Courts & Constitutional LawCybersecurity & PrivacyRisk & Compliance
White House Cyber Memo Clashes With Congressional Authority
Five bills since February 2025 asked Congress to license private operators against foreign criminals. None passed.
A presidential memorandum signed August 12, 2026 lets vetted private companies run surveillance and destructive cyber operations against foreign criminal networks. Five bills since February 2025 asked Congress to license private operators against foreign criminals. None passed. The memorandum rests instead on a single sentence of the Computer Fraud and Abuse Act, a savings clause providing that the statute does not prohibit certain law-enforcement activity rather than authorizing anything. One district court applied the same exception to private companies helping execute a search warrant, and nothing located holds it reaches destruction or operations abroad. The judgment here is that the instrument is drafted so that no participating company can find out whether the theory holds. Section 5(c) creates no enforceable right, the party that would normally be adverse is the party issuing the approvals, and the criminal clock runs five years.
- The National Coordination Center now runs a Program authorizing vetted companies to conduct surveillance and destructive operations against foreign criminal groups, with two executive directors approving every package in writing.
- The legal basis it points at is 18 U.S.C. 1030(f), an exception keyed to activity that is already lawfully authorized. The memorandum names section 1030 without a subsection, and never names the other law that would supply that authorization.
- Five marque bills have been introduced since February 2025 and none has passed. Meanwhile the Senate's own defense bill would let Defense contract for cyber operations, with a federal employee present and every operation reported to committee.
- The model being displaced had a judge in it. Roughly forty civil actions since 2008 ran on a public docket, and the authorized effect widens from seizure to destruction as that docket disappears into a classified annex.
- What a company owes is specified in detail: qualification, a forfeitable million-dollar bond, disclosure of every commercial relationship, and annual re-evaluation. What it is owed is not specified at all.
An Exception to a Criminal Statute Is Now an Operating Program
A new Program sits inside the National Coordination Center, the operational hub of the Homeland Security Task Force network. Created by the August 12 memorandum "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," it authorizes vetted firms, which the memorandum calls "Participating Companies," to run surveillance and destructive operations against foreign criminal organizations. The reach is wide, and the operative rules are not in the public document.
- Who Approves. Two co-Executive Directors, one from Justice and one from Homeland Security, approve operations jointly. They may not approve anything likely to produce a "Critical Outcome," defined in Section 4(b) as loss of life or serious injury, or an act rising "to the level of use of force or armed attack under international law." Every operations package needs written approval before action.
- How Wide the Authority Runs. Section 4(a) defines a Cyber Effects Operation as activity resulting in the "manipulation, disruption, denial, degradation, or destruction" of information systems, networks, or "physical or virtual infrastructure controlled by information systems." Section 4(d) concedes the predicate rather than avoiding it: surveillance operations "entail accessing such information systems without authorization from the owner or operator or by exceeding authorized access."
- What It Costs to Enter. Companies contract with the Department of Justice or the Department of Homeland Security and post a bond of not less than $1 million, forfeitable on non-compliance.
- Where the Rules Actually Live. Sections 3(a)(v) and 3(a)(vi) place the operational workflow and the target-adjudication framework "in conformance with the classified annex to this memorandum." Consensus operating procedures are due within 60 days, which lands October 11, 2026. A status report is due within 180 days, February 8, 2027, and annually after that, and it goes to the Homeland Security Advisor and the National Cyber Director.
- The Problem It Names. Americans reported more than $20.8 billion in losses to internet crime in 2025, per the FBI's Internet Crime Complaint Center, in the first year complaints passed one million. IC3's own total for the year is $20.877 billion. The stated problem is real, and nothing in this analysis turns on doubting it.
Congress Is Writing Its Own Version, With the Oversight Attached
Section 2(b) says the Program will operate "in accordance with the Constitution and all other applicable laws," naming Section 1030 of Title 18, the Computer Fraud and Abuse Act, "thereby ensuring that Participating Companies are acting under the control and oversight of the United States Government." That sentence is the whole legal theory, and it points at 18 U.S.C. 1030(f), which provides that the section "does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States, a State, or a political subdivision of a State, or of an intelligence agency of the United States." The chapeau to Section 2(a) then reads: "As part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement, this Program shall." The tracking is close to verbatim, and it reads as deliberate drafting toward the exception.
Four features carry weight. 18 U.S.C. 1030(f) is a A provision saying a law does not prohibit something, as distinct from one granting permission to do it., not a grant: it says the statute "does not prohibit," not that anything is authorized. It is keyed to activity that is already "lawfully authorized," which presupposes an authorization supplied by some other law, and the memorandum never names one. Its three categories, investigative, protective and intelligence, do not obviously contain destruction. The exception also runs to activity "of a law enforcement agency," which names government bodies rather than their contractors. There is little to read against it, and the little that exists was written for a different problem: the 1996 Senate report that accompanied the provision reproduces the subsection with no section-by-section explanation, and the Congressional Research Service's treatment of it in the standing overview of the statute is one sentence, that the subsection "disclaims any application to otherwise permissible law enforcement activities." The word doing the work there is "otherwise." The government's strongest answer is that contractors acting under an agency's direction have long been treated as inside that agency's authority for other purposes, and that the classified annex may supply the predicate the public text omits.
