Skip to content
LIVE // BREAKING
Legal

The White House Just Legalized Cyber Privateers

By K. Denise WashingtonEditor-in-ChiefAugust 14, 20266 min read
Share with tracking
?utm_source=reddit
The White House Just Legalized Cyber Privateers

The US government will now authorize private firms to hack overseas criminals. It’s a formal shift from defense to offense, but the companies hired to fight the fire also sell the fire trucks.

The long-whispered policy of 'hacking back' just left the gray market and went legit. For years, the official US government line has been a firm 'don't'—any offensive cyber action was the exclusive domain of the state. A new White House directive changes that equation entirely. According to a National Security Presidential Memorandum issued Thursday, the government will now authorize vetted private security firms to attack overseas cybercriminals directly. We're not talking about patching servers or analyzing malware anymore. We're talking about dismantling the infrastructure of the ransomware gangs and phishing crews that have plagued businesses and hospitals for the better part of a decade. The government is deputizing corporate security.

This isn't a free-for-all. The program, overseen by the Departments of Justice and Homeland Security, establishes a formal process for enlistment. Participating companies will be authorized to 'conduct Cyber Surveillance Operations and Cyber Effects Operations,' which is government-speak for using spyware and launching disruptive attacks. The targets are explicitly defined as foreign transnational criminal organizations, not state-sponsored actors, though distinguishing between the two is often a nightmare of misdirection. There are guardrails. Operations are forbidden from causing 'Critical Outcomes' like loss of life, and each approved company must deposit $1 million in an escrow account, forfeited if they break the rules. It’s a leash, but it’s a long one.

The winners here seem obvious: established security giants who can now add government-sanctioned offensive operations to their list of services. This creates a new, high-margin business line fighting everything from financial fraud to impersonation scams. The problem, as independent security researcher Kevin Beamont said in response to the memo, is the incentive structure. For years, the most profitable part of the cybersecurity industry has been incident response—cleaning up the mess after a ransomware attack. Putting the companies that sell the fire trucks and insurance policies in charge of preventing the fires seems, in his words, 'optimistic.' When your business model thrives on a perpetual crisis, are you truly motivated to end it?

In the next one to two years, expect a small, tightly controlled pilot program with a handful of trusted firms. The real test will be in the execution, which hinges on rules of engagement that are still being written. How will DHS and DOJ audit an attack on a server in a non-cooperative jurisdiction? What constitutes a proportional response? This policy formalizes the role of the corporate privateer in modern statecraft, blurring the line between a security vendor and a mercenary force. The program effectively outsources a function of national security to publicly-traded companies with quarterly earnings targets. The question isn't whether a contractor can successfully take down a criminal's command-and-control server. The question is who's accountable when they hit the wrong one and spark an international incident?

More in Legal