President Donald Trump signed a memorandum Tuesday authorizing vetted U.S. companies to conduct offensive cyber operations against foreign criminal networks, opening the door to private-sector "hack-back" activity that has long been prohibited under federal law.
What the Memo Authorizes
The directive permits pre-approved American firms to actively target overseas criminal infrastructure rather than merely defending their own systems. That marks a significant shift from the traditional posture, where offensive cyber actions have been reserved almost exclusively for government agencies and the military.
Under the framework, participating companies would be screened and cleared before taking part, aiming to keep such operations within a controlled set of trusted actors. The intent is to give the private sector new tools to disrupt ransomware gangs, fraud rings, and other malicious networks operating abroad.
Private firms can now go on the offensive against cybercriminals—but the legal exposure lands squarely on them.
The Legal Risk Falls on Firms
Despite the new authorization, companies that participate do so largely at their own legal peril. Existing statutes such as the Computer Fraud and Abuse Act have historically made unauthorized access to computer systems a crime, and the memorandum does not sweep away the tangle of liabilities that offensive operations can trigger.
That leaves participating firms to navigate uncertain terrain, where a poorly targeted or overly aggressive operation could expose them to lawsuits, regulatory scrutiny, or diplomatic fallout. Critics warn that "hack-back" campaigns can misfire, hitting innocent third parties whose systems were hijacked by attackers.
Key concerns raised by security experts include:
- The potential for collateral damage to bystander networks
- Difficulty attributing attacks accurately before striking back
- The risk of escalation with foreign governments or state-linked actors
For the cryptocurrency sector—frequently targeted by ransomware operators and cross-border fraud schemes—the policy could reshape how firms respond to threats, even as questions about accountability and oversight remain unresolved.
