The White House just gave private companies a license to hack back.
On August 12, President Trump signed a memorandum creating the first U.S. program authorizing vetted private companies to run offensive cyber operations against foreign cybercrime organizations, including operations that destroy data and systems. Participating firms must post at least $1 million in escrow, forfeited for violating program rules, and every operation needs written approval from both the Justice Department and Homeland Security. The memo authorizes two categories of work: covert "surveillance operations" that collect intelligence from foreign systems, and "effects operations" that disrupt or destroy them. Targets qualify unless "clear intelligence" ties them directly to a foreign government - a standard that leaves most Russia-based ransomware crews, which operate with state tolerance but not formal state control, well within bounds.
The policy is a sharp reversal. As recently as March, national cyber officials publicly rejected this exact idea, with then-adviser Thomas Lind telling a conference the administration wasn't interested in "fighting pirates with pirates." Now Congress's $1 billion earmark for offensive cyber operations has a private-sector outlet, and Google, which said last year it was preparing to join disruptive actions against cybercriminals, has company. Notably, the memo excludes state-directed hackers from its own target definition, even as it follows alerts about Iranian hackers probing U.S. water and energy infrastructure - the attackers most likely to draw a response are the ones this program can't touch.
A cybersecurity VP flagged the real cost: Americans conducting these operations overseas could be treated as non-uniformed combatants, a blunt reminder that "hack back" is a euphemism for acts with wartime consequences attached.