News · 2026-08-17
The executive order people keep reading as a license to hack back
The United States has not legalized private hack-back. The document behind a widely shared claim that it did is Executive Order 14390, signed March 6, 2026, and what it actually does is direct federal agencies to pull commercial cybersecurity firms into government-led disruption campaigns against foreign criminal networks. It grants private companies no new authority to touch systems they do not own, and the Justice Department's guidance on the country's main computer-crime statute is unchanged.
Key facts
- Executive Order 14390, "Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens," was signed March 6, 2026.
- The order tells agencies to use "relevant technical capabilities, threat intelligence, and operational insights from commercial cybersecurity firms and other non-Federal entities," qualified by the phrase "consistent with applicable law."
- The order does not mention artificial intelligence anywhere in its text.
- Primary source: the White House presidential-actions page.
Start with what the order says about itself. Section 1 lays out the target: ransomware, phishing, financial fraud, sextortion and impersonation, run as coordinated campaigns by transnational criminal organizations, sometimes with state backing. Then it states the policy in a line that is easy to over-read: "The United States shall counter attacks on Americans with a commensurate response that includes law enforcement, diplomacy, and potential offensive actions." Read alone, "potential offensive actions" sounds like an open door. Read in the sentence it lives in, the subject of that sentence is the United States -- the government -- not American companies.
The private-sector role is specified two sections later, and it is a supply role. Agencies are told to build an action plan naming the criminal organizations behind scam centers, and to stand up an operational cell inside the National Coordination Center to coordinate federal efforts to "detect, disrupt, dismantle, and deter -- including by involving the private sector as appropriate -- cyber-enabled criminal activity." The next subsection is the one that matters for the hack-back question, and every clause in it is a constraint: agencies shall, "consistent with applicable law," use commercial firms' capabilities and intelligence "to enhance attribution, tracking, and disruption." Enhance attribution. Not authorize intrusion.
If you want to know what this looks like when it runs, the Justice Department published the answer on June 3, 2026. In a Scam Center Strike Force operation the department called "Disruption Week," private companies took voluntary action against millions of social media, email and internet access accounts, and government information-sharing enabled private actors to voluntarily freeze more than $3.8 million in cryptocurrency tied to laundering. Every verb in that description is a company acting on its own systems and its own customers, with better intelligence than it had before. Nobody broke into anything. It is the difference between a bank freezing a suspect account because the FBI told it something, and the bank sending people to kick in a door.
The legal floor underneath all of this also has not moved. The Justice Department's charging guidance for the Computer Fraud and Abuse Act still treats unauthorized access and exceeding authorized access as prosecutable offenses, with prosecutorial discretion layered on top rather than a safe harbor written in. There is no private-retaliation exception. And when the government itself does the disruption, it goes through a judge: the department's own release on dismantling a DNS-hijacking network is explicit that the FBI conducted a court-authorized operation designed to neutralize hostile infrastructure while leaving normal service intact.
Why does an AI news site care about a cybercrime executive order? Because the pressure that produced the rumor is real even though the memo is not. Labs are now handing genuinely offensive capability to private firms under contract -- Anthropic to roughly fifty Glasswing partners, OpenAI to sixteen firms -- while the criminal enterprises on the other side are running AI-driven scam operations that outperform human operators. A company that has both a model capable of finding and chaining exploits and a live adversary burning its customers has an obvious temptation, and the gap between "we could" and "we may" is now doing a lot of load-bearing work. That gap is exactly what the rumor imagined had closed.
The caveat cuts both ways. Absence of a public instrument is not proof that nothing happened; classified authorities and non-public agreements exist, and an executive order is only one of several ways the executive branch acts. What can be said from the primary record is narrower and firmer: the publicly available authority is federal-led, legally constrained, and tethered to existing law, and anyone planning around a private right to retaliate is planning around a document that does not exist.
Key questions
Does Executive Order 14390 let private companies hack back?
What did the order actually create?
Is unauthorized access still a crime for a company acting in self-defense?
Cite this
APA
Ground Truth. (2026, August 17). The executive order people keep reading as a license to hack back. Ground Truth. https://groundtruth.day/news/the-executive-order-people-keep-reading-as-a-license-to-hack-back.html
BibTeX
@misc{groundtruth:the-executive-order-people-keep-reading-as-a-license-to-hack-back,
title = {The executive order people keep reading as a license to hack back},
author = {{Ground Truth}},
year = {2026},
month = {aug},
url = {https://groundtruth.day/news/the-executive-order-people-keep-reading-as-a-license-to-hack-back.html}
}
Comments are replies to this story on Bluesky — reply with any Bluesky account to join in.