<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks-amiaryn9n" -->

---
title: In a first, US will allow some private firms to carry...
description: The White House issued a presidential memorandum allowing vetted private companies to conduct offensive cyber operations, including surveillance via spyware...
canonical: https://daily.dev/posts/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks-amiaryn9n
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: In a first, US will allow some private firms to carry out cyberattacks | daily.dev
og:description: The White House issued a presidential memorandum allowing vetted private companies to conduct offensive cyber operations, including surveillance via spyware...
og:url: https://daily.dev/posts/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks-amiaryn9n
og:image: https://api.daily.dev/og/posts/aMiaRyn9n.png
og:image:alt: In a first, US will allow some private firms to carry out cyberattacks
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# In a first, US will allow some private firms to carry out cyberattacks

**[TechCrunch](https://daily.dev/sources/tc)** · 5 min read · 0 upvotes · 0 comments

## Summary

The White House issued a presidential memorandum allowing vetted private companies to conduct offensive cyber operations, including surveillance via spyware and disruptive attacks against criminals' data and systems, targeting international cybercrime such as ransomware and sextortion. This reverses decades of policy that restricted private firms to defensive cybersecurity. Participating companies must deposit $1 million in escrow, get sign-off from the Justice Department and Homeland Security, and operate under federal supervision, with guidance on program requirements expected within two months. Critics, including cybersecurity veteran Jake Williams, warn the policy is 'half-baked' and could expose American participants to being charged as combatants by foreign governments. The change comes amid ongoing Iranian-linked cyberattacks on U.S. water infrastructure and broader concerns about autonomous AI-driven cyberattacks reported by Anthropic, OpenAI, and Meta.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://techcrunch.com/2026/08/13/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks>

## Questions this post answers

### What does the new US presidential memorandum on offensive cyber operations allow private companies to do?

It allows vetted private companies to conduct offensive cyber operations against international criminal gangs and hackers, including surveillance such as spyware-based intelligence collection and disruptive attacks aimed at destroying criminals' data or systems. This reverses decades of policy that limited private firms to defensive cybersecurity. Participating companies must deposit $1 million in escrow and get Justice Department and Homeland Security sign-off before any operation, and cannot target Americans or U.S.-based systems.

_daily.dev helps security teams track policy shifts like this that reshape what private cyber operations are legally permitted._

### Does the new US cyber policy allow companies to hack back against attackers who targeted them?

No, the memorandum stops short of allowing companies to 'hack back' against cyber threats targeting them directly. Instead it authorizes vetted private companies, under federal supervision and after Justice Department and Homeland Security approval, to conduct offensive operations against international criminal gangs and hackers as part of a government-run program, not as independent retaliation for attacks on themselves.

_Security professionals evaluating offensive cyber policy changes can follow developments like this on daily.dev._

### What risks do critics say the new US offensive cyber operations policy creates for American cybersecurity workers?

Cybersecurity veteran Jake Williams, VP of research and development at Hunter Strategy, warned Americans participating in these operations could be classified as non-uniformed combatants while traveling overseas and risk indictment or detention by foreign governments, even without evidence, since the policy itself gives foreign governments cover to make such accusations. He also called the policy 'half-baked' and questioned whether it could avoid being abused.

_Practitioners weighing the legal exposure of offensive cyber work can stay on top of policy risks via daily.dev._

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#ransomware](https://daily.dev/tags/ransomware), [#offensive-security](https://daily.dev/tags/offensive-security)

[View this post on daily.dev](https://daily.dev/posts/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks-amiaryn9n)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"In a first, US will allow some private firms to carry out cyberattacks","url":"https://daily.dev/posts/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks-amiaryn9n","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks-amiaryn9n"},"datePublished":"2026-08-13T14:09:42.268Z","dateModified":"2026-09-14T06:18:05.735Z","description":"The White House issued a presidential memorandum allowing vetted private companies to conduct offensive cyber operations, including surveillance via spyware...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3538bbb5ac01cc71810379f1bf4a4f3d?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3538bbb5ac01cc71810379f1bf4a4f3d?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"TechCrunch","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"TechCrunch","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/tc","url":"https://daily.dev/sources/tc"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks-amiaryn9n","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,ransomware,offensive-security","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"TechCrunch","item":"https://daily.dev/sources/tc"},{"@type":"ListItem","position":3,"name":"In a first, US will allow some private firms to carry out cyberattacks"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks-amiaryn9n#faq","mainEntity":[{"@type":"Question","name":"What does the new US presidential memorandum on offensive cyber operations allow private companies to do?","acceptedAnswer":{"@type":"Answer","text":"It allows vetted private companies to conduct offensive cyber operations against international criminal gangs and hackers, including surveillance such as spyware-based intelligence collection and disruptive attacks aimed at destroying criminals' data or systems. This reverses decades of policy that limited private firms to defensive cybersecurity. Participating companies must deposit $1 million in escrow and get Justice Department and Homeland Security sign-off before any operation, and cannot target Americans or U.S.-based systems. daily.dev helps security teams track policy shifts like this that reshape what private cyber operations are legally permitted."}},{"@type":"Question","name":"Does the new US cyber policy allow companies to hack back against attackers who targeted them?","acceptedAnswer":{"@type":"Answer","text":"No, the memorandum stops short of allowing companies to 'hack back' against cyber threats targeting them directly. Instead it authorizes vetted private companies, under federal supervision and after Justice Department and Homeland Security approval, to conduct offensive operations against international criminal gangs and hackers as part of a government-run program, not as independent retaliation for attacks on themselves. Security professionals evaluating offensive cyber policy changes can follow developments like this on daily.dev."}},{"@type":"Question","name":"What risks do critics say the new US offensive cyber operations policy creates for American cybersecurity workers?","acceptedAnswer":{"@type":"Answer","text":"Cybersecurity veteran Jake Williams, VP of research and development at Hunter Strategy, warned Americans participating in these operations could be classified as non-uniformed combatants while traveling overseas and risk indictment or detention by foreign governments, even without evidence, since the policy itself gives foreign governments cover to make such accusations. He also called the policy 'half-baked' and questioned whether it could avoid being abused. Practitioners weighing the legal exposure of offensive cyber work can stay on top of policy risks via daily.dev."}}]}
```

