News · 2026-08-12
A White House memo lets vetted companies run offensive cyber operations under federal control
A presidential memorandum signed on August 12, 2026 creates a federal program allowing vetted American companies to carry out offensive cyber operations against foreign criminal organizations, under the direction and written approval of the Justice Department and the Department of Homeland Security. It is not the blanket hack-back authorization that early coverage suggested. It is closer to a procurement system for offensive cyber capability, with a one-million-dollar bond attached to noncompliance.
Key facts
- Signed August 12, 2026 and published as "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime", with an accompanying fact sheet.
- Operations run through the National Cyber Council, with co-Executive Directors from the Justice Department and Homeland Security serving as Program Executive Directors.
- Targets are restricted to foreign cyber-enabled transnational criminal organizations; anything touching a US person or US-connected system requires additional Justice Department review.
- Justice and Homeland Security may require a bond or escrow of at least one million dollars for noncompliance.
What it permits, precisely
The memorandum defines two operation types. Cyber Surveillance Operations are unauthorized-access activities conducted to collect intelligence while remaining undetected. Cyber Effects Operations are activities that can, in the memorandum's own words, "manipulate, disrupt, deny, degrade, or destroy" systems or information. That second category is the functional hack-back permission, and it is considerably broader than takedown-and-notify.
The limits are real but sit at the extreme end. The memorandum bars operations likely to cause loss of life, serious injury, or anything rising to the level of use of force or armed attack under international law. Between "send a strongly worded email" and "acts of war" there is an enormous amount of room, and the memorandum places most of it inside the program.
The oversight architecture is where the substance lives. Every operation package needs written approval from the Program Executive Directors before action. Companies are contractually vetted and reevaluated annually. Operations must be deconflicted against other federal equities, and outside contractual relationships must be disclosed. Standardized rubrics and templates govern how operations are documented. Notably, the deconfliction rules themselves live in a classified annex, which means the most operationally consequential guardrails are not public and cannot be independently assessed.
Why this needed a memo at all
The obstacle was the Computer Fraud and Abuse Act, which criminalizes access "without authorization" or in excess of authorized access, and which does not care whether your target deserved it. Lawfare's analysis of the administration's cyber strategy notes there had been no federal framework authorizing private companies to conduct offensive operations independently, and that no court has settled whether the statute's government-activity carve-out covers private contractors acting on the government's behalf. The Congressional Research Service primer lays out the same baseline.
The memorandum does not amend the statute. It routes the activity through federal supervision and hopes that suffices. Whether it does is a question a court will eventually answer.
The AI question underneath it
Here is where this connects to everything else on this site, and it is not a stretch. The memorandum's entire legal theory rests on a chain of human control: vetted company, written approval, federal supervision, Justice Department review, documented deconfliction. Remove any link and the activity looks exactly like the independent private hacking that the statute still criminalizes.
Now consider what an offensive operation actually looks like in 2026. The same week this memo was signed, DREAM published its analysis of an autonomous framework that ran twelve intrusion waves against government systems in four days, with up to eight agents running concurrently and a probabilistic engine reprioritizing targets between waves. Nobody signed a written approval for wave seven. That is the point of the architecture.
A supervised program that requires per-operation written approval is fundamentally incompatible with the tempo that makes agentic offense effective. Either participating companies run at human speed and give up the advantage, or they delegate target selection to a model and the approval becomes a rubber stamp over decisions nobody reviewed. Lawfare flags the same tension from the liability side, noting that autonomous tooling does not erase responsibility and that human involvement in AI-driven cyber action remains essential. The memorandum, written in the language of packages and approvals, does not appear to contemplate an operator that generates its own next step.
The counter-argument
The security community's objection to hack-back has been consistent for a decade and has not been answered here. The Electronic Frontier Foundation has long argued that normalizing break-ins and malware makes the overall ecosystem less secure, and that broad active-defense carve-outs sweep up researchers and innocent third parties. Attribution is the practical failure: criminal infrastructure runs on compromised machines belonging to people who did nothing wrong, so a counterattack lands on a victim rather than an attacker more often than anyone likes to admit. Hacker News discussions of the underlying question have converged on the same points, focusing on false flags, collateral damage, and escalation.
The memorandum's answer is supervision, not a technical solution to attribution. That is a reasonable bet if the supervision is real and the operations run at a pace humans can actually review. It is a much worse bet if the operator is a model that has already moved on.
Key questions
Does this legalize private companies hacking back on their own?
What are participating companies actually allowed to do?
What happens if a participating company breaks the rules?
Cite this
APA
Ground Truth. (2026, August 12). A White House memo lets vetted companies run offensive cyber operations under federal control. Ground Truth. https://groundtruth.day/news/the-white-house-put-private-companies-inside-a-supervised-offensive-cyber-program.html
BibTeX
@misc{groundtruth:the-white-house-put-private-companies-inside-a-supervised-offensive-cyber-program,
title = {A White House memo lets vetted companies run offensive cyber operations under federal control},
author = {{Ground Truth}},
year = {2026},
month = {aug},
url = {https://groundtruth.day/news/the-white-house-put-private-companies-inside-a-supervised-offensive-cyber-program.html}
}
Comments are replies to this story on Bluesky — reply with any Bluesky account to join in.