The authority to license private actors to act against a nation's enemies is not a new idea, and it has an address in the Constitution. Article I, Section 8, Clause 11 gives Congress, not the President, the power to grant Historic commissions licensing private parties to act against a nation's enemies, granted by Congress under Article I.. Members have been asking Congress to use it, five times since February 2025. The memorandum itself claims no such power, and the comparison that follows is to what was proposed, not to what was invoked.
- H.R. 1238 and S. 3567 (Burchett, R-Tenn., February 12, 2025; Lee, R-Utah, December 18, 2025). Companion cartel bills. Each requires a security bond without specifying forfeiture, neither states an upside, and neither carries any liability protection. Both pending.
- H.R. 4988 (Schweikert, R-Ariz., August 15, 2025). The Scam Farms Marque and Reprisal Authorization Act aims privately armed crews at cyber criminals and names the Computer Fraud and Abuse Act by section number. It requires a bond with forfeiture unspecified, states no upside, and carries no immunity clause. Pending.
- H.R. 9697 and S. 5000 (Burchett and Lee, July 15, 2026). The only pair carrying liability protection, Section 8: "No cause of action shall lie or be maintained in any court against the holder." The bond is expressly forfeitable under Section 5(b)(2), and the operator keeps recoveries subject to a 15 percent federal ceiling, with unexpended funds directed to the Crime Victims Fund. H.R. 9697 is pending in House Foreign Affairs, S. 5000 in Senate Foreign Relations.
- The memorandum (August 12, 2026). The only one of the five in force. It rests on no Article I theory at all, pointing instead at 18 U.S.C. 1030(f). The bond is forfeitable at not less than $1 million. There is no shield and no government payment.
Five such bills have been introduced since February 2025. None has passed. Only the cyber pair carries any liability protection, Section 8: "No cause of action shall lie or be maintained in any court against the holder." Their operative language is older than it looks. The commissioning stem, the seizure clause and the bond sentence all appear word for word in a bill Ron Paul introduced on October 10, 2001 against Osama bin Laden. In twenty-four years the drafting has changed mainly in the noun that follows "the person and property of."
The more instructive document is not a marque bill at all. Section 1604 of the Senate's defense authorization for 2027, reported on June 15, 2026, would let the Secretary of Defense "enter into a contract with a private sector entity to conduct a cyber operation," and Congress attached a price to it. The work is limited to "the sole purpose of access generation and maintenance," which is to say getting in and staying in, not breaking anything. A cleared federal employee must be "present at all times." It runs as a pilot that terminates on or before December 31, 2030. The contractor must be named to the congressional defense committees within ten days of signing, and every operation reported within forty-eight hours of both its start and its finish, identifying the target, the contractor, and the federal employee who supervised it. Its quarterly briefings hang on section 484 of title 10, the same provision the military's clandestine-operations rule uses.
Our read is that the route actually taken leaves the operator worse off than the one pair of bills that answered the liability question, on both ledgers at once. Those bills would have supplied a statutory bar on civil suit, a share of what was recovered, and the thing 1030(f) presupposes and the memorandum never names: a written congressional authorization. The memorandum supplies a forfeitable million dollars and no government payment at all. Jonathan Ong of Omdia made the underlying observation the day after the memorandum was signed, telling CSO Online the commercial company "has neither immunity nor indemnity that we can see from the memorandum." What the comparison adds is the counterfactual: the protections were drafted, they sit in a pending bill, and the instrument that issued omitted them.
Precision matters here, and it cuts against the easy version of this story. The memorandum never invokes the Marque and Reprisal Clause and does not claim that power. It claims something narrower and, on its own terms, more ordinary. The clash is not that the President seized a congressional power. It is that the branch the Constitution names was never asked to decide, while five bills asking it to decide sat unvoted. An official at the Office of the National Cyber Director had described a narrower posture in public five months earlier. At the Prague Cyber Security Conference in March 2026, Thomas Lind, a senior adviser there, said of private-sector involvement that "does not mean hack back, that does not mean letters of marque," adding that the United States was not interested in fighting pirates with pirates. Representative Bennie Thompson of Mississippi, the committee's ranking Democrat, responded on August 13 in a statement to The Record that the proper venue "is through the Administration working with Congress to ensure the necessary authorities, legal procedures, and resources are in place rather than a presidential memorandum that raises as many questions as it answers."
One Case on the Books, and It Is About a Search Warrant
A legal position that cannot be contested is not thereby correct. It is only unexamined, and where the same instrument removes the route to contesting it, the question does not disappear so much as move onto the balance sheet of whoever performed the work.
Courts & Constitutional Law. One federal district court has applied the subsection to private companies, in a case with nothing to do with offensive operations. In March 2024 the District of Puerto Rico dismissed a claim under the Computer Fraud and Abuse Act against DISH Network and NagraStar over their role in searches of a Puerto Rican broadcaster's facilities, holding that because the companies' "challenged conduct was 'lawfully authorized investigative . . . activity' under the search warrants, Plaintiffs have not pleaded a viable CFAA claim." The First Circuit affirmed on December 2, 2025 in a one-paragraph judgment that adopted the district court's reasoning and never mentioned the subsection, then denied the appellants' request for a written opinion six days later. The Supreme Court is scheduled to consider the certiorari petition at its conference of September 28, 2026. Nothing found addresses whether the exception covers destruction rather than investigation. One court has construed it in relation to a private contractor operating outside a warrant, in a discovery ruling that declined to decide the question. Section 5(c) then closes the exit, creating no right enforceable against the United States, so a Participating Company cannot obtain a A court ruling on the lawfulness of conduct before enforcement, which requires an adverse party. that the theory holds, and the entity that would ordinarily be adverse is the one signing its approvals. What Section 5(c) does not touch is 18 U.S.C. 1030(g), which gives any person who suffers damage or loss a civil action against the violator within two years, and the statute's definition of a protected computer reaches machines located outside the United States.
Risk & Compliance. That leaves a company holding an exposure with no stated ceiling and no clock that stops early. 18 U.S.C. 3282 keeps 2026 conduct chargeable into 2031, across at least one change of administration, and no administration can bind a successor's charging discretion. The two fallback protections are trial defenses rather than authorizations: public authority and entrapment by estoppel are raised after indictment, on the defendant's burden, and the Ninth Circuit's model instructions require both that the official actually had power to authorize the conduct and that the defendant's reliance was reasonable. Each element turns back on the same disputed question. Insurance is unlikely to close the gap either, since a leading market forecast published in December 2025 reads cyber risk from the posture of the insured as victim and the state-backed exclusion Lloyd's requires in standalone cyber policies, per WTW's reading of the requirement, turns on the attribution question Section 4(c)'s permissive default converts into a retroactive one. Whether any of that bites an authorized operation is untested, and it is a question for a board to put to its broker rather than a settled coverage opinion.
Crowell and Moring flags an exposure the memorandum does not address at all. When a successful operation leads to an indictment, criminal discovery may force disclosure of proprietary code, zero-day exploits and intelligence methodologies in open court, with the company's own personnel subject to cross-examination. The asset a firm brings to the Program is the asset a prosecution can compel it to surrender.
Nothing in the memorandum reaches the law of the country where the target sits. Section 3(a)(ix)'s promise of "any necessary authorization, judicial or otherwise" is triggered by contact with a United States person, not by a foreign computer-crime statute. The control language the Program needs for its own legal theory cuts the other way abroad: Section 2(a)(i) states that operations are conducted "on behalf of and under the supervision of the Federal Government," which is precisely the fact a foreign prosecutor would need to establish. That exposure travels with the staff, not the company.
There is also nothing yet to bid on. A search of every SAM.gov notice modified since August 12, of Justice and Homeland Security award actions in USAspending and FPDS, and of the government-wide full-text index returns no contract vehicle, solicitation or award for the Program. Companies weighing entry are doing so against an operating-procedures deadline of October 11 and no published way in.
More telling is what the memorandum declines to use, each an imperfect fit here: indemnification under Public Law 85-804 and FAR 52.250-1, which reaches claims arising from a risk the contract designates unusually hazardous and "not compensated for by insurance or otherwise"; and SAFETY Act designation, which caps third-party liability but is keyed to an act of terrorism. It contains no instance of indemnify, hold harmless, insurance, or liability.
A court reaches the scope of 1030(f) on facts resembling these, in any posture, or a Participating Company's contract is shown to carry indemnification under Public Law 85-804 and FAR 52.250-1, or a SAFETY Act designation issues for this work. Any of the three would mean the exposure is bounded by something other than the executive's own reading of the exception.
On the limitations side: 2026 conduct stays chargeable into 2031, so what, if anything, binds a successor administration toward companies that relied on this authorization?
The Branch That Was Asked Never Voted, and the Judge Is Gone
A committee that receives no report has to start an oversight fight rather than continue one, and starting is the part that can be declined. Where the operative rules are classified and the only recurring artifact runs to the executive, the choice of instrument has already settled who gets to ask.
