Editor’s Note: A presidential memorandum signed Aug. 12 tells the federal government to build a program that is not yet publicly operational, admitting vetted private companies to run surveillance and disruption operations against foreign criminal networks. Four weeks earlier, a bill landed in Congress to authorize much the same activity, with protections the memorandum cannot supply.
The consequences arrive on three fronts. Counsel weighing participation face a memorandum that names the Computer Fraud and Abuse Act as a boundary without waiving it, and that appears drafted to bring program work inside the statute’s law-enforcement exception. No court has tested whether that works. Information governance teams face a disclosure duty whose reach the memorandum leaves undefined. Discovery practitioners face a prospective evidence class built under federal direction, where the state-actor question and the preservation trigger both turn on facts nobody has yet.
One ambiguity sits underneath all of it. The memorandum has participating companies conducting operations, while the provision delegating approval authority describes department personnel doing so. A participant that never touches a foreign system carries far less exposure.
Watch two dates. Operating procedures are due on or about Oct. 11, the first status report on or about Feb. 8, 2027. Neither carries a publication requirement.
Content Assessment: A program that does not exist yet already has a Computer Fraud and Abuse Act problem
Information - 93%
Insight - 91%
Relevance - 90%
Objectivity - 90%
Authority - 89%
91%
Excellent
A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "A program that does not exist yet already has a Computer Fraud and Abuse Act problem."
Industry News – Cybersecurity Beat
A program not yet publicly operational, and an untested Computer Fraud and Abuse Act defense
ComplexDiscovery Staff
President Donald Trump signed a memorandum Aug. 12 directing the federal government to build a program that would let vetted private companies hack foreign criminal networks under government control. The program is not yet publicly operational, and neither is there a settled answer to the legal question at its center.
The document, titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” instructs the National Coordination Center to create and run a program admitting what the memorandum calls Participating Companies, private U.S. firms that would carry out two categories of operation against foreign cyber-enabled transnational criminal organizations. The White House fact sheet issued the same day describes the document as a national security presidential memorandum. It follows Executive Order 14390 and the administration’s cyber strategy, both issued March 6. The memorandum cites the order.
A program not yet publicly operational
The memorandum builds a framework for approving operations. On its own it authorizes none, and none has been announced. Two program executive directors, one drawn from the Justice Department and designated by the attorney general, the other drawn from Homeland Security, have 60 days to establish operating procedures, a deadline that lands on or about Oct. 11. The memorandum conditions approval on compliance with those procedures, so nothing can be approved until they are in place. Whether they are finished is not public.
No company has been named. The Record reported that the White House did not respond to questions about whether any firm had agreed to participate; TechCrunch reported that the White House did not immediately respond to the same question. Neither SecurityWeek nor BleepingComputer identified a participant. Vendors reading coverage that says the government has authorized private hacking should read the document instead, which says the government has ordered a program built.
One further thing the document leaves unsettled conditions much of what follows. The memorandum has Participating Companies conducting Cyber Surveillance Operations and Cyber Effects Operations. Yet the provision delegating approval authority to the two directors describes cyber operations conducted within the program by personnel of their respective departments. Read one way, companies execute and the government supervises. Read the other, companies build capability and propose targets while Justice and Homeland Security personnel do the touching. Wiley Rein lawyers, writing Aug. 14, treated the question as unresolved on the face of the text. The answer moves the legal exposure a long way: a company that never reaches into a foreign system has a much smaller Computer Fraud and Abuse Act problem than one that does.
The coordinating body has an unusual pedigree. The memorandum traces the National Coordination Center to Executive Order 14159 of Jan. 20, 2025, “Protecting the American People Against Invasion,” and specifically to that order’s Section 6(d). Section 6 establishes Homeland Security Task Forces in every state. Its stated objectives run to criminal cartels, foreign gangs and transnational criminal organizations operating inside the United States, to human smuggling and trafficking networks, and to enforcement of the immigration laws. Subsection (d) directs the attorney general and homeland security secretary to provide an operational command center to coordinate task force activity. The order’s published text does not use the name National Coordination Center, and the words cyber and computer do not appear in it. The center now told to stand up an offensive cyber program was created, under a different name, by an immigration enforcement order.
