> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Trump's 'Hack Back' Memo Lets (Some) Private Companies Strike Back Against Cybercrime Gangs
- URL: https://www.cybrsecmedia.com/trumps-hack-back-memo-lets-some-private-companies-strike-back-against-cybercrime-gangs/
- Published: 2026-08-25T17:45:07.000Z
- Updated: 2026-08-25T18:26:06.000Z
- Description: Many believe cybercriminal asymmetry allows foreign cybercrime gangs to operate with near impunity, and that decades of legislative fixes, like the repeatedly stalled Active Cyber Defense Certainty Act, have gone nowhere. Others are concerned that the doctrine may create more mayhem than it solves.
- Author: George V. Hulme
- Tags: Hacking Back, Trump Administration, Offensive Security, Article

Battered for decades by cybercriminals and ransomware crews, often operating within legal safe havens abroad, American companies have been fighting them with two hands tied behind their backs. 

Federal law barred them from striking back at their attackers, leaving offensive operations exclusively to the military and intelligence community: agencies too often too stretched to chase every criminal group siphoning billions from U.S. businesses and consumers. 

Earlier this month, the administration moved to break that logjam by signing a National Security Presidential Memorandum, "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime."

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

Many in the cybersecurity industry believe that asymmetry enables foreign cybercrime gangs to operate with near impunity, and that decades of legislative fixes, like the repeatedly stalled [Active Cyber Defense Certainty Act](https://www.congress.gov/bill/116th-congress/house-bill/3270?ref=cybrsecmedia.com), have gone nowhere. Others express concerns that the doctrine may create more mayhem than it solves.

When President Trump, on August 12, signed [the memo](https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/?ref=cybrsecmedia.com) that operationalizes the administration's March "Cyber Strategy for America" and an accompanying executive order targeting cyber-enabled crime and fraud, it marked the first time the White House has formally authorized private-sector offensive cyber operations: a sharp break from a bipartisan "no hack back" policy stretching back decades.

"It genuinely feels like the cyber equivalent of letters of marque, where private industry is authorized to conduct specific, targeted operations on behalf of the United States government," said John Strand, owner of Black Hills Information Security Inc. 

Strand and others have questions: How will program oversight work? What are the limits of the authorities granted by the memorandum? Who is responsible for ensuring those limits aren't exceeded? How does this fit within international law? 

"Those are all critical issues that need to be answered before a program like this reaches full maturity," Strand said.

However, Strand also acknowledges that there are strategic operational realities that must be met. 

"Our adversaries are already operating this way. We've seen multiple reports of China leveraging private cybersecurity companies to conduct offensive cyber operations. Russia has long relied on so-called private hackers who carry out activities that align with government objectives. When our adversaries embrace a model that we refuse to consider, it can leave the United States at a strategic disadvantage," he continued.

The memo does not, however, give companies a free operational hand.

## **No (government-sanctioned) wild west**

The program, when implemented, would create a government-run program administered through the Homeland Security Task Force's National Coordination Center, jointly overseen by two "Executive Directors" from the Justice and Homeland Security departments. Vetted "Participating Companies" may conduct two categories of activity against foreign "Cyber-Enabled Transnational Criminal Organizations": surveillance operations to gather intelligence on criminal networks, and "effects" operations to disrupt, degrade, or destroy their infrastructure.

The planned guardrails are substantial. Every operation requires written, per-operation approval from both Executive Directors before any action begins, and companies must halt and report any action that exceeds the approved scope. Participating firms must post a bond of at least $1 million, forfeited for contract violations, and pass annual technical-proficiency evaluations. Operations may not cause loss of life, serious injury, or anything rising to a "use of force" under international law. 

Targets are limited to criminal groups; entities "wholly operated" by a foreign government are excluded unless clear intelligence ties them to a state.

The DOJ and DHS have 60 days to write detailed operating procedures, and a classified annex governs coordination with the military and intelligence agencies. 

