SevenTnewS

Offensive Hacking Under Federal Oversight

The US is outsourcing offensive hacking. Knowing who to hit is the catch

A new presidential memorandum lets private cybersecurity firms conduct international attacks on foreign criminals under DOJ and DHS oversight, with a $1 million bond as the backstop. Researchers say the rule banning strikes on state-run groups is nearly impossible to apply.

Emmanuel Fabrice Omgbwa Yasse AI-assisted

2026-08-22 · 4 min read

The presidential memorandum reads like a clean division of labor: the government sets the rules, private cybersecurity firms do the hacking. In practice, the program gives those firms the power to surveil and disrupt foreign criminal networks, and asks them to make a targeting judgment that security researchers say is often impossible.

The program, first reported by Bloomberg and detailed by The Verge, describes private businesses as "underutilized" in the fight against criminal networks. "It is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime," the presidential memorandum states. The problem it targets is concrete: ransomware demands reached $120 million across 2025 and 2026, per the broader ransomware picture.

What the memorandum actually authorizes

Firms that join operate "under the control and oversight" of the federal government, with permission to surveil and disrupt criminal networks. The Department of Justice and the Department of Homeland Security oversee them, and companies must clear vetting requirements covering "technical proficiency, proven performance of cyber operations, facility security," and more.

The financial backstop is a bond or escrow of at least $1 million, which firms forfeit if they fail to comply with the contractual agreement. The memorandum also draws a limit on targets: companies may only hack groups that are "not an institutional part of a foreign government or wholly operated under a foreign government's direction."

RequirementWhat the memorandum says
OversightDOJ and DHS; firms act "under the control and oversight" of the federal government
Eligibility"Technical proficiency, proven performance of cyber operations, facility security," and more
Financial guaranteeBond or escrow of at least $1 million, forfeited for non-compliance
Target limitGroups that are not "an institutional part of a foreign government or wholly operated under a foreign government's direction"

The attribution problem the memo can't solve

That target limit sounds like a guardrail. Applying it is another matter. Cybersecurity Dive, which flagged the issue after the memorandum appeared, notes that identifying which criminal groups are affiliated with foreign governments is often difficult, and that a wrong call could put firms at risk of stoking geopolitical or legal conflicts. The difficulty is on display with Umbrij, an APT's Gmail-hijacking tool: on its face it is ordinary credential theft, exactly what the program is supposed to disrupt.

Ben Bernstein, a manager for the cybersecurity advisers team at Huntress, explains why the distinction breaks down in practice. "Threat actors don't launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network," Bernstein says. "That makes it practically impossible to 'strike back' without taking out innocent bystanders." Microsoft's CaptiveCrunch findings showed the SVR doing exactly this, compromising hotel Wi-Fi networks to reach its targets.

A policy built to strike criminals ends up striking infrastructure that belongs to no one in particular.

The people doing the work carry exposure that a federal contract does not erase. Jason Healey, a senior cyber conflict researcher at Columbia University, told Cybersecurity Dive that "anyone conducting these operations is doing so at substantial personal legal risk." The risk is personal, not just contractual: a single security decision can already land a US citizen in federal court, as the duress password case shows.

Jake Williams, vice president of research and development at Hunter Strategy, told TechCrunch, as reported by The Verge, that "Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas."

That label carries real weight. A non-uniformed combatant does not get the protections a soldier gets. In a foreign jurisdiction, a contractor who breaks into the wrong network cannot lean on sovereign immunity; the "control and oversight" language in the memorandum is precisely the line that would be tested if an operation went wrong.

The bond cuts the same way. It exists to keep firms honest, but it also means the first financial blow in any failed operation lands on the company, not the government.

From state monopoly to privatized offensive cyber

The shift ends a long-standing arrangement. The US government previously carried out its own cyber operations rather than relying on third parties, and President Donald Trump began making plans to bring private cybersecurity companies into the picture last year, according to Bloomberg.

Outsourcing offensive hacking is not like outsourcing other government work. The judgment calls happen across borders, with attribution that is rarely clean and consequences that are hard to contain. Cybersecurity Dive's warning about geopolitical conflicts is not hypothetical: it describes what happens when a private firm, chasing a criminal network, lands on infrastructure that a foreign government considers its own. The same fear of uncontained offensive capability prompted OpenAI to pause Astra when evaluations could not rule out the model hacking hardened systems on its own, as the Astra pause showed.

The program is a bet that the government can vet and supervise companies that are themselves betting a million dollars, and their employees' freedom, on the targeting question. The memorandum does not explain how the government will make that question answerable. It just calls the private sector "underutilized." The gap between the ambition and the mechanics is where this policy will live or die.

Get the tech essentials in 3 minutes every morning

One email, every weekday, with what actually matters in AI and tech.