For the first time, the federal government will let private companies hack back. President Donald Trump signed a National Security Presidential Memorandum (NSPM) on August 12, 2026, authorizing vetted U.S. companies to conduct offensive cyber operations against foreign criminal organizations—provided the operations remain under direct federal government control and oversight.
The memorandum, titled Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, directs the U.S. National Coordination Center (NCC) to establish a formal program permitting "Participating Companies" to run two categories of operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs): Cyber Surveillance Operations, aimed at covertly collecting intelligence, and Cyber Effects Operations, which can manipulate, disrupt, degrade, or destroy an adversary's systems.
The NCC was originally established under a January 2025 executive order on immigration enforcement and has since been repurposed as the government's cybercrime coordination hub.
How the program is structured
Every operation conducted under the program requires joint sign-off from two Program Executive Directors—one designated by the Attorney General, one by the Secretary of Homeland Security. Those directors coordinate approvals but cannot authorize any operation that would generate a "Critical Outcome," which the memo defines as an action likely to result in loss of life, serious injury, or conduct rising to the level of use of force or armed attack under international law.
Participating Companies must enter into direct contractual agreements with the Department of Justice or the Department of Homeland Security and undergo vetting against standards the memo directs the Program Executive Directors to finalize within 60 days, covering technical proficiency, facility security, personnel vetting, and operational reliability. Eligibility criteria are meant to accommodate both large firms with broad capacity and smaller, more specialized companies. Once accepted, companies must maintain a bond or escrow of at least $1 million, forfeitable for non-compliance, and face annual re-evaluation to remain in the Program.
The framework also lets Participating Companies enter commercial agreements with other private-sector entities and with federal, state, local, tribal, and territorial agencies, both to receive threat information collected through normal business activity and to propose responsive cyber operations to the NCC.
Private companies working with the Department of Justice on similar operations tied to law enforcement objectives isn't new, according to John Bambenek, President of Bambenek Consulting. What's changed, he said, is the scope of what those operations can now do. "Whether this yields any value depends on what procedures and requirements are put into place and whether they allow smaller security companies to become vetted," Bambenek said.
Built-in guardrails
The implementing guidance directed under the memo includes several oversight mechanisms: a Department of Justice review for any activity directed at a U.S. person or that otherwise implicates constitutional, statutory, or international-law obligations; minimization procedures and mandatory NCC notification if a company discovers it has exceeded the parameters of an approved operation, including unintentional targeting of a U.S. person or a domestic information system; and immediate notification requirements if a company discovers an imminent attack on U.S. critical infrastructure. A classified annex addresses operational deconfliction across the Departments of State, Treasury, War, Justice, and the intelligence community, as well as the adjudicatory framework meant to confirm that operations target only CE-TCOs.
The Program Executive Directors must deliver a status report to the White House within 180 days of the memo's signing and annually thereafter.
Industry reaction: wider access, wider risk
Expanding who can carry out offensive operations doesn't necessarily translate into less criminal activity, cautions Tim Mackey, head of software supply chain risk strategy at Black Duck. Attribution in cyberspace is already difficult, he noted, and without careful governance, individuals granted access to sophisticated surveillance capabilities could misuse that access for personal gain.
Mackey also pointed to a signal the memo sends beyond U.S. borders: "One message this memo does send to adversaries is the U.S. government needs private companies and their capabilities to defend against cyberattacks."
Moody's Ratings views the arrangement through a credit lens. Expanding the pool of organizations able to support government-directed operations could increase overall capacity relative to government-only action, said Leroy Terrelonge, SVP of cyber credit risk at Moody's Ratings, and the vetting and approval process is designed to preserve oversight and coordination. But the model isn't risk-free for the companies that opt in: firms operating under government direction could increasingly be perceived as "extensions of state power," Terrelonge said, potentially exposing them to retaliation, digital sovereignty disputes, and restrictions on cross-border operations.
Part of a broader policy push
The memorandum builds directly on Executive Order 14390, signed in March 2026, which directed a government-wide review of tools available to combat cyber-enabled fraud and established a dedicated operational cell within the NCC. The accompanying White House fact sheet frames this latest action as a response to escalating losses: Americans reported more than $20.8 billion in losses to cyber-enabled crime in 2025, up from the $12.5 billion figure cited when the March order was signed, with ransomware, phishing, financial fraud, sextortion, and impersonation scams named as primary drivers.
Effectively dismantling those operations means going after more than the individuals running scam centers, according to Rich Graham, director of the financial crimes practice at Moody's. It also requires targeting the shell companies and financial networks that let the schemes profit.
The move marks a notable expansion of the private sector's role in offensive cyber activity. Existing federal law, including the Computer Fraud and Abuse Act, has generally barred private companies from conducting cyberattacks or disruption operations without court authorization, a restriction that has kept so-called "hack-back" operations largely off-limits to industry. Mackey's and Bambenek's comments point to the central open question: whether the program's vetting and governance structure, still to be finalized, will be strong enough to manage that expanded access—a debate SecureWorld News will continue to track as implementing guidance takes shape over the coming months.
[RELATED: The Ransomware Victim that Hacked Back]

