<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="https://www.jain.com/assets/img/6adafce5-1.1"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>hack-back &#8211; Jain.com</title>
	<atom:link href="/tag/hack-back/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Data centers, connectivity, and security — news and analysis</description>
	<lastBuildDate>Sat, 26 Sep 2026 14:15:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>/wp-content/uploads/2026/08/jain-com-icon-512-150x150.png</url>
	<title>hack-back &#8211; Jain.com</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Hack-Back Memo Puts State Hackers Out of Scope, Despite Attacks on 45 Water Systems</title>
		<link>/white-house-hack-back-memo-private-firms-offensive-cyber-operations/</link>
		
		<dc:creator><![CDATA[Deepak Jain]]></dc:creator>
		<pubDate>Sun, 16 Aug 2026 16:00:00 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[critical infrastructure security]]></category>
		<category><![CDATA[cyber policy]]></category>
		<category><![CDATA[Department of Justice]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[hack-back]]></category>
		<category><![CDATA[offensive cyber operations]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[water utilities]]></category>
		<guid isPermaLink="false">/white-house-hack-back-memo-private-firms-offensive-cyber-operations/</guid>

					<description><![CDATA[The White House authorized vetted private firms to run offensive 'hack-back' cyber operations against foreign cybercrime groups. Its target rules exclude state-directed hackers, so utilities facing suspected Iranian attacks gain little new protection from it.]]></description>
										<content:encoded><![CDATA[<div class="jain-post-grid">
<div class="jain-post-main">
<section class="jain-tldr" aria-label="Plain-English summary">
<p class="jain-tldr-kicker">TL;DR · 30-second read</p>
<h2>The Short Version</h2>
<p>The American government will now let approved private companies break into, and even wreck, computers run by foreign criminal hacking gangs. In March, officials said they would not do this.</p>
<p>Each company must set aside at least $1 million, which it loses if it breaks the rules. Every attack needs written approval from the Justice Department and Homeland Security.</p>
<p>The catch: hackers working directly for a foreign government are off-limits. That matters because the order came after suspected Iranian attacks on water suppliers in 45 American towns.</p>
</section>
<p>Tom&#8217;s Hardware reported that President Donald Trump signed a presidential memorandum on August 12 creating the first US program that lets vetted private companies conduct offensive cyber operations against foreign cybercrime organizations. These include operations that destroy data and systems. Participating firms must post at least $1 million in escrow, which they forfeit if they break program rules. Every operation needs written approval from Department of Justice and Department of Homeland Security officials.</p>
<p>A National Coordination Center will run the program. Implementation guidance is due within 60 days. The policy reverses public statements administration officials made in March.</p>
<h2>Executive Summary</h2>
<p>The memorandum authorizes two kinds of activity. &#8220;Cyber Surveillance Operations&#8221; means getting into foreign systems without permission to gather intelligence while staying undetected. &#8220;Cyber Effects Operations&#8221; means disrupting or destroying those systems and their data. Both large firms and smaller specialists will be eligible. Participants may also sign commercial deals with other private firms and with state and local agencies to receive threat data and propose operations based on it.</p>
<p>This matters for two reasons. First, it turns offensive cyber activity, long treated as a government monopoly in the US, into something a licensed private sector can do under supervision. Second, its target definition is narrow. A group qualifies as a target unless &#8220;clear intelligence exists&#8221; that it is part of a foreign government or wholly run at a government&#8217;s direction. So the program is aimed at criminal ransomware crews, not at the state-directed actors behind many attacks on physical infrastructure. For operators of water, power and data center infrastructure, that distinction shapes what the program can and cannot do for them.</p>
<h2>The Target Line Runs Straight Through Critical Infrastructure</h2>
