The US government now wants private hackers on its payroll

The US government just quietly authorized private companies to hack foreign criminal networks on its behalf. And the rules for how that actually works? Not yet written.

As reported by Engadget, President Trump signed a national security presidential memorandum that allows private firms to carry out offensive cyberattacks against “transnational criminal organizations” on the federal government’s behalf. The stated targets include ransomware gangs, sextortion operators, financial fraudsters, and phishing networks. The administration says this taps the “capability and innovation of the private sector.” Whether that framing holds up to scrutiny is another matter.

To understand why this is a big deal, you need to know what the Computer Fraud and Abuse Act actually does. The CFAA is the primary federal law that makes hacking illegal in the United States. It applies to individuals and companies equally. Back in 2022, the Department of Justice said it wouldn’t go after good-faith security researchers, but this new memorandum goes far further. It gives the DOJ broad discretion to decline prosecution for offensive cyber operations conducted by vetted private actors. That’s a significant legal shift, and it didn’t require a vote in Congress.

The practical details are almost entirely absent right now. The memorandum hands the Homeland Security Task Force 60 days to figure out how companies will be screened and how attacks will actually be conducted. Participating firms must post a $1 million bond, which gets forfeited if they break from the government’s direction. So there’s a financial leash. But a leash isn’t a rulebook.

Here’s where it gets genuinely complicated for anyone who cares about digital rights. The memorandum offers protection from prosecution inside the United States. It says nothing about what happens when a private contractor hacks a server in, say, Russia or China, and that country decides to file charges of its own. The US has charged foreign state-backed hackers before. There’s no reason to assume adversaries won’t return the favor, targeting the individual employees of these private firms.

The timing matters too. The memorandum came after a wave of cyberattacks on water facilities in Minnesota and Michigan, attacks now linked to Iran. So there’s a real threat being responded to. But the response creates a new category of quasi-government hacker, operating with federal blessing but without a clear legal framework, accountability structure, or international legal protection. That combination should concern anyone who thinks about how power over digital infrastructure gets distributed and who actually controls it.

Private companies doing government offensive cyber work is not a small step. It’s a structural change to who gets to attack whom online, and on whose authority.