From Blackwater to Cyber-Privateers: When States Outsource Force
On August 12, 2026, President Donald Trump signed a National Security Presidential Memorandum titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.”
For the first time in U.S. history, private companies will be authorized to conduct offensive cyber operations against foreign criminal networks. These operations include covert break-ins into systems and disruptive attacks, and they will be conducted under the direction of the Department of Justice and the Department of Homeland Security.
Even though this memo is new, the pattern of public-private relationship in offensive actions, is not. It is convenient for governments to outsource coercive power to private companies, especially in conflict settings and now we are seeing the same in cyber.
Inside the Memorandum: What the Trump Offensive Cyber Program Authorizes
The memorandum tasks the National Coordination Center (NCC) to build a program where “Participating Companies” can conduct operations against foreign Cyber-Enabled Transnational Criminal Organizations in two categories:
- Cyber Surveillance Operations, which consist of covert intelligence collection via unauthorized access to systems
- Cyber Effects Operations, which consist of manipulation, disruption, denial, degradation, or destruction of systems
The program is co-directed by officials from DOJ and DHS. These officials must review and give approval for every operation before it proceeds.
- Companies must contract with the DOJ or DHS in order to conduct these operations. And then they have to undergo rigorous vetting, disclose all commercial relationships, and post a bond or escrow of at least $1 million, forfeitable for possible violations.
- Operations that could cause loss of life, serious injury, or rise to the level of armed attack under international law are explicitly barred.
- Targeting a U.S. person requires prior judicial or other authorization and if an operation accidentally hits a U.S. person or a U.S.-based system, the company must halt, run minimization procedures, and notify the NCC.

President Donald Trump speaks in the Oval Office of the White House on August 6, 2026. (Jim Watson/AFP/Getty Images/File)
The memo is not creating a completely new statutory authority. We are seeing a structuring of private participation as an extension of existing federal law enforcement powers under the Computer Fraud and Abuse Act, the 1986 law that criminalizes unauthorized access to computers.
Also, this is not the first time it has been tried. The Active Cyber Defense Certainty Act, introduced by Rep. Tom Graves (R-GA) in 2017 and reintroduced in 2019 with bipartisan cosponsorship, would have amended the CFAA to let victims leave their own networks to establish attribution, disrupt attacks, and retrieve stolen files, with FBI notification, but it died in committee both times.
The NSA, DOJ, and much of the cybersecurity industry opposed it on three grounds:
- Misattribution
- Collateral damage
- Escalation with foreign state actors
The last idea, escalation with foreign state actors, was considered for this memo. It explicitly avoids the overlap between cybercriminal organizations and nation-states. The program targets foreign criminal groups that are “not an institutional part of a foreign government”. But the memo is kind of vague when it comes to building that profile since such cybercriminal operations can be tied to state-sponsored actors or governments directly.
Additionally, the UN Working Group on the use of mercenaries stated in its 2020 report that individuals carrying out cyberattacks can be considered as undertaking mercenary-related activity under certain criteria. The memo doesn’t mention anything that protects individuals conducting such offensive actions.
Private Military Companies: How Governments Outsourced Force and Lost Control
This memo may create an industry that resembles the private military companies and their activities.
Even though this industry has been around for centuries, the modern private military industry began in post-apartheid South Africa with Executive Outcomes, which was founded in 1989 by former South African Defence Force lieutenant-colonel Eeben Barlow.

