08/17/2026
The U.S. will now allow private companies to launch offensive cyber attacks.
Under a newly issued presidential memorandum, the United States is crossing a major threshold by authorizing vetted private cybersecurity firms to carry out offensive cyber operations against international criminal networks targeting Americans.
Moving away from a decades-old policy that restricted private entities strictly to network defense, the new framework permits approved companies to conduct surveillance using spyware, disrupt target infrastructure, and destroy the data of foreign gangs.
The policy change aims to actively combat rising threats like ransomware, financial fraud, and sextortion. However, the government will maintain tight control, requiring participants to seek explicit approval from the Department of Justice and the Department of Homeland Security for every operation, with zero tolerance for targeting Americans or domestic systems.
While the administration seeks to leverage private-sector innovation, cybersecurity experts are raising serious alarms regarding the risks. Critics warn that permitting private individuals to conduct foreign cyber operations could invite severe diplomatic fallout or leave these professionals legally vulnerable, potentially exposing them to prosecution and arrest as non-uniformed combatants when traveling abroad. To participate, companies must also place $1 million in escrow, which is subject to forfeiture if they violate program guidelines. As federal agencies prepare to release specific eligibility and operational rules within the next two months, this unprecedented strategy faces both high stakes and potential legal battles over the future of privatized warfare.
source: Whittaker, Z. (2026). In a first, US will allow some private firms to carry out cyberattacks. TechCrunch.