The statute the memo tells companies to obey
Section 2(b) is where a prospective participant’s counsel should stop reading and start writing memos. It directs the center to conduct all program activities consistent with the Constitution and other applicable law and international obligations, including Section 1030 of Title 18, the Computer Fraud and Abuse Act. The memorandum invokes the statute as a boundary. It does not waive it, cannot waive it, and nowhere purports to.
Set that against the memorandum’s own definition of a Cyber Surveillance Operation, which covers collecting information or intelligence from systems where the operator intends to go unnoticed, and which states that such operations entail accessing systems without authorization from the owner or operator, or by exceeding authorized access. Those are the CFAA’s operative phrases, lifted into the definition of the conduct the program would approve.
The open question is whether the statute’s escape hatch reaches this program, and it cuts both ways. Section 1030(f) provides that the section does not prohibit lawfully authorized investigative, protective or intelligence activity of a law enforcement agency of the United States, a state or a political subdivision of a state, or of an intelligence agency of the United States. The exemption is written around the agency whose activity it is. The statute says nothing express about private parties performing that activity under federal direction, and it does not say the activity must be carried out by agency employees.
The memorandum reads as though drafted with that provision in mind. It casts program work as federal law enforcement activity, conducted on the government’s behalf, under federal supervision and subject to written approval. That is the argument for coverage. No prosecution or civil suit has tested it. A company weighing participation is pricing an untested reading of a criminal statute rather than relying on a settled one.
Three Jenner & Block lawyers flagged this gap five months before the memorandum issued. Writing in Lawfare on March 9 about the cyber strategy released March 6, partner Aaron R. Cooper, a former prosecutor in the Justice Department’s Computer Crimes and Intellectual Property Section, associate Philip Chertoff, and partner Shoba Pillay, also a former federal prosecutor, said no court has addressed whether the law enforcement exception protects private-sector entities engaged to perform such activities on the government’s behalf. Until Congress enacts legislation creating affirmative legal authority and liability protection, they said, the CFAA and state computer crime statutes remain in force whatever an executive document says, and companies should not rely on informal assurances that violations will not be prosecuted. Their firm advises the kind of company that would weigh participation, which is worth knowing when reading the advice. Five months on, the memorandum supplies the government-direction argument they anticipated, and leaves the question they identified exactly where it was.
Prosecution is only half the exposure. Section 1030(g) creates a civil remedy, but a narrower one than its first sentence suggests. A suit may be brought only where the conduct involves one of five enumerated factors: loss of at least $5,000 in a year, impairment of medical care, physical injury, a threat to public health or safety, or damage to a government computer used for justice, national defense or national security. Where only the loss threshold is met, damages are limited to economic damages. An action must begin within two years of the act complained of or of the discovery of the damage.
So the exposure is real but bounded. A claim would have to clear those thresholds and survive standing, causation and immunity questions, on facts nobody has yet. The memorandum’s general provisions do not help here either, and they are broader than they first read: the document creates no right or benefit enforceable against the United States or any other person. That governs what the memorandum itself creates. It does not reach a claim the statute makes independently available.
The Supreme Court has narrowed one of the statute’s two access theories and expressly left the other’s boundary open. Van Buren v. United States, decided June 3, 2021, held that a person exceeds authorized access by obtaining information from areas of a computer that are off-limits, not by misusing information he was entitled to obtain. In footnote 8, the Court said it need not address whether the access inquiry turns only on technological limitations or also on limits contained in contracts or policies. The memorandum’s definition names accessing without authorization first, and that is the clause whose outer boundary the Court declined to fix.
For counsel advising a prospective participant, the practical consequence is that the operating procedures due in October are operational and contractual safeguards rather than a legal safe harbor. They will govern how the government supervises the work. They cannot change what the statute permits. Build the CFAA analysis as a standing document now, before the procedures land, so the eventual comparison runs against a written baseline. Make the government’s written approval and direction, which the memorandum requires for every operations package before the company may act, a condition precedent in the contract rather than an operational courtesy.
Why collected evidence changes character under federal direction
A search by a private party acting on its own initiative sits outside the Fourth Amendment. A search by a party acting as an instrument or agent of the government does not, and in Skinner v. Railway Labor Executives’ Association, decided March 21, 1989, the Supreme Court looked to the government’s encouragement, endorsement and participation in sorting one from the other. The memorandum speaks to that axis three times, in three different formulations. Section 1 describes partnering with vetted companies subject to the direction and oversight of the federal government. Section 2(a) puts the operations themselves under the control and oversight of the federal government. The definition of Participating Companies has them conducting cyber operations under the direction of the United States Government. Those are the sentences a suppression motion will quote. Where any given operation falls is fact-specific, which is exactly why the facts need documenting while they are still fresh.
A second question sits beside it. Mayer Brown lawyers, writing Aug. 14, asked whether collection under the program would amount to electronic surveillance within the meaning of the Foreign Intelligence Surveillance Act, or would otherwise require a court order. The memorandum’s own answer is the authorization it requires before activity directed at a U.S. person is approved, judicial or otherwise. What that phrase covers, and who decides, is left to the procedures.
Commercial threat-intelligence workflows were not built to produce that record. They log telemetry, not authorization. Work the sequence backward from the courtroom and the gaps are obvious. A defendant challenging evidence traceable to a program operation will ask which director approved the package, in what writing, on what date, against what target list, under which rubric, and whether the activity stayed inside approved parameters. None of that lives in a threat-intelligence platform.
The preservation duty is the part that arrives first and gets noticed last. It is a common-law duty that Federal Rule of Civil Procedure 37(e) presupposes rather than creates, and the rule reaches information that should have been preserved in the anticipation or conduct of litigation. Anticipation is the trigger, not service of a subpoena, and the duty stays matter-specific: participation alone does not make any particular dispute reasonably foreseeable. What participation does is make the triggering events predictable. An exceedance notice, an unintended domestic contact, a misidentified target, a threatened claim or a government inquiry could each make litigation foreseeable and call for a documented preservation decision. A firm that treats an exceedance notice as an incident ticket rather than a moment to run that assessment is likelier to start its retention clock late. Scope the hold to the authorization ledger, the target packages, the approval correspondence and the minimization records, and write that scope down before there is a matter to write it for.
Then comes the collision practitioners should expect. A Rule 34 request aimed at operations packages meets a program whose operational workflow and targeting adjudication must in part conform to a classified annex, which means the responsive material and the standard governing it can sit on opposite sides of a classification boundary. Proportionality arguments get strange when the producing party cannot describe the burden without describing the program. Expect protective orders, ex parte submissions and government intervention in matters where the government is not a party, and expect the first few rounds to set the pattern for everything after.
The memorandum builds in its own tripwires, and each one generates paper. Procedures must require a company that discovers activity exceeding approved parameters, including unintentional targeting of a U.S. person, a system residing in the United States, or a system under a U.S. person’s control, to stop, run minimization and notify the center, which notifies the Justice Department. A separate provision requires immediate notice if a company discovers an imminent attack on U.S. critical infrastructure or comes to believe an approved operation may produce Critical Outcomes, the memorandum’s term for action likely to cause loss of life or serious injury or to rise to the level of use of force or armed attack under international law. Program executive directors may not approve operations producing those outcomes.
The document is not indifferent to domestic exposure. Procedures must also ensure that any program activity aimed at a U.S. person carries whatever authorization it needs, from a court or from somewhere else, before the operation wins approval. The same requirement reaches activity that implicates what the government owes under the Constitution, under federal statutes, or under international law. Read alongside the notification duties, that provision is the memorandum’s answer to the domestic-spillover objection. Whether it holds depends entirely on procedures nobody outside the program has seen, and the memorandum does not say they will ever be published.
Reading the government’s $20.8 billion loss figure
The fact sheet says American consumers reported losing over $20.8 billion to cyber-enabled crime in 2025, and that 73 percent of U.S. adults have experienced some kind of online scam or attack. It does not name a source for either figure, or for any of the other statistics it cites.
The nearest public figure, and the most recent available as of August 2026, is the FBI’s 2025 Internet Crime Complaint Center annual report, which gives $20.877 billion in losses across 1,008,597 complaints. The report characterizes that total as losses reported to IC3, not as consumer losses, and its category totals include $3.046 billion in business email compromise. The report also notes that its figures capture only what is reported to the FBI. The fact sheet’s version truncates where the underlying total rounds to $20.9 billion, and relabels the population that reported it. Practitioners citing the government’s number in board materials should cite the FBI report and its framing instead.
