The US Just Let Private Companies Hack Back. That’s Never Been Legal Before.

What do you do if a burglar breaks into your house?

Call the cops, probably. Maybe invest in a better lock. What you don’t do, at least not legally, is track the guy down and break into his house right back. That’s been the rule in cybersecurity too, for as long as cybersecurity policy has existed in this country. Get hacked, and you’re allowed to defend yourself. You are not allowed to hack back. Companies that tried it anyway didn’t become folk heroes, they became defendants, right alongside the attacker who started it.

On August 12, Uncle Sam decided the “just lock your doors” era is over.

Trump signed a National Security Presidential Memorandum creating a formal program that lets vetted private companies conduct offensive cyber operations against foreign criminal networks. Surveillance, disruption, and in some cases the outright destruction of infrastructure. Basically, permission to hit back, hard. Not against nation states, at least not on paper. Against criminal groups specifically, the ransomware gangs and scam operations that have spent years draining money out of ordinary Americans while mostly getting away with it, laughing, presumably, from a jurisdiction that doesn’t extradite.

Before you picture a bunch of IT guys strapping on capes, it’s worth being precise about what this actually allows. Nobody is getting a badge and a blank check. A company has to be vetted in advance just to qualify. Then for every single target, they need written pre-approval from federal officials before doing anything, under DOJ and DHS oversight. Skip that step and hack someone anyway, and you’re still fully exposed to prosecution under the Computer Fraud and Abuse Act, exactly as before, vigilante fantasy or not. So the honest framing isn’t “hacking is now legal.” It’s a small number of trusted companies acting almost like deputized contractors, under direct federal control, for specific approved targets. The government didn’t fling the door open. It built a narrow, guarded hallway with a bouncer at the end, and it’s deciding, case by case, who gets on the list.

Why now

Two reasons keep coming up, and neither is exactly subtle.

The first is money, and a lot of it. American consumers reportedly lost over $12.5 billion in a single year to online fraud, scams, and ransomware. Not a decade. A single year. And the number keeps climbing like it’s got somewhere to be.

The second reason is the one that actually explains the timing, and it’s basically a math problem. According to a former FBI director, China’s government backed hackers outnumber the FBI’s own cybersecurity staff 50 to 1. Fifty. To. One. That’s not a fair fight, that’s barely a fight at all. The government isn’t losing this one because it doesn’t care, it’s losing because it showed up outnumbered to a gunfight with a fraction of the ammo. Deputizing private companies that already have offensive-grade skills, built for red-teaming and threat hunting, is a faster way to close that gap than spending years building federal capacity from scratch.

My honest guess, and this part is speculation, not reporting: the underlying problem here isn’t new at all. That gap has been growing for years. What changed is that this administration decided to act on it rather than keep managing the decline quietly. Less dramatic story than “bold new offensive strategy,” probably closer to the truth.

Why people are uneasy about it

Even the officials closest to this policy aren’t fully comfortable with it, which is telling on its own. A few concerns keep surfacing, and none of them are the paranoid kind.

This is legal territory nobody has formalized before, so it’s genuinely unclear how international law or other governments will treat a private company acting with federal blessing against a target on foreign soil. Mistakes here also don’t stay small. If a vetted company misidentifies a target and hits the wrong system, that’s no longer just a company’s error, it happened with the government’s authorization attached, which turns a mistake into something closer to a diplomatic incident. Even the companies being asked to participate are reportedly still pushing for clearer answers on liability before they sign anything, which tells you the fine print isn’t settled yet either.

Where this probably goes

Memos like this tend to get narrowed, challenged in court, or quietly walked back once the liability questions start landing on someone’s actual desk. The companies being asked to participate are still asking for more clarity themselves. Worth watching closely, not something that’s fully settled yet.


Sources: The White House, CNN Politics, The Record, Bloomberg, Tech Times

Subscribe to our newsletter

Get the latest security tips, product updates, and news delivered to your inbox.