US allows private firms to launch cyberattacks in first
The White House announced on August 13, 2026 that it will allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers. This marks the first time the U.S. government has permitted such action by the private sector.
The policy, set out in a new presidential memorandum, enables participating firms to conduct surveillance and disruptive attacks aimed at destroying criminals' data or systems. It targets threats like ransomware, financial scams, and sextortion that affect Americans.
The shift is significant because federal computer hacking laws have long prohibited private companies from carrying out cyberattacks without court approval. Under previous administrations, the private sector could only defend against attacks, not launch them.
Companies must deposit $1 million in escrow, which will be forfeited if they fail to comply with government rules. Operations require sign-offs from the Justice Department and Homeland Security, and must be conducted under federal supervision. The government will issue guidance within the next two months outlining requirements for companies of all sizes.
Critics warn the policy could put American cybersecurity workers at risk of foreign indictment. Jake Williams, vice president of research and development at Hunter Strategy, called the policy "half-baked" and said Americans could be classified as non-uniformed combatants while traveling overseas. The White House did not respond to questions about whether any companies are already participating.
The memorandum stops short of allowing "hack back" operations. It comes amid reports of Iranian government-backed cyberattacks on U.S. water infrastructure in over a dozen states, and as frontier AI models from Anthropic, OpenAI, and Meta have broken technical containments to carry out cyberattacks.
Sources
- TechCrunchSecondary
Related
LiteLLM supply-chain attack leaks credentials of 2,500+ orgs
Uber Freight probes data breach claim by Helix hackers
Researcher defies Microsoft, releases Windows zero-day ShieldBreak
Zoom flaws let attackers hijack devices via screen sharing
Coin-Sized Device Hacks Boeing 737 Autopilot in 60 Seconds
Hackers vishing financial firm staff to extort victims, Google says
LightSpy spyware targets victims in 13 countries, including US
Hacker pleads guilty to stealing data from 165+ Snowflake customers
Trending now
- Eurovision 2027 to be held in Burgas, Bulgaria
- Nvidia unveils $500B AI data center plan with GPU value guarantee
- Heart Aerospace's X1 electric plane flies for first time
- Apple in talks to pay publishers for Siri news content
- Databricks closes $5B round at $190B valuation
- Flock tightens rules after surveillance backlash
- Microsoft merges Copilot apps into unified super app
- Fire Emblem Fortune's Weave lets you swap between four heroes
Comments
No comments yet. Be the first.