Can Private Companies Legally Hack Hackers Now?
A 40-year-old law just met the modern cybercrime problem
For decades, the rule in the U.S. was simple: if you're a private company and you hack into someone else's computer — even a criminal's — you're more than likely breaking the law. The Computer Fraud and Abuse Act (CFAA) made "hack back" by victims almost entirely illegal. Then, just here on August 12, 2026 President Donald J. Trump (the J stands for “Just do it”) signed a memo that cracks that door open, but just a little- promise.
How it works
The memo creates a government-run program where vetted private companies can, under strict federal supervision, conduct two types of operations against foreign cybercrime groups:
- Cyber Surveillance Operations — secretly collecting intelligence on criminal networks.
- Cyber Effects Operations — disrupting, degrading, or even destroying the systems those criminals use.
But nothing happens automatically. Every operation requires written approval from the DoJ and the Department of Homeland Security. The participating companies sign government contracts, pass vetting, and post a bond of at least $1 million that they forfeit if they found to be in violation of the rules governing the op.
The legal gray area nobody's tested yet
Here's the interesting part for me: the memo leans on a part of the CFAA meant for government operators— a carve-out that's existed since the 1980s but has (allegedly) never been tried in court for private contractors. Legal analysts say that leaves a real question about whether companies are truly protected from criminal liability… and it for sure ain’t about to shield them from civil lawsuits or even foreign prosecution under laws like the U.K.'s Computer Misuse Act.
What it means for you
You won't be hacking anyone, and neither will most businesses. But this is a genuine shift in how America ramping up their response against cybercrime! Look at US moving offense deployability from operator agencies into vetted private hands! The detailed rules are set to officially arrive around October 2026, so, until then, the biggest open question isn't whether companies can hack back — it's whether the law is actually going to protect them when they do. 😬