Is this hack-back or cyber letters-of-marque?
Cybersect
SubscribeSign in
Is this hack-back or cyber letters-of-marque?<br>No, but maybe
Robert Graham<br>Aug 13, 2026
Share
Generated by ChatGPT: https://chatgpt.com/s/m_6a7d568fb4e88191b167c38ca94b7239<br>The President has issued a memorandum on “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime”. It kinda allows a sort of “hack-back” and a sort of “letters-of-marque”, but not fully. I thought I’d discuss it.<br>The context is allowing private companies to help law enforcement and intelligence. Companies already do so, such as Booz Allen helping the NSA or Microsoft’s Digital Crimes Unit (DCU) that famously seizes hacker domains and takes down botnets.<br>Under the law, hacking any computer, even a foreign one, is against the law. There is an exception, 18 U.S.C. §1030(f) of the CFAA, which says: “This section does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States, a State, or a political subdivision of a State, or of an intelligence agency of the United States.”<br>This memorandum fits within that clause, rather than some other authority, like the Constitution’s “letters-of-marque” clause. It also means that companies are acting under the direction of law enforcement, and are not willy-nilly hacking back.<br>Every big tech company (Microsoft, Apple, Google, Amazon, Cisco, etc.) is more competent than the government at this sort of thing. This is partly because they can pay for better talent, but mostly because they run the infrastructure of the world, and can see things that governments are not allowed to see. I’ve worked as an outsider with many of these teams and they are consistently phenomenal.<br>In the past, the government has been trying to maintain control and get these organizations to share, and they do. But a smarter approach is to relinquish control, and let these organizations do what must be done.<br>That’s how I read this memo: instead of making them share data with us, let’s share authority with them, specifically, §1030(f).<br>What that means in practice is that while CrowdStrike is tracking down a Chinese APT group, they can get permission to hack some computers of that specific group. It’s not blanket permission to hack all APT groups — law enforcement still maintains control, requiring written approval of every operations package — but it’s more hacking than they are allowed to do today.<br>It’s a memo directing law enforcement (DOJ and DHS, running the program through the National Coordination Center) to set up the sorts of things they might allow CrowdStrike to do. These aren’t really enumerated to any clarity; the memo gives the program’s executive directors 60 days to write the operating procedures, and much of the detail lives in a classified annex.<br>It starts with defining terms, using the impossible-to-understand definitions you find in such documents that were designed by a committee.<br>Cyber Effects Operation — just means “hacking”, including major hacking that leads to “manipulation, disruption, denial, degradation, or destruction of information systems”.
Critical Outcomes — hacking that likely causes loss of life or serious injury, or rises to a “use of force” or “armed attack” under international law — in other words, something that will really piss off foreign governments.
Cyber Surveillance Operation — hacking, where the goal is surveillance, like hacking into a router to download flow logs. What’s not clear is whether such hacking is restricted to systems owned by the targets, or whether I can hack into the (innocent) data center hosting the bad guy’s computers.
Cyber-Enabled Transnational Criminal Organization (CE-TCO) — any APT group that isn’t conclusively proven to be part of a foreign government, or wholly operated under one’s direction. Thus, the GRU or SVR are off-limits, but it’s not clear all the groups they sponsor are. We suspect a lot of APT groups are sponsored by foreign governments, but as long as we haven’t proved it (the memo requires “clear intelligence” establishing the connection), they are fair game for hacking.
So is this “hack back ”? Possibly. If under assault, a company might call up Microsoft or CrowdStrike, who might then ask permission from law enforcement, then start remediating the hack through “hack-back” operations. But no, they can’t setup their own automated hack-back.<br>Is this “letters of marque and reprisal ” and “privateers” ? Mostly not. That applied in the olden days when privateers were out of contact for months, so had to use their own discretion. Here, the discretion mostly remains with law enforcement. Though, I wonder if it doesn’t eventually morph into law enforcement saying “stop bothering us, just do what you think is best”.<br>In particular, the old privateering let the pirate keep a portion of the booty, sharing it with the government. That doesn’t happen here. The companies don’t get to steal...