- › The August 13 memorandum lets vetted private firms run offensive operations against transnational criminal organizations, with spyware surveillance and destructive attacks both in scope.
- › It stops short of authorizing hack back, so a company still cannot strike the group that breached it.
- › Guardrails include a $1 million forfeitable escrow, per-operation approval from the Justice Department and Homeland Security, and a prohibition on targeting Americans or US systems.
- › Criminal infrastructure is overwhelmingly compromised third-party systems, and the US-systems carve-out does not protect a hacked server belonging to a business overseas.
- › If you operate outside the United States, your exposure is being downstream of an authorized operation with no notification and no obvious recourse.
The memorandum landed this morning and the headlines were wrong within the hour.
The Register called it a license to hack back. Others said the White House had authorized companies to go on the offensive against whoever hits them. If you read only the coverage, you would think a breached company can now return fire.
It cannot. The policy explicitly stops short of permitting hack back.
That distinction is not pedantry, and I want to spend a minute on what the document does authorize, because there is a genuine operational consequence buried in it that nobody is discussing.
What It Authorizes
The presidential memorandum, titled Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, was issued August 13. It permits private companies to conduct offensive cyber operations against international criminal organizations. Both surveillance using spyware and disruptive attacks intended to destroy criminal data or systems are in scope.
Participation is voluntary. The guardrails are real and worth listing.
A participating firm posts a $1 million escrow deposit, forfeitable for non-compliance. Every operation needs approval from both the Justice Department and Homeland Security before it runs. Operations targeting Americans or US systems are prohibited. Firms are supervised exclusively by the federal government, and must notify authorities of imminent attacks on critical infrastructure. Eligibility guidance is expected within two months and reportedly contemplates companies of all sizes.
So this is not a general license. It is a small, expensive, government-supervised program with per-operation sign-off, aimed outward at organized crime.
Which is a considerably better-designed policy than the headlines suggest, and it still has the problem below.
Criminal Infrastructure Belongs to Victims
Anyone who has done incident response already knows the next part, and policy discussion routinely skips it.
When you trace an intrusion back to a command and control server, you almost never find a machine the criminals own. You find a compromised virtual private server rented on a stolen card. A hacked WordPress box at a landscaping company. A forgotten development server at a university. A router in a small clinic. A machine at a freight brokerage that has been quietly relaying traffic for eight months while running the business it was bought for.
Criminal infrastructure is mostly other people’s infrastructure. That is the entire economic model: you do not pay for servers when you can take them.
Now put the memorandum against that. A destructive operation aimed at “criminals’ data or systems” lands on hardware. The hardware is usually somebody’s. And the protection written into the policy covers Americans and US systems.
A compromised server at a Brazilian clinic is not a US system. Neither is a hacked box at a German engineering firm, a Polish logistics company, or your own subsidiary’s cloud tenant in Singapore.
What That Means If You Are Not Participating
Almost nobody reading this will be in the program. A million dollars in escrow and per-operation federal approval sorts down to a handful of firms. The relevant question for everyone else is not whether to join. It is what happens if you end up downstream.
Run it concretely. A US-approved firm identifies criminal infrastructure. Part of that infrastructure is a virtual machine in your European subsidiary’s environment, compromised months ago and never detected. The operation runs. Something in your estate is degraded or destroyed.
You will experience that as an outage of unknown cause. Your team will work it as an incident. You will not get a phone call, because there is no notification duty running to the owner of a compromised system, and the operators have every reason not to disclose. Your logs will show hostile activity from an unfamiliar source, which will be accurate and completely misleading about who it was and why.
That is the exposure, and I do not think it is hypothetical. It is the ordinary consequence of authorizing destructive action against infrastructure whose ownership the actor cannot fully determine in advance.
The Escalation Nobody Priced
The other cost is one Jake Williams named today, and it deserves repeating because it is the kind of thing that becomes obvious in retrospect.
Williams called the policy half-baked and pointed out that American participants could be classified as non-uniformed combatants while traveling overseas. The staff of a participating firm are civilians conducting state-sanctioned attacks on targets in other countries. Several of those countries will take a view on that, and the view will not be favorable, and it will attach to individual people with passports.
There is also the reciprocity problem. The United States has spent years arguing that private offensive cyber operations are destabilizing and that states should restrain their proxies. Authorizing a supervised version makes that argument harder to make. Other governments will notice, and some of them already run exactly this arrangement with far less supervision and will be pleased to cite the precedent.
I am not arguing the policy is indefensible. The case for it is real: criminal groups operate from jurisdictions that will not act, law enforcement is outmatched on volume, and private firms have capability the government cannot hire fast enough. Somebody weighed that and chose. The guardrails suggest people thought hard about the domestic risks.
The guardrails do not address the foreign third party whose server is in the blast radius, and that is not a small gap.
What to Actually Do
Nothing here requires you to have an opinion about the policy. These are the things that change on your side regardless.
Find out what you own outside the United States
Not the entities. The systems. Cloud tenants, colocation, a subsidiary’s on-premises equipment, a legacy environment nobody migrated after an acquisition. The US-systems protection does not extend to any of it, and most organizations cannot produce that inventory quickly.
Treat unexplained destruction abroad as a real hypothesis
If a foreign-hosted system is degraded with no clear cause and no ransom demand, add “our machine was somebody else’s target” to the list of possibilities. It is not the first hypothesis and it should no longer be off the list. That changes what you preserve and how you write the timeline.
Hunt for relay activity in your own estate
The way you end up in this position is by hosting infrastructure for somebody else without knowing. Outbound connections nobody can explain, traffic through machines with no business reason to originate it, services listening that were never provisioned. This is the same hunting the incomplete patches work calls for, applied to a different question.
Ask your incident response retainer where they stand
If your provider or an affiliate joins the program, that is a conflict worth knowing about before you need them. A firm running offensive operations under federal supervision has obligations that may not sit comfortably alongside acting purely in your interest.
Do not let anyone in your organization read this as permission
Somebody will forward a “companies can hack back now” headline and someone else will float retaliating against a scanner or a phishing sender. It is not authorized, it was not authorized before, and unauthorized access remains a crime whatever the memorandum says about vetted firms operating abroad under two departments’ approval.
The Line I Keep Coming Back To
Every destructive operation runs against hardware, and hardware has an owner. In this category, the owner is usually a victim who has not been told.
Go find out what you run outside the country. Not the legal entities, the machines.
Want to know what your organization actually runs, and where? Take our free Human Attack Surface Score assessment, or contact us for a full risk assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Author Page →