Legalized "hack-back": Trump authorizes private companies to offensively retaliate against foreign cybercriminals

Cybersecurity Aug 13, 2026Add to bookmarks

Legalized "hack-back": Trump authorizes private companies to offensively retaliate against foreign cybercriminals
Illustration : Momiji Shirogane

A presidential memo directs the National Coordination Center to establish a regulated hack-back program. Private cybersecurity firms may apply for authorization to launch offensive attacks against foreign criminal organizations.

(1) What: An executive memo formalizing private hack-back

An executive memo signed by Donald Trump mandates the National Coordination Center (NCC) to establish a program allowing private cybersecurity firms to apply for authorizations for offensive operations against foreign criminal organizations. In plain terms: hack-back—long a legal gray area in the U.S.—now has an official framework, at least in intent.

The memo does not immediately grant access to hack-back. It instructs the NCC to build the program, including its eligibility criteria, limits, and controls.

(2) Who is impacted

For security firms: Those already operating in the offensive gray zone (takedowns of Command & Control, disruption of criminal infrastructure, sinkholing) now have a strong political signal—and a potential path to formal legitimacy.

For victims: The targets are explicitly "foreign cybercrime organizations"—ransomware groups, financial fraud, etc.—operating from abroad. Nation-states are theoretically excluded, but the line between organized crime and state actors is often blurred (Russia, North Korea, Iran).

For the CFAA: The Computer Fraud and Abuse Act historically prohibits offensive actions against third-party systems, even in retaliation. An executive memo can create an exception regime but does not change the law itself. A margin of legal uncertainty remains.

(3) What to do

The security community’s reaction is divided. Some experts welcome the clarification of engagement rules; others worry about the lack of explicit safeguards against misattributed operations (and collateral damage to shared infrastructure is real in such operations).

The CFAA and hack-back

The Computer Fraud and Abuse Act (1986) criminalizes unauthorized intrusions into third-party systems—even in retaliation. Legislative attempts to introduce a hack-back right (Active Cyber Defense Certainty Act, multiple versions since 2017) have never passed Congress. The Trump memo bypasses this blockage via executive action, without resolving the legal ambiguity for approved firms.

What to do now:

  • CISOs and security teams: No immediate action required. The program does not yet exist—wait for NCC guidance before considering any steps.
  • Security law firms: Begin documenting current "active defense" operations in anticipation of potential eligibility criteria.
  • Do not take any offensive initiative based solely on this memo—the legal framework remains incomplete, and CFAA exposure risk persists.
Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

6 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information