From pirates to privateers: Inside the White House’s gamble on outsourced cyberwarfare

US President Donald Trump has handed American companies a power the federal government has guarded jealously since the birth of modern computing: the authority to hack back.

A national security memorandum signed on August 12 directs the Departments of Justice and Homeland Security to build a program that lets vetted private firms conduct offensive cyber operations against foreign criminal networks, under federal “control and oversight.” Companies would be authorized to surveil hackers’ infrastructure and disrupt it — taking down servers, infiltrating machines with spyware — as part of what the memo frames as an underused tool against transnational cybercrime. Each operation needs prior government sign-off, and participating firms must post a bond or escrow of at least $1 million, forfeited if they step outside the rules.

The policy has already picked up an unofficial name in Washington cyber circles: cyber privateering. It is a deliberate echo of the eighteenth and nineteenth centuries, when governments issued letters of marque authorizing private ships to raid enemy vessels on the state’s behalf — a practice the United States has not formally used since the Civil War, and one most of the world agreed to abandon in 1856.

A reversal five months in the making

The shift is notable partly because senior officials in this same administration spent the spring ruling it out. In March, a senior adviser at the Office of the National Cyber Director told a conference that the White House was “not interested in fighting pirates with pirates.” National Cyber Director Sean Cairncross, addressing a Washington security summit around the same time, was explicit that private-sector offensive campaigns were “not what we’re talking about,” framing the administration’s ask of industry as intelligence-sharing rather than hacking.

What changed is less a single event than a build-up of pressure from Trump-aligned lawmakers. Senator Mike Lee introduced a bill in December authorizing letters of marque against drug cartels, followed by a companion measure this summer — the Cyber Letters of Marque and Reprisal Act — extending the same logic to cyberspace. Lee has described the approach as enlisting “digital privateers” to raid cartels and cybercriminals while splitting recovered assets with the government. Neither bill has advanced out of committee, but reporting indicates planning for an executive-branch version of the policy was already underway inside the administration by December, around the time Lee’s first bill landed. The memorandum effectively achieves through presidential authority what Lee’s legislation has not yet achieved through Congress.

Inside the memorandum

The program itself — still a framework rather than a finished system — will run through a National Coordination Center, to be jointly overseen by Homeland Security Secretary Markwayne Mullin and Attorney General Todd Blanche as co-executive directors. Participating firms must sign contracts with DOJ or DHS, undergo vetting on technical proficiency and personnel reliability, and disclose any outside commercial relationships tied to their government work. The memo’s language targets what it calls “Cyber-Enabled Transnational Criminal Organizations,” explicitly excluding foreign governments from the program’s remit — though it offers little guidance on cases where criminal syndicates have ties to state hacking units, a gap several analysts flagged as a significant omission.

Guardrails are built in on paper. Operations expected to cause death or injury, or that would cross the international-law threshold for “use of force,” are off the table. Companies that discover they have inadvertently touched a US person or a domestic system must halt immediately, run minimization procedures and report to the coordination center. DHS and DOJ have 60 days to finalize operating procedures — eligibility standards, disclosure rules, the mechanics of the bond requirement — though officials have said parts of the targeting and deconfliction framework will remain classified, limiting outside scrutiny of how the program actually functions once it is running.

The numbers driving the policy

The White House’s justification rests on a genuinely alarming trend line. The FBI’s Internet Crime Complaint Center recorded $20.9 billion in reported cybercrime losses in 2025, a 26 percent jump from the year before and the first time the figure has crossed $20 billion — up from $4.2 billion just five years earlier. Investment fraud accounted for the largest share at $8.6 billion, followed by business email compromise at $3 billion; ransomware complaints rose to 3,611 for the year, though the Bureau notes the reported losses from ransomware understate the real toll because they exclude downtime and remediation costs. IC3 also logged more than 75,000 sextortion reports in 2025, including thousands referred to the National Center for Missing and Exploited Children. It is that scale of loss, and the sense that federal law enforcement alone cannot keep pace with it, that the memo cites as the rationale for pulling in private capacity.

A precedent with a complicated history

The privateering comparison is doing a lot of work in the public debate, and it cuts both ways. Supporters note that the Constitution explicitly gives Congress the power to grant letters of marque, and that eighteenth- and nineteenth-century privateers were, for a time, a legitimate instrument of American naval strategy — President James Madison issued hundreds of them during the War of 1812. But the practice fell out of use after the Civil War, and the 1856 Paris Declaration formally abolished privateering under international law, even though the US never signed on. Critics point to the reason the practice collapsed in the first place: once privateers left port, governments had little ability to control what they did, and the line between sanctioned raiding and outright piracy blurred easily.

That history frames the core dispute among experts. Ari Redbord, head of policy at blockchain analytics firm TRM Labs and a former federal prosecutor, argues the comparison actually favors the new program — modern monitoring tools mean the government can track an authorized operation in real time in a way that was impossible for eighteenth-century navies watching a ship sail over the horizon. University of Surrey cybersecurity professor Alan Woodward takes the opposite lesson from the same history: a government can issue a commission, but it cannot guarantee that a private actor stays inside its lines, and privateering’s downfall wasn’t a moral failing so much as the accumulated cost of misconduct outweighing its benefits.

Other specialists focus less on the historical analogy and more on the operational risk. Chris Wysopal, co-founder of the cybersecurity firm Veracode, has pointed out that hacking a foreign data center to hit scammers could inadvertently knock out something else on the same infrastructure, like a hospital — and that company employees traveling abroad could become targets for detention by foreign governments once they’re known to be involved in state-sanctioned hacking. Former Cyber Command official Jason Kitka was more blunt in a social media post, describing the program’s incentive structure as a recipe for firms manufacturing billable threats. Security consultant Davi Ottenheimer, a longtime advocate of expanded private-sector “active defense,” nonetheless called the memo an embarrassment to the country. Columbia University researcher Jason Healey, a former cybersecurity official under President George W. Bush, said his concern isn’t the legal architecture of the program itself but the state of the institutions meant to watch it — pointing to what he described as the administration’s weakening of oversight bodies like the Office of the Director of National Intelligence. Michael Garcia, a former senior official at the Cybersecurity and Infrastructure Security Agency, summed up the reaction across the policy community more simply, calling it a philosophical shift in how Washington thinks about cyber offense.

Big technology firms have so far kept their distance publicly. Microsoft declined to comment on the policy; Google did not respond to requests for comment, according to reporting on the memo’s rollout.

What to watch

The next 60 days will determine whether this framework has real teeth or stays largely theoretical. DOJ and DHS must finalize the operating procedures that will decide who actually qualifies to participate, how the bond requirement will be enforced, and how much of the targeting process will remain classified. Legal challenges are widely expected, given that the program authorizes conduct that would otherwise violate US and foreign computer-crime statutes, and the memo does not fully resolve how contractor conduct becomes lawful under existing law. Congress has given no indication it plans to weigh in through legislation of its own, leaving Lee’s letters-of-marque bills as a parallel, unresolved track. And the hardest test will only come once the first operations actually launch: whether the “control and oversight” the White House has promised can survive contact with a cross-border hacking operation carried out by a company with its own commercial incentives, in a domain where, as one former official put it, tracking a target once it disappears into the network is far harder than watching a ship at sea.

Leave a Reply

Your email address will not be published. Required fields are marked *