Washington Just Signed Up Private Hackers. Here's What It Actually Means.

Washington Just Signed Up Private Hackers. Here's What It Actually Means.

Washington Just Signed Up Private Hackers. Here's What It Actually Means.

Hooded operator in a dark room with terminal screens and a Guy Fawkes mask

The White House has quietly put private companies on the offensive in the fight against foreign cybercrime. A national security memorandum signed August 12 directs the Justice Department and the Department of Homeland Security to stand up a program that lets vetted U.S. firms break into the networks of foreign criminal gangs — spy on them, disrupt their operations, and take their infrastructure apart — all under government supervision.

The order, titled Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, marks a first in American policy. Businesses that once could only report hacks to the FBI can now, under contract, be asked to go after the groups doing the hacking. The memo calls them Participating Companies. Critics call them cyber privateers.

Three hooded hackers celebrating in front of green terminal code displays

Supporters say it is a long-overdue answer to a loss problem: ransomware syndicates, pig-butchering rings, and payment-scam crews cost Americans tens of billions of dollars a year, and the FBI simply does not have the bodies to chase them all. Former FBI director Christopher Wray once testified that Chinese state-backed hackers outnumber FBI cyber personnel 50 to 1. Against that math, the argument goes, the country needs more hands on keyboards.

Opponents, including former homeland security officials and international law scholars, warn the country is handing civilian firms a license to cause damage in other people's networks — with liability, retaliation, and diplomatic blowback that the government has not fully priced in.

What the memo actually authorizes

Let's be precise about what this is and isn't. The memorandum does not legalize vigilante hacking. No company can wake up, pick a target, and start poking. Every operation requires written approval from co-executive directors at DOJ and DHS, and the target must be a foreign group classified as a cyber-enabled transnational criminal organization, or CE-TCO: a gang that runs cybercrime against U.S. persons or interests but is not an arm of a foreign government.

Two kinds of activity are on the table. Cyber surveillance operations let a company quietly reach into a gang's systems to collect intelligence, including information that could set up a later strike. Cyber effects operations are the blunt end: manipulation, disruption, denial, degradation, or outright destruction of the group's information systems and networks.

The guardrails are real, at least on paper. Participating companies must undergo rigorous vetting, post a bond of at least $1 million that the government can seize for non-compliance, and disclose every commercial relationship tied to the program. Any operation that could kill or seriously injure someone, or rise to the level of an armed attack under international law, is off the table — the co-executive directors cannot approve what the memo calls Critical Outcomes. If a company accidentally hits a U.S. person or a system inside the United States, it must stop, minimize, and report to the DOJ. DOJ and DHS get 60 days to write the full operating procedures, and the program gets a classified annex that lays out deconfliction with the military and the intelligence community.

The memo also nods to smaller players. The eligibility criteria are supposed to let in both large companies with critical capacity and smaller, more agile firms suited to specialized jobs — which reads like an invitation to the venture-backed offensive-security startups that have been circling government work for years.

Why now: the numbers behind the order

The scale of the problem has forced the conversation. Ransomware gangs operate like franchises: affiliates rent access to a group's encryptor and leak site, split the ransom, and move on. The Conti-descended crews that U.S. and allied agencies keep warning about — the same families behind the Gunra and INC ransomware waves this summer — run double extortion playbooks that squeeze victims twice, once for the decryptor and once for the stolen data. Add in business email compromise, fake investment platforms, and the scam call centers that target retirees, and the loss figures climb into the tens of billions annually.

The timing matters too. The order builds on Executive Order 14390 from March, which told the federal government to get more aggressive with cybercrime and fraud aimed at Americans. This memo is the private-sector phase of that same push. And it arrives right after a summer of uncomfortable headlines: an Iranian-linked attack on more than 30 water systems in Minnesota, a Cl0p campaign that leveraged a 9.8-severity flaw in PTC Windchill to steal data from dozens of companies, and a SonicWall zero-day chain that let INC Ransomware harvest credentials and TOTP seeds from hundreds of VPN appliances. Private defenders watching those stories roll by have asked the same question repeatedly: why are we only allowed to play defense?

