Protect.Computer
NEWS

White House Authorizes Private Firms to Hack Cybercriminals

· 1 min read · Network safety
White House Authorizes Private Firms to Hack Cybercriminals

President Trump signed a national security presidential memorandum (NSPM) on Wednesday that authorizes private cybersecurity companies to conduct offensive hack-back operations against foreign criminal organizations — a significant shift in how the United States approaches transnational cybercrime. Under the new framework, vetted security firms can apply to join a program overseen by the National Coordination Center (NCC), a body within the Homeland Security Task Force, and enter into contracts with either the Justice Department or the Department of Homeland Security. Once approved, participating firms may propose and carry out cyber operations targeting ransomware gangs, phishing operations, financial fraud networks, sextortion schemes, and impersonation scam campaigns.

The memorandum includes guardrails: participating companies must post a bond or escrow of at least $1 million that is forfeited if they violate their contractual agreements, must immediately halt operations if they discover they have exceeded approved limits — including any unintended targeting of U.S. citizens or U.S.-based infrastructure — and must notify the NCC immediately if that happens. All operations must also comply with the U.S. Constitution, federal law, and applicable international agreements. The White House cited 2025 figures showing that U.S. consumers lost more than $20.8 billion to cyber-enabled crime, framing the program as a tool to disrupt the criminal infrastructure enabling those losses. Security researchers have offered mixed reactions: Veracode co-founder Chris Wysopal called it “a major expansion of the private sector’s role in offensive cyber operations,” while former Cyber National Mission Force leader Jason Kikta described it more skeptically as “a perpetual motion machine for billable threats.”

Sources

Related reading