The Mercenary Memo: How Trump Just Privatized America’s Cyber Offense
By Vladimir Tsakanyan, PhD · Center for Cyber Diplomacy and International Security · cybercenter.space
Executive Summary
On August 12, 2026, President Donald Trump signed a National Security Presidential Memorandum that authorizes vetted American companies to conduct offensive cyber operations — “cyber surveillance operations” and “cyber effects operations” — against foreign criminal organizations, under the direction and control of the U.S. government. On September 9, the FBI released its first comprehensive public cyber strategy: a four-pillar blueprint that calls for more frequent disruption operations, quicker victim warnings, wider AI adoption, and a larger role for private industry — with dedicated teams building tailored strategies for “offensive hacking” operations.
This analysis argues that the two documents, read together, mark a structural shift in American cyber statecraft: Washington is privatizing a slice of its cyber offense. The memorandum is not a “hack back” law — the companies will not be freelancing vigilantes, and the Computer Fraud and Abuse Act still bars unilateral private hacking. But the U.S. government will now pay private cybersecurity firms to “manipulate,” “degrade,” “disrupt,” and “destroy” foreign adversary networks on its behalf. As Chris Wysopal of Veracode put it: “Not exactly ‘hack back,’ but definitely a major expansion of the private sector’s role in offensive cyber operations.”
The risks are not hypothetical. Microsoft’s Nick Carr, who ran the company’s global cybercrime and ransomware intelligence team for nearly four years, warns that attribution in criminal operations is so difficult that “people are regularly and willingly wrong on pretty important incidents” — and a misattributed disruption operation against infrastructure shared with a foreign state risks interstate escalation, a danger independent researcher Dr. Lukasz Olejnik flagged immediately. The program’s guardrails — 60-day operating procedures still being written, no express immunity for participating companies, and a red line drawn only at “loss of life” or “armed attack under international law” — remain drafts. What is being built here is the institutional machinery for a new kind of state-contracted cyber violence, and the details are being worked out in the dark.
1. The Memorandum: What Trump Actually Signed
The National Security Presidential Memorandum, signed August 12, 2026, builds on an executive order issued in March, Combating Cyber Crime, Fraud, and Predatory Schemes Against American Citizens, which directed agencies to take “rigorous actions” against cyber-enabled crime. The memorandum’s language is blunt about the motive: despite being “the most innovative and technologically advanced in the world,” the American private sector’s offensive cyber capabilities have “historically been underutilized” in the fight against criminal networks operating in cyberspace.
The directive is equally blunt about the method. The President ordered his administration to “leverage the capability and innovation of the private sector to help conduct these cyber operations under the direction, control, and authority of the U.S. Government.” The Homeland Security Task Force’s National Coordination Center (NCC) — a body stood up in 2025 — is instructed to “create, manage, and maintain a Program” that authorizes vetted U.S. companies, the “Participating Companies,” to conduct two kinds of operations against “foreign Cyber-Enabled Transnational Criminal Organizations” (CE-TCOs):
- Cyber Surveillance Operations — intelligence gathering on foreign criminal infrastructure, which the memo itself acknowledges will “inevitably involve some disruption or manipulation of systems” in order to stay undetected.
- Cyber Effects Operations — defined, in the memo’s words, as “the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon.”
The White House’s framing is a crime-fighting one. The fact sheet cited ransomware attacks, financial frauds, and other crimes run by foreign-based criminal organizations — referred to in the memo as “transnational criminal organizations.” It pointed to figures showing American consumers lost more than $20.8 billion to cyber-enabled crime in 2025, while 73 percent of U.S. adults have experienced some kind of online scam or attack. As Joshua Steinman, who served as senior director for cyber policy on the National Security Council during Trump’s first term, told NPR: “There’s a range of potential targets … like organized crime … people doing money laundering or other criminal activity.”
The targets are defined broadly: CE-TCOs are “any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests.” One notable carve-out, reported by The Register: the definition excludes entities directly associated with, or operating wholly on behalf of, foreign governments — the intelligence agencies’ territory, in other words, is off-limits to the contractors.
The control structure is government-run end to end. Participating companies must enter contractual agreements with the Department of Justice or the Department of Homeland Security and undergo “rigorous vetting.” Proposed operations go to co-executive directors appointed through DOJ and DHS, who sign off on real-world actions. The memo permits only “limited” operations, demands compliance with the Constitution, U.S. laws, and relevant international agreements, and draws two red lines: operations may not proceed if they would result in loss of life or serious injury, or if they would “rise to the level of use of force or armed attack under international law.” The screening criteria — technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence and reliability — are to be drafted within 60 days of signing, with explicit direction that the bar must allow both large and small companies to participate. The directors will report the program’s status to the National Cyber Director and the Homeland Security Advisor.
Perhaps the most consequential clause is the one that extends the program’s reach beyond the contracting firms themselves. The memorandum creates a framework for participating companies to enter agreements with other private entities, as well as federal, state, local, tribal, and territorial agencies, to gather threat information and propose cyber operations. A vetted company could, in principle, commission threat intelligence from firms outside the program and feed it into government-approved operations — a supply chain for state-sponsored cyber violence that extends deep into the commercial security industry.
2. The FBI’s Strategy: Faster Disruption, Wider Industry Role
Less than a month later, on September 9, 2026, FBI Assistant Director of the Cyber Division Brett Leatherman unveiled the bureau’s new cyber strategy at the Billington Cybersecurity Summit — the FBI’s first comprehensive public cyber strategy covering both criminal and national-security threats. Previous plans were classified or siloed inside threat-specific teams; this one is unclassified and has no classified annex, though Leatherman said threat-specific teams are developing detailed classified strategies for field-office use.
The strategy rests on four pillars: take the fight to the adversary; commit to victims through fast intelligence-sharing, direct notification, and help containing and recovering; build partnerships across government, allies, and industry; and strengthen the FBI itself — recruiting top cyber talent and deploying AI tools to triage data, support attribution, and accelerate malware analysis, “under human review and legal controls.”
The operational thrust is speed. Leatherman told reporters the bureau wants to move more regularly against hackers rather than waiting to be perfectly positioned: “If we can’t take action right now, let’s not wait six months till we’re positioned to take action,” he said, pointing to Cyber Command and authorities in Britain and Japan as potential partners. The strategy directs the FBI’s 56 field offices and overseas cyber personnel to coordinate investigations, help compromised organizations, and expand partnerships with government agencies, foreign authorities, and industry — and it calls for wider use of AI tools that could cut the time needed to warn organizations about threats.
The context matters. The FBI has already sharply increased the tempo of its disruption operations in recent years — takedowns targeting a Russian military intelligence agency’s router botnet, domains the Chinese government used to target U.S. critical infrastructure, and the AlphV ransomware gang. The new strategy formalizes that tempo and moves it “beyond the ad hoc.” And one detail in the Cybersecurity Dive reporting deserves attention: teams focused on specific kinds of operations, including “offensive hacking” and investigating operational-technology breaches, will develop their own tailored strategies. The bureau now has offensive-hacking teams writing their own playbooks.
Read alongside the August memorandum, the strategy is a demand signal. Nextgov/FCW’s reporting on the strategy explicitly connects the two: the FBI document arrived “as the Trump administration develops a program allowing vetted U.S. companies to conduct cyber operations against foreign criminal organizations under federal supervision,” with DOJ and DHS still working through implementation guidance. The bureau wants faster disruption; the memorandum offers it a new instrument — contractor-operated cyber effects — with which to disrupt.
3. The Legal Architecture: Government-Contracted Offense, Not Hack-Back
The most important thing to understand about the memorandum is what it is not. It is not a general “hack back” authorization. As legal analysts at WilmerHale observed, nearly every aspect of the program is built around government contracts, government approval, and government direction and control: participating companies operate under agreements with DOJ or DHS, submit proposed operations to government officials for review, and may act only after receiving federal authorization. The program “does not appear to authorize private offensive cyber operations in the commonly understood sense.”