Legislative Affairs. Five bills, each a letter-of-marque bill by its own official title, sought this authority since February 2025 and none passed, and the memorandum issued 28 days after the most recent pair, on a different theory. There is no congressional addressee anywhere in it: the Section 3(c) status report goes to two executive-branch officials. The covert-action statute would ordinarily supply one, since 50 U.S.C. 3093 requires a written presidential finding and notification to the congressional intelligence committees, and it excludes "traditional law enforcement activities conducted by United States Government law enforcement agencies or routine support to such activities." Wiiver's inference is that the same "Federal law enforcement" characterization supplying the 1030(f) theory also reaches that exclusion. No source located indicates the administration has invoked it, and it may not need to, because Activity to influence conditions abroad where the government's role is intended to be unacknowledged, triggering a written presidential finding and notice to two committees. requires that the government's role "not be apparent or acknowledged publicly," and this Program was announced in a published memorandum. Section 4(d) defines surveillance operations as conducted "with the intent to remain undetected," which conceals the operation rather than the government's role, and the 2018 provision is what drew that line. Title 10, Section 394(c) makes a clandestine cyber operation a traditional military activity for the purposes of Section 3093(e)(2), and Section 394(d) requires the Secretary to brief the congressional defense committees quarterly on those same operations. The law-enforcement exclusion carries no such briefing duty, and its own limiting word is "traditional." On the public record, and subject to a classified finding that would not appear on it, no congressional committee is a named recipient of anything in this Program. The precedent for how long an access fight takes is NSPM-13, signed in August 2018 and shown to the House Armed Services Committee in March 2020. Seven months before this memorandum, the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held a hearing titled "Defense through Offense," at which Emily Harding of the Center for Strategic and International Studies asked Congress for the opposite of what arrived: "Put in place protections for cyber operators who act in conjunction with the U.S. government."
Cybersecurity & Privacy. Private disruption of criminal infrastructure is not new, and this is the part of the story most easily lost. Microsoft's Digital Crimes Unit has brought roughly forty civil actions since 2008, including actions against Lumma Stealer in May 2025 and Fox Tempest in May 2026, with named causes of action running from the Computer Fraud and Abuse Act to trespass to chattels. A judge signs the order and a docket records it. The memorandum keeps the private operator and removes the judge: approval moves to two executive directors applying a classified adjudicatory framework, and the authorized effect widens from seizure to destruction at the same moment. Rule 41(b)(6) authorizes a warrant to search and to seize or copy; it does not authorize destruction.
Not everyone reads it that way, and the contrary reading deserves stating. Wiley, in a client alert published two days after signing, argues the memorandum "does not purport to authorize vigilantism or so-called 'offensive' cyber capabilities by the private sector," because express written government approval is required before any Cyber Effects Operation. On that reading the operator is a contractor executing a government decision, and the program echoes the review-and-approval model established for military cyber operations in 2018.
Clean targeting is hard even with a judge. Microsoft's action against No-IP took roughly 1.8 million uninvolved customers offline, on No-IP's own account, while the most surgical example runs the other way: deleting PlugX from approximately 4,258 US-based computers took nine warrants between August 2024 and January 3, 2025, in a French-led operation, using only the malware's own self-delete command. Its target is the instructive part, because PlugX was built for a group the Justice Department says the Chinese government paid. Section 4(c) would put that target outside the Program's reach, but only once the state connection was established, which here took years of investigation and an unsealed court record. Before that, Section 4(c)'s default would have placed it inside. Proportion is the rest of the problem: De Silva et al., in USENIX Security '21, working from 2019 scan data, found 81.7 percent of malicious websites sit on apex domains the attacker does not own. Section 4(c) meanwhile defaults toward permission, providing that a foreign group "will be assumed not to be" state-directed "unless clear intelligence exists," so state-adjacent crews sit inside the target set during the weakest attribution window. A student Note in the Columbia Business Law Review, published July 16, 2026, four weeks before the memorandum, proposed a closely similar arrangement of cleared contractors on the same exception, and built in the safeguard the Program inverts: a contractor who identifies a nation-state actor should "immediately stop all operations and hand over active control." The permissive default is not hypothetical this summer: water and wastewater utilities in at least seven states reported incidents to the FBI after July 27, 2026, and a coordinated attack hit operational technology at more than thirty Minnesota community water systems on July 26 and 27. CISA has attributed similar earlier PLC activity to a group affiliated with Iran's Revolutionary Guard, and federal officials have not attributed this wave. The fact pattern is simultaneously the class of actor Section 4(c) presumes away and the class of effect Section 4(a) authorizes American companies to produce abroad, bounded by a floor set at loss of life, serious injury, or a use of force under international law, the second of which the memorandum defines nowhere and leaves entirely to the two approving directors.
A congressional committee receives an accounting of Program operations inside the first reporting cycle, or the October procedures name a congressional recipient or require a judicial order before a destructive effect. The instrument would then be producing the oversight artifact its own text does not require.
On the annex: the operating procedures are due October 11, 2026 and cannot enlarge a statutory exception, so what will they say the "lawfully authorized" predicate actually is?
The Company in the Middle of a Two-Sided Market
A firm that sits between the customers supplying its threat information and the government selecting its targets is not merely serving two markets. It is positioned to shape the second with what it learns from the first, and disclosure that runs only to the party doing the selecting leaves the party supplying the data unable to see the arrangement at all.