<p>The memo arrived after suspected Iranian cyberattacks on water suppliers in 45 US municipalities. It also followed a CISA alert about Iranian hackers targeting programmable logic controllers (PLCs), the small industrial computers that open valves, run pumps and switch equipment at water and energy companies. Yet state-directed hackers fall outside the program&#8217;s own definition of a valid target. Private operators could go after a ransomware crew that encrypts a utility&#8217;s billing systems. They could not go after a government-run unit tampering with its treatment-plant controllers.</p>
<p>The line is drawn deliberately. Ransomware crews that operate with a state&#8217;s tolerance but not under its formal control stay within scope, a description that fits much of the Russia-based ransomware ecosystem. Once an actor is clearly an arm of a foreign state, the matter stays with government. For utility and industrial security teams, the practical conclusion is that nothing changes for defending operational technology against nation-state intrusion. Segmentation, monitoring and incident response for control systems remain their responsibility. The new program targets the financially motivated threat, not the geopolitical one.</p>
<p>There is also an ambiguity problem. Eligibility turns on whether &#8220;clear intelligence&#8221; ties a group to a government, and in practice attribution is often contested and slow. A group judged criminal today may later prove to have state links. That question will matter a great deal to any firm whose operation lands on the wrong side of the line.</p>
<h2>A $1 Million Bond on a Destructive Capability</h2>
<p>The escrow requirement is the program&#8217;s main economic control. A minimum of $1 million, forfeited for rule-breaking, is a meaningful commitment for a small specialist firm. Whether it is proportionate to the harm a destructive operation could cause is a separate question. Wiping servers that turn out to be shared with innocent third parties could produce losses well above that figure. The minimum works as a deterrent and an entry filter. It is not obviously a compensation fund.</p>
<p>The commercial provisions may matter more for the market&#8217;s shape. Participants can contract with other private firms and with state and local agencies, receive threat data and propose operations based on it. That creates a potential new service line for security vendors: selling disruption, not just detection. Two background facts point the same way. Congress earmarked $1 billion for offensive cyber operations in last year&#8217;s spending bill. Google said in August last year that it was preparing to take part in disruptive actions against cybercriminals. Large platform companies with deep telemetry into criminal infrastructure look like natural participants. Smaller firms may compete on specialized tasks, as the eligibility rules anticipate.</p>
<h2>Escalation, Legal Exposure and a Classified Annex</h2>
<p>DOJ and DHS officials cannot approve operations likely to cause loss of life or amount to an armed attack under international law. The memo does not prohibit such operations outright, however. Approval authority for them sits in a classified annex. Companies weighing participation, and the public, therefore cannot see the full rulebook for the highest-risk cases.</p>
<p>Personnel face exposure too. Jake Williams, vice president of research and development at Hunter Strategy, told TechCrunch that Americans involved in these operations &#8220;could easily be classified as non-uniformed combatants while traveling overseas.&#8221; That is a risk that falls on individual employees, not only on their employers, and firms will need to account for it in staffing, travel policy and insurance.</p>
<p>The speed of the reversal adds uncertainty. In March, Thomas Lind, then a senior adviser at the Office of the National Cyber Director, said the administration had no plans to authorize private offensive operations: &#8220;We&#8217;re not interested in fighting pirates with pirates.&#8221; National Cyber Director Sean Cairncross said the same week that companies running offensive campaigns were not what the administration meant when it asked industry for help. A policy that changed direction within months could change again, which makes long-term investment in offensive capability a harder bet.</p>
<h2>Collateral Risk Is Written Into the Rules</h2>