This distinction is doing heavy legal lifting. U.S. anti-hacking law — above all the Computer Fraud and Abuse Act — broadly bars people and businesses from hacking digital infrastructure, with narrow exceptions for law enforcement. As NPR noted, the memo does not change those laws; instead it mandates that any participating company be contracted with the federal government, which is the mechanism by which private hands obtain a lawful basis to do things the CFAA would otherwise prohibit. Defensive measures inside a company’s own network were always permissible; intruding into an attacker’s systems or impairing their data was not. The memorandum threads that needle by making the companies instruments of the state rather than independent actors.
That thread is thinner than it looks. The memorandum does not expressly grant participating companies immunity or indemnification, WilmerHale and eSecurity Planet both note — though that absence does not establish that contractors will bear all liability either. The allocation of risk will depend on the government contracts, the implementing procedures, insurance coverage, and applicable law. For the firms considering participation, the open questions are responsibility for collateral damage, incorrect attribution, retaliation, and operations affecting third-party infrastructure. Until the NCC publishes its operating procedures — due within 60 days — liability, indemnification, data use, and insurance coverage are all undecided. Companies are being invited to sign up for state-authorized offensive cyber operations before the rules that govern their legal exposure exist.
The international-law posture is asserted, not demonstrated. The memorandum promises compliance with “relevant international agreements” and draws its armed-attack red line in the language of international law — but the very existence of a government program paying private firms to degrade and destroy foreign networks, in cyberspace, against criminal (not military) targets, sits in legal territory no treaty has settled. The UK’s Supreme Court recently held in Kingdom of Bahrain v. Shehabi that foreign states carrying out hacking operations against individuals in the UK are not entitled to state immunity from tort claims — a ruling WilmerHale cites as underscoring the general legal risk surrounding cross-border cyber activity. Washington is building its program in a legal fog, and the fog extends to the foreign jurisdictions where these operations will land.
4. The Community Reacts: “A Big Shift” — and Three Warnings
The cybersecurity community’s response was immediate and split between welcome and alarm. Chris Wysopal, co-founder of Veracode, called the memorandum “a ‘big shift’ in US cyber policy” on X: “Not exactly ‘hack back,’ but definitely a major expansion of the private sector’s role in offensive cyber operations.” That formulation — not vigilante justice, but a state expanding its offensive bench — is the clearest single-sentence description of what happened.
Then came the warnings, and they cluster around three risks.
Attribution. Nick Carr, technical director of Microsoft’s Threat Intelligence Center and a former chief technical analyst at CISA, spoke from direct experience: “My biggest concern with private sector offensive action vs crime – having run the global cybercrime & ransomware intelligence team for almost four years – is just how difficult attribution in criminal operations is, and how few organizations can repeatably do it right (including certain gov agencies). People are regularly and willingly wrong on pretty important incidents.” His caveat — that the program could be designed to ensure better attribution work — is the thin thread of optimism. The government will have to certify that a target is a criminal organization before contractors act; the history of attribution suggests that certification will sometimes be wrong.
Escalation. Dr. Lukasz Olejnik, an independent cybersecurity and privacy researcher and consultant, warned that the license to destroy cyber-controlled infrastructure could hit state-linked systems and raise the risk of interstate escalation and conflict. The concern is structural: criminal infrastructure routinely shares hosting, cloud tenants, and transit networks with systems that touch state functions — or systems a foreign government believes touch its functions. An operation meant for a ransomware crew’s command servers can look, from the target’s capital, like an attack on the state. The memorandum’s armed-attack red line is a legal abstraction; adversaries will not necessarily apply it the way Washington’s lawyers do.
