Courts & Constitutional LawCybersecurity & PrivacyRisk & Compliance

White House Cyber Memo Clashes With Congressional Authority

Five bills since February 2025 asked Congress to license private operators against foreign criminals. None passed.

Josh LynwoodFounder
Published
Read time
27 min
Share
Where Things Stand

An Exception to a Criminal Statute Is Now an Operating Program

A new Program sits inside the National Coordination Center, the operational hub of the Homeland Security Task Force network. Created by the August 12 memorandum "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," it authorizes vetted firms, which the memorandum calls "Participating Companies," to run surveillance and destructive operations against foreign criminal organizations. The reach is wide, and the operative rules are not in the public document.

  • Who Approves. Two co-Executive Directors, one from Justice and one from Homeland Security, approve operations jointly. They may not approve anything likely to produce a "Critical Outcome," defined in Section 4(b) as loss of life or serious injury, or an act rising "to the level of use of force or armed attack under international law." Every operations package needs written approval before action.
  • How Wide the Authority Runs. Section 4(a) defines a Cyber Effects Operation as activity resulting in the "manipulation, disruption, denial, degradation, or destruction" of information systems, networks, or "physical or virtual infrastructure controlled by information systems." Section 4(d) concedes the predicate rather than avoiding it: surveillance operations "entail accessing such information systems without authorization from the owner or operator or by exceeding authorized access."
  • What It Costs to Enter. Companies contract with the Department of Justice or the Department of Homeland Security and post a bond of not less than $1 million, forfeitable on non-compliance.
  • Where the Rules Actually Live. Sections 3(a)(v) and 3(a)(vi) place the operational workflow and the target-adjudication framework "in conformance with the classified annex to this memorandum." Consensus operating procedures are due within 60 days, which lands October 11, 2026. A status report is due within 180 days, February 8, 2027, and annually after that, and it goes to the Homeland Security Advisor and the National Cyber Director.
  • The Problem It Names. Americans reported more than $20.8 billion in losses to internet crime in 2025, per the FBI's Internet Crime Complaint Center, in the first year complaints passed one million. IC3's own total for the year is $20.877 billion. The stated problem is real, and nothing in this analysis turns on doubting it.
Sources4See all 63
Congress was asked five times. What is Congress writing instead?

Congress Is Writing Its Own Version, With the Oversight Attached

Section 2(b) says the Program will operate "in accordance with the Constitution and all other applicable laws," naming Section 1030 of Title 18, the Computer Fraud and Abuse Act, "thereby ensuring that Participating Companies are acting under the control and oversight of the United States Government." That sentence is the whole legal theory, and it points at 18 U.S.C. 1030(f), which provides that the section "does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States, a State, or a political subdivision of a State, or of an intelligence agency of the United States." The chapeau to Section 2(a) then reads: "As part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement, this Program shall." The tracking is close to verbatim, and it reads as deliberate drafting toward the exception.

Four features carry weight. 18 U.S.C. 1030(f) is a A provision saying a law does not prohibit something, as distinct from one granting permission to do it., not a grant: it says the statute "does not prohibit," not that anything is authorized. It is keyed to activity that is already "lawfully authorized," which presupposes an authorization supplied by some other law, and the memorandum never names one. Its three categories, investigative, protective and intelligence, do not obviously contain destruction. The exception also runs to activity "of a law enforcement agency," which names government bodies rather than their contractors. There is little to read against it, and the little that exists was written for a different problem: the 1996 Senate report that accompanied the provision reproduces the subsection with no section-by-section explanation, and the Congressional Research Service's treatment of it in the standing overview of the statute is one sentence, that the subsection "disclaims any application to otherwise permissible law enforcement activities." The word doing the work there is "otherwise." The government's strongest answer is that contractors acting under an agency's direction have long been treated as inside that agency's authority for other purposes, and that the classified annex may supply the predicate the public text omits.

The authority to license private actors to act against a nation's enemies is not a new idea, and it has an address in the Constitution. Article I, Section 8, Clause 11 gives Congress, not the President, the power to grant Historic commissions licensing private parties to act against a nation's enemies, granted by Congress under Article I.. Members have been asking Congress to use it, five times since February 2025. The memorandum itself claims no such power, and the comparison that follows is to what was proposed, not to what was invoked.

