If cybersecurity professionals have been dreaming of “hacking back” and going after the cybercriminals, a new program may appear to offer the solution. It might even feel like a throwback to old western movies where the sheriff slaps a badge on members of the general public and deputizes them. But the devil is in the details, and those details may not quite have changed the playing field all that much.
On August 12, 2026, President Trump issued a National Security Presidential Memorandum (the “Memorandum”) establishing a new federal program that will allow vetted U.S. companies to participate in government-directed cyber operations against certain foreign transnational criminal organizations. Building upon the Administration’s broader efforts to address foreign cyber threats and cyber-enabled fraud, which we have discussed here and here, the Memorandum proposes a significant shift in public-private cybersecurity cooperation. Rather than limiting private sector involvement to threat sharing and defensive measures, it contemplates private companies taking government-authorized offensive measures against foreign criminal infrastructure. Despite this interesting approach, the Memorandum does not purport to create exceptions to liability under the Computer Fraud and Abuse Act (“CFAA”), meaning companies should proceed with extreme care.
Below, we provide an overview of the Memorandum’s key provisions and practical guidance for companies to consider as the program is developed.
Overview of the Memorandum
- Outlines a new public-private cyber operations program against foreign groups. The Memorandum directs the National Coordination Center (“NCC”) to establish a program under which approved “Participating Companies,” defined as private U.S. companies accepted into the program, may conduct two types of operations: “Cyber Surveillance Operations,” involving covert unauthorized access to systems to collect information or intelligence, and “Cyber Effects Operations,” which may manipulate, disrupt, deny, degrade or destroy information systems, networks, infrastructure or data. Operations can only be directed against foreign cyber-enabled transnational criminal organizations (“CE-TCOs”), which broadly include “any foreign group that conducts cyber-enabled crime” against the U.S. government, a U.S. person, or U.S. interests, while excluding nation-state threat actor groups operating as “an institutional part of a foreign government or wholly operated under a foreign government’s direction.” By October 12, 2026, DOJ and DHS, in coordination with the Homeland Security Council, must establish operating procedures for the program with eligibility criteria addressing technical proficiency, experience conducting cyber operations, facility security, personnel vetting, competence, and reliability. The criteria must permit participation by both large companies and smaller companies that may be suited to specialized operations.
- Participation will be limited and closely controlled. This program will not be a general authorization for companies to conduct offensive cyber actions. Participating Companies must act on behalf of, and under the supervision, operational control, and legal authority of, the federal government. The program will be jointly overseen by executive directors from the Department of Justice (“DOJ”) and Department of Homeland Security (“DHS”), and each proposed operation must receive written government approval before it proceeds. The Memorandum expressly requires program activities to be in accordance with the Constitution and comply with applicable U.S. law, including international obligations and the Computer Fraud and Abuse Act (“CFAA”). The Memorandum’s language closely tracks the CFAA’s exemption for “lawfully authorized investigative, protective, or intelligence activity” under 18 U.S.C. § 1030(f), which may be the intended basis for Participating Companies’ compliance with the CFAA. The Memorandum also establishes safeguards intended to limit unintended consequences. Among other things, a Participating Company that discovers that an operation has exceeded its approved scope—including through unintended targeting of a U.S. person or U.S.-based information system—must cease the operation, undertake required minimization measures and immediately notify the NCC. Operations that could result in death or serious injury, or could rise to the level of a use of force or armed attack under international law receive additional restrictions. DOJ or DHS will reevaluate Participating Companies at least annually and may also require Participating Companies to maintain a bond or escrow of at least $1 million that may be forfeited for contractual noncompliance.
- Provides a role for companies outside the program. Importantly, the Memorandum also contemplates participation by companies that are not themselves conducting cyber operations. Participating Companies may enter into commercial agreements with other private sector entities (not expressly U.S. companies, though further guidance could narrow this) to receive threat information collected through those entities’ ordinary business activities and use that information to propose responsive operations to the NCC.
Key Takeaways
- Do not treat the Memorandum as permission to “hack back.” The Memorandum does not provide companies with a general right to pursue attackers directly. Its framework applies to vetted companies acting under federal contract, direction, control, and authority and pursuant to approved operations. Companies should therefore continue to treat independent access to or disruption of an attacker’s infrastructure as presenting substantial legal risk, including criminal liability.
- Weigh the pros and cons of participation. Participating in this program is undoubtedly a dream come true for many cyber professionals. It could invigorate their work and provide valuable threat intelligence that helps their companies. For many cyber and tech companies, participating could present a real advantage. And disrupting criminal enterprise could also help reduce the rate of cybercrime. But the criminal enterprises could also direct their sights directly at Participating Companies, having significant adverse consequences. Additionally, as the program contemplates, operational disruption could inadvertently affect innocent third parties, which could lead to liability.
- Review existing cyber information-sharing channels. The Memorandum expressly contemplates Participating Companies obtaining information from other private entities to support proposed cyber operations. As such, private entities could find themselves supporting program activities without necessarily intending to do so, or may want to provide support but lack clarity about the appropriate process. As further information becomes available, such as whether Participating Companies can even disclose their participation, companies should consider whether their threat intelligence-sharing agreements, ISAC memberships, and other proactive information-sharing mechanisms address use by a Participating Company or the government for program activities, and what internal approvals and restrictions are appropriate.
- Discuss the new program with your incident response and cybersecurity vendors. Companies may want to ask key providers whether they expect to participate in the new program, whether client threat intelligence could be shared with the government or Participating Companies, and what contractual or confidentiality protections would apply. Addressing these topics in advance and ensuring alignment may help avoid difficult decisions during a fast-moving cyber incident.
- Update incident response playbooks. Companies responding to ransomware, fraud, data theft, or other cyber incidents typically focus on containment, remediation, law-enforcement engagement, and recovery. Companies may now want to consider whether threat intelligence developed during an incident could support a government-directed operation, including under what circumstances the company may engage law enforcement or a Participating Company, how to engage, and who can make that decision.
- Keep expectations realistic. The new framework may eventually provide an additional tool for disrupting foreign cybercriminal organizations, but operations will remain subject to federal approval, legal review, and other controls. Companies should view it as a possible complement to—not a substitute for—preventive controls, resilience, and traditional law-enforcement engagement.
* * *
To subscribe to the Data Blog, please click here.
The Debevoise STAAR (Suite of Tools for Assessing AI Risk) is a monthly subscription service that provides Debevoise clients with an online suite of tools to help them fast-track their AI adoption. Please contact us at STAARinfo@debevoise.com for more information.
The cover art for this blog post was generated by ChatGPT 5.6.