Federal Memo Would Let Private Firms Hack Foreign Criminals — With $1 Million on the Line
A presidential memorandum reported by The Verge puts the Justice Department and Homeland Security in charge of vetting cybersecurity companies for offensive operations abroad. Researchers question who gets hit when attribution goes wrong.

The Trump administration is starting a program that would let private cybersecurity companies carry out cyberattacks against foreign criminals, operating “under the control and oversight” of the federal government, according to a presidential memorandum described by The Verge in a report published August 13, 2026. The memorandum was published the previous day, Wednesday, August 12, 2026. Companies admitted to the program must hold a bond or escrow of at least $1 million, which they forfeit if they fail to comply with their contractual agreement, per the memorandum as reported by The Verge.
Two federal agencies would run the vetting. The Department of Justice and the Department of Homeland Security will oversee the private firms, according to that reporting. Firms must meet requirements in “technical proficiency, proven performance of cyber operations, facility security,” and more, the memorandum says.
The memorandum also draws a line around targets. Private firms will only hack groups that are “not an institutional part of a foreign government or wholly operated under a foreign government’s direction,” it states. The document describes private businesses as “underutilized” forces against criminal networks, and says: “It is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime.”
The line the memo draws is the hardest one to find
The carve-out for state-run groups is where the outside criticism lands. As Cybersecurity Dive pointed out, it can be difficult to identify which criminal groups are affiliated with foreign governments, which could expose cybersecurity firms to geopolitical or legal conflict, The Verge reports.
Jason Healey, a senior cyber conflict researcher at Columbia University, told Cybersecurity Dive that “Anyone conducting these operations is doing so at substantial personal legal risk.”
Jake Williams, vice president of research and development at Hunter Strategy, told TechCrunch that “Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas.”
Ben Bernstein, a manager on the cybersecurity advisers team at Huntress, raised a separate objection in comments carried by The Verge. “Threat actors don’t launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network,” Bernstein said. “That makes it practically impossible to ‘strike back’ without taking out innocent bystanders.”
Read together, the two problems compound. A firm that misidentifies a target risks a fight with a foreign state; a firm that identifies the target correctly may still have to go through a third party’s hardware to reach it. The $1 million bond is the only consequence described in the reporting, and it runs to the government, not to whoever owns the router in the middle.
What the reporting does not settle
The United States government previously carried out its own cyber operations rather than relying on third parties, The Verge notes. President Donald Trump began making plans to involve private cybersecurity companies last year, according to Bloomberg, which reported the memorandum first.
Several questions central to how this works in practice are not answered in the material reviewed here. The reporting does not name a single company admitted to the program — in Southern California, where defense and cybersecurity contractors cluster, or anywhere else. It does not describe how participating firms and their employees would be shielded from liability under existing federal computer-crime law. It does not give a date when licensing begins, or say how many firms the Department of Justice and the Department of Homeland Security expect to approve.
Those are the answers that will determine whether this is a narrow contracting mechanism or a broad one. Until implementation guidance appears, the public record is a memorandum, a bond requirement and a set of warnings from researchers who read it.

Comments 0