White House Opens Hack-Back Program to Private Firms
Trump memo directs the NCC to license private security firms for offensive cyber ops against foreign criminal organizations. $1M bond required for compliance.
Confirmed. President Trump signed a White House memo directing the National Coordination Center (NCC) to establish a program through which private security companies can apply for government authorization to conduct offensive cyber operations against foreign cybercrime organizations. Reported today by BleepingComputer and SecurityWeek.
Program is not yet operational. Application process and eligibility criteria: not published as of this writing.
What’s confirmed
- Memo signed. NCC is designated as the coordination and approval body.
- Framework envisions licensed offensive action — firms operating under government authorization, not freelance hack-back.
- Bond: contracts may require a $1 million forfeiture bond, surrendered on non-compliance with operational requirements.
- Target scope per current reporting: foreign cybercrime organizations. Domestic operations not addressed.
What’s unconfirmed — treat accordingly
Eligible firm criteria. Application timeline. Mission deconfliction with NSA and USCYBERCOM. CFAA liability exposure for NCC-authorized operators. Congressional notification requirements.
Analysis
Label: interpretive — not confirmed by current reporting.
The $1M bond is the structural tell. It’s a compliance choke-point: violate your operational mandate and you lose the bond, and presumably the authorization. Whether “fails to comply with operational requirements” is adjudicated by NCC, ODNI, DOJ, or some combination — and with what due process — isn’t addressed in current reporting. That gap matters.
Private offensive operations against foreign adversaries occupy legally ambiguous territory even with explicit authorization. The Computer Fraud and Abuse Act carves no general safe harbor for licensed hack-back against foreign targets. Whether this memo changes that for approved operators is unconfirmed.
Structural advantage in any application process will go to firms that already hold cleared personnel, active government contracts, and intelligence community relationships. In practice the eligible pool narrows fast.
What this means now
For most organizations: nothing immediately actionable. The program isn’t operational.
For firms that might seek authorization: legal and compliance review starts before the application window — not after. Watch NCC and CISA for official guidance.
The threat context this responds to is real: state-linked cybercrime crews — the kind documented in Operation Dream Job and the Jewelbug dual-ops case — operate at a tempo that traditional law enforcement channels can’t match. Whether licensed private operators change that calculus is a question that’s about to get tested.
Found this useful? Share it.


