Trump Memo Authorizes Private Firms to 'Hack Back' Against Foreign Cyber Threats

3 min readSources: Volokh Conspiracy

On August 12, 2026, President Trump authorized vetted U.S. firms to conduct offensive cyber operations against foreign hackers.

Why it matters: This policy shifts legal boundaries, challenging the Computer Fraud and Abuse Act's restrictions on unauthorized access and increasing compliance risks for cybersecurity and legal teams.

  • Signed August 12, 2026, authorizes offensive cyber operations by vetted U.S. companies.
  • Companies must escrow $1 million and secure DOJ and Homeland Security clearance per operation.
  • Operations include Cyber Surveillance (intelligence gathering) and Cyber Effects (disruptive actions).
  • A National Coordination Center will oversee operations; implementation rules due within 60 days.

On August 12, 2026, President Donald Trump signed a presidential memorandum granting select U.S. private companies authority to conduct offensive cyber operations against foreign cybercriminal groups. The memorandum distinguishes between Cyber Surveillance Operations, aimed at gathering intelligence, and Cyber Effects Operations, which involve disrupting hostile systems to degrade their capabilities.

This marks a significant policy change, emphasizing proactive defense through authorized private-sector involvement. The memorandum aligns with the broader objectives of the Trump administration’s National Cyber Strategy, which advocates for a more offensive cybersecurity posture.

Participating firms must escrow $1 million as financial assurance and obtain prior written approval from both the Department of Justice (DOJ) and the Department of Homeland Security (DHS) for each operation. These actions will be supervised by a newly established National Coordination Center, with detailed operational guidelines expected within 60 days of the memorandum's release.

The directive prohibits offensive actions likely to cause loss of life or be classified as acts of war, reserving such decisions for higher classified processes.

The memorandum encourages enhanced cooperation between private companies and government agencies to improve cyber threat intelligence sharing. This initiative responds to recent cyberattacks attributed to Iranian-linked groups targeting U.S. infrastructure and is supported by a reported Congressionally authorized $1 billion budget for offensive cybersecurity measures.

However, this directive raises significant legal and compliance questions, specifically related to the Computer Fraud and Abuse Act (CFAA), which forbids unauthorized access to computer systems within U.S. jurisdiction. Traditionally, hacking—even for defensive purposes—posed legal risks under CFAA. This memorandum challenges traditional interpretations by explicitly allowing government-sanctioned private offensive cyber operations.

Legal experts warn about the complex international ramifications, noting individuals employing hacking abroad could be considered non-uniformed combatants, a term referring to individuals engaged in hostilities without formal military status. This status raises questions under international law and the laws of armed conflict.

Thomas Lind, Deputy Director at the Office of the National Cyber Director, clarified in a press briefing that "We are not endorsing vigilante cyber actions, but enabling carefully vetted responses within legal frameworks."

Compliance officers and legal counsel should monitor the forthcoming implementation guidelines closely, as they will detail vetting criteria, operational limits, and oversight structures necessary to manage the evolving legal landscape.

By the numbers:

  • $1 million — escrow amount required from each participating company.
  • 60 days — deadline for implementation guidelines after memorandum release.
  • $1 billion — Congressional budget allocated for offensive cybersecurity initiatives

Yes, but: While authorizing offensive cyber actions by private firms may enhance U.S. cyber defense, it risks escalating international cyber conflicts and complicates legal liability under existing statutes.

What's next: Implementation guidelines and oversight protocols are due within 60 days, which will clarify operational and compliance requirements for affected firms.