The White House on August 12 authorized a program allowing vetted private companies to conduct offensive cyber operations against foreign cybercriminal groups, including destructive actions. Firms must post at least $1 million in escrow and obtain written approval from senior DOJ and DHS officials for each operation. The memo defines two operation types — covert surveillance and disruptive "effects" — sets a 60‑day timeline for guidance, and excludes clearly state‑controlled actors from targeting. Experts warn of legal risks for Americans involved overseas, and some approval rules remain in a classified annex.
White House Authorizes Vetted Private Firms To Launch Offensive 'Hack‑Back' Operations — What You Need To Know

On August 12, President Donald Trump signed a presidential memorandum establishing a U.S. program that allows vetted private companies to carry out offensive cyber operations against foreign cybercriminal groups, including actions that can disrupt or destroy data and systems.
The memorandum requires participating firms to deposit at least $1 million in escrow, a fund that may be forfeited if they violate the program's rules. Every proposed operation must receive written approval from senior officials at the Department of Justice (DOJ) and the Department of Homeland Security (DHS) before proceeding.
Two Types Of Authorized Operations
The memo defines two permitted categories of activity:
- Cyber Surveillance Operations — unauthorized access to foreign systems to gather intelligence while remaining undetected.
- Cyber Effects Operations — actions intended to disrupt or destroy foreign systems or the data stored on them.
A National Coordination Center will manage the program, and formal implementation guidance is due within 60 days. Eligibility rules are intended to admit both large technology firms and smaller companies with specialized capabilities.
Targeting Rules And Limits
Under the memorandum, a foreign group is a valid target unless there is "clear intelligence" showing it is institutionally part of a foreign government or wholly directed by one. That wording leaves within scope many ransomware crews that operate with state tolerance but not formal state control — a characteristic often associated with Russia-based ransomware groups.
The memo bars DOJ and DHS directors from approving operations likely to cause loss of life or that would amount to an armed attack under international law. Some approval authorities and higher-risk scenarios are reserved to a classified annex rather than the public memorandum.
Operational Safeguards And Concerns
Companies must immediately halt and notify the government if an operation unintentionally affects a U.S. person or a system on U.S. soil. Participating firms may also enter commercial arrangements with other private companies and with state and local agencies to receive threat intelligence and propose actions based on that information.
“We’re not interested in fighting pirates with pirates,” Thomas Lind said in March, reflecting earlier administration statements that appeared to rule out private offensive campaigns.
Expert Warnings And Context
Cybersecurity experts have raised legal and safety concerns. Jake Williams, vice president of research and development at Hunter Strategy, warned that Americans participating in overseas operations "could easily be classified as non‑uniformed combatants while traveling overseas," potentially exposing them to legal and personal risk.
The memorandum follows warnings about foreign cyber activity, including suspected Iranian attacks on municipal water systems and CISA alerts about threats to industrial controllers at utilities. Congress has already allocated roughly $1 billion for offensive cyber efforts in last year's spending bill, and some large firms have publicly signaled interest in disruptive actions against cybercriminals.
Bottom Line
The new program marks a major policy shift toward sanctioned private-sector involvement in offensive cyber operations. While it establishes guardrails — escrow, written approvals, and limits on operations that could cause loss of life — it also raises legal, operational, and international concerns that will shape debate as implementation guidance is released.
Help us improve.
