  • H.R. 1238 and S. 3567 (Burchett, R-Tenn., February 12, 2025; Lee, R-Utah, December 18, 2025). Companion cartel bills. Each requires a security bond without specifying forfeiture, neither states an upside, and neither carries any liability protection. Both pending.
  • H.R. 4988 (Schweikert, R-Ariz., August 15, 2025). The Scam Farms Marque and Reprisal Authorization Act aims privately armed crews at cyber criminals and names the Computer Fraud and Abuse Act by section number. It requires a bond with forfeiture unspecified, states no upside, and carries no immunity clause. Pending.
  • H.R. 9697 and S. 5000 (Burchett and Lee, July 15, 2026). The only pair carrying liability protection, Section 8: "No cause of action shall lie or be maintained in any court against the holder." The bond is expressly forfeitable under Section 5(b)(2), and the operator keeps recoveries subject to a 15 percent federal ceiling, with unexpended funds directed to the Crime Victims Fund. H.R. 9697 is pending in House Foreign Affairs, S. 5000 in Senate Foreign Relations.
  • The memorandum (August 12, 2026). The only one of the five in force. It rests on no Article I theory at all, pointing instead at 18 U.S.C. 1030(f). The bond is forfeitable at not less than $1 million. There is no shield and no government payment.

Five such bills have been introduced since February 2025. None has passed. Only the cyber pair carries any liability protection, Section 8: "No cause of action shall lie or be maintained in any court against the holder." Their operative language is older than it looks. The commissioning stem, the seizure clause and the bond sentence all appear word for word in a bill Ron Paul introduced on October 10, 2001 against Osama bin Laden. In twenty-four years the drafting has changed mainly in the noun that follows "the person and property of."

The more instructive document is not a marque bill at all. Section 1604 of the Senate's defense authorization for 2027, reported on June 15, 2026, would let the Secretary of Defense "enter into a contract with a private sector entity to conduct a cyber operation," and Congress attached a price to it. The work is limited to "the sole purpose of access generation and maintenance," which is to say getting in and staying in, not breaking anything. A cleared federal employee must be "present at all times." It runs as a pilot that terminates on or before December 31, 2030. The contractor must be named to the congressional defense committees within ten days of signing, and every operation reported within forty-eight hours of both its start and its finish, identifying the target, the contractor, and the federal employee who supervised it. Its quarterly briefings hang on section 484 of title 10, the same provision the military's clandestine-operations rule uses.

Our read is that the route actually taken leaves the operator worse off than the one pair of bills that answered the liability question, on both ledgers at once. Those bills would have supplied a statutory bar on civil suit, a share of what was recovered, and the thing 1030(f) presupposes and the memorandum never names: a written congressional authorization. The memorandum supplies a forfeitable million dollars and no government payment at all. Jonathan Ong of Omdia made the underlying observation the day after the memorandum was signed, telling CSO Online the commercial company "has neither immunity nor indemnity that we can see from the memorandum." What the comparison adds is the counterfactual: the protections were drafted, they sit in a pending bill, and the instrument that issued omitted them.

Precision matters here, and it cuts against the easy version of this story. The memorandum never invokes the Marque and Reprisal Clause and does not claim that power. It claims something narrower and, on its own terms, more ordinary. The clash is not that the President seized a congressional power. It is that the branch the Constitution names was never asked to decide, while five bills asking it to decide sat unvoted. An official at the Office of the National Cyber Director had described a narrower posture in public five months earlier. At the Prague Cyber Security Conference in March 2026, Thomas Lind, a senior adviser there, said of private-sector involvement that "does not mean hack back, that does not mean letters of marque," adding that the United States was not interested in fighting pirates with pirates. Representative Bennie Thompson of Mississippi, the committee's ranking Democrat, responded on August 13 in a statement to The Record that the proper venue "is through the Administration working with Congress to ensure the necessary authorities, legal procedures, and resources are in place rather than a presidential memorandum that raises as many questions as it answers."

Sources15See all 63
Intersections

One Case on the Books, and It Is About a Search Warrant

A legal position that cannot be contested is not thereby correct. It is only unexamined, and where the same instrument removes the route to contesting it, the question does not disappear so much as move onto the balance sheet of whoever performed the work.

Courts & Constitutional Law. One federal district court has applied the subsection to private companies, in a case with nothing to do with offensive operations. In March 2024 the District of Puerto Rico dismissed a claim under the Computer Fraud and Abuse Act against DISH Network and NagraStar over their role in searches of a Puerto Rican broadcaster's facilities, holding that because the companies' "challenged conduct was 'lawfully authorized investigative . . . activity' under the search warrants, Plaintiffs have not pleaded a viable CFAA claim." The First Circuit affirmed on December 2, 2025 in a one-paragraph judgment that adopted the district court's reasoning and never mentioned the subsection, then denied the appellants' request for a written opinion six days later. The Supreme Court is scheduled to consider the certiorari petition at its conference of September 28, 2026. Nothing found addresses whether the exception covers destruction rather than investigation. One court has construed it in relation to a private contractor operating outside a warrant, in a discovery ruling that declined to decide the question. Section 5(c) then closes the exit, creating no right enforceable against the United States, so a Participating Company cannot obtain a A court ruling on the lawfulness of conduct before enforcement, which requires an adverse party. that the theory holds, and the entity that would ordinarily be adverse is the one signing its approvals. What Section 5(c) does not touch is 18 U.S.C. 1030(g), which gives any person who suffers damage or loss a civil action against the violator within two years, and the statute's definition of a protected computer reaches machines located outside the United States.

Risk & Compliance. That leaves a company holding an exposure with no stated ceiling and no clock that stops early. 18 U.S.C. 3282 keeps 2026 conduct chargeable into 2031, across at least one change of administration, and no administration can bind a successor's charging discretion. The two fallback protections are trial defenses rather than authorizations: public authority and entrapment by estoppel are raised after indictment, on the defendant's burden, and the Ninth Circuit's model instructions require both that the official actually had power to authorize the conduct and that the defendant's reliance was reasonable. Each element turns back on the same disputed question. Insurance is unlikely to close the gap either, since a leading market forecast published in December 2025 reads cyber risk from the posture of the insured as victim and the state-backed exclusion Lloyd's requires in standalone cyber policies, per WTW's reading of the requirement, turns on the attribution question Section 4(c)'s permissive default converts into a retroactive one. Whether any of that bites an authorized operation is untested, and it is a question for a board to put to its broker rather than a settled coverage opinion.

Crowell and Moring flags an exposure the memorandum does not address at all. When a successful operation leads to an indictment, criminal discovery may force disclosure of proprietary code, zero-day exploits and intelligence methodologies in open court, with the company's own personnel subject to cross-examination. The asset a firm brings to the Program is the asset a prosecution can compel it to surrender.

Nothing in the memorandum reaches the law of the country where the target sits. Section 3(a)(ix)'s promise of "any necessary authorization, judicial or otherwise" is triggered by contact with a United States person, not by a foreign computer-crime statute. The control language the Program needs for its own legal theory cuts the other way abroad: Section 2(a)(i) states that operations are conducted "on behalf of and under the supervision of the Federal Government," which is precisely the fact a foreign prosecutor would need to establish. That exposure travels with the staff, not the company.

There is also nothing yet to bid on. A search of every SAM.gov notice modified since August 12, of Justice and Homeland Security award actions in USAspending and FPDS, and of the government-wide full-text index returns no contract vehicle, solicitation or award for the Program. Companies weighing entry are doing so against an operating-procedures deadline of October 11 and no published way in.

More telling is what the memorandum declines to use, each an imperfect fit here: indemnification under Public Law 85-804 and FAR 52.250-1, which reaches claims arising from a risk the contract designates unusually hazardous and "not compensated for by insurance or otherwise"; and SAFETY Act designation, which caps third-party liability but is keyed to an act of terrorism. It contains no instance of indemnify, hold harmless, insurance, or liability.

What would make this wrong

A court reaches the scope of 1030(f) on facts resembling these, in any posture, or a Participating Company's contract is shown to carry indemnification under Public Law 85-804 and FAR 52.250-1, or a SAFETY Act designation issues for this work. Any of the three would mean the exposure is bounded by something other than the executive's own reading of the exception.

Open question

On the limitations side: 2026 conduct stays chargeable into 2031, so what, if anything, binds a successor administration toward companies that relied on this authorization?

Sources14See all 63
The Weave

The Weave maps a single development across domains and across time. Each row follows one domain from where things stand now through the next eighteen months, and expands for the reasoning behind that trajectory.

Wiiver
SECTOR / DOMAINclick a domain to expand
As It Standsthe current status
Immediate0–6 months
Near-Term6–18 months
Business + Markets
The memorandum names no compensation, no indemnity and no liability cap. The only money term running to the government is the company's forfeitable bond.
No indemnity, no cap
The memorandum's §4(d) defines the activity as unauthorized access. Whether any exclusion bites an authorized operation is untested, a question for a board's broker.
A five-year tail
18 U.S.C. 3282 keeps 2026 conduct chargeable into 2031, across at least one change of administration, and §5(c) creates no right the company can enforce.
Qualification, bonding, disclosure, reporting and annual re-evaluation are all specified. Compensation is not mentioned anywhere in the operative text.
All cost, no stated revenue
The memorandum's §3(a)(iv) authorizes a forfeitable bond of not less than $1 million, and §5(b) makes the Program 'subject to the availability of appropriations.'
Conflict, disclosed upward only
§2(a)(iii) puts the company between threat information and government targeting. §3(a)(iii) discloses that only to the National Coordination Center, not to the customer.
Government + Policy
The memorandum names section 1030; one subsection, 1030(f), is the only theory that fits. No court has held it reaches destruction or a contractor abroad.
Exception, not authority
18 U.S.C. 1030(f) says the CFAA 'does not prohibit' certain law-enforcement activity. It authorizes nothing, and the memorandum names no other authorization.
Two statutes, one label
The same 'Federal law enforcement' phrase also reaches the covert-action exclusion at 50 U.S.C. 3093(e)(3). Wiiver's inference; no source says it was invoked.
Five marque bills asked Congress for this authority since February 2025. None passed. The memorandum names no congressional recipient.
Asked and bypassed
Five bills, each a letter-of-marque bill by its own title, sought the authority since February 2025. The memorandum issued 28 days after the last pair.
No congressional addressee
The memorandum's §3(c) report goes to the Homeland Security Advisor and the National Cyber Director. Wiiver's inference: the framing keeps the committee duty off.
Technology + Engineering
Private disruption of criminal infrastructure already runs through federal courts. The memorandum keeps the private operator and removes the judge.
Judge swapped for annex
Approval moves from an Article III judge on a public docket to two executive directors applying a classified adjudicatory framework under §3(a)(v) and (vi).
Attribution lag is permission
The memorandum's §4(c) assumes a group is not state-directed 'unless clear intelligence exists,' pointing destructive authority at the weakest attribution window.
wiiver.co · 5 impacted domains shownWiiverv1 · August 14, 2026
Looking Forward

