Canadian Cyber Security Journal
SOCIAL:
Filed under: Legislation

White House Authorizes Private Hack-Back Operations Against Cybercriminals — What It Means for Canada

What Happened

President Trump signed a National Security Presidential Memorandum on August 12, 2026, establishing the first formal U.S. program allowing vetted private security companies to conduct offensive cyber operations against cyber-enabled transnational criminal organizations. The Department of Justice and Department of Homeland Security jointly administer the program through a new National Coordination Center, led by two Executive Directors — one appointed by the Attorney General and one by the Secretary of Homeland Security.

Participating firms must receive written, per-operation approval before acting against a specific target. The memorandum does not grant blanket authority to hack back at will. Companies operating without specific per-operation authorization remain subject to civil and criminal penalties under the Computer Fraud and Abuse Act. The program targets criminal groups threatening American citizens, critical infrastructure, and domestic businesses, rather than nation-state actors.

Why This Matters for Canadian Organizations

Canada shares deeply interconnected digital infrastructure and cross-border data flows with the United States, and offensive operations against transnational criminal networks carry real risk of touching shared or adjacent systems, including infrastructure routed through or hosted in Canada. Misattribution during an authorized hack-back operation risks implicating Canadian networks compromised and repurposed by the same criminal group being targeted, creating legal and diplomatic complications regardless of intent.

The program also sets a precedent Canadian policymakers are likely watching closely. The Canadian Centre for Cyber Security and CSE currently operate under a government-only model for offensive cyber activity, and any move by a close ally toward private-sector offensive authorization raises questions about future coordination frameworks, information-sharing protocols under Bill C-26, and how Canadian firms should respond if approached to participate in similar U.S.-led operations.

What to Do

Security teams at Canadian organizations with U.S. operations or U.S.-hosted infrastructure should monitor guidance from CSE and the Canadian Centre for Cyber Security as this program develops, and document unusual network activity tied to transnational criminal operations for potential deconfliction purposes. Legal and compliance teams should review vendor contracts and incident response plans for clauses touching cross-border offensive cyber activity. Full details are available from SecurityWeek and BleepingComputer.

Enjoy this article? Don’t forget to share.