Private-Sector Hack-Back (Active Cyber Defense)
Hack back — also called active cyber defense or private-sector offensive cyber operations — is the idea that private entities should be allowed (or deputized) to take action beyond their own networks against attackers: establishing attribution, disrupting an ongoing intrusion, monitoring attacker behavior, or destroying stolen data. It sits on a spectrum from benign-adjacent techniques (beacons hidden in files that phone home when stolen) to outright intrusion into attacker or intermediary infrastructure. The debate is over two decades old and is one of the longest-running unresolved controversies in cyber policy.1^[2026 — Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations
The legal wall
In the U.S., nearly every form of hack back is criminal. The Computer Fraud and Abuse Act (CFAA, 18 U.S.C. § 1030) criminalizes accessing a computer “without authorization” or exceeding authorized access — § 1030(a)(5)(A) specifically covers knowingly transmitting code that intentionally causes damage — and “protected computer” covers essentially anything on the internet. The CFAA also creates civil liability, so a hack-back victim (or an innocent third party) can sue even if DOJ never prosecutes. DOJ’s own guidance to companies has long been blunt: do not hack into or damage the source computer. State computer-crime laws (NY § 156.10, CA § 502, VA § 18.2-152.4) and foreign statutes (UK Computer Misuse Act, German and Chinese criminal codes) pile on further exposure.2
One theory for legal cover: § 1030(f) exempts “lawfully authorized investigative, protective, or intelligence activity” of U.S. law-enforcement and intelligence agencies. Whether that exception can flow through to private firms acting under government direction has never been tested in court — but it is the likely legal theory beneath government-deputized private operations.3
The policy debate
For: government cannot be everywhere; victims facing an active intrusion shouldn’t have to wait for authorities who may never come; credible hack-back raises attacker costs and deters. Against: attribution is hard even for intelligence agencies — attackers route through compromised third-party infrastructure and false flags, so companies “fire back blindly” at innocents; collateral damage invites civil/tort suits and diplomatic incidents; retaliation can drag a company (and then the government) into escalation with a nation-state; and licensing private offense erodes the international norm the U.S. spent years building (“would we accept others doing this on our networks?”). Former NSA director Mike Rogers warned hack-back bills mean “putting more gunfighters out on the street in the Wild West.” Skeptics also question efficacy: ransomware groups have proven resilient to even coordinated law-enforcement takedowns.45
The ACDC Act (2017–2019)
The most prominent legislative attempt: Rep. Tom Graves’s Active Cyber Defense Certainty Act (H.R. 4036, 2017; revised with Rep. Gottheimer 2019). Two distinct mechanisms:6
- Beacon exclusion (§ 3): a full CFAA exemption for “attributional technology” — code originating on the defender’s own system that elicits locational/attributional data when stolen, without destroying data or creating intrusive access. The low-risk, high-value case; even critics mostly accepted it.
- Active cyber defense measures (§ 4): only an affirmative defense (you can still be charged and must litigate), limited to three purposes — attribution for law enforcement, disrupting continued unauthorized activity against the defender’s own network, and monitoring attacker behavior to build defenses — and voided by seven forbidden effects (intentional destruction of others’ data, reckless injury/financial loss, threats to public health/safety, more-than-reconnaissance on intermediary computers, persistent disruption, any impact on government/national-defense systems).
- FBI loop (§§ 5–6): mandatory advance notice to the FBI’s National Cyber Investigative Joint Task Force before deploying an ACDM, plus a voluntary preemptive-review pilot. Kristin Eichensehr’s key observation: looping in the FBI may make the private conduct attributable to the U.S. government under international law — the oversight mechanism itself creates state responsibility.
- The bill never emerged from committee; NSA and DOJ were openly skeptical. It also amended only the CFAA — leaving the Wiretap Act, ECPA, and state laws untouched — and offered no civil-liability protection.
