A White House memorandum signed in August 2026 directs the National Coordination Center to stand up a programme within 60 days allowing "vetted United States companies" to conduct offensive cyber operations against foreign Transnational Criminal Organizations.
Two categories are named:
Cyber surveillance operations — accessing sensitive data without owner authorisation.
Cyber effects operations — disruption, denial, degradation, or destruction of information systems.
Hack-back has been debated in Washington for fifteen years and has never survived contact with the law. This is the furthest an administration has gone toward authorising it.
Who can be targeted
Foreign groups conducting cyber-enabled crime against the US government, US persons, or US interests.
Excluded: groups that are "an institutional part of a foreign government or wholly operated under a foreign government's direction" — unless evidence establishes such a connection.
That carve-out is doing a great deal of work, and it is the hardest thing in the memo to operationalise. The distinction between a criminal group and a state-directed one is exactly what national intelligence agencies spend years and classified collection failing to settle. Ransomware crews sit on that line by design.
A company would be making that call from commercial telemetry, before acting, with liability attaching to getting it wrong.
The stated limits
Companies must stop operations that exceed approved parameters, including any targeting of:
- US persons
- US-located systems
- Systems under US control
They must apply minimisation procedures and immediately alert the NCC, which notifies the Department of Justice.
The mechanism here is self-assessment and self-reporting. The operator decides it has exceeded scope, and then tells the government. There is no prior judicial authorisation in what has been reported.
The legal problem is not subtle
Per Cybersecurity Dive, existing US laws prohibit private companies from conducting cyber attacks or disruption operations without court authorisation.
A presidential memorandum does not repeal the Computer Fraud and Abuse Act. It can shape enforcement priorities — the executive branch decides whom to prosecute — but it cannot make the underlying conduct lawful, and it does not bind:
- Foreign law. The target's systems sit somewhere. That jurisdiction's computer-crime statutes apply, and the operator's employees may travel.
- Civil liability. Criminal infrastructure runs on shared hosting. Destroying it damages third parties who have their own claims.
- A future administration. Enforcement discretion lasts as long as the discretion does. Companies would be relying on a policy that a successor can withdraw, with a five-year federal statute of limitations still running.
"Vetted" is the word carrying the risk. Vetting is not immunity.
The number in the fact sheet
An accompanying fact sheet cites $20.8 billion in losses reported by American consumers to cyber-enabled crime. The memo follows a March 2026 White House cybercrime initiative.
The figure is real and the frustration behind it is legitimate. Law enforcement takedowns are slow, extradition rarely works, and infrastructure reconstitutes within days. We have written repeatedly about groups engineering around takedowns — DeadLock putting its leak site on a blockchain, Kimwolf resolving command-and-control through ENS.
If seizure no longer works, the argument for letting the private sector act directly gets easier to make. That is the honest case for this memo.
The case against, stated as plainly
Attribution errors become acts of destruction. A takedown that hits the wrong host is an incident report. A destructive operation that hits the wrong host is a company destroying an innocent party's systems.
Criminal infrastructure is other people's infrastructure. It runs on compromised WordPress sites, hijacked cloud accounts and expired domains bought at auction. Degrading it means degrading assets belonging to victims.
It invites reciprocity. Once the US authorises private offensive operations, the argument that other states should not is materially weaker.
Nobody has said who pays for mistakes. The memo, as reported, describes reporting obligations. It does not describe indemnity.
What is not established
- We have not read the memo. Everything above comes from reporting on it and an accompanying fact sheet.
- No company has been named, and no vetting criteria are public.
- The NCC's programme does not exist yet. Sixty days from signature.
- Whether any statutory change is contemplated. Without one, the CFAA problem stands.
- Whether "destruction" means what it appears to mean. That is the most consequential word in the memo and it is not defined in what has been reported.
What to watch
- The 60-day mark, and whether the programme's rules are published or classified.
- Whether the vetted list is public. A secret list of companies authorised to break into systems is a different governance question from a published one.
- Whether DOJ issues declination guidance. That is the only thing that would give a participating company real comfort, and it would be the clearest signal the administration means it.
- Whether any incident response firm publicly declines to participate. The first refusal will be informative.