The U.S. government will for the first time allow vetted private companies to launch offensive cyber operations against international criminal gangs and hackers, the White House said on Wednesday.
In a newly published presidential memorandum, the Trump administration said the move will allow the federal government to use “innovative capabilities of the private sector” to combat cybercrime and threats targeting Americans, such as ransomware attacks, financial scams, and sextortion.
The memorandum allows private companies participating in the government’s program to conduct surveillance, like using spyware to collect intelligence, as well as make disruptive attacks aimed at the destruction of criminals’ data or systems.
The policy change marks a seismic shift in the U.S. government’s long-standing position under U.S. federal computer hacking laws, which broadly prohibit private companies from conducting cyberattacks or disruption operations without a court-authorized approval.
Private companies are regulated under the same computer hacking laws as anyone else in the United States, which prohibit people or companies from carrying out cyberattacks. The U.S. government’s position to date, through multiple administrations, has been that the private sector can defend against incoming cyberattacks, but not launch or operate them.
While the presidential memorandum establishes the new policy, it’s still in its early days and the government has not yet fully established how the program will operate. The new policy is likely to face legal challenges and opposition by critics, who have for years argued that private companies should not get involved with government hacking operations.
The government will issue guidance in the next two months outlining the requirements participating companies will have to meet before being allowed into the program. This guidance would consider companies of all sizes, including smaller private companies, which might be better suited for specialized operations, the memorandum reads.
Participating companies must deposit $1 million in escrow, which will be forfeited if the government finds out a company isn’t complying with its rules on how to conduct these operations. The memorandum directs the federal government to create procedures preventing any operation from targeting Americans or U.S.-based systems.
Any operation will require sign-offs from representatives from the Justice Department and Homeland Security before it can be approved. Operations are to be conducted exclusively under the supervision of the federal government.
The policy also requires any participating company to notify the government if it discovers an imminent cyberattack against critical U.S. infrastructure, such as power grids or water providers.
The White House did not immediately respond to TechCrunch’s questions about whether any private companies are already participating in the program.
The memorandum stops short of allowing companies to “hack back” any cyber threats. Critics have argued that private industry getting involved with government operations may spark diplomatic and international ramifications, such as if a foreign government complains that they were attacked by a U.S. company.
The policy, according to one cybersecurity veteran, could put Americans who work for private cybersecurity companies at risk of being indicted or taken into custody by a foreign government, much like how U.S. prosecutors have charged Chinese, Iranian, and Russian government hackers with cybercrimes targeting the United States.
“Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas,” said Jake Williams, an industry veteran who serves as vice president of research and development at cybersecurity company Hunter Strategy.
“The allegations that an American participated in these ops need not be true,” Williams told TechCrunch, noting that the administration’s policy alone creates cover for a foreign government to make such accusations.
Describing the policy as “half-baked,” Williams said that while the classified addendum likely answers some questions about how specific targets of U.S. offensive cyberattacks are chosen, he was not convinced the program would not be abused.
The Trump administration did not give a reason for the decision, only saying that the government is contending with a “growing threat” against Americans and businesses. The United States has been facing a number of international cyber threats amid widespread cuts and layoffs to federal cybersecurity staff since the start of the second Trump administration in January 2025.
Several U.S. states are currently reporting cyberattacks on their water infrastructure, which U.S. intelligence officials have reportedly privately attributed to Iranian government-backed hackers. Officials in over a dozen states, including Michigan, Minnesota and Georgia, have reported intrusions into local water providers, but no water safety alerts have had to be issued.
The intelligence community’s assessment of these threats comes after months of protracted war between the U.S. and Israel, and Iran. Following the start of the U.S.-led war in February, which resulted in the death of Iran’s supreme leader, the Iranian military has fired back with missiles targeting Western-owned data centers, as well as cyberattacks that are actively disrupting U.S. businesses and critical infrastructure.
The Trump administration’s cyber memorandum comes as the U.S. and other governments grapple with a spate of autonomous AI-driven cyberattacks targeting companies and organizations around the world. Anthropic, OpenAI, Meta and the U.K.’s AI Safety Institute have all reported that frontier AI models they were testing had broken their technical containments to carry out cyberattacks.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Source: https://techcrunch.com/2026/08/13/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks/