Trump Admin Lets Loose the Cyber Pirates
The White House will give cybersecurity firms permission to conduct “offensive cyber operations aimed at disrupting criminal organizations,” Bloomberg reported on Thursday.
Trump’s administration has spent months waffling on the idea, which is substantially similar to the centuries-old practice of issuing letters of marque. That’s a type of document from the Age of Sail which extended official protections to private vessels to attack pirates and enemy vessels, a legal (depending on who you ask ) and regulated form of piracy known as privateering.
A fact sheet on the National Security Presidential Memorandum (NSPM) states the interagency National Coordination Center will split oversight of the program between two executive directors from the departments of Homeland Security and Justice. The order encourages security firms to voluntarily enter intelligence-sharing agreements with government agencies from the local to federal level, and propose and help carry out “cyber operations that address those threats.”
Currently, most “offensive” cyber operations are undertaken by profit-minded criminals, military units like U.S. Cyber Command, or intelligence agencies and their various proxies. That’s because they’re potentially both illegal and interpretable as acts of aggression, not to mention that they can invite revenge. Private companies, fearing liability issues, have tended to draw the line at what’s called active defense, a somewhat ambiguous term that covers tactics like seeking court orders to take down hacker infrastructure or setting up honeypots.
The NSPM fact sheet states the program’s overseers will develop “rigorous procedures for the review and conduct” of offensive cyber operations. Curiously, cybersecurity firms which want to participate will be required to hold $1 million in bond/escrow, which may be forfeited in the case of a contract violation.
The idea of hacking back isn’t new. In 2019, CyberScoop noted it had attracted the moniker of “ worst idea in cybersecurity ” among cyber policy types, with experts pointing out that it is hard to accurately identify perpetrators and could result in damaging crossfire between governments and private actors. Even Trump’s own officials have, at times, denied even considering it.
In March 2026, CyberScoop reported then-Office of the National Cyber Director senior adviser Thomas Lind had shot down growing speculation the White House would embrace private offensive operations, stating at a conference the administration is “not interested in fighting pirates with pirates.” National Cyber Director Sean Cairncross told attendees at a security summit in D.C. around the same time that private offensive cyber operations are “not what we’re talking about” when asking for more help from industry.
There’s good reason for hesitation. Obfuscation is an ubiquitous element of cyber attacks, as attackers go to great lengths to prevent detection (at least until the commencement of the attack) and are happy to exploit information asymmetry in any way possible.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on gizmodo.com — the content belongs to Gizmodo.