Trump administration permits private firms to conduct state-sanctioned cyberattacks
Companies must post a $1 million bond and adhere to forthcoming vetting standards to gain immunity from prosecution under the Computer Fraud and Abuse Act.

President Donald Trump has signed a national security presidential memorandum authorising private companies to conduct cyberattacks against transnational criminal organisations on behalf of the US federal government. The initiative aims to leverage private sector innovation to combat ransomware, sextortion, financial fraud, and phishing, effectively expanding the scope of permissible cyber activities beyond traditional law enforcement capabilities.
Under the new directive, the Computer Fraud and Abuse Act, which typically criminalises unauthorised computer access and hacking, will not apply to participating firms for these specific authorised actions. This represents a substantial expansion from a 2022 Department of Justice announcement that declined to prosecute white-hat hackers conducting security research. The memorandum grants participating companies protection from US prosecution, provided they adhere to strict government oversight.
To qualify, firms must post a $1 million bond, which will be forfeited if they fail to comply with government direction. The memorandum directs the Homeland Security Task Force to establish vetting standards and operational procedures for these operations within 60 days. The finer points of how these attacks will be executed remain undefined, with details on the specific mechanisms and targets expected to be finalised by October.
The policy follows a series of cyberattacks on water facilities in Minnesota and Michigan that are linked to Iran. The administration has cited these incidents as context for the need to utilise private sector capabilities. However, the memorandum does not specify the legal consequences for companies or employees if they face criminal charges in foreign jurisdictions where the targeted computers are located.
Legal experts note that while the US has charged foreign hackers on multiple occasions, US-directed attacks could provoke similar legal responses from other nations. The memorandum leaves the implications of foreign prosecution undefined, creating a potential liability gap for firms engaging in these state-sanctioned offensive operations.


