Politics

White House authorises private firms to launch offensive cyber attacks against criminal gangs

A presidential memorandum released on 13 August 2026 permits vetted cybersecurity companies to conduct offensive operations – including surveillance and disruptive attacks – against international criminal organisations, subject to escrow deposits and inter‑agency sign‑offs.

Secure server rack in a federal data center designated for authorized offensive cyber operations

On 13 August 2026 the White House issued a presidential memorandum that, for the first time, permits vetted private cybersecurity firms to conduct offensive cyber operations against international criminal gangs and hackers. The announcement, reported by TechCrunch, marks a clear departure from the longstanding U.S. policy that barred private‑sector offensive hacking without a court order.

From defensive to offensive: the policy shift

The memorandum is introduced as a presidential directive published by the White House. It explicitly authorises participating companies to employ both surveillance tools – such as spyware – and disruptive techniques designed to destroy a criminal’s data or cripple their systems. The policy therefore expands the federal government’s cyber‑defence toolkit beyond traditional defensive measures.

Previously, U.S. law required private actors to obtain a court order before launching any offensive cyber activity. The new memorandum removes that hurdle, but replaces it with a set of procedural safeguards intended to keep operations accountable.

Operational safeguards: escrow and inter‑agency sign‑offs

According to the TechCrunch report, any firm that wishes to take part must deposit an escrow of 1 million USD per engagement. The escrow is forfeitable if the company fails to comply with the memorandum’s conditions. The requirement is meant to provide a financial deterrent against misuse and to ensure that firms have a stake in adhering to the rules.

In addition to the escrow, every offensive operation must receive sign‑offs from both the Department of Justice (DOJ) and the Department of Homeland Security (DHS). The dual‑agency approval process is designed to provide legal and national‑security oversight, although the memorandum does not specify the exact timeline for those approvals.

Implementation timeline and next steps

The memorandum was announced on 13 August 2026, and the packet notes that detailed guidance on program implementation is expected within two months of the announcement. That guidance is likely to spell out the application process for firms, the criteria used by DOJ and DHS to evaluate proposed operations, and reporting requirements for completed engagements.

Because the memorandum is a presidential directive rather than legislation, it can be altered or rescinded by a future administration. For now, the immediate effect is that private firms can begin preparing proposals that meet the escrow and sign‑off criteria.

Implications for the private cybersecurity sector

The policy opens a new market for firms that specialise in offensive cyber capabilities. Companies that have previously offered penetration‑testing or red‑team services may now be able to bid for government‑backed operations against criminal networks. The escrow requirement, however, could be a barrier for smaller players, as a $1 million USD deposit per engagement represents a significant capital outlay.

Industry analysts note that the shift could accelerate the development of offensive tools in the private sector, potentially leading to faster disruption of ransomware gangs, sextortion rings, and AI‑driven attack groups that have proliferated in recent years. At the same time, critics warn that delegating offensive authority to private actors raises questions about accountability, attribution, and the risk of collateral damage to innocent systems.

Legal and policy concerns

While the memorandum provides a procedural framework, it does not address several thorny issues. First, the definition of “vetted” private firms is left to the forthcoming guidance, leaving open how stringent the vetting process will be. Second, the memorandum does not specify what happens if an operation inadvertently harms non‑targeted infrastructure – a scenario that could raise liability questions for both the firm and the government.

Furthermore, the requirement for DOJ and DHS sign‑offs introduces inter‑agency coordination challenges. Past experience with cyber‑operations has shown that differing agency priorities can delay or complicate action. The memorandum’s lack of detail on the approval timeline means that the speed of response – a critical factor when confronting fast‑moving ransomware attacks – remains uncertain.

International ramifications

Allowing private firms to conduct offensive cyber actions against transnational criminal groups could have diplomatic repercussions. Although the memorandum targets criminal gangs rather than nation‑states, the tools used – especially disruptive attacks that destroy data – could be perceived as crossing a red line by foreign governments if they affect entities with ties to state actors.

To date, the White House has not indicated whether the memorandum will be coordinated with allied intelligence services. The absence of such coordination could complicate joint operations against criminal networks that operate across borders.

What remains unknown

  • The exact list of firms that will be approved under the new regime.
  • The detailed criteria that DOJ and DHS will use to evaluate each proposed operation.
  • The reporting and oversight mechanisms that will track the outcomes of offensive engagements.
  • Whether Congress will seek to codify or constrain the memorandum through legislation.

These gaps underscore the need for further clarification from the White House and the relevant agencies before the policy can be fully assessed.

Looking ahead

In the short term, the memorandum is likely to generate a wave of applications from private cybersecurity firms eager to enter the offensive arena. The escrow requirement will filter out firms that lack sufficient capital, potentially concentrating activity among larger, well‑funded players.

Long‑term, the policy could reshape the U.S. approach to cyber‑crime, moving from a purely defensive posture to a more proactive, disruption‑focused strategy. Whether that shift yields measurable reductions in ransomware payments, sextortion incidents, or AI‑driven attacks will depend on how quickly the guidance is issued, how rigorously the sign‑off process is applied, and how effectively the government can monitor and evaluate the outcomes of private‑sector operations.

For now, the memorandum stands as a historic pivot in American cyber policy – one that invites both optimism about new tools to combat criminal cyber actors and caution about the responsibilities that come with delegating offensive power to the private sector.