Trump Administration Announces New "Hacking Back" Program
The Volokh Conspiracy
Mostly law professors | Sometimes contrarian | Often libertarian | Always independent
About The Volokh Conspiracy Editorial Independence Who we are Books Volokh Daily Email Archives Search DMCA RSS
Trump Administration Announces New "Hacking Back" Program
But does it legalize hacking under the CFAA?
Orin S. Kerr | 8.17.2026 4:38 PM
The Trump Administration announced a new program on hacking back last week, allowing United States companies to hack back in some circumstances in cooperation with United States officials. The program is premised on some interesting theories about the scope of the Computer Fraud and Abuse Act, and I think it raises a lot of complicated issues under that statute.
In this post, I wanted to take a look at some of them.
First, here's the language from the Trump Administration's announcement:
. . . . The National Coordination Center (NCC), established pursuant to section 6(d) of Executive Order 14159 of January 20, 2025 (Protecting the American People Against Invasion), shall create, manage, and maintain a Program to authorize Participating Companies, as defined in section 4(f) of this memorandum, to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government. As part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement, this Program shall:
(i) be overseen by co-Executive Directors, one from the Department of Justice, designated by the Attorney General, and one from the Department of Homeland Security, designated by the Secretary of Homeland Security (Program Executive Directors). The Program Executive Directors shall be delegated authority to approve, after coordination with each other, cyber operations conducted within the Program by personnel of their respective departments, except that they may not approve operations resulting in Critical Outcomes, as defined in section 4(b) of this memorandum. Cyber operations shall only be approved after coordination between the Program Executive Directors, and any resulting operational action will be exclusively conducted on behalf of and under the supervision of the Federal Government pursuant to the Federal Government's lawful authorities;
(ii) require Participating Companies to enter into contractual agreements with the Department of Justice or the Department of Homeland Security, which shall ensure that Participating Companies undergo rigorous vetting and that their performance adheres to the strict operational procedures outlined in the implementation guidance directed in section 3 of this memorandum; and
(iii) permit Participating Companies to enter into commercial agreements with:
(A) private sector entities, from which the Participating Companies may receive for the purpose of proposing responsive cyber operations to the NCC any threat information collected in the course of those entities' normal business activities; and
(B) Federal, State, local, tribal, and territorial agencies, which will identify CE-TCO threats to the Participating Companies in a manner that enables them to propose cyber operations to the NCC that address those threats.
(b) The NCC........
