President Donald Trump signed a National Security Presidential Memorandum on Wednesday authorizing vetted private companies to conduct offensive hacking operations against foreign criminal networks — not by granting them new legal authority, but by structuring their participation as an extension of existing federal law enforcement, threading a 40-year-old statutory exemption in ways no appellate court has ever validated for private delegates.
The distinction matters. A decade of legislative proposals — most prominently the Active Cyber Defense Certainty Act, first introduced in 2017 — tried and failed to amend the Computer Fraud and Abuse Act (CFAA) to permit private-sector offensive cyber operations. Congress rejected the approach twice, citing misattribution risks, foreign policy complications, and the specter of uncoordinated private hacking cascading across international infrastructure. Wednesday’s memorandum does not amend anything. Instead, it relies on a clause buried in the CFAA’s original 1986 text: Section 1030(f), which states that the statute “does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States.” By anchoring private participation as “part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement,” the administration has built a private offensive cyber contractor industry without passing a single new law — and without resolving whether federal courts will accept that extension.
In 2025, American consumers reported losing more than $20.8 billion to cyber-enabled crime. The White House cited that figure as the primary justification for the memorandum, noting that 73% of U.S. adults experienced some form of online scam or attack. Ransomware, sextortion, phishing campaigns, and impersonation scams coordinated by foreign criminal organizations “are often run by sophisticated TCOs based outside the United States,” the fact sheet reads — criminal networks that U.S. law enforcement lacks the capacity and speed to disrupt at scale on its own.
Trump’s NSPM Creates a Two-Category Offensive Program
The memorandum directs the Homeland Security Task Force’s National Coordination Center (NCC) to create and manage a two-category program under which participating companies may conduct operations against foreign cyber-enabled transnational criminal organizations (CE-TCOs).
The first category, Cyber Surveillance Operations, covers covert intelligence gathering from computer systems, networks, telecommunications infrastructure, or embedded devices — including, where necessary, unauthorized access that must remain undetected. The second, Cyber Effects Operations, goes further: manipulation, disruption, denial, degradation, or destruction of information systems or infrastructure managed through information technology.
Two executive directors — one from the Department of Justice and one from the Department of Homeland Security — will jointly supervise the program. Participating companies must sign contracts with either agency and undergo what the memo calls “rigorous vetting,” covering technical proficiency, personnel security, and commercial relationships. Every proposed operation requires written pre-approval before it proceeds. Companies must maintain a bond or escrow of at least $1 million, forfeitable for non-compliance. If a firm accidentally accesses a U.S. person or domestic system, it must immediately halt operations, minimize any collected data, and notify the NCC immediately.
What the CFAA Exemption Actually Does — and What It Leaves Open
The legal structure that makes this memorandum possible has never been tested in a federal circuit court for the scenario it now governs.
CFAA Section 1030(f) was written in 1986 to ensure the statute wouldn’t be used against the government’s own investigators. The exemption covers “lawfully authorized investigative, protective, or intelligence activity” of U.S. law enforcement agencies. By characterizing private contractor operations as an extension of that lawfully authorized activity — operating under the direction, control, and authority of the U.S. government — the NSPM structures firms to inherit the exemption.
A July 2026 Columbia Business Law Review note by legal scholar Sophia Stener argues the 1030(f) exemption can extend to private organizations legally authorized to act by U.S. law enforcement, pointing to two recent federal district court decisions that support that reading. But Stener’s note also acknowledges this has not been resolved at the appellate level. Lawyers at Jenner & Block, analyzing the March 2026 National Cybersecurity Strategy’s predecessor proposals, were more cautious: no federal framework currently authorizes private companies to conduct offensive cyber operations, and the CFAA along with a patchwork of state and foreign hacking laws broadly criminalizes exactly the conduct the strategy envisioned.
That legal landscape has not fundamentally changed. The NSPM’s novel contribution is an interpretive argument, not a statutory amendment. If a court later rejects the argument that 1030(f) extends to private delegatees, firms that conducted operations under the program’s authority could face retroactive criminal exposure under the same statute the program was designed to work within.
