/

August 20, 2026

America Just Cracked Its Ban on Private Hacking: What the New Hack-Back Memo Really Means

For as long as there have been computer crimes, one rule has been close to absolute in the United States: private companies are not allowed to hack back. If a criminal gang breaks into your network, encrypts your files, and demands a ransom, you may defend your own systems all you like — but the moment you reach out and touch their computers, even to retrieve your own stolen data, you have very likely committed a federal crime yourself. The victim who strikes back becomes a lawbreaker. That has been the settled state of things for decades.

This week, that long-standing rule got its first serious crack. A national security memorandum signed by the President on August 12, 2026, directs the government to create a formal program under which vetted private companies could be authorized to conduct offensive cyber operations against foreign criminal organizations — to break into their systems, surveil them, and even disrupt or destroy them — all under government control and approval. It is one of the most significant shifts in U.S. cyber policy in years, and it’s exactly the kind of development this series exists to explain.

In our two earlier pieces on this subject, we looked at America’s offensive cyber capabilities — the ones you rarely hear about because they’re carried out quietly by the government — and made a running observation that these capabilities have a way of spreading outward over time. This memo is that theme becoming literal, official policy: for the first time, the government is moving to place a form of offensive cyber capability directly into private hands. So let’s do what this series always tries to do — explain clearly what actually happened, present honestly why smart people are both excited and alarmed about it, and do it all without cheerleading or hand-wringing. This is a genuinely contested policy, and you deserve both sides.

A quick word on how we’re covering this

This is a political story in a way most of what we write is not — it involves a specific administration and a specific presidential action. We’re going to name those facts plainly, because they’re facts, and then treat the policy itself the way we’d want any trusted expert to: evenhandedly. We hold no partisan position here, and you won’t find us praising or attacking the administration. Reasonable, serious people across the political spectrum genuinely disagree about whether this is a smart idea, and our goal is to help you understand the debate, not to tell you which side to land on. With that said, let’s dig in.

What the memo actually does

Strip away the headlines and here’s the substance. The memorandum directs a federal body — the National Coordination Center, working with the Departments of Justice and Homeland Security — to build and run a program that would let approved private companies go on offense against foreign cyber-enabled transnational criminal organizations. That’s the government’s term for the overseas gangs behind ransomware, large-scale phishing, romance and investment scams, sextortion, and the other predatory schemes that drain money from Americans. The White House cited a striking figure as motivation: American consumers reported losing more than $20 billion to cyber-enabled crime in a single year.

Companies that pass a vetting process would become “Participating Companies,” under contract with the government, and would be authorized to conduct two distinct categories of operation. It’s worth understanding the difference, because they represent very different levels of aggressiveness:

CategoryWhat it means in plain terms
Cyber Surveillance OperationsCovertly gathering intelligence from criminals’ systems, networks, and devices — including, where necessary, breaking in undetected to watch what they’re doing. Essentially, digital spying on the gangs.
Cyber Effects OperationsThe more aggressive tier: actively manipulating, disrupting, degrading, denying, or destroying the criminals’ systems and infrastructure. Not just watching — taking their operations apart.

The key legal move underneath all this concerns a 1986 law called the Computer Fraud and Abuse Act — the statute that makes unauthorized computer access a crime, and the very reason private hack-back has been off-limits. That law contains an exception for authorized law-enforcement activity. The memo’s approach is to position these vetted companies as operating under government control and oversight, as part of lawful law-enforcement operations, so that their actions fall within that exception rather than violating the law. In effect, it attempts to extend the government’s own legal permission to hack outward to cover approved private partners.

Two details are worth noting for balance. First, this program is aimed at criminal organizations, and reporting indicates it specifically excludes companies acting directly on behalf of foreign governments — it’s pointed at gangs, not designed as a tool against nation-states. Second, the memo does build in guardrails: every proposed operation reportedly must be approved by the government in advance, and companies are required to stop and alert authorities if they accidentally affect a U.S. person or system. Whether those guardrails are sufficient is precisely where the disagreement begins.

The case for it

Supporters of this approach make an argument that’s easy to understand and genuinely compelling on its own terms. It rests on a few pillars:

  • The talent and tools are in the private sector. The White House’s own framing is that American industry is the most innovative and advanced in the world, and that its speed, scale, and capability represent a real offensive advantage that has gone underused. Some of the sharpest cyber talent on earth doesn’t work for the government — it works for private security firms. This program aims to point that expertise at the criminals.
  • The current approach isn’t keeping up. Foreign cybercrime against Americans is enormous and growing, and it largely operates from places beyond the easy reach of U.S. law enforcement. Arrests and takedowns happen, but the gangs are numerous, resilient, and fast. The argument is that playing pure defense while losing tens of billions of dollars a year is a losing strategy, and that going on offense — disrupting the criminals’ own operations — could change the math.
  • Deterrence. Right now, attacking Americans from abroad is a relatively low-risk, high-reward business. The stated hope is to flip that calculation — to make targeting Americans genuinely dangerous for the criminals. A senior Homeland Security official captured the ambition bluntly at a recent security conference, saying the long-term goal is to make would-be attackers understand that the United States is the worst possible target because “we will mess you up.”
  • It’s not a free-for-all. Proponents emphasize that this isn’t vigilante hacking — it’s a controlled program with vetting, government contracts, advance approval of operations, and oversight from federal agencies. The idea is to harness private capability while keeping the government firmly in charge of when and how it’s used.

