Offensive Hacking Under Federal Oversight
The US is outsourcing offensive hacking. Knowing who to hit is the catch
A new presidential memorandum lets private cybersecurity firms conduct international attacks on foreign criminals under DOJ and DHS oversight, with a $1 million bond as the backstop. Researchers say the rule banning strikes on state-run groups is nearly impossible to apply.
Emmanuel Fabrice Omgbwa Yasse AI-assisted
2026-08-22 · 4 min read
The presidential memorandum reads like a clean division of labor: the government sets the rules, private cybersecurity firms do the hacking. In practice, the program gives those firms the power to surveil and disrupt foreign criminal networks, and asks them to make a targeting judgment that security researchers say is often impossible.
The program, first reported by Bloomberg and detailed by The Verge, describes private businesses as "underutilized" in the fight against criminal networks. "It is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime," the presidential memorandum states. The problem it targets is concrete: ransomware demands reached $120 million across 2025 and 2026, per the broader ransomware picture.
What the memorandum actually authorizes
Firms that join operate "under the control and oversight" of the federal government, with permission to surveil and disrupt criminal networks. The Department of Justice and the Department of Homeland Security oversee them, and companies must clear vetting requirements covering "technical proficiency, proven performance of cyber operations, facility security," and more.
The financial backstop is a bond or escrow of at least $1 million, which firms forfeit if they fail to comply with the contractual agreement. The memorandum also draws a limit on targets: companies may only hack groups that are "not an institutional part of a foreign government or wholly operated under a foreign government's direction."
| Requirement | What the memorandum says |
|---|---|
| Oversight | DOJ and DHS; firms act "under the control and oversight" of the federal government |
| Eligibility | "Technical proficiency, proven performance of cyber operations, facility security," and more |
| Financial guarantee | Bond or escrow of at least $1 million, forfeited for non-compliance |
| Target limit | Groups that are not "an institutional part of a foreign government or wholly operated under a foreign government's direction" |
The attribution problem the memo can't solve
That target limit sounds like a guardrail. Applying it is another matter. Cybersecurity Dive, which flagged the issue after the memorandum appeared, notes that identifying which criminal groups are affiliated with foreign governments is often difficult, and that a wrong call could put firms at risk of stoking geopolitical or legal conflicts. The difficulty is on display with Umbrij, an APT's Gmail-hijacking tool: on its face it is ordinary credential theft, exactly what the program is supposed to disrupt.
Ben Bernstein, a manager for the cybersecurity advisers team at Huntress, explains why the distinction breaks down in practice. "Threat actors don't launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network," Bernstein says. "That makes it practically impossible to 'strike back' without taking out innocent bystanders." Microsoft's CaptiveCrunch findings showed the SVR doing exactly this, compromising hotel Wi-Fi networks to reach its targets.
A policy built to strike criminals ends up striking infrastructure that belongs to no one in particular.
Legal and personal risk for American operators
The people doing the work carry exposure that a federal contract does not erase. Jason Healey, a senior cyber conflict researcher at Columbia University, told Cybersecurity Dive that "anyone conducting these operations is doing so at substantial personal legal risk." The risk is personal, not just contractual: a single security decision can already land a US citizen in federal court, as the duress password case shows.
Jake Williams, vice president of research and development at Hunter Strategy, told TechCrunch, as reported by The Verge, that "Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas."
That label carries real weight. A non-uniformed combatant does not get the protections a soldier gets. In a foreign jurisdiction, a contractor who breaks into the wrong network cannot lean on sovereign immunity; the "control and oversight" language in the memorandum is precisely the line that would be tested if an operation went wrong.
The bond cuts the same way. It exists to keep firms honest, but it also means the first financial blow in any failed operation lands on the company, not the government.
From state monopoly to privatized offensive cyber
The shift ends a long-standing arrangement. The US government previously carried out its own cyber operations rather than relying on third parties, and President Donald Trump began making plans to bring private cybersecurity companies into the picture last year, according to Bloomberg.
Outsourcing offensive hacking is not like outsourcing other government work. The judgment calls happen across borders, with attribution that is rarely clean and consequences that are hard to contain. Cybersecurity Dive's warning about geopolitical conflicts is not hypothetical: it describes what happens when a private firm, chasing a criminal network, lands on infrastructure that a foreign government considers its own. The same fear of uncontained offensive capability prompted OpenAI to pause Astra when evaluations could not rule out the model hacking hardened systems on its own, as the Astra pause showed.
The program is a bet that the government can vet and supervise companies that are themselves betting a million dollars, and their employees' freedom, on the targeting question. The memorandum does not explain how the government will make that question answerable. It just calls the private sector "underutilized." The gap between the ambition and the mechanics is where this policy will live or die.
Get the tech essentials in 3 minutes every morning
One email, every weekday, with what actually matters in AI and tech.