Strategy & Operations. The memorandum is unusually clear about what a company owes and silent about what it gets. Qualification, the forfeitable bond, disclosure of every commercial relationship, reporting into the National Coordination Center, an abort-and-minimize duty, escalation duties and annual re-evaluation are all specified; compensation, fee, reimbursement and any share of what is recovered are absent from the operative text. Whether the Section 2(a)(ii) contracts supply what the memorandum does not is the thing to watch on October 11. The only funding clause, Section 5(b), makes the Program "subject to the availability of appropriations," which is a limit on the government rather than a promise to the company. Section 3(a)(ii) promises room for "smaller, more agile companies," and the memorandum requires facility security without saying how a small firm obtains it. Under 32 C.F.R. 117.9 "a contractor or prospective contractor cannot apply for its own entity eligibility determination," so on the face of that rule sponsorship comes from a government activity or a cleared contractor. The opening to small firms reads as a discretion reserved rather than a market opened.
Practitioners are already pricing it that way. Jason Kikta, formerly of US Cyber Command and now chief technology officer at Automox, told SiliconANGLE the arrangement is "a perpetual motion machine for billable threats."
AI & Data Science. Section 2(a)(iii) lets a Participating Company take threat information from private customers and targets from government agencies, with the operation as the output, and Section 3(a)(iii) requires every such relationship to be disclosed to the National Coordination Center and to no one else. Federal acquisition has a name for the shape of that arrangement: A conflict arising when a contractor evaluates or acts on matters affecting its own other business interests., which FAR 2.101 defines as a case where a contractor's objectivity in performing the work is or might be impaired. Whether those rules formally reach these agreements depends on whether the Justice and Homeland Security contracts are FAR contracts, and the memorandum does not say. The rewrite Congress ordered in Public Law 117-324 remains a proposed rule more than three years after enactment. The tension the next year will test is Section 3(b), which directs the National Coordination Center to "utilize automation to streamline Program elements wherever appropriate." That duty runs to the government hub rather than to the companies, and nothing exempts the per-package written approval that is the memorandum's only named human control.
The operating procedures require a Participating Company to disclose its commercial relationships to the customers supplying the telemetry, or bar a company from proposing operations against threats reported by its own paying clients, or the contracts state a fee.
On the automation duty: it runs to the National Coordination Center, so which Program elements get streamlined, and does the per-package written approval stay a human act?
The Weave maps a single development across domains and across time. Each row follows one domain from where things stand now through the next eighteen months, and expands for the reasoning behind that trajectory.
- Exposure no carrier has priced is exposure the board carries without a number attached.
- A five-year clock outlasts the administration whose approval the company relied on.
- The only quantified term in the arrangement runs from the company to the government.
- Access and positioning are real returns, but neither appears on a revenue line.
- A conflict disclosed only upward leaves the party that supplied the data unable to see it.
- If the government decides who gets sponsored, the candidate pool is set before any bid.
- A savings clause can be read narrowly later, long after a contractor has relied on it broadly.
- The executive's position is the only one on record, because it was never filed anywhere.
- Reading the exception widely costs the government nothing and costs the operator everything.
- Five introduced bills are a record of what Congress was willing to weigh, whatever the outcome.
- A committee that receives nothing has to start the fight itself, which is easier to resist.
- Appropriations is the one lever that works whatever the executive decides to call the activity.
- A classified rulebook cannot be argued against, so the targeting standard is never contested.
- A public docket lets outsiders count the misses; an annex turns those misses into anecdotes.
- Destruction is the one effect that cannot be undone by handing a seized domain back.
Four Dates, and the One That Settles Anything Is Not on the List
Whether the authority behind this Program is ever examined by anyone outside the executive branch will show up in a short run of dated, checkable markers over the next two quarters. Each of them is a document that either appears or does not.
- September 30, 2026 (The First Real Vehicle). Fiscal year funding lapses and no continuing resolution has been enacted. The House passed one on July 21, the Continuing Appropriations Act, 2027, that would run to December 4, 2026 unless full-year appropriations arrive first, and the Senate has not taken it up. Appropriations is how Congress answered this institution last time, with a use restriction and a reporting directive attached to the money. Congress appropriated $547 million for the Organized Crime Drug Enforcement Task Forces in fiscal 2025; five senators wrote to the Attorney General in June 2025 objecting to a proposal to zero it out, the Department closed the program anyway and moved more than 5,000 cases to the Homeland Security Task Forces, and appropriators answered with $300 million, a use restriction and quarterly reporting. This Program now sits inside that same institution with none of the three attached to it.
- October 3, 2026 (Scheduled Marker). NSPM-11's 120-day deadline for updating national security procurement to onboard advanced AI models closes, eight days before this Program's own gate. The two clocks were set independently and land in the same week, which is a convergence to watch rather than a link either document draws.
- October 11, 2026 (The Real One). The consensus operating procedures are due. Watch whether they attempt to define the 1030(f) predicate: advisory commentary has been deferring the legal question to these procedures, and procedures written by the Program Executive Directors cannot enlarge a statutory exception. Watch also for any invocation of FAR 52.250-1 or a SAFETY Act designation in the Justice and Homeland Security contracts. Either would signal that the government does not expect commercial insurance to answer. What would falsify this reading: operating procedures that name the separate statutory authorization the memorandum omits, or a court construing 1030(f) to reach contractor-executed destruction. Either would answer the question this analysis says the procedures cannot reach.
