The Trump administration has issued a memo that would let private American companies hack foreign cybercriminals on behalf of the U.S. government, which is either a bold modernization of cyber defense or an absolutely unhinged idea, depending on who you ask. Spoiler: the people who actually know cybersecurity are mostly in the second camp. As NPR reports, participating companies could take actions that result in the "manipulation, disruption, denial, degradation, or destruction" of foreign computer systems — and they only need to put up a $1 million bond to do it.

The Pitch: Cyber Privateers, Like Pirates but With Venture Capital

According to a presidential memorandum issued late Wednesday and reported by NPR, the administration wants to contract private businesses through the Department of Justice or the Department of Homeland Security to go after foreign cybercriminal organizations. Companies would be vetted, put up $1 million that the government can claw back if they screw up, and then get a green light to access the computer networks of targets the government selects.

This idea has a name in some corners of Washington: cyber privateers. It is, as NPR notes, a term drawn from 16th century naval warfare, when governments handed private ship captains a legal license to attack enemy vessels. The fact that the intellectual ancestor of this policy is essentially state-sponsored piracy should tell you something about the conceptual firmness of the ground we're standing on.

Two Republican congressmen have already floated formal legislation pushing the privateer model. This memo doesn't go quite that far, but it got enthusiastic online applause from the people who wanted it to. That is not a reassuring detail.

Who Exactly Would Sign Up for This?

NPR asked the obvious question: which private companies would actually want to do this? The honest answer is: the ones that see a government contract opportunity, not necessarily the ones best equipped to handle the consequences.

Joshua Steinman, who served as senior director for cyber policy on the National Security Council during Trump's first term, told NPR that a lot of companies will see this as "an onramp to doing additional work for the United States government." He's talking about smaller firms, VC-backed startups, and any outfit looking to grab a lucrative federal contract. So picture a startup founded eighteen months ago, flush with Series B funding, now being handed a target list by the Department of Homeland Security and told to go disrupt foreign criminal networks. Does that sound airtight to you?

Arthur Tellis, a former Department of Defense staffer now at the Institute for Progress, told NPR he thinks these companies would probably be better at surveillance than at actually disrupting criminal enterprises. Which is a diplomatic way of saying they might be good at watching but not great at the part where things explode, metaphorically speaking.

The Part Where It Gets Actually Dangerous

Here's where this stops being funny and starts being genuinely alarming. Chris Wysopal, co-founder of cybersecurity firm Veracode and a veteran of the field, told NPR he has zero interest in participating, and his reasoning is worth reading slowly.

"You don't want to have collateral damage when your blast radius is too big at the data center you were trying to take down, and you took down a transportation company or hospital's servers," Wysopal said. Read that again. A private company, authorized by the U.S. government, launches a disruptive cyberattack on a foreign criminal network, miscalculates, and takes down a hospital's infrastructure instead. Who is responsible? The memo, as NPR reports, doesn't answer that question.

The targeting problem is just as thorny. The memo would bar private companies from attacking foreign governments directly, but as NPR points out, many foreign cybercriminals operate in a grey area between state-sponsored and genuinely independent. Get that classification wrong and a private American company may have just committed an act of war against a sovereign nation. The $1 million bond is not going to cover that particular liability.

The Legal Mess Hiding in Plain Sight

Paul Rosenzweig, who served as deputy assistant homeland security secretary for policy under George W. Bush and now runs a consulting firm in Washington, gave NPR the most quotable assessment of the memo: "It's not an incomparably bad idea, but it's a bad idea."

His core objection is the one that should be keeping lawyers up at night. "Anything that our new cyber-enabled private sector actors do overseas will assuredly be against the domestic law of a host of countries wherein they act," Rosenzweig told NPR. American anti-hacking laws currently bar individuals and businesses from doing almost exactly what this memo contemplates. The memo doesn't change those laws. It just says participating companies need to be under federal contract, and then gestures vaguely at DOJ and DHS to sort out the rest within two months.

Stacy O'Mara, chief policy officer at cybersecurity company Armadin, told NPR the document has her in "wait and see" mode, and flagged that major legal questions around authority and liability remain completely unresolved. Two months to figure out the legal framework for privatized international cyber warfare. That's the timeline. Two months.

What the Memo Actually Does (and Doesn't) Say

NPR notes that the memo is strikingly light on specifics for something with this level of operational and legal implication. It doesn't explain how private businesses would be authorized to perform work traditionally done by government agencies like intelligence collection or disruptive cyber operations. It doesn't describe what types of disruptive attacks would be permitted. It doesn't lay out the legal justification for those attacks. It doesn't explain the target-selection process in any meaningful detail.

What it does do is mandate that participating companies contract with DOJ or DHS, submit to unspecified "rigorous vetting," and park that $1 million deposit. Then it hands the genuinely hard questions to those two agencies and gives them sixty days to come up with answers. This is a memo that announces a dramatic departure from decades of U.S. policy and then says, essentially, details to follow.

The Dingo Take

Private companies hacking foreign targets on a government target list, with a two-month window to figure out the laws, and a $1 million bond as the safety net. This is not a policy. This is a term sheet for a disaster.

The administration has spent considerable energy dismantling the federal workforce and pushing government functions into private hands. Now it wants to outsource the part of national security that involves breaking into other countries' computer systems. The through-line here isn't innovation or modernization. It's the same ideology applied everywhere: government bad, contractor good, consequences somebody else's problem. And when a VC-funded startup takes down a hospital's servers in Frankfurt because it misidentified a target, the memo's authors will not be the ones answering for it.

Rosenzweig called it a bad idea while being careful not to call it the worst idea. That restraint is more than this memo deserves. The 16th century pirates at least had the honesty to admit they were pirates.

Sources