VMTech
Discuss a project

White House permits vetted firms to support offensive cyber operations

White House permits vetted firms to support offensive cyber operations

The White House has issued a presidential memorandum that, for the first time, will allow vetted private companies to conduct offensive cyber operations against international criminal gangs and hackers under federal supervision. The programme is intended to address threats to Americans and businesses, including ransomware, financial scams and sextortion.

Participating companies may conduct surveillance to collect intelligence, including through spyware, and may carry out disruptive actions aimed at criminals’ data or systems. Each participant must deposit $1 million in escrow, which can be forfeited if the government determines that the company has failed to comply with operational rules.

A narrow exception to the established approach

US federal computer-hacking laws have broadly barred private companies from conducting cyberattacks or disruption operations without court-authorised approval. Across successive administrations, the government’s position has been that private organisations may defend themselves against incoming attacks but may not launch or operate attacks themselves.

The memorandum changes that position only within a government programme. It does not permit private companies to “hack back” against threats on their own initiative. Operations must be conducted exclusively under federal supervision and require approval from representatives of the Justice Department and the Department of Homeland Security.

The administration has also directed agencies to establish procedures designed to ensure that no operation targets Americans or systems based in the United States. Companies admitted to the programme must notify the government if they discover an imminent cyberattack against critical US infrastructure, such as power grids or water providers.

Rules, accountability and international exposure

The operating model is not yet complete. The government plans to issue participation guidance within two months, including requirements that can apply to companies of different sizes. The memorandum says smaller firms may be suitable for specialised operations, but the White House did not say whether any companies are already taking part.

The policy is likely to attract legal challenges and criticism over private-sector involvement in government hacking activity. Jake Williams, vice president of research and development at Hunter Strategy, said Americans involved in such operations could be portrayed as non-uniformed combatants while travelling abroad, even where allegations of participation are untrue.

The decision arrives amid reported intrusions affecting local US water providers and wider concern about cyberattacks on businesses and critical infrastructure. It also follows heightened scrutiny of AI-related cyber capabilities, including the policy debate around US restrictions on Anthropic models and its implications for US software and AI providers.

What organisations should take from the change

For most businesses, the memorandum does not alter the prohibition on independently attacking an adversary. Security leaders should continue to focus on lawful defensive monitoring, resilient incident response and prompt escalation of credible threats. Companies that might seek a role in the programme will need to evaluate the forthcoming eligibility rules, compliance burden, escrow requirement, staff safety and cross-border legal exposure before committing resources.

#cybersecurity#offensivecyber#riskmanagement#criticalinfrastructure
Open analytics
On the site 0 views
min read 4 13.08.2026
Instagram

White House permits vetted firms to support offensive cyber operations

Open the post on Instagram ↗