The Privatization of Offensive Cyber Warfare

AI-generated image · Bay Street Wire
A new presidential memorandum allows private firms to launch cyberattacks, shifting sovereign military capabilities into a corporate framework with minimal guardrails.
The U.S. government has initiated a seismic shift in national security policy by authorizing vetted private companies to conduct offensive cyber operations against international hackers and criminal gangs. According to reporting from TechCrunch and The Verge, a presidential memorandum issued by the Trump administration allows these firms to engage in surveillance—including the use of spyware—and disruptive attacks designed to destroy criminal systems and data.
**Opinion: The Regulatory Vacuum** By outsourcing these capabilities, the U.S. is effectively migrating sovereign offensive power into the private sector. While the administration frames this as leveraging "innovative capabilities" to fight threats like sextortion, financial scams, and ransomware, the move creates a dangerous regulatory void. We are transitioning from a model of state-led operations to one where corporate entities execute acts of war, governed not by military code, but by contractual agreements and a $1 million escrow deposit.
Historically, U.S. federal computer hacking laws prohibited private companies from launching such operations without court approval. As TechCrunch reports, the government's long-standing position across multiple administrations was that the private sector should defend against attacks, not launch them. This new policy dismantles that firewall.
**The Mechanism of Oversight** Under the new rules, operations must be conducted under federal supervision, requiring sign-offs from the Justice Department and the Department of Homeland Security. The memorandum specifies that firms will only target groups that are not an institutional part of, or directed by, a foreign government. However, the practical application of this rule is fraught with risk.
Ben Bernstein, a manager for the cybersecurity advisers team at Huntress, told The Verge that threat actors often route traffic through innocent infrastructure, such as hospital networks or small business routers, making it "practically impossible" to strike back without harming innocent bystanders. Furthermore, Cybersecurity Dive noted that identifying which criminal groups are affiliated with foreign governments is notoriously difficult.
**Sovereign Risks and Corporate Liability** The geopolitical ramifications are severe. Jake Williams, vice president of research and development at Hunter Strategy, told TechCrunch that Americans working for these firms could be classified as "non-uniformed combatants" while traveling abroad. Williams warned that the policy provides cover for foreign governments to make such accusations, even if they are untrue. Jason Healey, a senior cyber conflict researcher at Columbia University, told Cybersecurity Dive that anyone involved in these operations faces "substantial personal legal risk."
This shift arrives at a moment of extreme volatility. TechCrunch reports that the U.S. has seen widespread cuts to federal cybersecurity staff since January 2025, while facing active threats from Iranian government-backed hackers targeting water infrastructure in states including Georgia, Michigan, and Minnesota. This follows a U.S.-led war that began in February and resulted in the death of Iran's supreme leader.
As the government prepares to issue further guidance over the next two months, the administration has not yet fully established how the program will operate. While the memorandum prohibits "hacking back" and forbids targeting Americans or U.S.-based systems, the reliance on private firms to execute offensive strikes represents a fundamental redistribution of state power to the corporate world.

