Skip to content
Rush Commerce
Field Notes3 min read

US lets vetted private firms run offensive cyber ops

A presidential memo authorizes approved companies to hack foreign criminal networks under DOJ and DHS sign-off. What offensive cyber authority changes for your vendor list.

For decades the answer to "can we hack back?" was no, and the Computer Fraud and Abuse Act was the whole conversation. That changed this week. A National Security Presidential Memorandum signed August 12 authorizes vetted private companies to conduct offensive cyber operations against foreign criminal networks — under government approval, with money posted as a bond. If you buy security services, your vendor's capability sheet is about to grow a new section.

What actually happened

Per The Record and TechCrunch, the memo was released Wednesday evening. The shape of it:

  • What's authorized: intelligence collection, including spyware, and disruptive operations aimed at destroying criminal data or systems. Targets are limited to transnational cybercrime, fraud, and predatory schemes — ransomware crews, scam networks, sextortion operations.
  • Who approves: every operations package needs written sign-off in advance from Justice Department and Homeland Security representatives. Companies propose; the government approves.
  • Cost of entry: at least $1 million in bond or escrow, forfeited on rule violations. Plus personnel vetting, facility security, technical-proficiency standards, annual evaluation, and disclosure of all contractual relationships.
  • Hard limits: no operations causing loss of life or amounting to use of force under international law. Immediate notification required if an operation touches US persons or US-controlled systems.
  • Timeline: agencies have two months to publish operating procedures.

The administration cited $20.8 billion in cyber-related losses reported by Americans last year as the rationale. Not everyone is sold — Rep. Bennie Thompson argued the venue for this is Congress, not a memorandum.

Why it matters for your business

You will not be hacking anyone. Three things still land on your desk.

Vendor claims are about to get loud. Within two months, expect security vendors to market "offensive capability" in ways that outrun what they're actually cleared to do. The program requires approval, escrow, and vetting. Ask which of those a vendor holds, in writing. A firm doing your pen test is not a firm running sanctioned operations abroad.

Nothing about your patch queue changed. No sanctioned operation protects an unpatched edge device. Retaliation against criminal infrastructure is slow, selective, and not yours to schedule. Patch by exploitation, not severity still does more for you this quarter than any policy shift.

Blast radius is a real risk. Disruption operations against shared criminal infrastructure can knock over things sitting next to it. If your business depends on hosting or payment rails in higher-risk jurisdictions, the manual fallback plan matters more, not less.

Key takeaways

  • A presidential memo signed August 12 lets vetted private firms run offensive cyber operations against foreign criminal groups
  • Every operation needs advance written approval from DOJ and DHS; companies must post at least $1M in bond or escrow
  • Limits: no loss of life, no use of force, immediate notification if US persons or systems are touched
  • Agencies have two months to publish operating procedures — vendor marketing will arrive sooner
  • Ask vendors for written proof of program participation; keep patching on exploitation evidence regardless

Not sure what your security vendors actually do for you? We audit the stack — what's monitored, what's patched, what's just a line item — and build the systems that close the gaps. Tell us what you're running, or see how we work.

Sources: The Record, TechCrunch.

  • #cybersecurity
  • #policy
  • #vendor-risk
  • #ransomware
  • #compliance
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.