<p>The memo requires any company that unintentionally hits a US person or a system on US soil to halt operations and notify the government immediately. That clause concedes that operations aimed abroad can land at home. Criminal groups commonly route activity through rented servers and compromised machines owned by unrelated parties. Hosting providers, cloud platforms and data center operators therefore have a direct interest in how approvals weigh that possibility, and in how quickly they would be told if their infrastructure were affected.</p>
<p>Defenders more broadly face a quieter risk: retaliation. A criminal group whose systems are destroyed by a US firm may not distinguish between that firm and US targets generally. The memo&#8217;s safeguards govern how operations are approved. They do not change who absorbs the response.</p>
<h2>Background</h2>
<p>For decades, US law and policy have treated breaking into someone else&#8217;s computer as illegal, even when that someone is an attacker. Offensive cyber operations have been reserved for government agencies such as the military and intelligence community. Proposals to let private victims &#8220;hack back,&#8221; including the Active Cyber Defense Certainty Act introduced in Congress in 2017, never became law. Critics warned of misattribution, collateral damage and escalation.</p>
<p>Pressure grew as ransomware crews, many operating from jurisdictions beyond the reach of US law enforcement, hit hospitals, pipelines and municipalities. Some large technology firms have already worked with authorities to take down criminal infrastructure, and Google said last year it was preparing to take part in disruptive actions. The August 12 memorandum is the first formal framework for private firms to go further, under federal supervision.</p>
<section class="jain-sources" aria-label="Sources">
<h2>Sources</h2>
<p>Source: <a href="https://news.google.com/rss/articles/CBMizAFBVV95cUxOQmhTUnhjTHFhbjJwRGpVNTYtWG9xc2I2ODRydWctOVJhWmhhMmcwUlhsdGZVZERMMGQ4Q2lCSDdOX0tyNnhuR05EWVBHVG5iYkQ1V1pqMWtFM0FTYnlob1lrOWEzX0dWZ2RsSTUtdm93WjA2S3k4UjBLeTk4SzVsdUh2ZTduUmhMS0lDVFhZTlNBeUdQS19lcXZZb2cxN1ZGQVRPd3daX2VOZm5iZUtFU2gwcmxjM1BHUERHS3FWMVdxS1VVWEFrUm1Vdmk?oc=5">White House authorizes private companies to launch &#8216;hack-back&#8217; cyberattacks that destroy data and systems, targeting foreign cybercrime organizations</a>. Tom&#8217;s Hardware on the August 12 presidential memorandum creating a supervised private offensive cyber program.</p>
</section>
</div>
<aside class="jain-rail">
<section class="jain-gaps" aria-label="What the release does not say">
<p class="jain-gaps-kicker">⚠ What They Aren’t Saying</p>
<h2>What the Release Doesn&#8217;t Say</h2>
<ul>
<li><strong>Participants:</strong> Neither the administration nor any company had said which firms have applied or been vetted. Google, which said last year it was preparing to take part in disruptive actions against cybercriminals, had not said whether it will join this program.</li>
<li><strong>Rules still to come:</strong> Implementation guidance is due within 60 days. The administration had not published the eligibility criteria, how escrow amounts above the $1 million minimum are set, or what the National Coordination Center will require for approval.</li>
<li><strong>Liability and redress:</strong> The administration had not explained how third parties harmed by an operation, including US hosting and cloud providers, would be compensated. It also had not said whether the escrow serves that purpose, or how attribution disputes over the &#8220;clear intelligence&#8221; standard will be resolved.</li>
</ul>
</section>
<section class="jain-faq">
<h2>Frequently Asked Questions</h2>
<h3>What did the White House authorize?</h3>
<p>A presidential memorandum signed August 12 created the first US program letting vetted private companies conduct offensive cyber operations against foreign cybercrime organizations. These include surveillance inside foreign systems and operations that disrupt or destroy systems and data.</p>
<h3>What is a &#x27;hack-back&#x27; operation?</h3>
<p>Hack-back means an organization going on the offensive against attackers rather than only defending its own networks. It can include breaking into the attacker&#8217;s systems to gather intelligence or to disable or destroy the tools and data they use.</p>
<h3>What two types of operations does the memo allow?</h3>
<p>&#8220;Cyber Surveillance Operations,&#8221; which means unauthorized access to foreign systems to collect intelligence while staying undetected, and &#8220;Cyber Effects Operations,&#8221; which means disrupting or destroying those systems and the data on them.</p>
<h3>Who approves each operation?</h3>
