← Back to Freedom News

Freedom News / Technology & Cyber Policy

TECHNOLOGY & CYBER POLICY

Multiple outlets report Trump has signaled approval for U.S. companies to target cybercriminals; legal basis not public

Reporting from The New York Times, The Seattle Times and Business Standard says the administration has given a green light to private offensive cyber actions, but none of the reports includes a public memo or legal text spelling out authority or limits.

By Freedom News Staff • Freedom News Media • August 14, 2026

What multiple news reports say

Reporting by The New York Times, The Seattle Times and Business Standard states that the White House has effectively given U.S. companies the green light to aim hacks at cybercriminals. The accounts present this as a shift in U.S. practice that would encourage or permit private-sector offensive cyber actions—sometimes called "hack back" or "active defense."

None of the three supplied reports published a copy of a formal White House directive, Department of Justice opinion, Office of Legal Counsel memo, or other primary document that would specify the legal authority, operational limits, or oversight mechanisms for such activity. The summaries reviewed for this article therefore reflect independent reporting of the development rather than a first‑hand review of any underlying legal text.

Why the underlying document matters — and what is not yet clear

When government officials signal a change that could authorize private offensive cyber operations, the exact legal instrument matters because it defines who may act, under what circumstances, and who bears legal and diplomatic responsibility. A formal White House statement, an Attorney General directive, a Justice Department legal opinion, or a change in criminal enforcement policy would carry different legal and practical consequences.

The reports do not identify the precise statutory or regulatory authority being invoked, whether the change would take the form of executive guidance, a formal memo from the Office of Legal Counsel, a DOJ policy statement, or an update to Department of Homeland Security or CISA guidance. They also do not include any text that would define limits such as geographic scope, targets excluded (for example, victims or U.S. persons), required reporting or approval processes, or protections against civil or criminal liability for participating companies.

Because that text is not published in the supplied reporting, key legal questions remain: would private actors be shielded from prosecution under federal statutes that prohibit unauthorized access to computers, who would adjudicate disputes over attribution and responsibility, and how would liability to victims be handled if an operation goes wrong?

Context and customary concerns about private offensive cyber actions

Policy debates around whether private companies should be allowed to undertake offensive cyber measures are longstanding. Advocates argue that in some cases active defense by private parties can disrupt criminal operations more quickly than law enforcement can. Critics warn that allowing private offensive operations raises practical and legal risks, including misattribution, collateral damage to innocent systems, escalation with other states or criminal groups, and conflicts with existing criminal statutes and international law.

Where reporting does not provide the legal text, readers should understand that authorization in principle is not the same as a clean legal carve-out. Existing federal law includes statutes that criminalize unauthorized computer access and related activity; absent a clear, public safe‑harbor or statutory amendment, companies that perform offensive cyber operations could still face criminal or civil exposure. The reports reviewed do not document any new statutory safe-harbor being enacted.

Operational and diplomatic risks the reporting highlights

Even without the underlying memo, the cited reporting makes clear why cybersecurity professionals and foreign-policy observers treat the question as consequential. Identifying the origin of an attack with certainty is often technically difficult; private countermeasures risk striking the wrong targets. Mistakes can damage critical infrastructure, harm innocent third parties, or trigger retaliatory action by other states that view such countermeasures as extraterritorial use of force or unauthorized interference.

The reports do not include comprehensive reactions from cybersecurity firms, civil‑liberties organizations, or allied governments. Absent those documented responses, it remains an open question how industry will respond operationally and whether Congress, foreign partners, or courts will push back or seek clearer rules and oversight.

What to watch next

Because the underlying legal instrument is not included in the supplied reporting, the immediate items to watch are any publication of a White House statement, a Justice Department or Office of Legal Counsel opinion, departmental guidance from CISA or FBI, and statements from congressional committees that oversee cyber policy. Those documents and statements would show the legal mechanics: who can act, what approvals are required, what limits apply, and how accountability will be enforced.

Observers should also watch for rapid vendor and industry statements clarifying whether any private offensive actions will be undertaken, how insurers treat liability for such operations, and whether international partners issue diplomatic protests or seek multilateral rules. Absent public legal text, reporters and oversight bodies should press for the specific language that authorizes or constrains private offensive cyber measures.

Sources reviewed