
Vetted U.S. firms can now conduct surveillance and destructive cyber operations under federal supervision.
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works .
In March, Thomas Lind, then a senior adviser at the Office of the National Cyber Director, told a conference the administration had no plans to authorize private offensive operations. "We're not interested in fighting pirates with pirates," Lind said. National Cyber Director Sean Cairncross said the same week that companies running offensive campaigns weren't what the administration meant when it asked industry for more help.
The memorandum authorizes two categories of activity: "Cyber Surveillance Operations," meaning unauthorized access to foreign systems to collect intelligence while staying undetected, and "Cyber Effects Operations," meaning the disruption or destruction of systems and the data on them. A National Coordination Center manages the program, implementation guidance is due within 60 days, and eligibility rules will admit both large firms and smaller companies suited to specialized tasks. Any company that unintentionally hits a U.S. person or a system on U.S. soil must halt operations and notify the government immediately.
A foreign group qualifies as a target under the memo unless "clear intelligence exists" establishing it's institutionally part of a foreign government or wholly operated under one's direction. Ransomware crews that operate with state tolerance but not formal state control, a description that fits much of the Russia-based ransomware ecosystem, stay well within the target scope. The DOJ and DHS directors can't approve operations likely to cause loss of life or rise to an armed attack under international law.
The memo stops short of prohibiting such operations, with approval authority for them sitting in a classified annex. Participating companies can also sign commercial deals with other private firms, and with state and local agencies, to receive threat data and propose operations based on it.
NSA using Claude Mythos for 'offensive cyber operations,' report claims
Key considerations
- Investor positioning can change fast
- Volatility remains possible near catalysts
- Macro rates and liquidity can dominate flows
Reference reading
- https://www.tomshardware.com/tech-industry/cyber-security/SPONSORED_LINK_URL
- https://www.tomshardware.com/tech-industry/cyber-security/white-house-authorizes-private-companies-to-hack-foreign-cybercrime-groups#main
- https://www.tomshardware.com/membership
- This week on Tom's Hardware Premium: August 14, 2026 — Testing the BC-250, our interview with Intel's Robert Hallock, and a big week for optical
- PBS broadcaster loses access to 50TB of data comprising 70 years of TV history after contracted cloud storage vendor goes defunct — public TV channel sues Iron
- Catastrophic optical disc shattering blamed on cleaning chemicals and packing foam — another data preservation concern to add to bit rot and laser rot
- Best in Class: Stream PC Games and Study on the Same Laptop With GeForce NOW
- Devs blame Windows for VLC media player bug that causes 33-second delay when playing MP3 files — creators allege Microsoft Defender blocking plugin cache is to
Informational only. No financial advice. Do your own research.