Search results for

All search results
Best daily deals

Affiliate links on Android Authority may earn us a commission. Learn more.

The US government wants private companies to start hacking the hackers

The Trump administration is set to allow cybersecurity firms to fight fire with fire.
By

Aug 14, 2026 — 5:42 PM ET

The US government has a new approach to cybersecurity.
Ryan Haines / Android Authority
TL;DR
  • The US is creating a program that lets vetted private companies conduct offensive cyber operations against foreign criminal groups.
  • Operations will require federal approval and supervision, with participating firms potentially putting up at least $1 million in escrow.
  • The policy marks a major shift from the US stance that private companies can defend against hackers but not attack them.

If you thought cybersecurity companies were supposed to keep hackers out rather than go looking for a fight, the US government begs to differ. A new presidential memorandum will allow vetted American companies to conduct offensive cyber operations against foreign criminal groups, provided the government calls the shots.

As reported by TechCrunch, the Trump administration’s memorandum sets up a federal program under which private companies could conduct both surveillance and disruptive cyber operations against foreign cyber-enabled criminal organizations. The aim is to tackle threats such as ransomware, fraud, and other cybercrimes targeting Americans.

The companies won’t simply be handed a digital license to cause havoc. Every operation will require written approval from the program directors at the Justice Department and the Department of Homeland Security, with the firms acting under federal supervision. Participating companies may also be required to put up at least $1 million in a bond or escrow account, which could be forfeited if they break the rules.

The powers are still pretty significant. The memorandum allows operations that can manipulate, disrupt, degrade, or destroy computer systems and data, while surveillance operations can involve secretly accessing systems without the owner’s permission to gather intelligence.

There are guardrails. The program is intended to target foreign criminal groups rather than governments, and companies must stop and report any operation that accidentally targets a US person or a US-based system. The precise rulebook isn’t finished yet, with officials given 60 days to establish the operating procedures.

The move marks a major departure from the US government’s traditional position that private companies can defend against hackers but shouldn’t launch attacks themselves. Cybersecurity veteran Jake Williams told TechCrunch the plan was “half-baked,” warning that Americans involved could face legal trouble or accusations from foreign governments when traveling overseas.

Follow

Thank you for being part of our community. Read our Comment Policy before posting.