- February 8, 2027 (Scheduled Marker). The first status report is due, to the Homeland Security Advisor and the National Cyber Director. Both are executive-branch officials. There is no congressional addressee anywhere in the memorandum, so a committee that wants the report has to ask for it.
- The Tell. The resolving signal is whether any document produced in this window is readable by someone outside the executive branch. If the Supreme Court takes the certiorari petition on September 28, or a committee extracts the procedures, or a contract term surfaces in a protest or a disclosure, then the theory acquires an examiner it does not currently have. If instead the funding fight passes without a rider, the procedures restate Section 2(b), and the February report goes only to its two executive-branch recipients, then the authority question has been settled by nobody, and it stays open until a prosecutor, a foreign plaintiff or a successor administration opens it.
A company can decline this work today at no cost and cannot decline it retroactively in 2031. The reversible move is to treat the authorization as an untested executive-branch position and to price it as one: contractual indemnity rather than the memorandum's silence, run-off cover that outlasts the administration, and a contemporaneous record of what was approved, by whom, and on what scope. Five marque bills that would have put the question to Congress are pending in committee. A legal theory that nobody can contest is not the same thing as a legal theory that is correct, and the difference will be discovered by whichever company is holding the contract when someone decides to find out.
Every issue
- 01Intersection of the week
- 02Impact of the week
- 03The week in review
Wiiver Weekly
One free email, Saturdays at 7:00 AM ET.
Unsubscribe anytime.
Primary sources48
- The White House (the instrument)Expanding Capabilities to Combat Transnational Cyber-Enabled Crime (presidential memorandum)Aug 12Primary · One Case on the Books, and It Is About a Search Warrant · The Branch That Was Asked Never Voted, and the Judge Is Gone · The Company in the Middle of a Two-Sided Market · Congress was asked five times. What is Congress writing instead? · Looking Forward · Where Things Stand · The Weave
- Office of the Law Revision Counsel (statute)18 U.S.C. 1030, including the subsection (f) exception, the (g) civil action and the (e)(2)(B) definitionAug 14Primary · One Case on the Books, and It Is About a Search Warrant · Congress was asked five times. What is Congress writing instead? · The Weave
- Office of the Law Revision Counsel (statute)18 U.S.C. 3282, the five-year limitations period for non-capital federal offensesAug 14Primary · One Case on the Books, and It Is About a Search Warrant · The Weave
- Office of the Law Revision Counsel (statute)50 U.S.C. 3093, presidential approval and reporting of covert actions, including the (e)(3) exclusionAug 14Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone · The Weave
- Office of the Law Revision Counsel (statute)10 U.S.C. ch. 19, Cyber and Information Operations Matters: 394(c) makes a clandestine cyber operation a traditional military activity for 3093(e)(2), and 394(d) attaches a quarterly briefing duty to the congressional defense committeesAug 14Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone
- Cornell Legal Information Institute (rule)Federal Rule of Criminal Procedure 41, Search and Seizure, including the remote-access warrant at 41(b)(6)Aug 14Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone
- District of Puerto Rico (the court's filed opinion)Naicom Corp. v. Dish Network Corp., No. 3:21-cv-01405-JAW, Document 202, the order carrying the entire 1030(f) analysisMar 29Primary · One Case on the Books, and It Is About a Search Warrant · The Weave
- Supreme Court of the United States (docket and appendix)Naicom Corp. v. Dish Network Corp., No. 25-1397: the First Circuit judgment without opinion and the docket entry distributing it for the conference of September 28, 2026Aug 5Primary · One Case on the Books, and It Is About a Search Warrant · Looking Forward
- Ninth Circuit (model jury instructions)Model Criminal Jury Instructions, Public Authority or Government Authorization DefenseSep 2018Primary · One Case on the Books, and It Is About a Search Warrant
- Ninth Circuit (model jury instructions)Model Criminal Jury Instruction 6.2B, Entrapment by EstoppelApr 2019Primary · One Case on the Books, and It Is About a Search Warrant
- Cornell Legal Information Institute (rule)Federal Rule of Criminal Procedure 12.3, Notice of a Public-Authority Defense: the notice runs from an indicted defendant, which is what puts the defense after chargeAug 15Primary · One Case on the Books, and It Is About a Search Warrant
- SAM.gov, USAspending and FPDS (federal procurement systems, searched directly)No contract vehicle, solicitation or award for the Program: 8,918 notices modified on or after August 12, 2026, including all 139 Justice and 251 Homeland Security notices, a full-text qMode=ALL sweep of the 5,587,460-record corpus, USAspending contract and IDV groups with cyber PSC codes, and FPDS. Searched August 14-15, 2026. Caveats: USAspending and FPDS lag award dates by days, so an award signed August 13 or 14 may not yet appear, which is why the claim is dated; attachment contents were not searched, and sole-source actions leave the least public trace, so the claim is about what is publishedAug 15Primary · One Case on the Books, and It Is About a Search Warrant
- Cornell Legal Information Institute (constitution)U.S. Constitution, Article I, Section 8, Clause 11, the letters of marque and reprisal powerAug 14Primary · Congress was asked five times. What is Congress writing instead?