<p>Every operation requires written approval from officials at the Department of Justice and the Department of Homeland Security. A National Coordination Center manages the overall program.</p>
<h3>How much must a company put up to participate?</h3>
<p>Participating firms must post at least $1 million in escrow. They forfeit it if they break the program&#8217;s rules.</p>
<h3>Can companies target state-sponsored hackers?</h3>
<p>No, not when the link is clear. A foreign group qualifies as a target unless clear intelligence shows it is institutionally part of a foreign government or wholly operated at a government&#8217;s direction. State-directed hackers fall outside the program&#8217;s definition.</p>
<h3>Are ransomware gangs valid targets?</h3>
<p>Generally yes. Ransomware crews that operate with a state&#8217;s tolerance but not its formal control remain within scope, a description that fits much of the Russia-based ransomware ecosystem.</p>
<h3>Does the program help water and power utilities?</h3>
<p>Only partly. It targets criminal groups, but the suspected Iranian attacks on water suppliers in 45 municipalities, and the PLC targeting CISA warned about, involve actors that may fall under the state-directed exclusion. Utilities still carry the burden of defending their control systems.</p>
<h3>Can operations cause loss of life?</h3>
<p>DOJ and DHS officials cannot approve operations likely to cause loss of life or amount to an armed attack under international law. The memo does not ban them outright, though. Approval authority for such cases sits in a classified annex.</p>
<h3>What happens if an operation hits a US target by mistake?</h3>
<p>A company that unintentionally affects a US person or a system on US soil must halt operations and notify the government immediately.</p>
<h3>Didn&#x27;t the administration rule this out earlier?</h3>
<p>Yes. In March, Office of the National Cyber Director adviser Thomas Lind said there were no plans to authorize private offensive operations: &#8220;We&#8217;re not interested in fighting pirates with pirates.&#8221; National Cyber Director Sean Cairncross made similar remarks that week.</p>
<h3>What risks do employees of participating firms face?</h3>
<p>Jake Williams of Hunter Strategy told TechCrunch that Americans involved could be classified as non-uniformed combatants while traveling overseas. That is a personal legal and safety risk, beyond the company&#8217;s own liability.</p>
<h3>Can small companies take part?</h3>
<p>Yes. Eligibility rules are to admit both large firms and smaller companies suited to specialized tasks. Participants may also sign deals with other private firms and with state and local agencies to receive threat data and propose operations.</p>
<h3>When will the program&#x27;s detailed rules be published?</h3>
<p>Implementation guidance is due within 60 days of the August 12 memorandum. It should clarify eligibility, vetting and the approval process.</p>
<h3>Is there funding behind US offensive cyber efforts?</h3>
<p>Congress earmarked $1 billion for offensive cyber operations in last year&#8217;s spending bill. The memo itself does not say whether any of that money supports the private program.</p>
</section>
</aside>
</div>
<p><script type="application/ld+json">{"@context": "https://schema.org", "@graph": [{"@type": "NewsArticle", "headline": "Hack-Back Memo Puts State Hackers Out of Scope, Despite Attacks on 45 Water Systems", "description": "The White House authorized vetted private firms to run offensive 'hack-back' cyber operations against foreign cybercrime groups. Its target rules exclude state-directed hackers, so utilities facing suspected Iranian attacks gain little new protection from it.", "image": ["/wp-content/uploads/2026/09/white-house-hack-back-memo-private-offensive-cyber-operations.webp"], "author": {"@type": "Organization", "name": "jain.com Editorial"}, "datePublished": "2026-09-26T14:15:56.024418+00:00"}, {"@type": "FAQPage", "mainEntity": [{"@type": "Question", "name": "What did the White House authorize?", "acceptedAnswer": {"@type": "Answer", "text": "A presidential memorandum signed August 12 created the first US program letting vetted private companies conduct offensive cyber operations against foreign cybercrime organizations. These include surveillance inside foreign systems and operations that disrupt or destroy systems and data."}}, {"@type": "Question", "name": "What is a 'hack-back' operation?", "acceptedAnswer": {"@type": "Answer", "text": "Hack-back means an organization going on the offensive against attackers rather than only defending its own networks. It can include breaking into the attacker's systems to gather intelligence or to disable or destroy the tools and data they use."