On August 12, 2026, Donald Trump signed a National Security Presidential Memorandum authorizing vetted private companies to conduct offensive cyber operations against transnational criminal organizations. The document, managed by the DHS National Coordination Center with joint DOJ and DHS oversight, marks a reversal from the administration's position expressed just five months earlier. In March 2026, Thomas Lind, then senior adviser at the Office of the National Cyber Director, publicly stated: "We're not interested in fighting pirates with pirates." The shift from that refusal to "digital letters of marque" — as Nicholas Weaver termed them — has no official explanation in the available sources.
- Every operation requires written joint approval from the DOJ and DHS co-Executive Directors, with an escrow deposit of at least $1 million per participating company
- The program distinguishes between "Cyber Surveillance Operations" (unauthorized access for intelligence) and "Cyber Effects Operations" (manipulation, destruction, or degradation of systems)
- Companies may target U.S. infrastructure and individuals if involved in large-scale cybercrime, but must halt operations if unintended impact occurs on uninvolved U.S. systems
- The NSPM provides no shield against civil liability under the Computer Fraud and Abuse Act, nor protections from criminal discovery that could expose proprietary tools and methodologies in court
The Two Operation Categories and the Escrow Filter
The program structures authorized activities into two distinct categories. "Cyber Surveillance Operations" permit unauthorized access to computer systems to gather intelligence. "Cyber Effects Operations" go further: they encompass manipulation, destruction, or degradation of systems, networks, or data. Both require co-signature from the DOJ and DHS co-Executive Directors, a mechanism sources describe as ensuring political oversight but which also introduces operational latency.
The requirement for an escrow of at least $1 million, forfeitable upon rule violation, acts as an entry filter. According to Risky Business, companies must also possess secure facilities and personnel with a proven record. The combination of these requirements — financial, infrastructural, and reputational — could exclude smaller cybersecurity firms, those that traditionally innovate in technical niches but lack the liquidity for million-dollar escrows. The risk, highlighted by multiple sources, is a fragmentation between large vendors with resources for compliance and smaller vendors relegated to the margins of observation.
The Deconfliction Gap and the International Void
Converging sources flag a structural deficit in the governance mechanism. No provision emerges for deconfliction with international partners: Europol, Interpol, and Five Eyes allies do not appear in the described framework. This absence is particularly critical for operations that, by definition, cross sovereign jurisdictions and shared infrastructure.
The "civil shield" problem also remains open. According to the legal analysis published on Mondaq, the NSPM grants federal criminal immunity but offers no protection against civil actions under the CFAA, nor against tort or intellectual property claims. Moreover, criminal discovery procedures could force companies to reveal proprietary tools and offensive methodologies in court, with long-term effects on competitiveness.
From Lind to Trump: The Mystery of the Five-Month Pivot
The timeline highlights an unexplained contradiction. In March 2026, the administration had explicitly ruled out this path. Tom's Hardware cites Thomas Lind in a public intervention: the position was a flat rejection. The March 2026 executive order, which the NSPM extends, merely ordered priority for the fight against scam compounds and ransomware — without delegating offensive actions to the private sector.
What changed between March and August is not documented in the available sources. Tom's Hardware mentions a "classified annex" for sensitive operations, but its content is inaccessible. TechCrunch sent specific questions to the White House without receiving a response. The Guardian submitted detailed requests to DHS and the White House, also without result. The full text of the NSPM is not public in the available source set.
"You should also consider the unreliability of the Trump regime's designations for targeting. They've routinely designated civilian or even functionally nonexistent organizations as criminal or terrorist organizations. You cannot trust their assurances that the bad guys you're harming are actually bad guys."
— Dave Wilburn, Mastodon thread, cited by Risky Business
The Risk of the "Ununiformed Combatant"
The geopolitical dimension adds a further layer of danger. Jake Williams, VP of R&D at Hunter Strategy, told TechCrunch that Americans participating in these operations "could easily be classified as non-uniformed combatants while traveling overseas." The quote, reported by TechCrunch on August 13, 2026, raises a concrete operational scenario: technical personnel from private companies crossing physical borders into countries where their digital activities are traceable to attacks face undefined legal status.
The dossier does not specify how the NSPM protects contractors from legal actions by foreign states, nor how their status is managed in case of detention or extradition. The impact on cyber insurance coverage for participating companies is also not addressed in the available sources.
The Countdown: 60 Days and the October Window
The program must be operational within 60 days of the memo's signing, with an estimated date around October 11, 2026, according to Risky Business. This window is tight for a framework requiring construction of oversight infrastructure, company vetting, and definition of operational protocols. Operations not approvable if they risk loss of life or armed attack exclude some scenarios, but do not clarify who assesses this risk case by case.
Congress had appropriated $1 billion for offensive cyber operations in the latest spending bill, reports Tom's Hardware. It is unclear whether that budget connects directly to the NSPM or represents a parallel funding line for government operations.
Why It Matters
The dossier does not document which companies are already participating or have expressed interest in the program. GovTech cites a Google "disruption unit" and Sandra Joyce on private-sector offensive initiatives, but does not verify Google's involvement in the specific NSPM. The source does not specify the actual economic value of contracts nor the mechanisms for verifying unintended impact on third-party systems.
The brief lists no corrective measures for the identified structural gaps: no international deconfliction procedure, no civil shield, no management of criminal discovery, no protection for personnel abroad. For CISOs and lawyers at cybersecurity firms, the regime introduces unquantifiable legal and operational risks: direct participation, involvement via MSSP, or even simply supplying tools to operators in the program could expose them to undefined chains of liability.
For the sector as a whole, the NSPM represents a global test case on the delegation of coercive cyber powers to the private sector. If replicated, the model could normalize the figure of the "digital privateer" with national oversight but without international coordination. The consequences of this fragmentation are not in the brief, but the documented gaps suggest an incomplete structure in a field where operational error carries immediate geopolitical costs.
Sources
- https://news.risky.biz/risky-bulletin-white-house-lets-private-companies-carry-out-offensive-cyber-ops/
- https://www.mondaq.com/unitedstates/terrorism-homeland-security-defence/1831518/license-to-hack-the-white-house-greenlights-private-sector-offensive-cyber-operations
- https://www.tomshardware.com/tech-industry/cyber-security/white-house-authorizes-private-companies-to-hack-foreign-cybercrime-groups
- https://www.govtech.com/blogs/lohrmann-on-cybersecurity/hacking-back-is-back-white-house-to-enable-cyber-privateers
- https://techcrunch.com/2026/08/13/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks/
- https://www.theguardian.com/us-news/2026/aug/13/donald-trump-private-companies-cyber-attack
Information verified against cited sources and current as of publication.
Sources
- https://support.signal.org/hc/en-us/articles/10223569377562-Automatic-Key-Verification
- https://www.stepsecurity.io/blog/teampcp-supply-chain-attack-cicd-secrets-cloudsek-disclosure
- https://www.island.io/
- https://risky.biz/feeds/risky-business-news/