In a first, US will allow some private firms to carry out cyberattacks
The White House says vetted private companies can join offensive cyber operations against criminal gangs and hackers. The move marks a major shift in U.S. hacking policy.
Intelligence analysis by GPT-5.4 Mini

The Trump administration’s new memorandum opens the door for some private firms to participate in government-supervised offensive cyber operations, including surveillance and disruptive attacks. It is a sharp departure from the long-standing view that private companies may defend but not hack back.
The U.S. is changing the rules so some private security companies can help the government fight bad hackers by going on the attack, not just blocking attacks. It is like letting a guard dog help chase burglars, but only while the police watch closely.
Analysis
Presidential memorandum
The most important detail is not that the White House wants more cyber muscle. It is that the administration is trying to formalize a role for private companies inside offensive operations that federal law has traditionally kept off-limits. That makes the policy less like a temporary exception and more like an attempt to redraw the line between defense and state-directed hacking.
That line matters because cyber operations are unusually hard to contain once they leave the narrow lane of self-protection. The article makes clear that companies would not be freelancing on their own; they would operate under federal supervision and need sign-offs from the Justice Department and Homeland Security. Even so, the move normalizes a model in which private expertise becomes an instrument of coercive state action.
The administration’s framing also reveals its priorities. It says the government is confronting a growing threat to Americans and businesses, while the article ties the decision to ransomware, financial scams, sextortion, and attacks on critical infrastructure. The policy is therefore being sold not as a geopolitical stunt, but as an escalation in the fight against cybercrime.
Escrow
The escrow requirement is a clue that the government expects both risk and noncompliance. A $1 million deposit is meant to force discipline, but it also shows how much trust the program will demand from participants. Smaller firms may be included, according to the memorandum, yet the financial barrier and compliance burden could still favor established contractors.
The rules also suggest the government is trying to preempt the most obvious dangers. Operations cannot target Americans or U.S.-based systems, and companies must notify the government if they detect an imminent cyberattack on critical infrastructure. Those safeguards are important, but they do not answer the harder question of how broad a target list the program will eventually allow.
There is also a practical uncertainty baked into the design. The article says the government has not fully established how the program will operate, and detailed guidance is still two months away. That means the policy is real, but its day-to-day mechanics, oversight standards, and abuse-prevention rules are still being assembled after the fact.
Jake Williams
The strongest criticism in the piece comes from Jake Williams, who argues the policy could expose Americans working for cybersecurity firms to retaliation abroad. His warning is not just about legal risk; it is about the way foreign governments might characterize private U.S. contractors once they are linked to offensive operations. In that scenario, even unproven allegations could create real personal danger.
That concern points to one of the policy’s deepest weaknesses: attribution cuts both ways. If the U.S. uses private firms to conduct attacks, other countries may respond by treating those firms as state proxies, especially if a campaign lands on the wrong side of diplomatic tensions. The article notes that critics have already spent years arguing private industry should not be folded into government hacking operations for exactly this reason.
Williams also calls the plan "half-baked," which captures the broader tension in the story. The administration is reaching for speed and flexibility at a moment of rising cyber pressure, but the article repeatedly shows a program that is still incomplete, legally exposed, and vulnerable to abuse claims. That combination makes the policy bold, but not yet stable.
Key points
- The White House says vetted private firms may help conduct offensive cyber operations under federal supervision.
- The program would allow surveillance and disruptive attacks, but not unsupervised hack-back efforts.
- Participating companies would need to place $1 million in escrow and follow government rules.
- The memo requires procedures to avoid targeting Americans or U.S.-based systems.
- Critics warn the policy could trigger legal challenges, foreign retaliation, and risks to private cybersecurity workers.
If the program is tightly controlled, it could give the U.S. faster and more specialized tools against ransomware crews, scammers, and attacks on critical infrastructure. The involvement of vetted firms may also help the government tap expertise it no longer has in-house after cyber staff cuts.
The biggest risk is that the policy blurs the line between lawful defense and offensive hacking, opening the door to legal fights and diplomatic blowback. It could also put private cybersecurity workers in danger if foreign governments treat them as state-backed attackers.

