A White House memorandum signed by Donald Trump on 12 August authorizes vetted private US companies to conduct offensive cyber operations against foreign transnational criminal groups, including surveillance and disruptive 'cyber effects' operations. State-directed hackers such as North Korean groups are explicitly excluded from being targets, though grey areas exist around Russian, Chinese and Iranian state-linked criminal actors. Companies must meet vetting standards, maintain a $1 million bond, disclose contracts, and get case-by-case government approval; operations cannot cause loss of life or rise to an armed attack. Critics warn of legal exposure for participants abroad, likely legal challenges under the Computer Fraud and Abuse Act, and a classified addendum whose contents remain undisclosed.
Table of contents
What the White House says it is forWhat the memorandum authorisesWho can be targeted, and who cannotIt is not hack-backWhat companies have to doThe limits the memorandum setsWhat supporters sayWhat critics sayThe legal questionThe context reported around itWhat happens nextQuestions this post answers
Can private US companies now legally hack foreign cybercriminals under the new White House memo?
Yes, under a memorandum signed by Donald Trump on 12 August, vetted US companies can conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign transnational criminal organizations, but only under government contract and case-by-case approval, not as unilateral hack-back. State-directed hackers, like those working for foreign governments, are excluded as targets. Operating procedures are due within 60 days, so no operation can be approved before then. Security teams tracking how offensive cyber authority is evolving can follow developments like this on daily.dev.
What financial and vetting requirements must companies meet to participate in the US offensive cyber operations program?
Companies must disclose all contractual relationships to a National Coordination Center and maintain a bond or escrow of at least $1 million against non-compliance. Minimum standards cover technical proficiency, experience with cyber operations, facility security, personnel vetting and reliability. Every operation package requires written approval from Program Executive Directors, and each company's participation is reviewed at least annually. Professionals evaluating regulatory compliance burdens in cybersecurity can keep up with policy shifts like this on daily.dev.
Are North Korean state-sponsored hackers a legal target under the new US offensive cyber operations memo?
No, the memorandum excludes groups that are an institutional part of a foreign government or wholly operated under a foreign government's direction, which covers North Korean hackers who work at state direction. Grey areas remain, since many Eastern European gangs are believed to operate with tacit Russian government consent, and Chinese and Iranian state hackers sometimes moonlight as criminals. Anyone mapping which threat actors fall inside or outside new cyber policy rules can track it on daily.dev.