Private Cyber Operations Are Now Part of U.S. Power
Private cyber operations now have a formal federal pathway: vetted American companies may conduct government-directed operations against qualifying foreign criminal networks — under contract, under review, and under federal control.
Five months ago, the White House said this was exactly what it would not do. Now it has built the mechanism to do it.
Private cyber operations are no longer a hypothetical policy debate. On August 12, 2026, President Trump signed a National Security Presidential Memorandum, Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, creating a formal U.S. program under which vetted private companies can be authorized to conduct cyber-surveillance and cyber-effects operations against foreign criminal networks — not on their own authority, but under direct federal control.
What This Article Is Actually About
This is not an argument for corporate vigilantism. This is not a claim that any company may now “hack back.” This is about the U.S. Government creating a supervised mechanism for transferring private technical capability into public operational power — and the question is how authority, accountability, legal responsibility and risk travel with that transfer.
Signal One
The Private Sector Is Moving Inside the Operation
Previously, private companies often detected, defended, informed, sued or disrupted activity on systems they controlled. The new program creates a path for selected companies to participate directly in government-authorized external operations.
Signal Two
This Is Not a Free-Range Hack Back
Every operation requires federal review and written direction. Targeting, legal authority and operational control remain government functions.
Signal Three
Authority Creates a New Accountability Chain
The more private capability becomes state capability, the more important target validation, deconfliction, oversight, reporting and responsibility become.

I. Five Months From “Not Hack Back” to a Program
In March, as the administration rolled out its new cyber strategy, a senior White House official stood in front of reporters and closed a door. Asked whether the private sector would be authorized to strike back at hackers, the White House’s March position on private offensive campaigns was direct: “That does not mean hack back, that does not mean letters of marque. We’re not interested in fighting pirates with pirates.” The National Cyber Director made the same point the same week, at the McCrary Cyber Summit, telling industry the administration wanted their visibility into threats, not their offense.
Five months later, a presidential memorandum has built the thing that was ruled out. It does not hand companies a general license to retaliate. Instead, it creates a federal program, run by the Department of Justice and the Department of Homeland Security, through which vetted companies can be authorized, case by case, to conduct private cyber operations against qualifying foreign criminal infrastructure. The distance between March and August is not a contradiction so much as a narrowing: from ruling out private offense entirely, to building a specific, supervised lane for it.
II. What Private Cyber Operations Now Mean
The August 12 presidential memorandum defines two categories of activity. A Cyber Surveillance Operation is intelligence collection: accessing a target’s systems without authorization, or beyond authorization, to gather information, with intent to stay undetected. The program’s definition of cyber effects operations goes further: action that manipulates, disrupts, denies, degrades or destroys systems, infrastructure or the information inside them.
Both categories describe real technical reach into someone else’s systems. Neither describes a company acting on its own judgment. Every operation in either category has to move through the same federal gate before a participating company may act, and the memorandum is careful to say who that gate excludes: only foreign groups that meet the program’s definition of a cyber-enabled transnational criminal organization qualify as targets. A group presumed to be acting on behalf of a foreign government falls outside that definition entirely. This is a program built around criminal networks, not state adversaries, and the distinction is load-bearing, not incidental.
III. A Private Company, Acting With Government Authority
To take part, a company has to be vetted and under contract with DOJ or DHS, meeting standards the memorandum leaves to those agencies to set: technical proficiency, personnel security, a track record of reliable performance. Every operations package a company proposes still needs coordinated, written approval from the program’s two executive directors before any action happens.
That structure answers the question that matters most here. The capability is private. The authority is public. Public accountability begins with the government that authorizes and directs the operation, while the participating company remains bound by its contract, the program’s procedures and applicable law. The contractor model is familiar in other federal domains; what is new here is the operational lane being built for private cyber capability.
The memorandum also draws a line companies will need to hold. Operating under the program does not replace a company’s ordinary right to defend its own networks; that authority already existed and continues separately. What the program adds is narrower: a legal channel into systems a company never controlled, opened only with federal direction and closed the moment that direction ends.
IV. The Million-Dollar Bond Is Not the Main Safeguard
The most quotable detail in the memorandum is a financial one: DOJ and DHS can require a participating company to post a bond or hold funds in escrow, at least one million dollars, forfeited if the company breaks its contract. It is a real requirement, but framing it as the safeguard undersells what the document actually builds around it.
The heavier machinery is procedural. Operating rules, due within sixty days, have to cover target validation, legal deconfliction across agencies, protections for U.S. persons and domestic systems, a stop-and-report duty the moment an operation drifts outside its approved scope, and annual review of whether a company stays eligible to participate at all. For private cyber operations, those procedures matter more than the headline bond: they are what are supposed to keep an operation from becoming a mistake with consequences.
Worth noting precisely: the memorandum does not require every participating company to post that bond automatically. It authorizes DOJ and DHS to mandate one as a condition of a company’s specific contractual agreement. The number is real, but it is a contractual lever, not a universal entry fee — and it is smaller, as a governance tool, than the reporting and review structure sitting around it.
V. The Internet Does Not Respect Clean Target Boundaries
Lawfare’s analysis of private cyber offense, published in May, points to a structural problem that predates this memorandum: criminal infrastructure rarely sits by itself. Attackers route through rented servers, hijacked accounts and shared cloud environments that also carry legitimate traffic that has nothing to do with the crime.
