Trump memo opens private hacking: 2 GOP 'privateer' bills in play
President Trump's Aug. 12 memo authorizing private companies to hack foreign cybercriminals raises unresolved questions under the Computer Fraud and Abuse Act and international law. Legal and RegTech professionals must assess liability, authorization bounds, and potential court challenges.
Beat this week
Last 7 days · Regulation
Impact 5.8/10 (+0.1 vs prior). Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 8 percentage points.
This story sits in Regulation — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
Legal briefing
Key takeaways
- President Trump's Aug.
- 12 memo authorizing private companies to hack foreign cybercriminals raises unresolved questions under the Computer Fraud and Abuse Act and international law.
- Legal and RegTech professionals must assess liability, authorization bounds, and potential court challenges.
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1The presidential memorandum was issued late Wednesday, August 12, 2026, according to WJCT and KUAF reporting.
- 2The memo could authorize private U.S. businesses to disrupt foreign organizations the government labels as cybercriminals or gather intelligence on those groups.
- 3It does not amend existing U.S. anti-hacking laws, including the CFAA, but mandates participating companies be contracted with the federal government.
- 4Two Republican congressmen introduced cyber "privateer" legislation after the Trump administration took office in 2025.
- 5Former NSC cyber policy official Joshua Steinman said potential targets include organized crime and money laundering operations.
- 6The memo does not grant full privateer authority and does not explain how private companies would legally lead government work.
There's a range of potential targets … like organized crime … people doing money laundering or other criminal activity.
Commenting on the presidential memorandum's scope
Analysis
For legal and RegTech practitioners, the Trump administration's Aug. 12, 2026 memorandum is less a cyber operations document than a stress test for the Computer Fraud and Abuse Act. It does not amend the anti-hacking statute, but it directs that participating private companies be federal contractors — a sentence that raises federal preemption, state law, and liability questions.
On August 12, 2026, the Trump administration issued a presidential memorandum that could authorize some U.S. businesses to hack, disrupt, or gather intelligence on foreign cybercriminals selected by the U.S. government. The memo, reported on August 15 by NPR member stations WJCT and KUAF, represents a dramatic departure from the traditional division of labor in which only government agencies conduct offensive cyber operations. It does not change existing anti-hacking laws, but it does mandate that any participating company be contracted with the federal government, creating a narrow contractual pathway for private-sector offensive action.
For legal and RegTech practitioners, the Trump administration's Aug.
The legal foundation is deliberately thin. The Computer Fraud and Abuse Act broadly bars unauthorized access to protected computers, with exceptions primarily for law enforcement and authorized government activity. The memorandum does not amend the CFAA or the Electronic Communications Privacy Act, and it does not fully explain how a private business would take the lead on work traditionally performed by the U.S. government, such as espionage or disruptive cyber operations. Instead, it appears to rely on federal contracting status as a form of authorization, a position that would likely invite immediate legal challenges from civil liberties organizations, foreign governments, and possibly technology companies whose infrastructure could be affected.
Joshua Steinman, who served as senior director for cyber policy on the National Security Council during President Trump's first term, said the range of potential targets includes organized crime groups and people engaged in money laundering or other criminal activity. That framing suggests the program is not limited to state-sponsored advanced persistent threats but could encompass a broad set of financially motivated criminal actors. The memo does not give private businesses the full authority sought by "cyber privateer" legislation, a term drawn from 16th-century naval warfare, but it elicited online praise from proponents of that idea.
Since the Trump administration took office in January 2025, two Republican congressmen have introduced legislation calling for cyber privateers to take the fight to foreign hackers. The new memorandum does not enact those bills into law, but it moves in the same direction. Private corporations have long worked with the federal government to disrupt cybercriminals, but largely as contractors fulfilling a support role rather than as lead actors in offensive operations. By contrast, this program would allow private businesses to conduct disruption or intelligence gathering directly against government-selected targets abroad.
For the cybersecurity and government contracting industries, the memorandum raises immediate commercial questions. Companies with offensive cyber capabilities — including incident response firms, threat intelligence vendors, and specialized government contractors — would need to assess whether participation is commercially viable given legal uncertainty, reputational risk, and the possibility of retaliatory attacks. The requirement to be a federal contractor may favor established defense and intelligence contractors with existing clearance infrastructure, but it could also open a new market for smaller firms that develop exploit tools or disrupt botnets. Yet no company has publicly stated an intent to participate, and the administration has not identified which agencies would oversee the program or how targets would be chosen.
What to Watch
Operating private offensive hacks against foreign perpetrators raises significant international and diplomatic risks. Foreign governments may view a U.S. company's intrusion into computers on their soil as a violation of sovereignty, even if the target is a criminal group. Attribution errors could result in damage to legitimate systems or provoke confidential retaliation against U.S. businesses and critical infrastructure. The memo provides no public mechanism for independent oversight, no standards for evidence before a target is selected, and no explanation of what happens if a private contractor exceeds the scope of its government contract. These gaps are likely to become the focus of congressional hearings and potentially litigation.
Looking ahead, the program's viability will depend on regulatory guidance, contracting rules, and the administration's willingness to defend the legal theory that federal contracting can authorize private hacking. If operationalized, it would alter the public-private boundary in cyberspace and may encourage other countries to adopt similar programs, eroding the norm that offensive cyber operations are a state function. Legal challenges could come quickly, and the outcome would shape not only this program but the future of the CFAA and private-sector hackback. For now, the memorandum is best understood as a policy signal rather than a fully formed operational framework.
Cite This Page
"Trump memo opens private hacking: 2 GOP 'privateer' bills in play." Legal & RegTech Intelligence Brief, August 15, 2026. https://getlegalbrief.com/story/trump-memo-private-hacking-legal-analysis
How we covered this story
Every story in our legal coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the legal space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled legal-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |