Security Neutral 7

Trump memo opens private hackback: 2 GOP bills echo 16th-century privateers

The Trump administration's Aug. 12 memorandum would authorize U.S. federal contractors to perform offensive cyber operations against government-selected foreign cybercriminals, a shift from government-only operations. Security leaders need to understand operational, legal, and threat-intel implications for the private sector.

· 4 min read · Verified by 2 sources ·

Beat this week

Last 7 days · Security

13 stories
5.4 avg impact
8% positive
8% negative
vs prior 7 days +2 +2 stories vs prior 7 days

Impact 5.4/10, unchanged. Counts are stories in our record, not a market forecast.

Open the change report

Coverage balance Balanced directional read. Positive and negative coverage are within 0 percentage points.

  • 8% positive
  • 85% neutral
  • 8% negative

This story sits in Security — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.

Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.

Cybersecurity briefing

Key takeaways

7 impact
Neutralsentiment
2sources
4min read
  1. The Trump administration's Aug.
  2. 12 memorandum would authorize U.S.
  3. federal contractors to perform offensive cyber operations against government-selected foreign cybercriminals, a shift from government-only operations.
  4. Security leaders need to understand operational, legal, and threat-intel implications for the private sector.
Drawn from
  • news.wjct.org
  • kuaf.com

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1The presidential memorandum was issued late Wednesday, August 12, 2026, according to WJCT and KUAF reporting.
  2. 2The memo could authorize private U.S. businesses to disrupt foreign organizations the government labels as cybercriminals or gather intelligence on those groups.
  3. 3It does not amend existing U.S. anti-hacking laws, including the CFAA, but mandates participating companies be contracted with the federal government.
  4. 4Two Republican congressmen introduced cyber "privateer" legislation after the Trump administration took office in 2025.
  5. 5Former NSC cyber policy official Joshua Steinman said potential targets include organized crime and money laundering operations.
  6. 6The memo does not grant full privateer authority and does not explain how private companies would legally lead government work.

Who's Affected

U.S. private sector firms
companyPositive
Foreign cybercriminal organizations
organizationNegative
U.S. government agencies
governmentNeutral
International allies
governmentNegative

Analysis

Offensive Private Sector Case
  • Fills government resource gaps against cybercrime
  • Companies can use insider knowledge of threat actors
  • Federal contracts could provide legal cover
Hackback Risks
  • CFAA still bars unauthorized hacking outside contract
  • Attribution errors could target innocent systems
  • International blowback and retaliation risks

Analysis

For security teams, the Aug. 12 memo marks the first serious federal program to put offensive hackback capabilities in corporate hands — without changing the anti-hacking laws that still make such actions a felony outside a federal contract. CISOs and threat-intel leads must track how this affects vendor risk, attribution confidence, and the legal line between defense and offense.

On August 12, 2026, the Trump administration issued a presidential memorandum that could authorize some U.S. businesses to hack, disrupt, or gather intelligence on foreign cybercriminals selected by the U.S. government. The memo, reported on August 15 by NPR member stations WJCT and KUAF, represents a dramatic departure from the traditional division of labor in which only government agencies conduct offensive cyber operations. It does not change existing anti-hacking laws, but it does mandate that any participating company be contracted with the federal government, creating a narrow contractual pathway for private-sector offensive action.

On August 12, 2026, the Trump administration issued a presidential memorandum that could authorize some U.S.

The legal foundation is deliberately thin. The Computer Fraud and Abuse Act broadly bars unauthorized access to protected computers, with exceptions primarily for law enforcement and authorized government activity. The memorandum does not amend the CFAA or the Electronic Communications Privacy Act, and it does not fully explain how a private business would take the lead on work traditionally performed by the U.S. government, such as espionage or disruptive cyber operations. Instead, it appears to rely on federal contracting status as a form of authorization, a position that would likely invite immediate legal challenges from civil liberties organizations, foreign governments, and possibly technology companies whose infrastructure could be affected.

Joshua Steinman, who served as senior director for cyber policy on the National Security Council during President Trump's first term, said the range of potential targets includes organized crime groups and people engaged in money laundering or other criminal activity. That framing suggests the program is not limited to state-sponsored advanced persistent threats but could encompass a broad set of financially motivated criminal actors. The memo does not give private businesses the full authority sought by "cyber privateer" legislation, a term drawn from 16th-century naval warfare, but it elicited online praise from proponents of that idea.

Since the Trump administration took office in January 2025, two Republican congressmen have introduced legislation calling for cyber privateers to take the fight to foreign hackers. The new memorandum does not enact those bills into law, but it moves in the same direction. Private corporations have long worked with the federal government to disrupt cybercriminals, but largely as contractors fulfilling a support role rather than as lead actors in offensive operations. By contrast, this program would allow private businesses to conduct disruption or intelligence gathering directly against government-selected targets abroad.

For the cybersecurity and government contracting industries, the memorandum raises immediate commercial questions. Companies with offensive cyber capabilities — including incident response firms, threat intelligence vendors, and specialized government contractors — would need to assess whether participation is commercially viable given legal uncertainty, reputational risk, and the possibility of retaliatory attacks. The requirement to be a federal contractor may favor established defense and intelligence contractors with existing clearance infrastructure, but it could also open a new market for smaller firms that develop exploit tools or disrupt botnets. Yet no company has publicly stated an intent to participate, and the administration has not identified which agencies would oversee the program or how targets would be chosen.

What to Watch

Operating private offensive hacks against foreign perpetrators raises significant international and diplomatic risks. Foreign governments may view a U.S. company's intrusion into computers on their soil as a violation of sovereignty, even if the target is a criminal group. Attribution errors could result in damage to legitimate systems or provoke confidential retaliation against U.S. businesses and critical infrastructure. The memo provides no public mechanism for independent oversight, no standards for evidence before a target is selected, and no explanation of what happens if a private contractor exceeds the scope of its government contract. These gaps are likely to become the focus of congressional hearings and potentially litigation.

Looking ahead, the program's viability will depend on regulatory guidance, contracting rules, and the administration's willingness to defend the legal theory that federal contracting can authorize private hacking. If operationalized, it would alter the public-private boundary in cyberspace and may encourage other countries to adopt similar programs, eroding the norm that offensive cyber operations are a state function. Legal challenges could come quickly, and the outcome would shape not only this program but the future of the CFAA and private-sector hackback. For now, the memorandum is best understood as a policy signal rather than a fully formed operational framework.

Source cluster

Primary reporting

2articles

Cite This Page

"Trump memo opens private hackback: 2 GOP bills echo 16th-century privateers." Cyber Intelligence Brief, August 15, 2026. https://getcyberbrief.com/story/trump-memo-private-hackback-cyber

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.