State computer crime laws in New York, California, Virginia, and other states remain on the books regardless of federal authorization, and were not addressed in the memorandum. Foreign computer crime statutes — from the United Kingdom’s Computer Misuse Act to equivalent laws in the countries hosting criminal infrastructure — create further exposure for U.S. firms operating abroad. Operations targeting networks that pass through or are hosted in countries with aggressive cybercrime statutes could subject participating firms to prosecution under foreign law even when the U.S. operation itself is fully compliant.
Industry and Civil Liberties: A Sharp Division
The cybersecurity community’s response split along predictable lines — but with a notable precision about exactly what the memorandum does and doesn’t do.
Jason Kitka, a former U.S. Cyber Command official, was sharply critical, calling the memorandum a “perpetual motion machine” for contractors in a social media post. The phrase points to a structural concern: when private firms are paid to identify and propose offensive operations against criminal networks, they have a financial incentive to find, or construct, a continuous stream of targets. The oversight requirement — that the NCC must approve every proposed operation — is meant to check this dynamic, but the concern is that the approval process could become captured by contractors whose revenues depend on operational volume.
Chris Wysopal, co-founder of Veracode and a veteran of the early internet security world, called it a major policy shift in U.S. cyber while noting it stops well short of the more permissive hack-back proposals that have circulated for years. The distinction Wysopal draws is exact: prior proposals would have given private firms operational independence; this NSPM puts them inside the government’s command structure.
Josh Steinman, co-founder of the cybersecurity firm Galvanick and a former senior White House cyber official during Trump’s first term, praised the policy development.
The civil liberties dimension centers on the memorandum’s definition of Cyber Surveillance Operations. The definition explicitly includes unauthorized access carried out covertly to gather intelligence — a formulation that, depending on implementation, could function as a broad domestic surveillance authority if programs are not tightly scoped. The memorandum’s requirement for immediate cessation and data minimization when a U.S. person is accidentally accessed is a first-line protection. The classified implementation procedures the NCC will develop over the next 60 days will determine how robust that protection actually is in practice.
A Decade of Failed Legislation, One Executive Memorandum
The proposal to enlist private-sector cyber operators in offensive missions has been debated in Washington since at least 2013, as the scale of state-sponsored intellectual property theft became clear. Some officials estimated those losses at hundreds of billions of dollars annually — a scale of harm the government lacked the resources to address through traditional law enforcement.
The Active Cyber Defense Certainty Act, first introduced in 2017 by Representative Tom Graves (R-Ga.) and reintroduced in 2019, would have amended the CFAA to create a legal defense for companies conducting certain retaliatory operations against their attackers. It never passed. The NSA, DOJ, and much of the cybersecurity industry opposed it on the grounds that uncoordinated private hacking could cause collateral damage — sophisticated attackers routinely route operations through compromised third-party systems, meaning a private counterstrike could disable innocent infrastructure — misfire on civilian networks, or trigger escalation with foreign state actors. Former NSA Deputy Director Rick Ledgett summarized the prevailing view: allowing private sector hack-backs would be, in his words, “an epically stupid idea.”
In recent conservative and national security circles, a parallel proposal gained traction: cyber letters of marque, reviving the constitutional mechanism by which Congress once licensed private sea captains to attack enemy ships on behalf of the United States. Representative David Schweikert (R-Ariz.) introduced the Scam Farms Marque and Reprisal Act (H.R. 4988), which would delegate to the president the authority to commission private operators against foreign cybercriminals. That bill has been referred to the House Committee on Foreign Affairs and has not advanced.
Wednesday’s NSPM takes a structurally different approach. Rather than creating new authority — via Congressional amendment or letters of marque — it claims existing authority through the CFAA’s 1030(f) exemption. The administration does not need Congress to act. The tradeoff is that without Congressional buy-in, the legal architecture rests on an untested judicial interpretation rather than an explicit statutory grant.
How This Fits the Administration’s Cyber Strategy Timeline
The NSPM is the third significant executive action in what the administration has framed as a multi-phase offensive cyber policy framework.
