White House taps security firms for offensive hack-back operations

The White House has taken a significant step in its fight against foreign cybercrime organizations by signing a memo that enables private security companies to participate in offensive hack-back operations. The national security presidential memorandum (NSPM) instructs the National Coordination Center (NCC) to establish a program that would allow these firms to apply for approval to conduct cyber operations targeting transnational criminal groups under the authority of the US government.

The program, which is overseen by executive directors designated by the Justice and Homeland Security departments, aims to disrupt foreign organizations involved in ransomware attacks, phishing campaigns, financial fraud, sextortion schemes, and impersonation scams. These types of attacks have resulted in significant losses for US consumers, with over $20.8 billion reported lost to cyber-enabled crime in 2025 alone.

To participate in the program, private security companies will undergo a rigorous vetting process before entering into contracts with one of the two departments. They must also maintain a bond or escrow of at least $1 million that will be forfeited if they fail to comply with contractual agreements. Furthermore, participating companies are required to immediately stop operations if they discover activity exceeding approved limits, including unintended targeting of US citizens or US-based systems.

The White House has emphasized the importance of this program in disrupting foreign cybercrime organizations and protecting US consumers from these types of attacks. Chris Wysopal, co-founder of Veracode, described the memo as “a pretty big shift in US cyber policy” and a major expansion of the private sector’s role in offensive cyber operations. Jason Kikta, former leader of the Cyber National Mission Force and CTO of Automox, likened it to “a perpetual motion machine for billable threats.”

The program is intended to leverage the capabilities of the US private sector to conduct cyber operations that would be difficult or impossible for the government to accomplish on its own. By partnering with private security companies, the White House hopes to disrupt and dismantle foreign cybercrime organizations and protect US consumers from these types of attacks.

In practical terms, this development means that private security companies will have a new opportunity to work closely with the government to conduct offensive cyber operations against foreign cybercrime organizations. While some experts have raised concerns about the potential risks and unintended consequences of such operations, others see it as a necessary step in the fight against cybercrime. As the White House continues to evolve its cyber policy, one thing is clear: the stakes are high, and the need for effective countermeasures has never been more pressing.

In light of this development, it’s essential for individuals and organizations to remain vigilant and take proactive steps to protect themselves from cyber threats. This includes staying up-to-date on the latest security patches, using strong passwords and multi-factor authentication, and being cautious when interacting with online services or clicking on suspicious links. By taking these precautions, we can all play a role in disrupting foreign cybercrime organizations and protecting our digital lives from these types of attacks.


Source: Bleeping Computer — 2026-08-13