America Unleashes Corporate Cyber Militias: The Radical Policy Letting Private Companies Strike Back at Hackers

The U.S. government is quietly authorizing private companies to launch offensive cyberattacks against foreign hackers, reversing decades of policy. The shift raises profound questions about escalation, liability, and whether privatized cyberwar can be controlled.
America Unleashes Corporate Cyber Militias: The Radical Policy Letting Private Companies Strike Back at Hackers
Written by Juan Vasquez

For decades, the rules of cyberwar have been simple: if someone hacks you, call the FBI. Don’t touch anything. Don’t retaliate. Let the government handle it.

That era is ending.

The United States has begun signaling to private companies that they can go on offense — launching counterattacks against the foreign hackers who’ve been pillaging American intellectual property, disrupting critical infrastructure, and holding corporate networks hostage with ransomware. The concept is known colloquially as “hacking back,” and it represents one of the most dramatic shifts in American cybersecurity doctrine in a generation.

As The Economist reported, the policy change reflects a growing consensus within the Trump administration that the federal government alone cannot defend American networks against the scale and sophistication of state-sponsored cyber intrusions, particularly from China, Russia, and North Korea. The sheer volume of attacks has overwhelmed government agencies. Private companies, which own and operate the vast majority of American critical infrastructure, are being told they can fight back.

This isn’t a small procedural tweak. It’s a fundamental reordering of who does what in cyberspace.

From Defense to Offense: How Washington Changed the Rules

The legal architecture governing computer intrusions in the United States has long been hostile to any form of private-sector retaliation. The Computer Fraud and Abuse Act of 1986 — the primary federal statute covering hacking — makes it a crime to access any computer system without authorization, full stop. There’s no self-defense exception. A company that traces an attack back to a server in Shanghai and disrupts that server is, under existing law, committing a federal crime indistinguishable from the original intrusion.

This legal reality has frustrated corporate security teams for years. They watch attacks unfold in real time, often knowing exactly where the malicious traffic originates, and can do nothing but absorb the blow and file a report. The asymmetry is staggering: attackers operate with impunity while defenders are handcuffed by their own government.

The shift began gathering momentum during the first Trump administration, when then-National Security Adviser John Bolton loosened some of the interagency restrictions on U.S. Cyber Command’s offensive operations. But those changes applied to military and intelligence agencies, not private companies. The current policy evolution goes further, extending at least tacit authorization — and in some cases explicit encouragement — for corporations to conduct offensive cyber operations against foreign adversaries.

According to The Economist, administration officials have been quietly briefing major defense contractors, financial institutions, and technology firms on the parameters of acceptable action. The guidance reportedly distinguishes between “active defense” measures — such as deploying deceptive technologies, planting tracking beacons in stolen data, and disrupting command-and-control infrastructure used by attackers — and outright offensive operations designed to destroy an adversary’s capabilities. The former is being broadly encouraged. The latter remains more restricted but is no longer categorically off-limits.

No formal executive order has been published. No legislation has been passed. The administration appears to be operating through a combination of policy memoranda, prosecutorial discretion signals from the Department of Justice, and direct engagement with industry leaders. It’s a deliberate ambiguity — one that gives companies room to act while preserving the government’s ability to deny formal authorization if something goes wrong.

And things can go wrong. Spectacularly.

The cybersecurity community has debated hack-back policies for over a decade, and the objections are well-rehearsed. Attribution in cyberspace is notoriously difficult. Sophisticated attackers routinely route their operations through compromised systems in third countries, meaning a retaliatory strike aimed at a Chinese military hacker could actually hit a hospital server in Brazil or a university network in Germany. The potential for collateral damage is enormous. The potential for escalation is arguably worse — a private company’s botched counterattack could trigger a diplomatic crisis or provoke a retaliatory strike against American infrastructure.

There’s also the moral hazard problem. If companies know they can strike back, some will invest less in defensive security and more in offensive capabilities, which does nothing to harden the networks that actually need protecting. Security researchers have warned that hack-back authority could create a market for corporate cyber mercenaries — firms that sell offensive services to companies that lack in-house capabilities, with minimal oversight and maximal risk.

But the administration’s calculation appears to be that the status quo is worse. The scale of Chinese cyber espionage against American companies — detailed extensively in recent indictments and intelligence assessments — has reached what officials describe as an existential threat to U.S. economic competitiveness. The Volt Typhoon and Salt Typhoon campaigns, attributed to Chinese state-sponsored groups, penetrated American telecommunications providers and critical infrastructure operators with alarming depth. Ransomware gangs operating from Russia have extracted billions of dollars from American businesses and municipal governments. The FBI and CISA, despite significant budget increases over the past decade, simply don’t have the manpower to respond to every incident.

So the government is outsourcing.

The Private Sector’s New Arsenal — and Its Limits

Several major cybersecurity firms have already been developing offensive capabilities in anticipation of this policy shift. Companies like CrowdStrike, Mandiant (now part of Google Cloud), and Palo Alto Networks have threat intelligence operations that rival those of mid-sized national intelligence agencies. They track specific hacking groups, identify their infrastructure, and in some cases maintain persistent access to the systems those groups use. The technical capability to “hack back” already exists in the private sector. What’s been missing is legal permission.

The new guidance reportedly creates a tiered framework. At the lowest level, companies are encouraged to deploy “active defense” technologies — honeypots, deception networks, and beacon-equipped decoy files that phone home when accessed by unauthorized parties. These measures operate primarily within the defender’s own network and raise minimal legal concerns. The next tier involves actions that extend beyond the company’s own systems: disrupting botnets, sinkholing command-and-control domains, and corrupting stolen data in transit. This is where the legal gray area begins. The highest tier — penetrating an attacker’s systems to gather intelligence, destroy stolen data, or degrade the attacker’s capabilities — remains the most controversial and the most tightly controlled.

Companies pursuing higher-tier actions are expected to coordinate with the government, though the exact mechanism for this coordination remains murky. Some firms have reportedly been assigned points of contact within the NSA or FBI Cyber Division. Others have been told to work through sector-specific agencies — the Department of Energy for power utilities, the Treasury Department for financial institutions, the Department of Health and Human Services for hospitals and pharmaceutical companies.

The international implications are significant. American companies operating globally must contend not only with U.S. law but with the legal frameworks of every country where their networks touch. The European Union’s Network and Information Security Directive, updated in 2024, contains no hack-back provisions and could expose American firms to criminal liability in EU member states if offensive operations transit European infrastructure. The Budapest Convention on Cybercrime, to which the United States is a signatory, similarly provides no framework for private-sector offensive operations.

Allied governments have reacted with a mixture of fascination and alarm. The United Kingdom’s National Cyber Security Centre has reportedly engaged in quiet consultations with Washington about the policy but has not endorsed it publicly. Australia’s Signals Directorate — which already conducts offensive cyber operations through its military arm — has expressed interest in developing a parallel framework for Australian companies, according to industry sources familiar with the discussions. But most European governments remain deeply skeptical.

Not everyone in the American cybersecurity establishment is on board, either. Former CISA Director Chris Krebs, before his recent legal entanglements with the current administration, had expressed reservations about hack-back authorities, arguing that they would complicate attribution efforts and create new attack surfaces. Several former NSA officials have echoed these concerns, noting that private-sector offensive operations could inadvertently compromise ongoing government intelligence collection by alerting adversaries to the fact that their infrastructure has been identified.

The insurance industry is watching closely. Cyber insurance policies have traditionally excluded coverage for offensive operations, and it’s unclear whether insurers will adjust their underwriting to account for the new risk profile. If a company launches a counterattack that provokes retaliation resulting in a massive data breach, who pays? The company that struck back? Its insurer? The government that encouraged the action? These questions remain unanswered.

There’s a historical parallel worth examining. In the 18th and 19th centuries, governments routinely issued “letters of marque” authorizing private ships to attack enemy vessels — essentially legalizing piracy in service of national interests. The practice was eventually banned by the 1856 Declaration of Paris, after centuries of abuse, diplomatic incidents, and the recognition that privatized warfare was fundamentally incompatible with the rule of law. Critics of the hack-back policy argue that America is repeating this mistake in a new domain.

Proponents counter that the analogy breaks down because cyber operations are inherently more controllable and less lethal than naval warfare. A well-executed counterattack can disable an adversary’s infrastructure without physical destruction or loss of life. And the speed of cyber operations — measured in milliseconds, not months — makes government-only responses impractical. By the time a federal agency gets involved, the attacker has already exfiltrated the data, encrypted the network, and moved on.

The technology sector’s response has been predictably split along commercial lines. Companies that sell offensive tools and threat intelligence services see enormous market opportunity. Companies that sell defensive products worry about a world where their customers spend less on firewalls and more on attack capabilities. And companies that are primarily targets — retailers, manufacturers, healthcare providers — are cautiously optimistic but nervous about the operational complexity of conducting offensive cyber operations while simultaneously running a business.

One thing is clear: the genie isn’t going back in the bottle. Whether through formal legislation, executive action, or simply continued prosecutorial forbearance, the United States is moving toward a model in which private companies play an active offensive role in cyberspace. The question isn’t whether this will happen. It’s whether America can build the oversight mechanisms, legal frameworks, and international agreements necessary to prevent it from spiraling into chaos.

That work hasn’t started yet. And the attacks aren’t slowing down.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us