How far the commercial-agreement disclosure reaches
The operating procedures must require participating companies to disclose to the center all contractual relationships entered under the program’s commercial-agreements provision, the one letting them take threat information from private entities and from federal, state, local, tribal and territorial agencies. Wiley Rein read that as broader than the subcontractor disclosures federal contractors are used to. What the memorandum does not say is how far it reaches: whether contract text, customer identities or data-processing terms travel with the disclosure, or only the fact of the relationship. Separately, procedures must provide for evaluating each company for continued participation at least annually. The memorandum does not expressly tie the two together, so whether disclosures must be refreshed at each review is one of the questions the October procedures will answer.
Managed-detection and threat-intelligence vendors should assume their customer agreements, data-processing addenda and privacy notices are in scope for revision. A customer whose telemetry feeds a proposed government operation has an interest in knowing that, and a contract silent on the point is a contract that will be read against its drafter.
Buyers of those services have the more immediate task, because the disclosure architecture runs through them and they currently have no contractual visibility into it. Four questions belong in the next renewal. Does the provider intend to seek admission to the program, and will it say so in writing. Does the current agreement permit customer telemetry to be routed into a proposed government operation, and if the agreement is silent, whose reading of silence governs. What notice, if any, would the customer receive, and does it survive a government instruction not to give it. And if customer-identifying material accompanies the required disclosure, how will the government handle it, and will the disclosure have to be refreshed at annual review. A right to advance notice, an express carve-out of customer data from program submissions, and an audit right over what gets disclosed are all cheaper to negotiate now than to litigate later.
The financial gate is explicit. Procedures must authorize the two departments to require a bond or escrow of not less than $1 million, forfeitable on contractual non-compliance, alongside standards for technical proficiency, prior performance of cyber operations, facility security and personnel vetting. The memorandum directs that procedures leave room for smaller, agile firms alongside large ones, which reads as an acknowledgment that the standards will otherwise function as a market gate. If they do, buyers should expect a two-tier market within a year, in which a handful of cleared providers market federal adjacency as a differentiator and everyone else answers questions about why they are not in the program.
What to settle before the 60-day clock expires
Personnel exposure is the risk the document addresses least. Jake Williams, identified by TechCrunch as vice president of research and development at Hunter Strategy, said in remarks that outlet reported that Americans taking part in these operations could be labeled non-uniformed combatants while traveling abroad, and that such allegations need not be true to cause harm. Underneath that sits the ordinary version of the same risk: other countries have computer crime statutes too, and a U.S. company’s operation does not become lawful in the target’s jurisdiction because a U.S. official approved it in writing. Firms with staff or assets abroad should treat travel policy, entity structure and insurance as part of the participation decision rather than as an afterthought to it.
Reaction split, and it did not sort by who stands to sell into the program. Most of the voices on the record work in or around the security industry, and they landed on every side of it. Michael Garcia, a former CISA official now at Monument Advocacy, told CyberScoop he reads the memorandum as a philosophical shift in policy, and said he worries about attribution, about striking a foreign government by accident, and about the absence of court oversight. On that last point the two things sit together rather than in conflict: the memorandum’s one judicial hook, the authorization required before activity directed at a U.S. person is approved, does not reach operations aimed abroad, which is nearly all of them.
Davi Ottenheimer, an independent security consultant, reached for the same historical comparison this article does and did not intend it as a compliment: he told CyberScoop that letters of marque fell out of favor in the 1800s for good reason, given the violence they unleashed, and called the memorandum an embarrassment to the country. Joshua Steinman, a White House cyber official in Trump’s first term, told the outlet that Russia and China already operate this way at scale and framed the memorandum as parity. Will Barker, a cybersecurity adviser at Huntress, said in written comments to CyberScoop that the guidance due in 60 days is what will matter.
Two more industry voices reached the record the same day. CyberScoop and BleepingComputer both reported Veracode co-founder Chris Wysopal describing the move as a large shift in U.S. cyber policy, and Jason Kikta, a former Cyber National Mission Force official now at Automox, questioning it as a generator of billable work rather than of security outcomes.
Congress has been circling this idea for years, and the most recent attempt landed four weeks before the memorandum issued. The Cyber Letters of Marque and Reprisal Act, introduced July 15 by Sen. Mike Lee, R-Utah, as S. 5000, with a House companion introduced the same day by Rep. Tim Burchett, R-Tenn., as H.R. 9697, would let the president issue letters of marque and reprisal against foreign cyber threats, and it would require the private recipients to post security bonds and log what they do. Lee’s bill went to the Senate Foreign Relations Committee, Burchett’s to House Foreign Affairs. Neither chamber has enacted it, and the same holds for the Active Cyber Defense Certainty Act in 2017 and a marque-and-reprisal bill, H.R. 4988, introduced in 2025.
Set the bills beside the memorandum and the structural overlap is hard to miss: vetted private operators, government-defined missions, bonding, recordkeeping and reporting, and restrictions around U.S. persons. The bills go considerably further. They would supply express congressional authorization, permit seizure and repatriation of assets, fund bounties out of recovered proceeds, prescribe activity logs and bar causes of action for the conduct they authorize. That last item is the one the executive branch cannot write for itself, and it is the one a general counsel would most want to see. The Jenner & Block authors, writing in March, read the record as leaving the statutory position unchanged. An executive document that directs compliance with the CFAA does not alter what the CFAA prohibits.
Two dates now govern. Operating procedures are due on or about Oct. 11, and the first program status report goes to the deputy chief of staff for policy and homeland security adviser and to the national cyber director on or about Feb. 8, 2027, annually after that. Neither date carries a publication requirement. The memorandum directs that the procedures be established and that the report be delivered inside the government, and it says nothing about releasing either. Counsel should plan for the possibility that the first binding terms of this program become known to participants through a contract negotiation rather than through a public document, with parts of the operational workflow and the targeting adjudication conforming to a classified annex they will never see.
Which raises the question every general counsel in this market will face by autumn. If the safeguards are contractual rather than statutory, and the government can revise them, and the criminal statute underneath has never been tested against this arrangement, what would your board need to see before you signed that contract?

News sources
- Expanding Capabilities to Combat Transnational Cyber-Enabled Crime (The White House)
- Fact Sheet: President Donald J. Trump Expands Capabilities to Combat Transnational Cyber-Enabled Crime (The White House)
- Executive Order 14159: Protecting the American People Against Invasion (Federal Register)
- Executive Order 14390: Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens (GovInfo)
- 18 U.S.C. 1030: Fraud and related activity in connection with computers (Office of the Law Revision Counsel)
- Van Buren v. United States, No. 19-783 (Supreme Court of the United States)
- Skinner v. Railway Labor Executives’ Association, 489 U.S. 602 (Justia)
- Federal Rule of Civil Procedure 37 (Legal Information Institute)
- 2025 Internet Crime Report (FBI Internet Crime Complaint Center)
- Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations (Lawfare)
- Trump turns to private sector in offensive hacking operations memo (CyberScoop)
- Trump taps cyber firms to go on offensive against criminals (The Record)
- In a first, US will allow some private firms to carry out cyberattacks (TechCrunch)
- White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs (SecurityWeek)
- White House taps security firms for offensive hack-back operations (BleepingComputer)
- A bold new strategy or a dangerous precedent? Experts are divided on Trump memo (CyberScoop)
- Lee Bill Authorizes American Hackers to Fight Foreign Cyberattacks (Office of Sen. Mike Lee)
- Mike Lee runs bill allowing American hackers to target foreign cyberthreats (KSL)
- Navigating the New Presidential Memorandum on Transnational Cyber Enabled-Crime (Wiley Rein LLP)
- Presidential Memorandum Authorizes Vetted Private Companies to Conduct Offensive Cyber Operations Against Foreign Criminal Organizations (Mayer Brown)
- 5000, Cyber Letters of Marque and Reprisal Act, as introduced (GovInfo)
- H.R. 9697, Cyber Letters of Marque and Reprisal Act, as introduced (GovInfo)
Assisted by GAI and LLM technologies
Additional reading
- Recent AI evaluation incidents expose gaps in containment, configuration and evidence
- When hacktivists join the fight: A closer read of Cyber Law Toolkit scenario 36
- Beijing contests House Salt Typhoon report as Congress weighs a wider cleanup
- Restore the controller, risk losing evidence: federal water guidance leaves the sequence open
- Policy without control: the AI governance gap in IBM’s 2026 Cost of a Data Breach Report
- ShinyHunters’ July 31 deadline for EY arrives after third-party tax-data breach
- The new negligence baseline: how voluntary CI Fortify guidance becomes Exhibit A in post-breach litigation
Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more legible for practitioners, policymakers, and business leaders.


























