Government Approved Hack Back??
- Ben Card

- Aug 17
- 4 min read
The White House Just Authorized Private Firms to Hack Back Against Cybercriminals

A New Federal Program for Offensive Cyber Operations
For as long as ransomware gangs, phishing crews, and fraud rings have operated from overseas with near-total impunity, U.S. businesses have been told to focus on defense: patch faster, back up more, train employees better. That changed this week. On August 12, 2026, President Trump signed a national security presidential memorandum directing the National Coordination Center to build a formal program. This will allow vetted private security companies to apply for approval to conduct offensive cyber operations against transnational criminal organizations, under the direct control and authority of the U.S. government, as first reported by BleepingComputer.
The stated goal is disruption, not just documentation. The memo is aimed squarely at the criminal infrastructure behind ransomware attacks, phishing campaigns, financial fraud, sextortion schemes, and impersonation scams; the everyday threats that drain money and productivity from American companies. The scale of the problem is what makes the policy shift notable: the White House cited more than $20.8 billion in reported losses to cyber-enabled crime in 2025 alone, a figure drawn from consumer and business complaints tracked through the FBI Internet Crime Complaint Center.
Guardrails, Vetting, and Financial Accountability

This is not a green light for freelance hacking. The program will be overseen by executive directors designated jointly by the Department of Justice and the Department of Homeland Security. Participating firms must go through a formal vetting process and enter into contractual agreements with one of the two departments before conducting any operation. Companies will also be encouraged to coordinate with federal, state, local, and tribal agencies to gather threat intelligence and jointly propose which operations are worth pursuing.
The financial and legal accountability built into the program is significant. Participating companies must maintain a bond or escrow of at least one million dollars, which is forfeited if they violate the terms of their agreement. Every operation has to comply with the U.S. Constitution, federal law, and applicable international obligations, and firms are required to immediately halt activity and notify the National Coordination Center if an operation exceeds its approved scope, including any unintended targeting of U.S. citizens or U.S.-based systems. Those are meaningful constraints on what has historically been an unregulated and legally murky practice.
What This Means for U.S. Businesses and Organizations
The most important thing for business leaders to understand is what this program does not change: unauthorized access to a computer system is still a federal crime under the Computer Fraud and Abuse Act. That applies to your organization just as much as it applies to a criminal gang. Only companies formally vetted and contracted through the Department of Justice or Department of Homeland Security under this new program will have any legal cover to conduct offensive operations. Attempting to retaliate against attackers on your own, sometimes called hacking back, remains illegal regardless of how the White House frames this policy.

Where this could matter to your organization is in vendor conversations. Expect a wave of security firms to market themselves around this new authority in the coming months. Any vendor claiming they can hack back on your behalf should be able to point to actual participation in the vetted federal program described in the memo, not just general offensive-security experience. Until the program is fully established and its participants are public, the safest assumption is that no vendor working with your organization currently holds that authority.
None of this changes the fundamentals of good security practice in the meantime. Ransomware, phishing, and fraud are still best addressed through strong defensive controls, incident response planning, and employee awareness. The groundwork for these fundamentals are outlined in resources like CISA's StopRansomware guidance. They should be used alongside prompt reporting of incidents to the FBI so that federal agencies have the data they need to prioritize disruption efforts under programs like this one.
Industry Reaction and Open Questions
Security industry veterans were quick to weigh in. Veracode co-founder Chris Wysopal called the memo a pretty big shift in U.S. cyber policy and a major expansion of the private sector's role in offensive cyber operations. A characterization that captures just how far this departs from the government's traditionally defense-first public posture on cybersecurity.

Others were more skeptical about incentives and oversight. Former Cyber National Mission Force leader and Automox CTO Jason Kikta described the program as a perpetual motion machine for billable threats; a pointed warning that a pay-per-operation model could reward firms for finding or manufacturing justification to act rather than for resolving threats efficiently. How the Justice and Homeland Security departments vet participants, and how transparently the program reports on outcomes, will determine whether that concern proves to be warranted.
Whatever shape the program ultimately takes, it signals that the federal government now sees the private security industry as a direct partner in offensive disruption, not just a defensive vendor. That is a meaningful shift in how cybercrime is fought in the United States, and it is one every security-conscious organization should be tracking as the details of the program become public.
If your organization wants help making sense of what this policy shift means for your security posture, vendor due diligence, or compliance obligations, or simply wants a clear-eyed assessment of where your defenses stand today, reach out to Webcheck Security. Our team can help you cut through the noise and focus on the controls that actually reduce your risk.




Comments