Aug 13, 2026
Policy

Trump private cyber firms hack back program targets foreign criminal groups

Trump ordered a DOJ- and DHS-supervised program for vetted cyber firms to surveil and disrupt foreign criminal networks.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Trump private cyber firms hack back program targets foreign criminal groups
Photo: The Register

President Donald Trump has ordered a federal program that could put private cybersecurity companies to work conducting surveillance and disruptive operations against foreign cybercrime groups. The Trump private cyber firms hack back initiative is not a broad right for companies to access or attack other networks: participants must work under federal contracts, direction and oversight, with individual operations approved through the program.

The Aug. 12 presidential memorandum directs the National Coordination Center to establish the program, supervised by executive directors from the Justice Department and Department of Homeland Security. Operations must be carried out on behalf of, and under the supervision of, the federal government, according to the memorandum.

The White House says the effort is aimed at foreign transnational criminal organizations that use cyber-enabled crime against Americans. Its fact sheet cited more than $20.8 billion in consumer-reported losses from cyber-enabled crime in 2025, an administration-provided figure.

Can private cyber firms hack back under Trump’s program?

Only within the government-run program. Companies can propose operations using threat information obtained through normal commercial activity or supplied by government bodies, but DOJ and DHS leadership must coordinate on approval. The framework does not authorize independent offensive activity by private firms.

The target set is foreign cyber-enabled transnational criminal organizations, not entities directly associated with or acting wholly for foreign governments, according to reporting by The Register. That distinction narrows the program away from nation-state targets, even where criminal groups may operate from foreign jurisdictions.

What operations could companies perform?

The memorandum permits two types of work: Cyber Surveillance Operations and Cyber Effects Operations. Surveillance is intended to gather intelligence and may support later effects operations, The Register reported. Cyber Effects Operations cover manipulation, disruption, denial, degradation or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident on those systems.

The program bars approvals for operations producing “Critical Outcomes.” Cybersecurity Dive reported that the memorandum defines that boundary to include loss of life or serious injury, as well as activity that would amount to the use of force or an armed attack under international law.

Controls and unresolved legal exposure

Companies will need contracts with DOJ or DHS and must clear vetting requirements. Within 60 days, the departments’ program directors and the Homeland Security Council must set operating procedures covering technical proficiency, prior cyber-operations performance, facility security, personnel vetting, competence and reliability. The rules are also meant to admit both large providers and smaller specialists.

The procedures can require a bond or escrow of at least $1 million, forfeitable for contractual noncompliance. Participating companies must disclose specified commercial relationships to the National Coordination Center.

The August memorandum is more specific than the administration’s March cyber strategy, which promised incentives for private companies to identify and disrupt adversary networks but did not expressly authorize private offensive operations. A Skadden analysis said the Computer Fraud and Abuse Act generally prohibits unauthorized computer access and can carry criminal and civil penalties. The Register reported that no court has decided whether the law’s exception for lawfully authorized government investigative, protective or intelligence activity extends to contractors doing this work under federal direction.

For cyber vendors, the immediate commercial question is not a new standalone hack-back market. It is whether the coming procedures create a viable federal contracting channel, and how much legal protection and operational control the government is prepared to provide.

This story draws on original reporting from The Register.

More from Policy

All Policy →