Collateral damage. Pareekh Jain, CEO of Pareekh Consulting, told CSO that “avoiding collateral damage is extremely hard,” noting that criminals “hide inside real company networks, hack smart home devices, and rent standard cloud servers using stolen credit cards.” The infrastructure the contractors will be authorized to “manipulate, disrupt, degrade, and destroy” is shared, rented, and compromised — other people’s servers, other people’s cloud instances, other people’s routers. “Cyber effects” operations against such targets have a blast radius problem that no amount of government oversight fully solves, because the information the overseers need to bound the blast radius is precisely what criminal targets are best at hiding.
5. The Privateers Are Back — As Contractors
The historical analogy arrived almost immediately. “The United States just revived privateering for the digital age,” wrote Jeff Gray, who led training for DHS’s emergency response team and now leads incident response training at CISA, in an essay for Nextgov. The analogy is literal: in the 17th and 18th centuries, governments issued letters of marque authorizing privately owned ships to attack foreign vessels — the legal distinction between a privateer and a pirate was the government’s commission. Gray acknowledges the term is not a perfect fit — letters of marque are granted by Congress, not the president — but insists the substance holds: “The government is authorizing private actors to conduct offensive cyber operations on its behalf, under its control. That’s privateering.”
The idea has been circling Washington for years. TRM Labs’ Ari Redbord described the concept as effectively granting “cyber letters of marque,” resurrecting long-standing fears about escalation and collateral damage. Two Republican congressmen — Senator Mike Lee’s Cyber Letters of Marque and Reprisal Act in the Senate and Representative David Schweikert’s Scam Farms Marque and Reprisal Authorization Act of 2025 in the House — introduced bills to formalize the privateer model, invoking Congress’s Article I power to “grant Letters of Marque and Reprisal,” unused since the War of 1812. Administration officials discussed privateering contracts in closed-door meetings as far back as 2025, Nextgov reported, though the consensus was that a 200-year-old maritime authority would not cleanly map onto cyberspace and that a modern, tailored authorization would be needed.
The August memorandum is that tailored authorization — built by presidential memorandum rather than statute, and directed at criminal organizations rather than nation-state adversaries. It stops well short of the Lee and Schweikert vision of independently commissioned cyber privateers: the companies here are supervised contractors, not commissioned corsairs. But the direction of travel is unmistakable. One cybersecurity executive told Nextgov the logic plainly: “Instead of a law-enforcement person pushing the button, it will be a private-sector person” — and predicted that “every Israeli cyber startup will jump at the chance.”
Gray also offered the strategic rationale, and its honesty is refreshing: he called the strategy “strategically sound” while predicting it would provoke a short-term increase in attacks and, over the longer term, cause adversaries to shift tactics, accelerate operations, and gain additional “cover” to hide their operations. His observation about Russia — which has been “doing this sort of thing for years,” enlisting or coercing private companies and groups to carry out cyberattacks against Western targets — is the uncomfortable mirror. Washington is formalizing, with lawyers and vetting procedures, a model of state-contracted cyber violence that Moscow has practiced informally and deniably for a decade. The difference is oversight and legality. Whether adversaries see that difference, in the moment a server farm goes dark, is the open question.
The context of urgency is real. CrowdStrike reported in February that AI-assisted cyberattacks rose 89 percent in 2025. The March executive order, the August memorandum, the September FBI strategy, and a Pentagon cyber strategy expected this month — previewed as emphasizing offensive operations, AI adoption, and closer industry ties — form a coherent sequence: an administration that has decided the state cannot fight this war alone and is reaching for every available instrument, including the country’s commercial cyber arsenal.
6. Why It Might Go Wrong
Three structural problems could make this program fail on its own terms — or succeed in ways Washington will regret.
The attribution gap is load-bearing. Every operation under the program rests on the government’s claim that the target is a criminal organization and not a state, a legitimate business, or a mixture of all three. Carr’s warning is the practical version: even government agencies get attribution wrong “regularly and willingly” on important incidents, and criminal infrastructure is designed to be misattributable — bulletproof hosts fronted by compromised routers, cloud instances rented with stolen identities, command servers nested inside legitimate corporate networks. The program’s design acknowledges this by requiring government review of proposed operations. But review is only as good as the intelligence feeding it, and the program’s own commercial agreements clause invites participating companies to commission outside firms to gather that intelligence — widening the circle of people with incentives to produce actionable-looking targets.
