Skip to main content
Geopolitics & DefenseGovernment & Policy

US Authorizes Private Cyber Firms to Strike Foreign Targets

Government briefing room with podium and chairs in natural daylight.

"The United States just revived privateering for the digital age," wrote Jeff Gray, who led training for DHS’s emergency response team and currently leads incident response training with the Cybersecurity and Infrastructure Security Agency.

The presidential memo and its authorities

A White House presidential memo, announced Wednesday, directs the U.S. government to pay vetted private cybersecurity companies to take offensive actions against foreign adversary computer networks. The memo authorizes private firms to “manipulate,” “degrade,” “disrupt,” and “destroy” those networks, while forbidding companies from taking actions that could “result in the loss of life or serious injury.” The policy requires companies to be vetted and places supervision under the departments of Justice and Homeland Security.

Private actors: "privateering" and practical limits

Commentators inside and outside government immediately reached for history and caution. Jeff Gray framed the new approach as a revival of privateering — the maritime practice in the 17th and 18th centuries in which governments issued letters of marque to authorize private captains to attack enemy shipping. Gray also acknowledged the analogy is imperfect: letters of marque historically were granted by Congress, not the president. Still, he summarized the breaking point plainly: “The government is authorizing private actors to conduct offensive cyber operations on its behalf, under its control. That's privateering.”

Supporters argue the move fills a capability gap. The memo itself argues that “American businesses’ innovative capabilities have historically been underutilized” to “secure a critical offensive cyber advantage for the United States.” A founder of a prominent U.S. cybersecurity firm that works with the U.S. government said the policy “makes sense,” warning that AI will increase the volume of attacks and that expanding takedown activity is appropriate: “There will be more cyberattacks for sure, so I do think you want to expand the takedown activity as well.” That same executive predicted a change in who ultimately executes actions: “Instead of a law-enforcement person pushing the button, it will be a private-sector person.”

AI, escalation, and the changing risk environment

Officials and executives who spoke about the policy also warned it could provoke more immediate activity by adversaries and longer-term tactical shifts. Gray expects a short-term increase in attacks and a longer-term adversary response that will “shift tactics, accelerate operations, and gain additional ‘cover’ to hide their operations.” The cybersecurity executive noted an urgency driven by adversaries’ adoption of new tools: a February report from cybersecurity company CrowdStrike found that AI-assisted cyberattacks rose 89 percent in 2025.

Observers also pointed to precedent for state-aligned private activity. The memo cites that Russia has been enlisting, or coercing, private companies and groups to carry out cyberattacks against Western targets — a fact presented in the memo as context for the United States’ decision to harness private capability.

Contractor-operated systems and field engineers: Shield AI, SpaceX, Anduril

The memo comes as software-focused weapons and systems are already being operated by private firms close to combat and operations. The article records examples in which private vendors run systems that support military missions: SpaceX operates the Starlink satellites that connect U.S. troops; under the first Trump administration the Pentagon paid Anduril to maintain and update drones in the field while deploying alongside special operations forces; and in April CENTCOM hired Shield AI to provide intelligence, surveillance, and reconnaissance with its V-BAT drone under a contractor-owned, contractor-operated arrangement.

A former senior defense official interviewed in 2025 argued that the job of fighting increasingly looks like engineering, saying many of these technologies are “super exquisite, they're fragile, they're very technical. The people that built them are the ones that know how they work.” That practical logic is echoed by Shield AI co‑founder Brandon Tseng: “We aren’t just bringing the V-BAT product and service to the Navy; we’re bringing a world-class team with a wealth of operational experience and the ability to produce undeniable outcomes for our warfighters.”

What this means for private cybersecurity companies, the departments of Justice and Homeland Security, and contractor-operated drone firms

  • Private cybersecurity companies: Firms that win vetting and oversight approval will be authorized and paid to conduct offensive operations short of causing “loss of life or serious injury.” Executives already expect demand for takedown activity to rise and for private-sector personnel to be those executing operations.
  • Departments of Justice and Homeland Security: DOJ and DHS will be the supervising agencies responsible for the new program’s operational and legal oversight, tasked with enforcing the memo’s limits and vetting private actors.
  • Contractor-operated drone and systems firms: Companies operating sensitive systems in the field — the template cited by examples such as Shield AI, SpaceX, and Anduril — will see the memo as an extension of a broader trend that places developers and engineers closer to operational use and faster iteration at the front lines.

The presidential memo formally puts private coders and cybersecurity firms into a role the U.S. government has historically retained: taking offensive action against adversary networks. The document insists on vetted, supervised execution with a bright-line prohibition on operations that could “result in the loss of life or serious injury.” At the same time, commentators capture a familiar tradeoff: harness private ingenuity to move faster and close capability gaps, and accept the risk of short-term escalation and longer-term shifts in how adversaries operate. The memo revives an old vocabulary — privateering — for a new domain, and leaves policymakers and practitioners to test whether modern controls will keep private cyber operations under the “control” its authors promise.

Read the original Defense One story