Taken together, it’s a coherent vision: the criminals are sophisticated, fast, and largely beyond reach, so deputize the country’s best private talent — under government control — to take the fight to them. For a lot of people watching cybercrime flourish year after year, that has real appeal.

The case against it

The concerns are equally serious, and they come not from people who are soft on cybercrime but from cyber-policy experts, legal scholars, and former government cyber officials who worry about the ways this could go wrong. Their objections are worth laying out just as fully:

  • Attribution is genuinely hard. The foundational problem with any form of hacking back is that it’s often extremely difficult to know for certain who’s really behind an attack. Sophisticated criminals routinely route their operations through the hacked computers of innocent third parties and disguise their tracks. A private firm striking at what it believes is a criminal’s system could, in reality, be attacking a hospital, a small business, or an ordinary person whose device was hijacked — causing real harm to an innocent victim who had nothing to do with anything.
  • Collateral damage and escalation. Cyber operations don’t always stay contained. An operation meant to disrupt one criminal network can spill over onto shared infrastructure and affect systems that were never the target. And striking at criminals — some of whom have murky ties to foreign governments — risks provoking retaliation, potentially against the very companies doing the work, or their employees, who would not have the legal protections that shield government personnel.
  • The legal foundation is untested. The memo’s core legal theory — that government authorization brings these private operations within the law-enforcement exception — has never been validated by an appellate court. And U.S. authorization does nothing about foreign law: a company hacking a server located in another country could be committing a serious crime under that country’s laws, regardless of what a U.S. memo says. Legal experts have flagged this as a real, unresolved exposure for any firm that participates. Notably, similar hack-back proposals have come before Congress before and been rejected, precisely over these kinds of concerns.
  • The incentive problem. One former U.S. Cyber Command official pointedly described the arrangement as a “perpetual motion machine” for contractors. The worry is structural: if private companies are paid to find and carry out offensive operations, they have a financial incentive to keep finding targets — a continuous appetite for operations that the government’s approval process would have to actively restrain. Critics question whether that oversight will hold up under commercial pressure.
  • The slippery slope. Perhaps the deepest worry, voiced by more than one expert, is where this leads. Today it’s vetted firms targeting foreign criminal gangs under government control. But the precedent — private companies conducting offensive cyberattacks — is a significant line to cross, and some fear it could gradually expand toward private operations against tougher targets, or erode the norm that offensive force is something only governments wield.

The honest bottom line on the debate: both sides are arguing in good faith about a real dilemma. Cybercrime against Americans genuinely is enormous, relentless, and largely beyond the current reach of law enforcement — the problem the memo is trying to solve is not imaginary. And the risks the critics raise — hitting the wrong target, collateral damage, escalation, untested law, commercial incentives to keep hacking — are not imaginary either. This is not a case of obvious good versus obvious bad. It’s a hard trade-off between the desire to finally take the fight to the criminals and the many things that can go wrong when you unleash offensive capability, even carefully. Where you come down likely depends on how you weigh those against each other.

What happens next, and why it matters to everyone

It’s important to be clear about the timeline: this memo is a direction to build a program, not a switch that was flipped overnight. It instructs the government to establish the rules, the vetting, and the oversight structure. The real substance — who qualifies, exactly what they’ll be permitted to do, how operations get approved, and how the guardrails work in practice — will be worked out in the implementation, and that’s where many of the hardest questions will actually be answered. This is the opening move, not the finished picture.

So why does a policy about elite firms hacking foreign gangs matter to an ordinary business owner or an everyday internet user? A few reasons. Most directly, the entire stated purpose is to reduce the flood of ransomware, scams, and fraud aimed at Americans — which is to say, at the small businesses and individuals who are the usual victims. If it works as intended, the goal is fewer criminals successfully targeting you. More broadly, this is a landmark moment in the ongoing story we’ve been tracking across this series: the steady movement of serious cyber capability outward from government into the wider world. Watching how this program is built — how carefully the guardrails are drawn, how the oversight actually functions — will tell us a great deal about the shape of digital security in the years ahead.

And it’s a reminder of the larger truth this series keeps circling back to. The world of cyber offense, once the exclusive and secret domain of nation-states, is steadily becoming something broader and more visible — its tools, its talent, and now its very authority spreading outward. Whether that makes ordinary people safer or introduces new dangers is a question we’re all going to be living inside of, and answering together, for a long time to come. For now, the sensible posture is the one this series has always advocated: understand what’s happening, resist the easy certainties on both sides, and watch closely as the details unfold. This story is very far from over.

Sources: White House national security presidential memorandum (August 12, 2026) and accompanying White House statements; The Record (Recorded Future News); CyberScoop; FedScoop; Help Net Security; BleepingComputer; Cybersecurity Dive; The Register; and legal analysis published by Lawfare, August 2026. Expert commentary quoted or paraphrased reflects the views of the individuals cited. This article summarizes a contested policy and takes no position on it.

From the same category