The escalation ladder has no private-sector rungs. When a government agency conducts a cyber operation, the target state can read it through the grammar of statecraft: a law-enforcement action, an intelligence operation, an armed attack. When a company degrades infrastructure under government contract — with the 60-day procedures still unpublished, the liability regime unresolved, and the operation’s existence possibly never acknowledged — the target state sees an ambiguous event and must decide what it is. Olejnik’s warning about interstate escalation is really a warning about misreading: the memorandum draws its red lines in American legal categories, but the consequences will be interpreted in Beijing, Moscow, and Tehran according to their own. An operation that destroys a server cluster shared between a ransomware crew and a state-linked telecom is a law-enforcement success in Washington and a provocation in the target’s capital.
The talent and accountability question is unanswered. The memorandum requires that participation criteria “enable involvement from large and small companies,” and one executive’s prediction that foreign startups will “jump at the chance” points to the incentive structure: the program creates a market in government-commissioned offensive cyber operations. Markets optimize for volume and price, not restraint. The federal government’s oversight apparatus — co-executive directors at DOJ and DHS, written approval for each operation, 60-day procedures — is designed for a deliberate, small-scale program. Whether it can govern a competitive industry of offense-for-hire firms, some of them young and hungry, without becoming a rubber stamp is unproven. And the absence of express immunity or indemnification means the first wrong-target incident will produce a legal and political fight — over who ordered what, who knew what, and who pays — that the program’s architects have chosen not to preempt.
None of this is an argument that doing nothing was working. Americans lost more than $20.8 billion to cyber-enabled crime in a single year; ransomware crews operate from safe-haven jurisdictions with impunity; the FBI’s disruption tempo, while rising, has not bent the curve. The administration’s diagnosis — that private-sector capability is being underutilized while criminals exploit the gap — is not wrong. The question is whether formalizing the privateer model, under procedures still being written, against adversaries who hide inside civilian infrastructure, produces deterrence or merely produces more, faster, and harder-to-control cyber conflict.
Conclusion: The Privatization of Cyber Offense
Two documents, one month apart, tell a single story. The August memorandum gives private American companies a government commission to surveil, degrade, disrupt, and destroy foreign criminal networks. The September FBI strategy gives the bureau a mandate for faster, steadier disruption — and an explicit invitation for industry to join the fight. Together, they move American cyber policy across a line that two decades of debate treated as fixed: the monopoly of the state over offensive cyber operations is being opened, by contract, to the private sector.
The defenders of the program have a case. The offensive toolkit of a modern cybersecurity firm is extraordinary; leaving it on the bench while ransomware crews loot the country is a choice with a body count measured in hospital outages and emptied retirement accounts. The government’s direction-and-control architecture is, on paper, a serious attempt to avoid the vigilante chaos that “hack back” has always threatened. And the red lines — no loss of life, no armed attack under international law — are real constraints, if they are honored.
But the critics are describing the world as it is. Attribution is hard and often wrong. Criminal infrastructure is entangled with civilian and state systems. Adversaries will not read American legal categories the way American lawyers do. The liability regime is unwritten. The procedures are drafts. And the market being created — government contracts for offensive cyber effects — will reward the firms that act fastest and most often, not the ones that are most careful.
Washington has decided that the cyber war against criminal organizations can no longer be fought by the state alone, and it has hired the private sector to fight it. That is the “big shift” Chris Wysopal named. Whether it is a triumph of American ingenuity or the moment the United States discovered that commissioning digital privateers was easier than controlling them will be decided in the first operations — and in the first incident where the target turns out to have been someone else’s infrastructure, someone else’s state, or someone else’s war. The marque has been issued. The sea is full of ships flying the wrong flag.
Vladimir Tsakanyan is a cybersecurity policy analyst and political commentator covering cyber diplomacy, geopolitical threat intelligence, and the intersection of technology and national security.