The experts are split — badly

Reaction from the security community has been anything but uniform. Scott Shackelford, who runs the Center for Applied Cybersecurity Research at Indiana University, called the order "a meaningful response to a growing problem" with guardrails attached, while noting that accountability mechanisms for bad actors remain undefined. Jason Healey, a senior cyber conflict researcher at Columbia, said he would have hated the idea a decade ago but the country has moved past the point where defense alone was a realistic option. "That horse left the barn a long time ago," he told Cybersecurity Dive. Huntress chief executive Kyle Hanslovan came out in favor, framing the program as a necessary "coalition of the willing" against AI-powered autonomous threats.

Others are less charitable. Paul Rosenzweig, a former deputy assistant homeland security secretary for policy under George W. Bush, called it a bad idea outright. "There are much better ways to revive what it seems to me is an essentially governmental function," he said. Chris Wysopal, co-founder of Veracode, worries about the blast radius: a company trying to take down a data center in another country could accidentally take a hospital or a transportation operator with it. Erica Lonergan, a cyber conflict expert at Columbia, pointed to the unknown details around vetting, goal-setting, and oversight, and asked directly whether this is a slippery slope toward private offensive operations against nation-states.

The legal analysis firm Wiley was careful to note that the memo does not actually authorize hack-back in the loose sense — participants act only with express government approval, so the difference between "government-contracted operator" and "vigilante" stays intact, at least in the text. But Wiley also flagged the practical unknowns: what happens when a participating company stumbles on stolen U.S. data during an operation against a gang, how deconfliction works when the intelligence community refuses to share its own classified operations with contractors, and whether the government will stand behind a company when a foreign government decides to arrest its traveling employees.

The risks nobody has answered yet

International law is the sharpest edge here. Gary Corn, a former staff judge advocate at U.S. Cyber Command who now directs the Technology, Law & Security Program at American University, points out that the United States is accountable under international law for cyberattacks its private contractors carry out, even if the company violated program rules. And the definitional loophole is real: the memo assumes a criminal group is not government-directed unless clear intelligence says otherwise, but plenty of gangs operate in the hazy middle — think of the Iran-linked teams that American officials say front for the state, or Russia's long courtship of groups like Evil Corp. A company that misreads that line and hits a government-adjacent target could start a geopolitical fire with one packet.

There is also the target-selection problem. The internet is not a clean pipe from the United States to a gang's servers; traffic flows through systems in a dozen countries, each of which has its own laws and its own opinion about American companies running operations on their turf. Rosenzweig put it plainly: anything these companies do overseas will run afoul of the domestic law of the countries where the operations occur. Even allies that have followed Washington's lead on cyber engagement have not gone this far, and Shackelford warns the program could isolate the U.S. diplomatically and set back years of norm-building.

What happens next

The real work starts now, inside two agencies that are not famous for moving fast. DOJ and DHS have 60 days to produce operating procedures: vetting standards, approval workflows, deconfliction rules, reporting templates. The co-executive directors must review and sign off on every operations package in writing before a company acts. After 180 days, the program directors owe the White House a status report, and every participating company faces at least an annual reevaluation.

For the companies themselves, the calculus is not simple. Participation offers revenue and a seat at the table, but the work is classified-adjacent, mostly unadvertisable, and legally exposed. Anyone who signs up needs indemnification terms, legal representation commitments, and written approval records for every action. The firms that thrive will be the ones that treat this as a government-contracting exercise first and a hacking exercise second.

Larger questions linger. Can a program built on secrecy ever be held accountable? Will the oversight survive a change in administration? Does hiring private muscle actually reduce the volume of ransomware, or just move the fight around? Wysopal's answer to the last one is blunt: "I don't think you can sort of offense your way to security." The memo's own authors would probably agree the capability is not a cure — but they have decided the country can no longer afford to leave the offense entirely to the government.

Whether that bet pays off will be measured in the 60-day rulemaking, the first 180-day report, and the first operation that goes sideways. The program the White House sketched on August 12 is a framework, not a finished machine. The details — who gets vetted, who gets targeted, who gets blamed when something breaks — are still being written.

For the Cybersecurity desk, this is the story to watch through the fall.

Sources: White House memorandum, NPR, CNN, Cybersecurity Dive, Wiley analysis.

← Back to Home