President Trump has authorized private American companies to conduct offensive cyber operations against targets overseas, provided they are not working for a foreign government.
Trump signed the memorandum on August 12, and the White House published it that night. The document runs to five sections. It creates a National Coordination Center to manage the new program, with two Program Executive Directors overseeing operations. One director is designated by the Attorney General, the other by the Secretary of Homeland Security.
Handing offensive hacking authority to private firms blurs a line Washington has spent decades insisting on: that cyberattacks are the government's business, not a contractor's. The explicit carve-out for state-backed hackers reads like an attempt to keep the program aimed at criminal groups and non-state actors, not to open a proxy fight with rivals like Russia or China. Either way, it puts US legal machinery in the business of licensing private hacking, a shift oversight bodies will want to watch closely.
Private-sector offensive hacking has operated in a legal gray zone for years. This memo does not invent that industry. It just gives a slice of it Washington's blessing.