Drooid Logo
Back to story perspectives

Full Breakdown

Trump Administration Authorizes Private Companies to Hack Foreign Cybercriminals

8/16/2026, 3:02:07 AM

New Presidential Memo Expands Private Sector Role in Offensive Cyber Operations

The White House issued a national-security memorandum directing the Departments of Justice and Homeland Security to create a program that lets vetted U.S. companies conduct “cyber surveillance operations” and “cyber effects operations” against transnational criminal organizations abroad. Participating firms must sign contracts, undergo vetting, and post a $1 million bond that can be forfeited for non-compliance. Target selection and permissible techniques are not detailed in the memo.

Background & Context

U.S. anti-hacking statutes, chiefly the Computer Fraud and Abuse Act, generally prohibit private unauthorized access, with limited exceptions for law-enforcement-directed activities. The memo does not amend the CFAA but requires any participating company to operate under a federal contract, marking a shift from the traditional contractor-support role.

Key Figures & Groups

  • President Donald Trump – author of the memorandum.
  • Joshua Steinman – former senior director for cyber policy on the National Security Council.
  • Arthur Tellis – former Department of Defense staffer.
  • Stacy O’Mara – chief policy officer at Armadin.
  • Paul Rosenzweig – former deputy assistant secretary for policy at DHS.
  • Chris Wysopal – co-founder of Veracode.
  • Joseph Alm – assistant secretary of homeland security for cyber, infrastructure, risk and resilience.
  • Scott Shackelford – professor at Indiana University.
  • Jason Healey – senior cyber-conflict researcher at Columbia University.
  • Erica Lonergan – professor at Columbia University.
  • Gary Corn – former staff judge advocate at U.S. Cyber Command.

Data & Statistics

  • Bond requirement: $1 million per company, forfeitable for violations.
  • Procedural deadline: DHS and DOJ have 60 days to issue operating procedures, including standards for vetting, de-confliction, and reporting.

Official Statements & Responses

Joseph Alm described the long-term goal as “terrifying” adversaries so they view the United States as a “worst target.” Steinman argued that a faster-paced private sector could bolster offensive capabilities if “very measured” in its initial efforts.

Criticism & Opposition

Legal scholars and industry experts warned the program could blur sovereign boundaries and increase escalation risk. Tim Mackey said endorsing private companies to conduct offensive cyberactivity is likely to increase criminal and nation-state activity. Lonergan expressed “significant concerns” about vetting, goal setting, risk mitigation, and oversight, calling it a potential “slippery slope.”

Verbatim Quotes

  • “There's a range of potential targets … like organized crime … people doing money laundering or other criminal activity,” — Joshua Steinman
  • “It's not an incomparably bad idea, but it's a bad idea,” — Paul Rosenzweig
  • “You don't want to have collateral damage when your blast radius is too big at the data center you were trying to take down, and you took down a transportation company or hospital's servers,” — Chris Wysopal
  • “Our long-term goal is to terrify those who would target Americans, such that they know we’re actually the worst target in the world because we will mess you up,” — Joseph Alm
  • “This administration action is a meaningful response to a growing problem and does have some guardrails in place,” — Jason Healey

Conflicting Reports & Gaps

Experts note difficulty distinguishing proxy actors from state-sponsored groups such as Iran-linked Handala and Russia-linked Evil Corp. The memo does not clarify handling of accidental targeting of U.S. persons or liability for companies prosecuted abroad.

What’s Next

Within 60 days, DHS and DOJ must publish detailed procedures, including technical competency standards, de-confliction protocols, and reporting obligations. Companies will decide whether to apply amid unresolved legal questions and collateral-damage risks.