Sentry

On 13 August 2026, the White House signed a memorandum that overturns something that’s held firm in US policy for decades. Vetted private companies in the United States can now run offensive cyber operations against criminal hacking groups, not just defend their own networks, but actually go after the people behind the attacks.

TechCrunch broke the story, and it’s worth understanding properly, because this isn’t only a US story. It has real consequences for individuals and businesses here in Australia too, and not necessarily in the way you’d expect.

What the policy actually allows

It pays to be precise here, because a lot of the coverage has shorthanded this as “hack back,” and that’s not quite accurate. This isn’t a rule that lets any company that gets breached retaliate against whoever attacked them.

What the memorandum, titled Expanding Capabilities to Combat Transnational Cyber Enabled Crime, actually does is direct the Department of Justice and Homeland Security to build a formal program, run through a new National Coordination Center, that brings vetted private firms in against transnational criminal groups specifically. Think ransomware gangs, sextortion operations, phishing rings, and financial fraud networks. Once approved, these firms can run surveillance, including spyware, and disruptive operations aimed at damaging or destroying the criminals’ own data and infrastructure. Distributed denial of service attacks and encryption lockouts are both explicitly on the table.

To take part, a company needs approval from both departments for every operation, has to meet vetting standards that are still being finalised, and must post a US$1 million bond that’s forfeited if it breaks the rules. The detailed guidance on how all this will actually work is due within about two months of the announcement, so this is still very much in progress.

Even people inside the industry aren’t fully sold on it. One cybersecurity veteran quoted in the coverage described the policy as underdeveloped, pointing out that the process for choosing targets still isn’t clear, and that Americans working on these operations could face genuine legal risk if a foreign government decides to treat them as combatants.

Why Australians should be paying attention

Australia hasn’t gone down this road. Under our own law, private companies here can’t run offensive hacking operations, regardless of who the target is or where they’re based. That’s not about to change.

But the criminal groups this new US program is aimed at don’t operate inside national borders, and neither will the operations targeting them. That creates exposure on two fronts.

For individuals. Ransomware, sextortion, and scam operations targeting Australians are frequently run by the same kind of transnational groups this program is built to disrupt. If it works as intended, that’s genuinely good news. But disruption operations rarely stay perfectly contained, and the more of them that happen, the more chances there are for something to spill over in a way nobody planned for.

For organisations. This is where the bigger, less talked about risk sits.

The collateral damage problem

Here’s something anyone working in this field already knows well. Cyber criminals almost never launch attacks from infrastructure they actually own. They compromise someone else’s first, then use it as a base.

Ransomware operators, botnets, and scam networks routinely hijack servers, cloud accounts, and business networks belonging to completely unconnected, legitimate companies, and run their operations through that hijacked infrastructure. It’s standard tradecraft, and it’s exactly why attribution in cyber security is so difficult in the first place. A business running an exposed remote access service, an unpatched server, or simply no real monitoring can be compromised and used this way for months without anyone noticing.

Now put the new US policy next to that reality. Vetted private firms are being authorised to run destructive operations against the infrastructure criminal groups are using, and the memorandum specifically directs the government to build procedures that stop these operations from targeting Americans or systems based in the United States. There’s no equivalent protection described for infrastructure sitting outside the US. If that infrastructure turns out to be a hijacked server belonging to an Australian business, rather than something the criminals actually own, that business could end up hit twice. Once by the original compromise, and again by a disruption operation aimed at what looks, from the outside, like the attacker’s own systems.

This isn’t just speculation on our part either. Threat intelligence commentary following the announcement has already raised this exact concern, pointing out that attackers’ heavy reliance on compromised foreign infrastructure makes attribution harder and increases the risk of unintended escalation once private firms start operating offensively at this scale.

For a business caught in that position, there’s very little good about it. You didn’t choose to be hijacked. You may not even know it happened. And if an operation backed by a foreign government lands on your systems as a result, you’re the one left dealing with the outage, the investigation, the possible data breach notification obligations, and the reputational damage, with no real path to recourse against the firm that caused it.

Australian SMBs are the most exposed

This isn’t a distant, hypothetical risk. ASD’s most recent Annual Cyber Threat Report shows the ACSC received more than 84,700 cybercrime reports last year, roughly one every six minutes, and responded to over 1,200 serious incidents, up 11 per cent on the year before. The average reported cost of a cybercrime incident for small businesses rose 14 per cent to $56,600. Denial of service attacks, the exact kind of tool now being handed to vetted private firms under this new program, rose 280 per cent.

Small and medium businesses tend to have fewer resources for detection and monitoring than larger organisations, which is exactly what makes them easy to compromise quietly and use as a launch pad. Often nobody notices until something goes wrong, sometimes from a direction nobody was watching.

Start closing the gaps now, before this escalates

further

The rules for this US program aren’t even finalised yet. That makes now the right time to get ahead of it, not after the first case of a business getting caught in someone else’s cyber conflict makes headlines.

The businesses least likely to end up as unwilling collateral damage are the ones that have already closed the obvious gaps. Exposed services locked down. Systems patched. Access properly controlled. Real visibility into what’s actually happening across the network.

This is the work we do every day at Sentry Cyber. We run comprehensive risk assessments and penetration tests for Australian businesses to find out where you’re genuinely exposed, not where you assume you are. From there we build a practical roadmap, usually run over 1 to 2 years, to close those gaps properly and get you certified against recognised frameworks like ISO 27001, Essential Eight, and SMB1001. Certification is really just the byproduct of doing the fundamentals properly, which is also exactly what keeps a business off the list of easy targets in the first place.

If you want a clear picture of where your business actually stands today, get in touch with our team at Sentry Cyber https://sentry.cy/contact-us/. It’s a far better conversation to have now than after finding out your systems were part of someone else’s fight.