A White House National Security Presidential Memorandum on combating transnational cyber-enabled crime reportedly creates a formal pathway for U.S. private companies to conduct government-authorized hack-back operations under federal oversight. The reported policy shift moves beyond the long-standing model in which companies were limited to detecting, responding to, and reporting intrusions, and instead directs the Department of Justice and Department of Homeland Security to oversee a new mechanism for offensive action against foreign transnational criminal organizations.
According to the reports, participation would require case-by-case written approval through a joint DOJ-DHS coordination structure, with firms posting at least a $1 million bond and operating under defined federal supervision. The legal basis is said to rely on executive interpretation of the Computer Fraud and Abuse Act and its government-activity exception in 18 U.S.C. § 1030(f), rather than a new law, leaving the framework vulnerable to court challenges and possible retroactive liability if that interpretation fails. The reports also warn that misattribution, collateral damage to third-party infrastructure, escalation, and cross-border sovereignty disputes could create significant operational and legal risk for participating companies.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
On August 12, 2026, President Trump signed a National Security Presidential Memorandum described as shifting the long-standing boundary between private cyber defense and offensive action. The memorandum directs the Department of Justice and the Department of Homeland Security and is reported to create a formal mechanism for government-authorized private-sector hack-back operations under federal oversight.
A later Active Cyber Defense Certainty Act proposal in 2019 likewise did not move beyond congressional committees, leaving prior legal limits on private-sector hack-back unchanged.
The article states that proposed U.S. hack-back legislation, the Active Cyber Defense Certainty Act, was introduced in 2017 and 2019 but did not advance beyond congressional committees.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.