In March 2026, Trump signed Executive Order 14390, directing federal agencies to coordinate responses to cybercrime, scam centers, and other cyber-enabled fraud targeting Americans. That order was accompanied by the release of the Trump administration’s National Cybersecurity Strategy, which explicitly envisioned private-sector firms taking an expanded role in offensive operations — but stopped short of formal authorization. In June 2026, a separate NSPM bolstered the cybersecurity of America’s National Security Systems. Wednesday’s memorandum operationalizes the March 2026 strategy with the legal scaffolding the earlier document lacked.
The NCC has 60 days from the signing to establish operating procedures, in coordination with the Homeland Security Council. Program directors must report on the program’s progress within 180 days, then annually thereafter. The practical shape of the program — which firms qualify, what operations get approved, how targeting decisions are made, and how domestic protection mechanisms will be enforced — will emerge from that 60-day procedure-writing process, the details of which will partly remain classified.
Do Private Cyber Firms Actually Have These Capabilities?
The memorandum explicitly states that both large and small firms will be eligible to participate, suggesting the administration envisions a diverse contractor ecosystem rather than a small number of large defense incumbents.
The market for offensive cyber capability has already expanded substantially in anticipation of policy frameworks like this one. The venture-funded offensive cyber sector includes firms that deploy automated attack pipelines capable of operating at machine speed across many simultaneous targets. The legal uncertainty that has historically constrained this sector — specifically, the lack of any authorization to operate on foreign networks without government backing — is precisely what the NSPM is designed to resolve.
Whether participating firms can reliably distinguish criminal infrastructure from innocent co-located networks, attribute operations accurately to the right actors, and avoid triggering foreign government responses are technical and operational questions the program’s oversight architecture will need to answer. The bond/escrow requirement and written-approval process are meant to enforce accountability, but the underlying technical challenges — misattribution, shared infrastructure, collateral damage — are the same ones that sank previous hack-back proposals.
Frequently Asked Questions
What is the CFAA Section 1030(f) exemption, and why does it matter for this program?
The Computer Fraud and Abuse Act has prohibited unauthorized access to computer systems since 1986. Section 1030(f) carves out an exception: the statute does not apply to lawfully authorized investigative or intelligence activities of U.S. law enforcement agencies. The NSPM structures participating private firms as operating under that carve-out by requiring them to work under federal contracts, under written pre-approval, and under the legal authority of the DOJ or DHS. No federal appellate court has ruled on whether this extension to private delegatees is valid — meaning the legal foundation is an interpretation, not a settled precedent, and firms that rely on it do so with some residual legal risk. See Stener’s 2026 Columbia Law Review analysis for the academic case for extension.
What specifically distinguishes this NSPM from the “hack back” proposals Congress rejected twice?
The defeated Active Cyber Defense Certainty Act (ACDC Act) would have amended the CFAA to give private firms an independent legal defense for retaliatory hacking — meaning companies could act on their own initiative, without government direction, as long as they met certain conditions. This NSPM does not create independent private authority at all. Participating firms must receive written approval for every operation, work under government contracts, and operate under the direction and oversight of federal law enforcement. They are closer to government subcontractors than to private vigilantes — which is both the feature that makes this approach legally defensible and the structural constraint that limits how fast or how broadly it can scale. See the CyberScoop analysis of the memo for expert perspectives on this distinction.
Can the program accidentally surveil Americans?
The memorandum contains explicit protections: if a participating firm accidentally accesses a U.S. person or domestic system, it must immediately halt and notify the NCC. Operations that could implicate constitutional rights, federal law, or international obligations require DOJ review and judicial authorization before proceeding. Whether those safeguards will hold in practice depends on the classified implementation procedures the NCC will publish within 60 days — details that civil liberties advocates are likely to scrutinize closely.
What about criminal exposure in other countries where targeted networks are located?
Federal authorization under the CFAA does not override foreign computer crime laws. U.S. firms conducting operations against networks hosted in the United Kingdom, European Union member states, or other jurisdictions with their own hacking statutes could face criminal exposure in those countries regardless of the NSPM’s domestic authorization. The memorandum does not address foreign jurisdictional exposure, which Lawfare analysts identified as a material compliance risk for firms considering participation.
Click Here For The Original Source.