Four Dates, and the One That Settles Anything Is Not on the List

Whether the authority behind this Program is ever examined by anyone outside the executive branch will show up in a short run of dated, checkable markers over the next two quarters. Each of them is a document that either appears or does not.

  • September 30, 2026 (The First Real Vehicle). Fiscal year funding lapses and no continuing resolution has been enacted. The House passed one on July 21, the Continuing Appropriations Act, 2027, that would run to December 4, 2026 unless full-year appropriations arrive first, and the Senate has not taken it up. Appropriations is how Congress answered this institution last time, with a use restriction and a reporting directive attached to the money. Congress appropriated $547 million for the Organized Crime Drug Enforcement Task Forces in fiscal 2025; five senators wrote to the Attorney General in June 2025 objecting to a proposal to zero it out, the Department closed the program anyway and moved more than 5,000 cases to the Homeland Security Task Forces, and appropriators answered with $300 million, a use restriction and quarterly reporting. This Program now sits inside that same institution with none of the three attached to it.
  • October 3, 2026 (Scheduled Marker). NSPM-11's 120-day deadline for updating national security procurement to onboard advanced AI models closes, eight days before this Program's own gate. The two clocks were set independently and land in the same week, which is a convergence to watch rather than a link either document draws.
  • October 11, 2026 (The Real One). The consensus operating procedures are due. Watch whether they attempt to define the 1030(f) predicate: advisory commentary has been deferring the legal question to these procedures, and procedures written by the Program Executive Directors cannot enlarge a statutory exception. Watch also for any invocation of FAR 52.250-1 or a SAFETY Act designation in the Justice and Homeland Security contracts. Either would signal that the government does not expect commercial insurance to answer. What would falsify this reading: operating procedures that name the separate statutory authorization the memorandum omits, or a court construing 1030(f) to reach contractor-executed destruction. Either would answer the question this analysis says the procedures cannot reach.
  • February 8, 2027 (Scheduled Marker). The first status report is due, to the Homeland Security Advisor and the National Cyber Director. Both are executive-branch officials. There is no congressional addressee anywhere in the memorandum, so a committee that wants the report has to ask for it.
  • The Tell. The resolving signal is whether any document produced in this window is readable by someone outside the executive branch. If the Supreme Court takes the certiorari petition on September 28, or a committee extracts the procedures, or a contract term surfaces in a protest or a disclosure, then the theory acquires an examiner it does not currently have. If instead the funding fight passes without a rider, the procedures restate Section 2(b), and the February report goes only to its two executive-branch recipients, then the authority question has been settled by nobody, and it stays open until a prosecutor, a foreign plaintiff or a successor administration opens it.

A company can decline this work today at no cost and cannot decline it retroactively in 2031. The reversible move is to treat the authorization as an untested executive-branch position and to price it as one: contractual indemnity rather than the memorandum's silence, run-off cover that outlasts the administration, and a contemporaneous record of what was approved, by whom, and on what scope. Five marque bills that would have put the question to Congress are pending in committee. A legal theory that nobody can contest is not the same thing as a legal theory that is correct, and the difference will be discovered by whichever company is holding the contract when someone decides to find out.

Sources10See all 63

Every issue

  1. 01Intersection of the week
  2. 02Impact of the week
  3. 03The week in review

Wiiver Weekly

One free email, Saturdays at 7:00 AM ET.

Unsubscribe anytime.

Sources and Verification
48 of the 63 sources cited here are primarystatutes, rules, bill text, court filings, agency advisories and the memorandum itself, read directly
Primary sources48
Secondary sources, by sector15
Government + Policy6
Business + Markets6
v1 · Reviewed by Josh Lynwood · August 14, 2026
Back to top