SECURITY
SECURITY
SECURITY
President Donald Trump signed a national security presidential memorandum Wednesday authorizing vetted private companies to carry out hacking operations against foreign criminal groups.
The memorandum, “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” tells the Homeland Security Task Force’s National Coordination Center to build the program. Executive directors from the Justice Department and Homeland Security will run it. Approved firms may conduct what the document calls cyber surveillance operations. They may also run cyber effects operations, which the memo defines as disrupting or destroying a target’s systems.
Companies do not get blanket authority. Each has to sign a contract with Justice or Homeland Security. Screening covers technical proficiency, facility security and personnel background. Written sign-off is required before any operation runs.
A firm that breaches its terms forfeits a bond of at least $1 million. Program directors have 60 days to publish the operating procedures, including the adjudicatory framework for picking targets.
Operations likely to kill or seriously injure people are barred. So is anything that rises to a use of force under international law. A firm that exceeds its approved parameters has to stop at once. The same applies if it hits a U.S. person or system by mistake. The Computer Fraud and Abuse Act still applies.
Legalizing hack-back would also take an act of Congress. Two attempts have failed. Then-Rep. Tom Graves of Georgia put forward the Active Cyber Defense Certainty Act in 2017 and again in 2019. It would have amended the statute to give companies an affirmative defense for striking back on their own. Neither version got a floor vote.
The White House put consumer losses to cyber-enabled crime at $20.8 billion in 2025 and said 73% of U.S. adults have been hit by an online scam or attack. Wednesday’s memo extends Executive Order 14390. Trump signed that order, “Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens,” on March 6.
Jason Kikta, a former U.S. Cyber Command official now chief technology officer at Automox Inc., called the program “a perpetual motion machine for billable threats.”
Ben Bernstein, who runs the cybersecurity advisors team at managed detection and response company Huntress Labs Inc., sees the trouble starting with the source of criminal traffic. “Threat actors don’t launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network,” he said in comments emailed to SiliconANGLE.
Striking back without hitting bystanders is close to impossible on that terrain, he said. Adversary infrastructure also burns down within hours. By the time a vetted firm nominates a target and clears deconfliction review, Bernstein said, its operators will be “shooting at ghosts.”
Huntress co-founder and Chief Executive Kyle Hanslovan backs the program. He described close public and private collaboration as “no longer an option” against organized cybercrime. Autonomous AI attacks are his other reason. Hanslovan said deconfliction is the risk. Private activity that disrupts a long-running government access operation can cost arrests and diplomatic leverage.
“It’s a government program, not a private-sector free-for-all,” said Will Barker, a cybersecurity advisor at Huntress. He said the 60-day guidance is the document worth watching, because it sets the entry bar. Set it high and the work goes to well-funded defense contractors. Barker also expects Congress to weigh in, on grounds that letting private companies disrupt foreign systems is constitutionally significant.
No specific companies have been named as participants.
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.