}}, {"@type": "Question", "name": "What two types of operations does the memo allow?", "acceptedAnswer": {"@type": "Answer", "text": "\"Cyber Surveillance Operations,\" which means unauthorized access to foreign systems to collect intelligence while staying undetected, and \"Cyber Effects Operations,\" which means disrupting or destroying those systems and the data on them."}}, {"@type": "Question", "name": "Who approves each operation?", "acceptedAnswer": {"@type": "Answer", "text": "Every operation requires written approval from officials at the Department of Justice and the Department of Homeland Security. A National Coordination Center manages the overall program."}}, {"@type": "Question", "name": "How much must a company put up to participate?", "acceptedAnswer": {"@type": "Answer", "text": "Participating firms must post at least $1 million in escrow. They forfeit it if they break the program's rules."}}, {"@type": "Question", "name": "Can companies target state-sponsored hackers?", "acceptedAnswer": {"@type": "Answer", "text": "No, not when the link is clear. A foreign group qualifies as a target unless clear intelligence shows it is institutionally part of a foreign government or wholly operated at a government's direction. State-directed hackers fall outside the program's definition."}}, {"@type": "Question", "name": "Are ransomware gangs valid targets?", "acceptedAnswer": {"@type": "Answer", "text": "Generally yes. Ransomware crews that operate with a state's tolerance but not its formal control remain within scope, a description that fits much of the Russia-based ransomware ecosystem."}}, {"@type": "Question", "name": "Does the program help water and power utilities?", "acceptedAnswer": {"@type": "Answer", "text": "Only partly. It targets criminal groups, but the suspected Iranian attacks on water suppliers in 45 municipalities, and the PLC targeting CISA warned about, involve actors that may fall under the state-directed exclusion. Utilities still carry the burden of defending their control systems."}}, {"@type": "Question", "name": "Can operations cause loss of life?", "acceptedAnswer": {"@type": "Answer", "text": "DOJ and DHS officials cannot approve operations likely to cause loss of life or amount to an armed attack under international law. The memo does not ban them outright, though. Approval authority for such cases sits in a classified annex."}}, {"@type": "Question", "name": "What happens if an operation hits a US target by mistake?", "acceptedAnswer": {"@type": "Answer", "text": "A company that unintentionally affects a US person or a system on US soil must halt operations and notify the government immediately."}}, {"@type": "Question", "name": "Didn't the administration rule this out earlier?", "acceptedAnswer": {"@type": "Answer", "text": "Yes. In March, Office of the National Cyber Director adviser Thomas Lind said there were no plans to authorize private offensive operations: \"We're not interested in fighting pirates with pirates.\" National Cyber Director Sean Cairncross made similar remarks that week."}}, {"@type": "Question", "name": "What risks do employees of participating firms face?", "acceptedAnswer": {"@type": "Answer", "text": "Jake Williams of Hunter Strategy told TechCrunch that Americans involved could be classified as non-uniformed combatants while traveling overseas. That is a personal legal and safety risk, beyond the company's own liability."}}, {"@type": "Question", "name": "Can small companies take part?", "acceptedAnswer": {"@type": "Answer", "text": "Yes. Eligibility rules are to admit both large firms and smaller companies suited to specialized tasks. Participants may also sign deals with other private firms and with state and local agencies to receive threat data and propose operations."}}, {"@type": "Question", "name": "When will the program's detailed rules be published?", "acceptedAnswer": {"@type": "Answer", "text": "Implementation guidance is due within 60 days of the August 12 memorandum. It should clarify eligibility, vetting and the approval process."}}, {"@type": "Question", "name": "Is there funding behind US offensive cyber efforts?", "acceptedAnswer": {"@type": "Answer", "text": "Congress earmarked $1 billion for offensive cyber operations in last year's spending bill. The memo itself does not say whether any of that money supports the private program."}}]}]}</script></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