The 2025–2026 shift: from debate to deputization
- March 2026: the administration’s National Cybersecurity Strategy made private-sector offensive participation its tentpole under “Shape Adversary Behavior” — incentives for companies to “identify and disrupt adversary networks,” against nation-state actors as well as criminals. Officials: “unapologetic, unafraid to do offensive cyber” (NSC’s Bulazel); proactive “costs and consequences” (National Cyber Director Cairncross).7
- 2025: Rep. Schweikert’s Scam Farms Marque and Reprisal Authorization Act (H.R. 4988) would delegate the Article I § 8 letters-of-marque power to the President to commission “privately armed and equipped persons” to seize persons and property of cybercriminal enterprises abroad — the privateering analogy made literal. Referred to House Foreign Affairs; not passed.8
- August 12, 2026: an NSPM (“Expanding Capabilities to Combat Transnational Cyber-Enabled Crime”) directed the Homeland Security Task Force’s National Coordination Center to stand up a program in which vetted private security companies conduct cyber operations against foreign transnational criminal organizations “under the direction, control, and authority of the U.S. Government.” Mechanics: two Executive Directors (DOJ + DHS), vetting before contracting, a **20.8B in reported 2025 consumer losses).9
- Reactions split on expected lines: Veracode’s Chris Wysopal — “a pretty big shift in US cyber policy… a major expansion of the private sector’s role in offensive cyber operations”; former Cyber National Mission Force leader Jason Kikta — “a perpetual motion machine for billable threats.”10
Open questions
- Legal basis untested: the CFAA and state statutes remain in force; an NSPM cannot amend them. The program presumably rests on § 1030(f) direction-and-control theories that no court has ruled on. Companies are advised not to rely on informal non-prosecution assurances.11
- Attribution at private-sector scale: the Eichensehr problem is now live — operations “at the direction of the U.S. Government” are exactly the fact pattern that makes private conduct state-attributable under the ILC Articles, with countermeasure rights for aggrieved states.
- Escalation and misidentification: TCOs hide behind false flags and innocent intermediary infrastructure — the same resilience that blunts takedowns (see blockchain-c2-infrastructure for the takedown-resistant end of that spectrum).
- Incentive design: bond/escrow + forfeiture is a real constraint, but Kikta’s jab names the failure mode — a standing private offensive market monetizes the threats it claims to suppress.
Cross-domain connections
- Letters of marque / privateering (history): the Constitution’s marque-and-reprisal clause licensed private violence under sovereign authority — with bonds, prize courts, and abuse problems that rhyme with the $1M escrow and vetting regime. H.R. 4988 makes the analogy explicit text. Privateering was eventually killed by the 1856 Declaration of Paris partly because states couldn’t control their licensees — the same control problem the hack-back debate keeps rediscovering.
- Norms (game theory): the “norms erosion” objection is a live instance of how norms collapse — not by repeal but by the norm-setter’s own defection; the U.S. built the “unauthorized hacking is criminal” norm and is now carving a sovereign exception to it.
- Structural vs. behavioral fixes: deputizing offense is the supply-side mirror of the finding in security-awareness-training — when behavioral programs underperform, institutions reach for structural levers, including ones with their own second-order risks.
See Also
- blockchain-c2-infrastructure — the takedown-resistant ransomware infrastructure this program aims at
- military-innovation-and-adaptation — offense/defense adaptation cycles at organizational scale
- norms — the enforcement/erosion dynamics underneath the policy debate
- security-awareness-training — the structural-vs-behavioral pattern in security policy
- ufc-mma-business-model — the theatrical mirror: state ground hosting private spectacle; both blur who owns legitimate violence
Sources
- 2026 — White House taps security firms for offensive hack-back operations
- 2026 — Fact Sheet: President Donald J. Trump Expands Capabilities to Combat Transnational Cyber-Enabled Crime
- 2026 — Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations
- 2019 — Hackback Is Back: Assessing the Active Cyber Defense Certainty Act
Footnotes
-
2019 — Hackback Is Back: Assessing the Active Cyber Defense Certainty Act ↩
-
2026 — Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations ↩
-
2026 — Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations ↩
-
2019 — Hackback Is Back: Assessing the Active Cyber Defense Certainty Act ↩
-
2026 — Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations ↩
-
2019 — Hackback Is Back: Assessing the Active Cyber Defense Certainty Act ↩
-
2026 — Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations ↩
-
2026 — Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations ↩
-
2026 — Fact Sheet: President Donald J. Trump Expands Capabilities to Combat Transnational Cyber-Enabled Crime ↩
-
2026 — White House taps security firms for offensive hack-back operations ↩
-
2026 — Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations ↩