from a country whose sovereignty was breached in the process, lands on the State Department's desk, not the contractor's. This is precisely the scenario that led prior administrations, of both parties, to keep offensive cyber operations inside the government rather than delegate them outward.

The diplomacy dimension

For anyone watching this through a foreign-policy lens rather than a purely technical one, the more interesting question is how this lands internationally. The United States has spent years pushing a norm, through the UN Group of Governmental Experts and Open-Ended Working Group processes, that only states should conduct offensive cyber operations, precisely to avoid the escalation and attribution chaos that comes with letting private actors act on a state's behalf. A formal program that licenses companies to conduct cyber effects operations against targets in other countries, however tightly supervised, sits awkwardly next to that argument. Allies who have resisted their own hack-back lobbies will be watching for whether this becomes precedent they are pressured to match, and adversaries have an obvious rhetorical opening: pointing to American cyber privateers whenever the U.S. criticizes state-tolerated criminal hacking elsewhere. The program's success or failure over the next year will likely be judged less by how many criminal networks it disrupts and more by whether it stays inside its guardrails without a single high-profile misfire.

Sources: Washington Post, Bloomberg, CNN, TechCrunch, CyberScoop, Lawfare, The Register, BleepingComputer