U.S. Authorizes Private Cyberattacks With $1 Million Escrow as Critics Warn of Legal Risks
Updated
Updated · TechCrunch · Aug 13
U.S. Authorizes Private Cyberattacks With $1 Million Escrow as Critics Warn of Legal Risks
3 articles · Updated · TechCrunch · Aug 13
Summary
A new presidential memorandum lets vetted private firms conduct offensive cyber operations against international criminal gangs and hackers under federal supervision—the first such U.S. authorization.
The program allows surveillance and disruptive attacks, including spyware use and destruction of criminals’ data or systems, but stops short of permitting companies to independently “hack back.”
Companies must post $1 million in escrow, notify the government of imminent attacks on critical infrastructure, and secure Justice and Homeland Security sign-offs; detailed guidance is due within two months.
Critics say the shift could trigger legal challenges, diplomatic blowback and risks for U.S. cybersecurity workers abroad, who could face foreign accusations tied to government-backed operations.
The policy comes as Washington cites growing ransomware, scams and sextortion threats, state water systems report intrusions linked privately to Iran, and AI-driven cyberattacks spread globally.
Will outsourcing offensive cyber operations actually stop ransomware, or simply invite devastating retaliation against American businesses?
Could unleashing private tech companies to hack foreign criminals accidentally trigger an uncontrollable global cyber war?
What happens when a corporate cyber counterattack mistakenly disrupts a foreign government's critical infrastructure?
U.S. Authorizes Private Companies to Launch Offensive Cyberattacks: The August 13, 2026 Memorandum and Its Global Risks
Overview
In August 2026, the U.S. government, facing rising AI-driven cyber threats, Iranian cyberattacks, and major losses from cybercrime, authorized vetted private companies to launch offensive cyber operations against transnational criminal groups. These firms must contract with federal agencies, undergo strict vetting, and post a $1 million bond, which they forfeit if they break the rules. While this policy aims to strengthen national cyber defense, it exposes companies to legal risks under U.S. and foreign laws, makes them targets for retaliation by hostile groups, and risks collateral damage to innocent networks. The move also sets a global precedent, prompting adversaries to justify their own private cyber operations and straining international alliances.