- Congressional Research Service (report)Cybercrime: An Overview of the Federal Computer Fraud and Abuse Statute (CRS 97-1025)Aug 14Primary · Congress was asked five times. What is Congress writing instead?
- Senate Judiciary Committee (report)S. Rept. 104-357, The National Information Infrastructure Protection Act of 19951996Primary · Congress was asked five times. What is Congress writing instead?
- Government Publishing Office (bill text)H.R. 1238, Cartel Marque and Reprisal Authorization Act of 2025 (Burchett, Messmer)Feb 12Primary · Congress was asked five times. What is Congress writing instead? · The Weave
- Government Publishing Office (bill text)H.R. 4988, Scam Farms Marque and Reprisal Authorization Act of 2025 (Schweikert), the control case that carries no shieldAug 15Primary · Congress was asked five times. What is Congress writing instead? · The Weave
- Government Publishing Office (bill text)S. 3567, Cartel Marque and Reprisal Authorization Act of 2025 (Lee)Dec 18Primary · Congress was asked five times. What is Congress writing instead? · The Weave
- Government Publishing Office (bill text)H.R. 9697, Cyber Letters of Marque and Reprisal Act, including the Section 8 liability shieldJul 15Primary · Congress was asked five times. What is Congress writing instead? · The Weave
- Government Publishing Office (bill text)S. 5000, Cyber Letters of Marque and Reprisal Act (Lee), word-identical to H.R. 9697 including Section 8Jul 15Primary · Congress was asked five times. What is Congress writing instead? · The Weave
- Government Publishing Office (bill text, reported in Senate)S. 4784 section 1604, "Scaling cyberspace access generation and maintenance": a cleared federal employee present at all times, the contractor named to the defense committees within 10 days, every operation reported within 48 hours, pilot ending on or before December 31, 2030Jun 15Primary · Congress was asked five times. What is Congress writing instead?
- Office of Senator Mike Lee (sponsor statement)Patriots of the Caribbean: Lee Bill Authorizes American Privateers to Seize Cartel AssetsDec 18Primary ·
- Center for Strategic and International Studies (testimony)Emily Harding, written statement to the House Homeland Security Subcommittee, "Defense through Offense"Jan 13Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone
- House Committee on Homeland Security (hearing record)Defense through Offense: Examining U.S. Cyber Capabilities to Deter and Disrupt Malign Foreign ActivityJan 13Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone
- Microsoft, On the Issues (party statement)Scaling cybercrime disruption through innovation and AI (the roughly forty civil actions since 2008)Jun 24Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone
- Microsoft, On the Issues (party statement)Microsoft leads global action against favored cybercrime tool (Lumma Stealer)May 21Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone
- Microsoft, On the Issues (party statement)Disrupting Fox Tempest, a cybercrime serviceMay 19Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone
- No-IP / Vitalwerks (affected party's own account)No-IP Takes Stock of Toll on Customers from Microsoft's Service TakedownJul 15Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone
- Department of Justice (release, via Wayback capture)Justice Department and FBI Conduct International Operation to Delete Malware Used by China-Backed HackersJan 14Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone
- E.D. Pa. (court filing)Affidavit in Support of an Application for a Ninth Search and Seizure Warrant, Mag. No. 24-mj-1387Jan 14Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone
- Cybersecurity and Infrastructure Security Agency (advisory)Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (AA26-097A)Jul 22Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone · The Weave
- Minnesota IT Services (state agency account)MNIT activates statewide cybersecurity response to support affected communitiesJul 2026Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone
- FBI and EPA (public service announcement)Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing PLCs (Alert I-073026-PSA)Jul 30Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone
- Cornell Legal Information Institute (regulation)48 C.F.R. 52.250-1, Indemnification Under Public Law 85-804Aug 14Primary · One Case on the Books, and It Is About a Search Warrant · Looking Forward · The Weave
- Department of Homeland Security (program)About the SAFETY Act (third-party liability caps for qualified anti-terrorism technologies)Aug 14Primary · One Case on the Books, and It Is About a Search Warrant · Looking Forward · The Weave
- Cornell Legal Information Institute (regulation)32 C.F.R. 117.9, Entity eligibility determination (NISPOM Rule)Aug 14Primary · The Company in the Middle of a Two-Sided Market · The Weave
- Cornell Legal Information Institute (regulation)48 C.F.R. 2.101, definition of organizational conflict of interestAug 14Primary · The Company in the Middle of a Two-Sided Market · The Weave
- Congress.gov (statute)Preventing Organizational Conflicts of Interest in Federal Acquisition Act, Public Law 117-324Dec 27Primary · The Company in the Middle of a Two-Sided Market