Sources: 1. Infosecurity Magazine, “Trump Authorizes Private Sector Participation in Offensive Cyber Operations,” September 2026 — https://www.infosecurity-magazine.com/news/trump-private-offensive-cyber/ 2. Nextgov/FCW, “New FBI cyber strategy seeks faster action against hackers, larger industry role,” September 9, 2026 — https://www.nextgov.com/cybersecurity/2026/09/new-fbi-cyber-strategy-seeks-faster-action-against-hackers-larger-industry-role/415869/ 3. Nextgov/FCW, “As warfare becomes engineering, the era of the digital mercenary dawns,” August 14, 2026 — https://www.nextgov.com/cybersecurity/2026/08/warfare-becomes-engineering-era-digital-mercenary-dawns/415442/ 4. Reuters, “Trump signed memo to allow use of cyber tools to target transnational criminal organizations, White House says,” August 12, 2026 — https://www.reuters.com/world/trump-signed-memo-allow-use-cyber-tools-target-transnational-criminal-orgs-white-2026-08-12/ 5. Nextgov/FCW, “Trump admin empowers private US firms to go after transnational cybercriminals,” August 2026 — https://www.nextgov.com/cybersecurity/2026/08/trump-admin-gives-private-us-firms-ability-go-after-transnational-cybercriminals/415398/ 6. FedScoop, “The White House looks to the private sector in a new offensive hacking operations memo,” August 2026 — https://fedscoop.com/radio/president-donald-trump-signed-a-national-security-memorandum-wednesday/ 7. The Register, “Trump wants to grant private cyber firms a license to hack back,” August 13, 2026 — https://www.theregister.com/security/2026/08/13/trump-wants-to-grant-private-cyber-firms-a-license-to-hack-back/5287420 8. Computer Weekly, “Trump enlists private sector for offensive cyber operations,” August 17, 2026 — https://www.computerweekly.com/news/366648818/Trump-enlists-private-sector-for-offensive-cyber-operations 9. NPR/WKYU, “Trump administration wants to allow companies to hack foreign cybercriminals,” August 15, 2026 — https://www.wkyufm.org/news/2026-08-15/trump-administration-wants-to-allow-companies-to-hack-foreign-cybercriminals 10. WilmerHale, “Trump Administration Directs Establishment of Program for Private-Sector Participation in Cyber Operations Against Transnational Criminal Organizations,” August 2026 — https://www.wilmerhale.com/api/sitecore/module/pdfgeneration?itemurl=%2fen%2finsights%2fclient-alerts%2f20260818-trump-administration-directs-establishment-of-program-for-private-sector-participation-in-cyber-operations-against-transnational-criminal-organizations&itemid=%7b5babc934-0d8c-4159-8238-36e3f010e65c%7d 11. Cybersecurity Dive, “New FBI cyber strategy promises increase in adversary disruptions,” September 2026 — https://www.cybersecuritydive.com/news/fbi-cybersecurity-strategy-disruptions-information-sharing/829913/ 12. ExecutiveGov, “FBI Releases Four-Pillar Cyber Strategy,” September 2026 — https://www.executivegov.com/articles/fbi-releases-cyber-strategy-four-pillars 13. eSecurity Planet, “President Trump Signs Memo Expanding Private Sector Role in Offensive Cyber Operations,” August 2026 — https://www.esecurityplanet.com/cybersecurity/news-trump-private-sector-offensive-cyber-operations-us/ 14. Nextgov/FCW, “An 18th-century war power resurfaces in cyber policy talks,” May 2025 — https://www.nextgov.com/cybersecurity/2025/05/18th-century-war-power-resurfaces-cyber-policy-talks/405526/?oref=ng-skybox-post 15. The Register, “Bill would give hackers letters of marque against US enemies,” August 2025 — https://www.theregister.com/security/2025/08/21/bill-would-give-hackers-letters-of-marque-against-us-enemies/835732?td=keepreading


Leave a comment