Skip to content
Sunday, 16 August 2026 Dubai · GST
UAE, UNFILTERED
Trend Analysis

America Is Hiring Private Companies to Disrupt Cybercriminals

The United States is creating a legal route for private companies to do something cybersecurity firms are normally told not to do: reach back into a criminal network and disrupt it.

Share this story

The United States is creating a legal route for private companies to do something cybersecurity firms are normally told not to do: reach back into a criminal network and disrupt it.

A presidential memorandum signed August 12 directs a federal program that can authorize vetted US companies to conduct cyber surveillance and “cyber effects” operations against specified foreign transnational criminal organizations. Those effects can include disruption, denial, degradation or destruction of information systems. The important caveat is just as large as the headline: participating companies do not receive a free-standing license to hack back. Operations are supposed to be approved, supervised and conducted on behalf of the US government.

The Robius Action Brief
Important
Why it matters

The program moves private cybersecurity companies closer to government-directed offensive operations instead of limiting them to defense, investigation and takedown support.

Who should care

Cybersecurity firms, legal teams, multinational companies and UAE organizations that share threat intelligence with US partners should understand the boundary.

Opportunities

The program could disrupt ransomware, fraud and criminal infrastructure faster when government and private threat intelligence can be combined.

Risks or limitations

Attribution errors, shared infrastructure and cross-border effects create legal, diplomatic and collateral-risk questions even under government supervision.

What happens next

DOJ and DHS program leaders must establish operating procedures, with the memorandum setting a 60-day implementation window.

What you can do

Do not interpret the policy as permission for corporate hack-back; keep defensive response, evidence preservation and law-enforcement escalation separate.

Who benefits

US authorities gain access to private-sector capability and speed; selected cybersecurity companies could gain a new government-directed operating role.

Who can participate

Only vetted US participating companies under federal contracts and oversight; ordinary businesses are not authorized to hack attackers back.

What readers should monitor

Watch which companies participate, how targets are approved, what oversight is disclosed and whether operations create unintended effects.

What the Memorandum Actually Creates

The program sits under a federal National Coordination Center and is to be overseen jointly by the US Department of Justice and Department of Homeland Security. Participating companies must be vetted and operate under contracts that define what they may do.

The White House language is unusually direct. It defines cyber effects operations as activity that can manipulate, disrupt, deny, degrade or destroy information systems, networks, infrastructure or information. That is offensive capability, not just monitoring.

But the operational control stays with government. The memorandum says resulting actions are to be conducted on behalf of and under federal supervision. It also requires deconfliction across relevant agencies, and allows contracts to require a bond or escrow of at least $1 million that can be forfeited for noncompliance.

This Is Not Corporate Hack-Back

The distinction matters because “hack back” has long been tempting shorthand for companies frustrated by ransomware and fraud. A victim sees the attacker’s infrastructure and wants to break it. The problem is that infrastructure can be compromised, rented, shared or located in another jurisdiction. The machine you attack may not belong to the criminal you think it does.

This program does not tell ordinary US companies, much less companies in the UAE, that they may retaliate on their own. It creates a controlled channel for selected companies acting under government authority against designated foreign criminal organizations.

That is also why the fairness test matters here. The policy is a major expansion of private participation in offensive cyber activity, but private contractors have supported governments in cyber and intelligence work before. The new part is the formal program and the explicit operational role, not the invention of public-private cyber cooperation.

Why UAE Companies Should Still Watch It

The policy does not change UAE law. A Dubai company does not gain any new authority because Washington created a US program.

The relevance is operational. Cybercrime is cross-border, and UAE businesses often use US cloud, security, payment and threat-intelligence providers. If those providers start participating in government-directed disruption operations, the boundary between commercial threat intelligence and government action becomes more important to understand.

Our recent work on agent and infrastructure security focused on containing what software can reach. The same discipline applies during incident response: know which actions your own team is authorized to take, which belong to a vendor and which require law enforcement.

The Real Risk Is Mistaking Speed for Authority

Cyber defenders increasingly operate at machine speed. AI can identify infrastructure, correlate indicators and propose actions far faster than a human analyst. That makes a government-approved offensive program more technically plausible. It also makes mistaken action more scalable.

The control question is therefore familiar: who can authorize the irreversible step? Detection can be automated aggressively. Destruction should have a much higher bar. The White House memorandum tries to put that bar in government approval and operating procedures. Whether that works in practice is the story to watch.

The Robius Layer

The cybersecurity industry has spent years telling companies not to chase attackers across the internet. The US is not abandoning that rule for everyone. It is creating a supervised exception for selected private operators acting as an extension of government power.

That may improve disruption of transnational cybercrime. It also creates a new category of contractor whose work sits somewhere between cybersecurity service and state action. The first question is no longer only whether private companies can do it. It is how tightly the authority is bounded when they do.

Sources

Robius.news — Dubai, UAE — 2026 | Built to be first. Built to be trusted.