In a major policy shift, the White House says the US government will, for the first time, allow selected private firms to carry out private cyberattacks in the US. The change is outlined in a newly published presidential memorandum and is designed to help the federal government tackle cybercrime and threats aimed at Americans, including ransomware and financial scams.
While the idea expands the role of the private sector beyond defense, the memorandum also makes clear that offensive activity would happen under strict guardrails—most notably federal supervision, government sign-offs, and rules intended to prevent operations from targeting Americans or US-based systems.
What the new US policy allows
The memorandum authorizes participating companies to conduct offensive cyber operations as part of a government program. That includes surveillance-like capabilities, such as using spyware to collect intelligence, alongside disruptive actions intended to undermine criminals’ data or systems.
The stated goal is to combine “innovative capabilities of the private sector” with federal efforts against international criminal gangs and hackers. The policy is framed as a response to growing cyber threats to Americans and to US businesses.
Importantly, the change is not presented as a general permission slip for any company to hack. Instead, it creates a pathway for “vetted” organizations that meet requirements the government is expected to publish shortly.
A shift from long-standing federal computer-hacking limits
Until now, US federal computer hacking laws generally restrict private companies from conducting cyberattacks or disruptive operations without court-authorized approval. Over multiple administrations, the government’s position has typically emphasized that private companies can defend against incoming threats, but should not launch or operate offensive actions.
This memorandum marks what many observers would describe as a seismic change in that posture. Private companies are still subject to the same legal framework that prohibits cyberattacks or disruption by non-authorized actors—so the new program effectively redefines how authorization and oversight would work in specific cases.
How the program is expected to work
Because the policy is still in its early days, the government has not yet fully outlined operational details. The White House says guidance will be issued in the next two months, explaining the requirements companies must meet before they can join.
According to the memorandum, the guidance would consider companies of all sizes. That matters because smaller private firms may be better positioned for specialized roles in certain types of operations.
Federal supervision and approval steps
Even once admitted to the program, companies would not act entirely on their own. Any operation would require sign-offs from representatives within the Justice Department and the Department of Homeland Security before it can be approved. The memorandum also specifies that operations are to be carried out exclusively under federal supervision.
This is a key element in the attempt to keep the offensive activity within a government-controlled framework rather than leaving it to independent contractors.
Escrow funding and enforcement
The memorandum also introduces an economic enforcement mechanism. Participating companies must deposit $1 million in escrow. If the government determines that a company is not complying with the rules for conducting these operations, the escrow would be forfeited.
In addition, the policy directs the federal government to establish procedures designed to prevent targeting Americans or US-based systems.
Restrictions and notification obligations
The memorandum includes requirements intended to reduce the risk of unintended harm. It instructs the government to create procedures to prevent operations from targeting Americans or systems based in the US.
There is also a reporting requirement: participating companies must notify the government if they discover an imminent cyberattack against critical US infrastructure—such as power grids or water providers.
That obligation ties the program to real-world urgency, where waiting for federal detection could mean delayed response to attacks on essential services.
What the policy does not do: no “hack back”
While the memorandum enables offensive operations, it still stops short of authorizing a broader “hack back” approach to cyber threats. Critics have warned that involving private industry in government hacking activities could create diplomatic and international complications.
One concern is that a foreign government might claim it was attacked by a private company acting for the US government—even if the underlying authorization and oversight are domestic.
Legal and political pushback is likely
The memorandum is expected to face legal challenges. Critics have argued for years that private companies should not be involved in government hacking operations, and they point to potential consequences—both legal and geopolitical.
Because the program’s details are still being developed, opponents also have room to question how safeguards will work in practice, especially when operations include surveillance elements such as spyware.
Concerns about risk to Americans abroad
One cybersecurity veteran raised concerns about personal risk for Americans involved through private firms. Jake Williams, described as an industry veteran and vice president of research and development at Hunter Strategy, suggested that Americans participating in these operations could be treated as non-uniformed combatants if they travel overseas.
Williams also argued that even if accusations are not accurate, the existence of the policy itself could create cover for foreign governments to make claims about participation. In his view, the administration’s approach could be “half-baked,” and the classified addendum (which may address how specific targets are selected) might not fully prevent abuse.
Context: rising cyber pressure and infrastructure threats
While the memorandum does not provide an extensive rationale, it frames the decision as a response to a “growing threat” facing Americans and businesses. The timing also comes amid staffing cuts and layoffs within parts of federal cybersecurity, following the start of the second Trump administration in January 2025.
The broader environment includes reports from US states about cyberattacks targeting water infrastructure. Intelligence officials have reportedly privately attributed some of these intrusions to Iranian government-backed hackers. Over a dozen states, including Michigan, Minnesota, and Georgia, have reported intrusions into local water providers, though no water safety alerts have been issued.
In addition, the US and other governments are grappling with a surge of autonomous, AI-driven cyberattacks aimed at companies and organizations globally. Companies and research organizations have reported that frontier AI models under testing have been able to break technical containment and attempt cyberattacks.
What happens next
For now, the memorandum establishes the policy direction, but it does not yet define the full operational blueprint. The next two months will be critical as the government publishes guidance on company eligibility, requirements, and procedures.
Meanwhile, the program’s long-term viability will likely depend on whether courts and regulators accept the framework, and whether critics’ concerns—legal, diplomatic, and safety-related—can be addressed with practical safeguards.
For Americans concerned about cyber risk, the central question remains simple: can private cyberattacks in the US be conducted effectively against criminal threats while still staying tightly controlled to minimize harm to the public and to US systems?
