Lead story
The US Just Gave Private Companies a Licence to Hack Foreign Criminals
A White House memo circulated this week quietly rewrote a foundational rule of American cyber policy: from now on, private security firms can launch offensive cyberattacks against foreign criminal networks — provided they follow a strict set of rules and post a US$1 million bond that gets forfeited if they don't.
It is the first time a US administration has formally authorised the private sector to conduct offensive cyber operations. Experts are already calling it one of the most significant shifts in US cyber policy in decades.
What the memo actually says
Firms that qualify can surveil and actively disrupt foreign-based cybercrime organisations. The operations are bounded — companies must stay within defined parameters, and the bond requirement is designed to ensure compliance. There's an obvious government interest here: outsourcing offensive cyber capacity to the private sector is cheaper, faster, and politically easier than running it all through federal agencies.
The White House framing is squarely about ransomware gangs and foreign criminal syndicates — not nation-state adversaries, where the legal and diplomatic stakes are far higher.
Why this is a big deal
For years, US law under the Computer Fraud and Abuse Act has left private firms in an awkward position: they can watch attackers rummage through their networks but can't legally reach back. "Hack back" has been a perennial policy debate, consistently shot down because the risks of misattribution, escalation, and collateral damage were deemed too high.
This memo doesn't fully legalise hack-back for everyone — it creates a contracted, licensed model where vetted firms act almost like cyber mercenaries under government contract. Think private military contractors, but for keyboards.
The risks nobody is talking about yet
Misattribution is the obvious one. Cybercriminals routinely route attacks through third-party infrastructure — universities, hospitals, small businesses — that have nothing to do with the actual gang. A firm that "hacks back" and hits an innocent bystander's system is now holding a $1 million liability bag, at minimum.
There's also the escalation question. Nation-state actors and criminal groups often share infrastructure. An offensive action against what looks like a criminal network could inadvertently poke a state-affiliated group — and the diplomatic fallout lands on the US government, not the private contractor.
What to watch
The memo is a signal, not a finished framework. Implementing regulations still need to be written. Expect intense lobbying from major security vendors — CrowdStrike, Palo Alto, and others that already run large threat intelligence operations would be natural candidates for these contracts.
For Australian readers, this matters in a few ways. Australia has historically followed US cyber policy closely, and the Australian Signals Directorate has its own partnerships with the private sector. If the US model produces results — or blowback — expect Canberra to be watching very carefully. The question of whether Australia's own legislative framework under the Security Legislation Amendment (Critical Infrastructure) Act could ever accommodate a similar arrangement is now worth asking openly.
