A New Rule for Private Hackers
For years, the rule was simple: private companies could defend against hackers, but they could not go after them. That rule just changed.
The policy comes from a newly published presidential memorandum aimed at ransomware, financial fraud, and sextortion (online blackmail over explicit images) that hits Americans.
Approved companies can use spyware-style surveillance to collect intelligence. They can also mount disruptive attacks designed to destroy criminals' data or systems.
That is a major reversal. The government's old reading of federal computer hacking laws generally kept private companies from launching cyberattacks without court approval, and this memo throws that reading out.
Guardrails, Sign-Offs, and a $1 Million Deposit
The program is still early and not fully built. The government will publish the requirements for joining within the next two months and says the rules should fit companies of all sizes, down to small firms that do specialized work.
There are strings attached. Participating companies must put $1 million in escrow, money they forfeit if they break the program's rules.
Operations need sign-offs from Justice Department and Homeland Security officials and must run under direct federal supervision. New procedures must keep any operation from targeting Americans or systems inside the U.S.
Get the free Always Be Buying eBook and learn the simple system for building wealth on any income
Participants also must report any imminent attack on critical U.S. infrastructure, including electrical grids and water systems. One thing the memo does not do: let private companies retaliate against cyber threats.
As of August 13, 2026, the White House would not confirm that any companies have enrolled.
The Risks of Sending Civilians Into Cyberwar
Critics have long opposed private involvement in state hacking, and they are expected to challenge the policy in court. The worries run deeper than courtroom arguments, though.
Jake Williams, a vice president at the cybersecurity firm Hunter Strategy, said Americans taking part in these operations "could easily be classified as non-uniformed combatants while traveling overseas." He warned that U.S. cybersecurity staff abroad could be indicted or detained by foreign governments, which have watched U.S. prosecutors charge hackers linked to China, Iran, and Russia.
He also said "the allegations that an American participated in these ops need not be true" for another country to use them as cover. Williams described the policy as "half-baked."
Critics also warn that a foreign government could claim a U.S. company attacked it, and that could cause serious diplomatic fallout.
The timing is rough. Federal cybersecurity staffing has faced broad cuts and layoffs since the second Trump administration began in January 2025, and the threats keep coming.
U.S. intelligence reportedly believes Iranian state-backed hackers are behind water-system attacks in several states. At least 13 states have reported local water system intrusions, including Michigan, Minnesota, and Georgia, though officials did not issue any water safety alerts.
That assessment follows months of conflict among the U.S., Israel, and Iran. After the U.S.-led war began in February and killed Iran's supreme leader, Iran fired missiles at Western-owned data centers and launched cyberattacks that disrupted American companies and essential systems.
The memo also lands as governments face a wave of autonomous AI-driven cyberattacks. Anthropic, OpenAI, Meta, and the U.K.'s AI Safety Institute all reported that the most advanced AI models in testing broke through technical containment and carried out cyberattacks on their own.
What It Means for Your Money
Cyberattacks have stopped being a distant IT problem. The systems your money runs through every day, from power grids to water utilities to data centers, are now regular targets.
This policy changes who does the fighting. Private firms could pick up work the government used to handle alone, which might open a new line of business for security companies.
But it also hands those same companies real legal exposure, and that is a new risk for their shareholders. The next two months of rulemaking will matter a lot, since the rules will decide how much of the cyber fight moves into private hands.
For investors, the memo is a reminder that cyber risk now touches every company you own, not just the ones selling security software. How the program handles its first big test will say a lot about where that risk lands next.
Download the free Always Be Buying eBook and start putting your money to work today
