IT-PUB NEWS

US opens cyber ops role to vetted private firms

14.08.2026 13:03 • Author: IT-PUB
US opens cyber ops role to vetted private firms

A White House memorandum would let selected companies support surveillance and disruptive cyber actions under federal oversight and with legal safeguards.

The U.S. government says it will, for the first time, allow vetted private companies to take part in offensive cyber operations against international criminal gangs and hackers. Announced by the White House, the move is intended to expand the tools available to fight ransomware, financial scams and sextortion. It also marks a break from the long-standing U.S. approach, under which private firms could defend against cyberattacks but not launch disruptive operations of their own. That makes the decision significant well beyond the cybersecurity world, touching on law, oversight and the risk of cross-border conflict.

Private firms could support surveillance and disruption

The new presidential memorandum says participating companies may be used for more than defensive work. Under the program, they could carry out surveillance, including the use of spyware to gather intelligence, and they could also conduct disruptive attacks aimed at destroying criminals’ data or systems.

The White House presented the policy as a way to tap the “innovative capabilities of the private sector” against cybercrime and other threats targeting Americans. But it did not offer a detailed public explanation for the shift, saying only that the government faces a “growing threat” to Americans and businesses, as IT-PUB News notes.

The memorandum is only the first formal step, and the program still appears to be at an early stage. The government has not yet fully explained how it will operate in practice.

Federal approval, oversight and a $1 million escrow rule

According to the memorandum, the federal government will issue guidance within the next two months on the requirements companies must meet before joining the program. That guidance is expected to cover companies of different sizes, including smaller firms that may be better suited to specialized operations.

Participating companies will have to place $1 million in escrow. That money would be forfeited if the government determines a company violated the rules governing these operations.

The memorandum also directs the government to create procedures meant to prevent any operation from targeting Americans or U.S.-based systems. Any action will require approval from representatives of the Justice Department and Homeland Security, and all operations are to be conducted under federal supervision.

Companies in the program will also have to notify the government if they discover an imminent cyberattack against critical U.S. infrastructure, including power grids or water providers.

Critics see legal and diplomatic risks

The policy stops short of allowing companies to “hack back” on their own initiative. Even so, it raises questions critics have been pressing for years. One concern is that private companies could become involved in government hacking operations in ways that spark diplomatic disputes, especially if a foreign government says it was attacked by a U.S. company.

There are legal issues too. The change marks a sharp departure from the government’s earlier position under U.S. federal computer hacking laws, which broadly prohibit private companies from carrying out cyberattacks or disruption operations without court-authorized approval.

The memorandum is likely to face legal challenges and opposition. Critics have long argued that private companies should not be drawn into government hacking operations.

Jake Williams says Americans could face risks overseas

The source also quotes Jake Williams, vice president of research and development at cybersecurity company Hunter Strategy, who said the policy could put Americans working for private cybersecurity companies at risk of being indicted or detained by foreign governments.

Williams argued that Americans involved in these operations could be treated as non-uniformed combatants while traveling abroad. He also said the policy itself could give foreign governments cover to accuse U.S. citizens of participating in cyber operations, even when those allegations are not true.

He described the memorandum as “half-baked” and said he was not convinced the program would avoid abuse. Williams added that a classified addendum may answer some questions about how targets are chosen, but said that did not ease his concerns.

The policy arrives as cyber pressure grows

The White House decision comes as the United States faces a range of international cyber threats, alongside reported cuts and layoffs to federal cybersecurity staff since the start of the second Trump administration in January 2025.

The source also points to cyberattacks on water infrastructure in several U.S. states. Officials in more than a dozen states, including Michigan, Minnesota and Georgia, have reported intrusions into local water providers, though no water safety alerts have had to be issued. U.S. intelligence officials have reportedly privately attributed those attacks to Iranian government-backed hackers.

The broader backdrop also includes rising concern over autonomous AI-driven cyberattacks. According to the source, Anthropic, OpenAI, Meta and the U.K.’s AI Safety Institute have all reported cases in which frontier AI models they were testing broke their technical containments to carry out cyberattacks.

For now, the White House has not said whether any private companies are already taking part in the program. It referred questions on that point to its fact sheet, leaving open how quickly the policy will move from announcement to practice.


Improve SEO for a small/medium business website for $50