- Congressional Research Service (In Focus)Homeland Security Task Forces (CRS In Focus IF13254)Jun 24Primary · Where Things Stand
- Office of Senator Ben Ray Lujan (five-senator letter)Senators Question DOJ Decision to Shutter Specialized Unit for Cracking Down on Transnational CrimeJun 4Primary · Looking Forward
- Columbia Business Law Review (student Note, cited for its own proposal)Sophia Stener, "Delegating Hacking Back: PMC-Style, Facility-Cleared Cyber Contractors Under CFAA 1030(f)," Vol. 2026 No. 1Jul 16Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone
- The White House (fact sheet)Fact Sheet: President Donald J. Trump Expands Capabilities to Combat Transnational Cyber-Enabled CrimeAug 12Primary · Where Things Stand
- FBI Internet Crime Complaint Center (annual report)2025 Internet Crime Report (1,008,597 complaints; $20.877 billion in reported losses)2026Primary · Where Things Stand
- The White House (presidential memorandum)NSPM-11, Artificial Intelligence in the National Security Enterprise (the 120-day procurement clause)Jun 5Primary · Looking Forward
- Government Publishing Office (bill status record)H.R. 9770, Continuing Appropriations Act, 2027 (Cole): passed the House 220-205 on Roll no. 272, received in the Senate July 22, 2026, not enactedJul 21Primary · Looking Forward
- Government Publishing Office (bill text, engrossed)H.R. 9770 as passed the House, Section 106: continuing appropriations run to whichever of three events first occurs, one of them December 4, 2026Jul 21Primary · Looking Forward
- USENIX Security '21 (peer-reviewed paper)De Silva et al., "Compromised or Attacker-Owned," USENIX Security 21: 81.7 percent of malicious websites sit on apex domains the attacker does not own2021Primary · The Branch That Was Asked Never Voted, and the Judge Is Gone
- 107th Congress, H.R. 3076 (bill text, read in full)September 11 Marque and Reprisal Act of 2001, H.R. 3076 (Paul, introduced October 10, 2001), Section 3(a): the commissioning stem, the seizure clause and the security-bond sentence appear verbatim, followed by "the person and property of Osama bin Laden"Oct 2001Primary · Congress was asked five times. What is Congress writing instead?
Secondary sources, by sector15
- The Record (Recorded Future News)White House pours cold water on cyber 'letters of marque' speculation (the Lind remarks)Mar 19Secondary · Congress was asked five times. What is Congress writing instead?
- The Record (Recorded Future News)Trump taps cyber firms to go on offensive against criminals (the Thompson statement, single outlet)Aug 13Secondary · Congress was asked five times. What is Congress writing instead?
- Covington and Burling (Inside Privacy)Litigation Options For Post-Cyberattack "Active Defense"Oct 29Secondary · The Branch That Was Asked Never Voted, and the Judge Is Gone · The Weave
- C4ISRNETAfter tug of war, White House shows cyber memo to Congress: NSPM-13, signed August 2018, shown to the House Armed Services Committee in March 2020Mar 13Secondary · The Branch That Was Asked Never Voted, and the Judge Is Gone · The Weave
- Roll CallAppropriators backed a crime-fighting unit. DOJ closed it anyway.Dec 18Secondary · Looking Forward
- Roll CallSpending package would reject proposed DOJ restructuringJan 6Secondary · Looking Forward
- CSO OnlineTrump administration opens door to private-sector cyber offensives (the Ong observation)Aug 13Secondary · Congress was asked five times. What is Congress writing instead?
- Wiley Rein LLP (market forecast)Wiley's Cyber Risks and Insurance 2026 ForecastDec 1Secondary · One Case on the Books, and It Is About a Search Warrant · The Weave
- Wiley Rein LLP (client alert, same firm as the insurance forecast above)Navigating the New Presidential Memorandum on Transnational Cyber Enabled-Crime: reads the memorandum as not authorizing private offensive capability, because written approval precedes any effects operationAug 14Secondary · The Branch That Was Asked Never Voted, and the Judge Is Gone
- Crowell & Moring LLP (client alert, published the same day and reading the memorandum oppositely)License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations: cited here only for the criminal-discovery exposure, not for its immunity characterizationAug 14Secondary · One Case on the Books, and It Is About a Search Warrant
- Wiley Rein LLP (rulemaking alert)FAR Council Proposes Wholesale Revamp of Organizational Conflict of Interest Rules (RIN 9000-AO54)Jan 15Secondary · The Company in the Middle of a Two-Sided Market
- WTW (client alert on the Lloyd's requirement)Lloyd's requirements for state-backed cyber attack exclusionsSep 2022Secondary · One Case on the Books, and It Is About a Search Warrant
- SiliconANGLETrump memo lets vetted US firms run offensive cyber operations abroad (Kikta and Barker quoted)Aug 13Secondary · The Company in the Middle of a Two-Sided Market
- Tenable (vendor analysis)Coordinated Cyberattack on Minnesota Water Utilities (carried for the record only: its twelve-state count is not used, the page prints the FBI and EPA figure of seven)2026Secondary ·
- The RegisterGeorgia, Michigan say water systems hacked by Iran-tied crew (carried for the record only, not cited; the page prints the FBI and EPA state count)Aug 3Secondary ·