That is precisely why the memorandum requires operating procedures to address unintentional targeting of U.S. persons or domestic systems, with a mandatory stop-and-notify step if it happens. The requirement exists because the risk is real, not theoretical. Confident attribution, in infrastructure this tangled, is work, not a formality.
VI. Disruption Week Shows What Changed
The clearest before-and-after sits two months earlier. In June, the Justice Department’s June Disruption Week shared intelligence with companies including Apple, Coinbase, Google, Meta and Microsoft. Those companies voluntarily disrupted scam accounts and infrastructure on their own platforms, acting under their own terms of service, freezing several million dollars in fraud-linked crypto and cutting off more than a million accounts.
That was real cooperation, and it stayed inside a boundary: companies acting on systems they controlled. The new program contemplates something the June operation did not: authorized entry into a target’s own external systems, under a federal legal umbrella built specifically for that purpose. The boundary that held in June is the one August moves.
VII. The Rules Are Still Being Written
Program executive directors have sixty days to finalize the operating procedures this entire structure depends on, and a status report is due to the White House within a hundred and eighty days, and annually after that. Almost everything that will determine whether this program operates within the safeguards the memorandum describes sits inside procedures not yet public: how eligibility gets decided, how a target gets adjudicated, what triggers a stop, what becomes public reporting and what stays classified.
The memorandum itself sets a floor worth noting. Program directors cannot approve an operation expected to cause loss of life or serious injury, or to rise to the level of a use of force or armed attack under international law. That ceiling exists on paper now. Whether it holds in practice is the next chapter of this story, and it will be a slower one than this week’s headline.
For operators watching this space, the sixty-day window is the thing to calendar. It is where private cyber operations move from memorandum language into an operating system of checks — or reveal where those checks are thinner than the announcement suggested.
KMOB1003 Doctrine
The Authority Chain
Target
A qualifying foreign cyber-enabled transnational criminal organization is identified.
Vet
A U.S. company must meet program eligibility, technical and personnel standards.
Authorize
The operational package is reviewed, legally deconflicted and receives written federal direction.
Account
Execution, reporting, minimization, compliance and continued program eligibility follow the operation.
The important question is not whether the private company has the capability. It is who gives that capability authority — and who owns the consequences when it is used.
Signal Breakdown
Signal: The Federal Government is creating a program that allows vetted U.S. companies to execute cyber-surveillance and cyber-effects operations against qualifying foreign cybercriminal organizations.
Impact: Private cybersecurity capacity can now become part of government operational capacity rather than remaining solely defensive, informational or platform-controlled.
Watch: The implementation rules due within 60 days — particularly target approval, legal review, deconfliction, U.S.-person protections, reporting and accountability.
Power Is Often Hidden in the Operating Model.
The headline is about cyberattacks. The deeper story is about how institutions decide who may act, under whose authority, with whose technology, and at whose risk.
Creator & Institutional Infrastructure
NordVPN Complete
Security Still Begins at the Connection You Control.
This article is about state-scale cyber authority, not consumer VPNs. At the individual and small-operator level, the practical security work is more ordinary: protecting routine connections, reducing exposure on public networks, and treating access as something worth securing before a crisis begins.
Genspark
Research the Authority Behind the Headline.
The phrase “private companies can conduct cyberattacks” is easy to repeat and easy to oversimplify. Genspark can support source discovery and comparison when operators need to move past the headline and examine primary policy, competing analysis and institutional context.
ClearCRM
Keep the Human Chain of Follow-Up Visible.
Large institutional systems do not fail only because technology breaks. Responsibility also disappears across inboxes, departments, vendors and handoffs. ClearCRM gives operators a way to organize relationships, follow-up and workflow around the people responsible for moving work forward.
Spines Hybrid
Turn Institutional Knowledge Into a Record.
Policies change quickly. The people who study, lead and explain those systems need durable ways to preserve what they learned. Publishing can turn analysis, expertise and institutional memory into an owned record that survives the news cycle.
Disclosure: KMOB1003 may earn a commission from qualifying purchases through select partner links. Editorial coverage is produced independently.
The Operator’s Bookshelf
KMOB1003 Reads
As an Amazon Associate, KMOB1003 may earn from qualifying purchases.
Disclosure: KMOB1003 may earn a commission from qualifying purchases through select partner links. Editorial coverage is produced independently.
KMOB1003 After the Article
Continue the Signal
Private capability is becoming public power. Here’s where the signal keeps moving.
KMOB1003 Culture Docent
WARM Global Dance Radio Chart Top 20 — En Español
Global dance radio presented in Spanish. Saturdays at 3 PM Eastern on KMOB1003.
Ask the Docent →
KMOB1003 Artist Services
The deal no longer guarantees the push.
Artists can no longer assume a record company will build the full marketing machinery around the work. Build the media positioning, audience strategy and campaign infrastructure around the music.
Explore Artist Services →
KMOB1003 Spoken Word
The Voice Gallery
Voices that do not wait for permission.
Enter the Voice Gallery →
The Global Collection
Tools. Services. Access. Infrastructure.
Explore the KMOB1003 network of creator tools, publishing, privacy, travel, live culture, style and services built around how people create, move and grow.
Explore the Collection →
Global Reach. Powerful Stories. Lasting Impact.