Alissa Knight, CEO and Chief AI Officer at Assail, Inc. said in an email to CYBR.SEC.Media that the memo builds a lane for companies to "run surveillance and effects operations against transnational cybercrime groups; under contract, under bond, under direct government approval. This is a testament to the fact that the private sector already has the capability the public sector needs and that it's time for us to get to work."

The legal foundation, though, looks shaky. 

The program leans on an untested reading of the Computer Fraud and Abuse Act's exemption for "lawfully authorized" law-enforcement activity, and the memo does not explicitly grant companies immunity from hacking statutes. If a court rejects that theory, participating firms could face civil or criminal exposure. That's a risk the Justice Department itself has previously acknowledged in reaffirming that hack-back activity is generally unlawful.

## **Industry reaction mixed**

Industry reaction has split sharply. Veracode co-founder Chris Wysopal called it "[a pretty big shift in U.S. cyber policy](https://x.com/WeldPond/status/2087713067517755464?ref=cybrsecmedia.com)," while noting it stops short of fully permissive hack-back. Former U.S. Cyber Command official Jason Kitka [warned](https://bsky.app/profile/kikta.net/post/3mswcedijcc2w?ref=cybrsecmedia.com) the incentive structure could become "a perpetual motion machine for billable threats," and many experts told reporters the concept creates unacceptable escalation risks, potentially exposing private employees to foreign retaliation historically reserved for government personnel. 

Josh Shaul, CEO at Allure Security, said, "If cybersecurity vendors engage in offensive security operations against nation-states, we should expect those nations to respond to those companies directly, potentially disproportionately. Responses could include denial-of-service attacks, ransomware, IP theft, exposure of sensitive client data, or leakage of internal sensitive data. We've seen breaches like this before (Sony Pictures, Ashley Madison, etc.), and they hit the businesses hard. As such, there's a lot for a company to consider here when it comes to risk versus reward." 

David Silva, founder and CEO of CyberX, said he can see real benefit in bringing private-sector offensive security capabilities into these operations. "Cybercriminal groups can rebuild infrastructure quickly, move between hosting providers and change techniques faster than traditional government processes sometimes allow," he said. 

He added that private security companies already have specialized researchers, tooling and visibility into criminal infrastructure. Putting some of that capability behind government-authorized operations could increase the speed and frequency with which criminal infrastructure is identified and disrupted.

"But the hardest problem is not gaining access to a server," Silva added. "It is being absolutely certain that you are attacking the right server and the right organization."

As Silva noted, attackers routinely use compromised systems, proxies, and third-party infrastructure. The machine from which an attack appears to originate may itself be another victim. "An offensive operation based on bad attribution could therefore damage an innocent organization or infrastructure in another country," he said. 

The memorandum does recognize that risk, as it requires an operation to stop and the government to be notified when activity unintentionally reaches a U.S. person, a system in the United States, or a system controlled by a U.S. person.

There is another difficult area around state involvement, he continued, as the program is aimed at foreign cyber-enabled transnational criminal organizations. These groups are not institutional parts of a foreign government or wholly directed by one. "In practice, the line between an independent criminal group, a state-tolerated group and a state-directed group can be much harder to establish than it looks on paper," Silva said.

That's why, ultimately, he and others see the effort as having the potential to reduce and increase escalatory reactions simultaneously. "If it remains tightly controlled, with strong attribution standards, government deconfliction, narrow targeting and human approval for every operation, it could make life significantly harder for transnational cybercriminal groups without creating a private cyber free-for-all," Silva said. "If those controls weaken over time and it evolves into companies being broadly licensed to retaliate, I believe the risk changes completely."

"The difference between a useful program and a dangerous precedent will be the degree of government control over the target, the operation and the consequences," he concluded.

Key details remain unresolved: which companies will apply, how the classified annex will work, and whether Congress will ratify, constrain, or defund a framework built on a presidential memorandum rather than on statute. And not much will be answered for the next couple of months as the DOJ and DHS write the operating procedures. 

[ ![HOU.SEC.CON CTA](https://s3.us-east-1.amazonaws.com/assets.cybersecmedia.com/HSC+CTA.jpg) ](https://houstonseccon.com/?ref=cybrsecmedia.com)