Ground Truth.
AI, checked against the source.

News · 2026-08-17

The executive order people keep reading as a license to hack back

The United States has not legalized private hack-back. The document behind a widely shared claim that it did is Executive Order 14390, signed March 6, 2026, and what it actually does is direct federal agencies to pull commercial cybersecurity firms into government-led disruption campaigns against foreign criminal networks. It grants private companies no new authority to touch systems they do not own, and the Justice Department's guidance on the country's main computer-crime statute is unchanged.

Key facts

Start with what the order says about itself. Section 1 lays out the target: ransomware, phishing, financial fraud, sextortion and impersonation, run as coordinated campaigns by transnational criminal organizations, sometimes with state backing. Then it states the policy in a line that is easy to over-read: "The United States shall counter attacks on Americans with a commensurate response that includes law enforcement, diplomacy, and potential offensive actions." Read alone, "potential offensive actions" sounds like an open door. Read in the sentence it lives in, the subject of that sentence is the United States -- the government -- not American companies.

The private-sector role is specified two sections later, and it is a supply role. Agencies are told to build an action plan naming the criminal organizations behind scam centers, and to stand up an operational cell inside the National Coordination Center to coordinate federal efforts to "detect, disrupt, dismantle, and deter -- including by involving the private sector as appropriate -- cyber-enabled criminal activity." The next subsection is the one that matters for the hack-back question, and every clause in it is a constraint: agencies shall, "consistent with applicable law," use commercial firms' capabilities and intelligence "to enhance attribution, tracking, and disruption." Enhance attribution. Not authorize intrusion.

If you want to know what this looks like when it runs, the Justice Department published the answer on June 3, 2026. In a Scam Center Strike Force operation the department called "Disruption Week," private companies took voluntary action against millions of social media, email and internet access accounts, and government information-sharing enabled private actors to voluntarily freeze more than $3.8 million in cryptocurrency tied to laundering. Every verb in that description is a company acting on its own systems and its own customers, with better intelligence than it had before. Nobody broke into anything. It is the difference between a bank freezing a suspect account because the FBI told it something, and the bank sending people to kick in a door.

The legal floor underneath all of this also has not moved. The Justice Department's charging guidance for the Computer Fraud and Abuse Act still treats unauthorized access and exceeding authorized access as prosecutable offenses, with prosecutorial discretion layered on top rather than a safe harbor written in. There is no private-retaliation exception. And when the government itself does the disruption, it goes through a judge: the department's own release on dismantling a DNS-hijacking network is explicit that the FBI conducted a court-authorized operation designed to neutralize hostile infrastructure while leaving normal service intact.

Why does an AI news site care about a cybercrime executive order? Because the pressure that produced the rumor is real even though the memo is not. Labs are now handing genuinely offensive capability to private firms under contract -- Anthropic to roughly fifty Glasswing partners, OpenAI to sixteen firms -- while the criminal enterprises on the other side are running AI-driven scam operations that outperform human operators. A company that has both a model capable of finding and chaining exploits and a live adversary burning its customers has an obvious temptation, and the gap between "we could" and "we may" is now doing a lot of load-bearing work. That gap is exactly what the rumor imagined had closed.

The caveat cuts both ways. Absence of a public instrument is not proof that nothing happened; classified authorities and non-public agreements exist, and an executive order is only one of several ways the executive branch acts. What can be said from the primary record is narrower and firmer: the publicly available authority is federal-led, legally constrained, and tethered to existing law, and anyone planning around a private right to retaliate is planning around a document that does not exist.


Primary source, verified: read the paper →

Key questions

Does Executive Order 14390 let private companies hack back?

No. The order directs federal agencies to use commercial firms' technical capabilities, threat intelligence and operational insights, and it repeatedly conditions that on being 'consistent with applicable law.' It creates no new authority for a private company to access a system it does not own.

What did the order actually create?

It created a review-then-action-plan-then-operational-cell sequence: agencies review existing frameworks, submit an action plan naming the criminal organizations behind scam centers, and stand up a coordination cell inside the National Coordination Center to run federal disruption efforts against those networks.

Is unauthorized access still a crime for a company acting in self-defense?

Yes. The Justice Department's charging guidance for the Computer Fraud and Abuse Act still treats unauthorized access and exceeding authorized access as prosecutable offenses, and it contains no carve-out for private retaliation.
Cite this

APA

Ground Truth. (2026, August 17). The executive order people keep reading as a license to hack back. Ground Truth. https://groundtruth.day/news/the-executive-order-people-keep-reading-as-a-license-to-hack-back.html

BibTeX

@misc{groundtruth:the-executive-order-people-keep-reading-as-a-license-to-hack-back,
  title  = {The executive order people keep reading as a license to hack back},
  author = {{Ground Truth}},
  year   = {2026},
  month  = {aug},
  url    = {https://groundtruth.day/news/the-executive-order-people-keep-reading-as-a-license-to-hack-back.html}
}

Topics: cybersecurity · policy · ai-security · law · vulnerabilities

Comments are replies to this story on Bluesky — reply with any Bluesky account to join in.