The White House Just Authorized Private Firms to Hack Back at Ransomware Gangs
Cybersecurity

The White House Just Authorized Private Firms to Hack Back at Ransomware Gangs

A new presidential memorandum lets vetted security companies run offensive cyber operations against foreign cybercrime groups, backed by a required one million dollar bond and oversight from Justice and Homeland Security.

PublishedAugust 14, 2026
Read time5 min read
Share

A New License for Private Cyber Offense

The White House signed a national security presidential memorandum this week directing the National Coordination Center to stand up a formal program allowing private security companies to conduct approved offensive cyber operations against foreign cybercrime organizations. The move marks a significant departure from decades of policy that kept offensive hacking authority almost entirely inside government agencies, opening a regulated but real path for contractors to act against ransomware crews, phishing operators, and fraud networks operating from outside U.S. jurisdiction.

Under the program, companies seeking to participate must first go through a vetting and security clearance process before they can contract with the government to run operations. That requirement puts this squarely in different territory than the loosely defined hack-back proposals that have circulated in Washington for years without gaining traction, since it creates a formal licensing structure rather than simply removing legal liability for retaliatory hacking by any company that wants to try it.

The Financial Guardrails

Every participating firm must post a minimum one million dollar bond or escrow that is forfeitable if the company violates the terms of its authorization. That bond functions as a direct financial stake in compliance, giving companies a concrete reason to stay within the boundaries the government sets rather than treating approval as a blank check for aggressive action once a contract is signed. The bond requirement also functions as a filter on who can realistically participate, since it favors established firms with the balance sheet to absorb a forfeiture over smaller shops that might otherwise be tempted to operate more loosely once licensed.

Operations must also comply with the U.S. Constitution, federal law, and applicable international agreements, and companies are required to immediately cease operations if they exceed their approved limits or if an operation risks touching U.S. citizens or U.S. systems. That last condition addresses one of the oldest objections to private hack-back activity: the risk that retaliatory operations misidentify infrastructure and strike systems that have nothing to do with the original attack, including domestic ones.

Oversight Sits With Justice and Homeland Security

Executive directors from the Department of Justice and the Department of Homeland Security will oversee the program, giving both law enforcement and homeland security equities a seat at the table for approving and monitoring operations. That dual oversight structure suggests the administration wants operations treated as much like law enforcement actions as like military or intelligence activity, a distinction that matters for how evidence gathered during these operations might later be used in prosecutions.

The program is explicitly scoped to foreign criminal organizations rather than nation-state actors, and it names ransomware, phishing, financial fraud, sextortion, and impersonation scams as its target categories. That framing keeps the program in the crime-fighting lane rather than opening it up as a tool against state-sponsored espionage groups, at least as currently described, though the boundary between criminal ransomware affiliates and state-tolerated or state-directed groups has blurred considerably in recent years.

Why the Administration Is Moving Now

The memorandum cites more than twenty billion dollars in reported consumer losses to cyber-enabled crime in 2025 as part of its justification, a figure that reflects years of frustration inside government at how little deterrent effect prosecutions and sanctions have had on ransomware and fraud operators who mostly sit beyond the reach of U.S. law enforcement. Years of takedown operations against specific ransomware infrastructure have shown groups can rebuild and rebrand within months, which has pushed policymakers toward more sustained and aggressive countermeasures.

Private companies already sell offensive-adjacent services, including active defense, threat actor infrastructure disruption, and intelligence gathering that sits close to the line of what this program formally authorizes. Licensing that activity rather than leaving it in a legal gray area gives the government visibility into what firms are actually doing and a mechanism to shut down operations that go wrong, rather than discovering after the fact that a contractor took action the government never approved.

A Divided Industry Reaction

Reaction from security industry leaders split along familiar lines. Veracode co-founder Chris Wysopal called it a major expansion of the private sector's role in offensive cyber operations, framing it as a meaningful shift in how the government uses private capability against threats it has struggled to reach through traditional law enforcement channels. That view treats the program as a pragmatic response to a threat landscape that has outpaced government capacity to respond directly.

Automox CTO Jason Kikta offered a sharper warning, describing the risk of the program becoming a perpetual motion machine for billable threats. His concern points to a structural problem with paying private companies to fight an adversary: firms whose revenue depends on the threat continuing have a weaker incentive to actually eliminate it than a government agency does, and building a durable contracting relationship around offensive operations could create exactly that dynamic over time.

What This Means for Enterprise Security Leaders

For CISOs and general counsel, the program raises a practical question well before any operation happens: what obligations does an enterprise have if a licensed firm's counter-operation touches infrastructure connected to your environment, even indirectly. The requirement that operations stop immediately if they risk hitting U.S. systems offers some protection, but enterprises whose networks have been used unknowingly as relay points by ransomware infrastructure could find themselves adjacent to activity they never asked for and have no visibility into.

The more immediate effect will likely be on how enterprises think about reporting incidents to federal authorities. A credible offensive response option gives law enforcement a stronger reason to want early notification of ransomware and fraud incidents, since faster reporting means a better chance any licensed counter-operation can act while attacker infrastructure is still live. Enterprises that have been slow to report incidents for fear of scrutiny now have a new reason to reconsider that calculus.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#white-house#hack-back#offensive-cyber-operations#nspm#department-of-justice#department-of-homeland-security#cybercrime-policy#public-private-partnership