All news
cybersecurityregulationfunding

US Lets Vetted Firms Hack Back at Cybercriminals

31 Aug 2026

For the first time, the U.S. government will allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers. A presidential memorandum establishing the policy was published on Wednesday, marking a significant shift in how Washington approaches ransomware, financial scams, and sextortion threats.

What the policy allows

Under the new framework, private companies can conduct surveillance using spyware and carry out disruptive attacks against criminals' data or systems. The policy explicitly targets threats like ransomware attacks, financial scams, and sextortion — activity that has hit local infrastructure hard. Officials in more than a dozen states, including Michigan, Minnesota, and Georgia, have reported intrusions into local water providers.

Companies of all sizes are being considered, including smaller private firms that the policy suggests might be better suited for specialized operations. But participation isn't free: companies must deposit at least $1 million in escrow or bond, and every operation requires sign-off from Justice Department and Homeland Security representatives, who will also oversee the private firms involved.

The government plans to issue detailed guidance on participation requirements within the next two months.

Where this came from

According to the report's timeline, President Trump began making plans to involve private cybersecurity companies last year, ahead of the second Trump administration's start in January 2025. Wednesday's memorandum formalizes that effort into policy.

The risks are real — and mostly unresolved

Experts quoted in the underlying reporting flag serious concerns. Jake Williams, vice president of research and development at Hunter Strategy, warned that Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas. Jason Healey, a senior cyber conflict researcher at Columbia University, said anyone conducting these operations does so at substantial personal legal risk.

There's also an attribution problem. Private firms are only authorized to hack groups that are "not an institutional part of a foreign government or wholly operated under a foreign government's direction" — but distinguishing state-linked actors from independent criminals is notoriously difficult. Get it wrong, and a company could find itself accused of attacking a foreign government, with diplomatic fallout to match.

There's also a collateral-damage risk. Ben Bernstein, a manager on Huntress's cybersecurity advisers team, noted that threat actors rarely launch attacks from clearly labeled servers in places like Moscow. Instead, they route traffic through compromised, innocent infrastructure — a vulnerable router at an Ohio dental office, or a hospital network. Offensive operations aimed at criminal infrastructure could inadvertently hit these unrelated, innocent systems.

Beyond attribution and diplomacy, participating employees could face indictment or detention by a foreign government if operations go wrong.

What's still unclear

Several important details remain undefined. It's not yet known which specific companies have applied or been vetted. The government hasn't specified how it will verify, in practice, that a criminal group lacks foreign government affiliation. There's no public information on what legal protections — if any — will be offered to employees who face prosecution abroad, nor on how the $1 million escrow will be used if an operation causes harm. How success will be measured is also an open question.

Why founders should care

This policy plausibly opens a new, government-sanctioned market for offensive cybersecurity services — a category that likely didn't exist as a legitimate business line for most U.S. firms until now. Founders in cybersecurity should treat the next two months as a critical window: the forthcoming guidance will likely determine eligibility criteria, operational limits, and oversight mechanics that could shape whether smaller, specialized firms can realistically compete against better-capitalized players able to post the $1 million bond.

At the same time, the legal and diplomatic risks flagged by experts suggest that founders considering entry should probably budget for significant legal exposure and compliance overhead from day one — including the possibility that employees traveling internationally could face personal liability. The attribution challenge around state-linked actors also suggests compliance and targeting processes will need to be unusually rigorous, since a mistaken attack on a state-affiliated group could carry consequences well beyond a typical business risk.

For now, there are more open questions than answers. Founders interested in this space should watch closely for the government's guidance, expected within roughly two months, before making commitments.

Sources