Hacker working in office showing cyber ops

New White House Cyber Ops Order Appears to Authorize Digital Privateering

The White House has announced what appears to be a drastic policy change, authorizing some private companies to participate in offensive cyber ops against foreign entities designated as criminal. While the initial announcement reads like an establishment of a form of privateering for the digital age, most of the program’s terms have yet to be established and the ones presently announced put major restrictions on participation.

White House cyber ops order authorizes private surveillance and disruption actions

Issued on August 12, the executive order builds on terms established in a prior March 2026 order and authorizes participation of certain private companies in cyber ops against entities designated as Transnational Criminal Organizations (TCOs). In general the list of TCOs is limited to major international cartels and known terrorist organizations. Program participants will not be authorized to attack foreign governments.

The program will be established and run primarily by the National Coordination Center (NCC), with additional ongoing oversight by the Department of Justice and the Department of Homeland Security. Participants will be required to undergo a vetting process by and enter into contracts with these entities that clearly delineate their potential actions against TCOs.

Most of the fine details of the cyber ops program are to be established by mid-October, but the initial order does lay out some additional requirements for private participants. They will be screened for “appropriate levels of technical proficiency,” and will have to put up a bond or escrow of $1 million USD that will be forfeit if they violate the terms of the program.

The order also states that there is no specific size requirement for participants, and that smaller organizations may be authorized for “specialized or discrete tasks.” As to what those tasks are, the initial order specifies that cyber ops can involve espionage and disruptive “denial of service” attacks on authorized targets. However, it does not authorize “hacking back” in manners already proscribed by the Computer Fraud and Abuse Act (CFAA).

Key details still needed to evaluate impact of cyber ops order

The move may well be in response to China’s priority focus on cyber ops, with CISA issuing warnings in recent years that Chinese espionage personnel outnumber those in the US by 50 to 1. In large part that is due to outsourcing of hacking duties by the Chinese government to numerous private firms that specialize in espionage missions.

However, those Chinese firms appear to be greenlit to attack foreign governments and critical infrastructure on their own. The Russian government is also thought to have given tacit approval to its domestic criminal hacking groups to attack such targets, so long as they avoid domestic entanglements or causing major international incidents. The US cyber ops involvement would officially restrict private firms from getting involved with foreign governments or espionage, instead directing them to shut down foreign crime syndicates that cause millions to billions of dollars in damage via theft, fraud and business disruption.

In addition to keeping pace with China, the US government has stated that Iran has been engaging in a general campaign of cyber attacks since the beginning of the war and is likely responsible for a recent spate of breaches at local water providers in about a dozen states. While these intrusions were successful, none have caused any known water quality or safety issues as of yet. In late July the FBI issued a memorandum to critical infrastructure operators with industrial control systems from Rockwell, Schneider Electric and Siemens that they can expect attempts on them from Iranian hackers if they are exposed to the open internet.

Many additional questions remain about the cyber ops program, and may not be answered until the initial deadline for development comes in October. One is what level of liability participants might face beyond having to give up their $1 million bond. For example, it remains unclear how things would be handled should a disruption operation inadvertently spill over into foreign critical infrastructure. And if a company participates in such operations, it could mark their employees as criminals when they travel abroad. There are also substantial civil liberties questions, particularly if an operation ends up targeting American citizens living abroad.

Jake Williams, Faculty, IANS Research, expands on these potential concerns: “I think the whole strategy is half baked. Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas. The allegations that an American participated in these ops need not be true. The program even existing creates top cover for such an accusation.”

“Separately, the program seems as though it was written to be abused,” Williams adds. “It’s not clear how targeting would be established. If intelligence was 100% on a target being a TCO, then why not use existing legal authorities and existing government operators?”

Given the presently announced restrictions, the new cyber ops bill is likely to target scam and ransomware gangs based in Asia most heavily. This follows from a March executive order in which the administration called out foreign “scam centers” as TCOs and demanded that foreign governments take action against them once identified or face penalties such as sanctions, visa restrictions and cuts to foreign financial aid. While Chinese nationals are frequently involved with these scam centers they tend to be operated out of smaller Southeast Asian nations such as Thailand, Burma and Cambodia, with workers essentially enslaved after being caught up in human trafficking schemes that promise legitimate jobs.