In a first, US will allow some private firms to carry out cyberattacks

Cider99861 pts0 comments

In a first, US will allow some private firms to carry out cyberattacks | TechCrunch

SearchSubmit

Site Search Toggle

Mega Menu Toggle

Topics

Latest

AI

Amazon

Apps

Biotech & Health

Climate

Cloud Computing

Commerce

Crypto

Enterprise

EVs

Fintech

Fundraising

Gadgets

Gaming

Google

Government & Policy

Hardware

Instagram

Layoffs

Media & Entertainment

Meta

Microsoft

Privacy

Robotics

Security

Social

Space

Startups

TikTok

Transportation

Venture

More from TechCrunch

Staff

Events

Startup Battlefield

StrictlyVC

Newsletters

Podcasts

Videos

Partner Content

TechCrunch Brand Studio

Contact Us

Image Credits: Towfiqu Photography (opens in a new window) / Getty Images

Security

In a first, US will allow some private firms to carry out cyberattacks

Zack Whittaker

7:09 AM PDT · August 13, 2026

The U.S. government will for the first time allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers, the White House said on Wednesday.

In a newly published presidential memorandum, the Trump administration said the move will allow the federal government to use "innovative capabilities of the private sector" to combat cybercrime and threats targeting Americans, such as ransomware attacks, financial scams, and sextortion.

The memorandum allows private companies participating in the government’s program to conduct surveillance, like using spyware to collect intelligence, as well as make disruptive attacks aimed at the destruction of criminals’ data or systems.

The policy change marks a seismic shift in the U.S. government’s long-standing position under U.S. federal computer hacking laws, which broadly prohibit private companies from conducting cyberattacks or disruption operations without a court-authorized approval.

Private companies are regulated under the same computer hacking laws as anyone else in the United States, which prohibit people or companies from carrying out cyberattacks. The U.S. government’s position to date, through multiple administrations, has been that the private sector can defend against incoming cyberattacks, but not launch or operate them.

While the presidential memorandum establishes the new policy, it’s still in its early days and the government has not yet fully established how the program will operate. The new policy is likely to face legal challenges and opposition by critics, who have for years argued that private companies should not get involved with government hacking operations.

The government will issue guidance in the next two months outlining the requirements participating companies will have to meet before being allowed into the program. This guidance would consider companies of all sizes, including smaller private companies, which might be better suited for specialized operations, the memorandum reads.

Participating companies must deposit $1 million in escrow, which will be forfeited if the government finds out a company isn’t complying with its rules on how to conduct these operations. The memorandum directs the federal government to create procedures preventing any operation from targeting Americans or U.S.-based systems.

Any operation will require sign-offs from representatives from the Justice Department and Homeland Security before it can be approved. Operations are to be conducted exclusively under the supervision of the federal government.

The policy also requires any participating company to notify the government if it discovers an imminent cyberattack against critical U.S. infrastructure, such as power grids or water providers.

When reached by email, a White House spokesperson did not answer TechCrunch’s questions about whether any private companies are already participating in the program, and referred to the White House’s fact sheet.

The memorandum stops short of allowing companies to "hack back" any cyber threats. Critics have argued that private industry getting involved with government operations may spark diplomatic and international ramifications, such as if a foreign government complains that they were attacked by a U.S. company.

The policy, according to one cybersecurity veteran, could put Americans who work for private cybersecurity companies at risk of being indicted or taken into custody by a foreign government, much like how U.S. prosecutors have charged Chinese, Iranian, and Russian government hackers with cybercrimes targeting the United States.

"Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas," said Jake Williams, an industry veteran who serves as vice president of research and development at cybersecurity company Hunter Strategy.

"The allegations that an American participated in these ops need not be true," Williams told TechCrunch, noting that the administration’s policy alone creates cover for a foreign government to make such accusations.

Describing the policy as...

government private companies policy operations cyberattacks

Related Articles