Executive Outcomes members believed to be in Sierra Leone
In the early 1990s, South Africa’s special forces were downsized and Barlow built a company out of the surplus talent. Later on, Angola’s government hired EO in 1993, paying $40 million per contract to fight UNITA rebels. EO’s forces, working alongside Angolan troops, recaptured major urban centers and pushed UNITA to the negotiating table which ultimately led to the Lusaka Protocol in 1994.
The world saw EO next in the Kono district working with Sierra Leone in May 1995. They helped government forces retake the diamond-rich Kono district, which produced two-thirds of the country’s diamonds. EO was paid, in part, through those mines and this transaction established a model where private military companies profited directly from the resources of the countries they fought in.
This model was not new but usually such companies operate as tools of their own governments’ foreign policy and the payment structure they follow is a way to keep these groups under control. As long as a company’s revenue depends on its own government, that government retains control. Executive Outcomes, and years later Wagner, complicated this relationship by building independent, and substantial, income streams that allowed them to sustain themselves without needing their own governments.
Once a private military company can fund itself outside the state that runs it, that state’s grip will loosen. Wagner’s June 2023 mutiny, when Prigozhin marched with his fighters toward Moscow, was the sharpest example of what happens when that grip loosens.
Recent Examples
Later on we saw similar companies from the USA. Blackwater (now Constellis Holdings) for example, was founded in 1997 by former Navy SEAL Erik Prince. They began with a CIA contract for the Kabul station in 2002 and expanded into Iraq. By the mid-2000s it was the most prominent private military contractor in the country. DynCorp, a Virginia-based firm, received a huge share of State Department reconstruction funds in Afghanistan. Triple Canopy, founded in 2003 by U.S. Army Special Forces veterans, eventually merged with Academi (Blackwater’s renamed successor) under Constellis Holdings in 2014.
Then we started hearing from Russia. The Wagner Group, created in 2014 with former GRU officer Dmitry Utkin as commander and Yevgeny Prigozhin as director, operated differently from Western companies. Blackwater and DynCorp worked under government contracts with at least nominal oversight, but Wagner acted as an arm of Russian foreign policy while Moscow officially denied any connection. Wagner fighters appeared first in the Donbas in 2014; from 2015 they expanded to Syria, and eventually deployed across numerous African states.

From Prigozhin’s viral video of him frustrated with the government and asking for assistance including ammunition at the beginning of May 2023, approximately 2 months before his daily mutiny on 23th of June
The appeal to governments was the same for all of them. It was flexible, deniable, and capabilities could be deployed faster than regular military forces and without the same political costs. In each case, the relationship grew beyond its original scope. That appeal is also the reason why these companies created problems almost everywhere they operated like Blackwater’s Nisour Square killings, DynCorp’s human trafficking activities and Wagner’s civilian executions in Moura, Mali.
The Digital Successors to Private Military Companies
Firms taking actions that can be considered offensive is not a completely new phenomenon. Companies that sell surveillance tools and offensive hacking capabilities to governments operate in a legal and ethical gray zone that mirrors the PMC world almost exactly.
Companies like Israel’s NSO Group, Italy’s Hacking Team, the UK-German Gamma Group, the UAE’s DarkMatter, and the Intellexa consortium built and sold offensive hacking and surveillance tools to governments worldwide. Their products ended up targeting journalists, activists and dissidents. When exposed, the consequences followed the same pattern as PMCs. They were blacklisted, sanctioned, faced with court verdicts, and then reorganized under new names.
However, with this memo, things have been placed on an even more legal framing. And we don’t think that the US will be the only company legalizing such actions. Others will, surely, follow.
Bringing this matter onto a legal footing will also lead to an increase in grey-area activities. Government agencies or companies can now be targeted legally as a result of any conflict, war, friction, or diplomatic dispute. This new sector can be politicized in every way possible.
The consequences of this will go even further than the recklessness of PMCs. Because cybersecurity is already an area that’s ignored and overlooked. Incidents in the physical world during conflicts receive much more media coverage while cyberattacks don’t get nearly as much. Under the natural invisibility of this field, companies can engage in much more activity.
Conclusi̇on
In general, nothing we’re seeing is new in terms of the actions taken by companies and governments. Companies will now be more active, and their aggressive actions will shift slightly into a gray area while also increasing in frequency.
At the same time the memo does include safeguards. Companies have to obtain written federal approval for every operation, mandatory bonding, annual reviews, and an immediate halt if a U.S. person or system is accidentally caught up. Whether those hold under operational pressure, given what we’ve seen from PMCs and cyber firms operating under similar promises, remains an open question.
We can expect similar laws, and the actions companies will take in response to them, to emerge in other countries as well. Other nations are unlikely to stand idly by. While countries in the Global South may not be very active on this issue publicly with their private companies, they will prioritize it within their own government institutions. The fact that companies are not being established there should not imply that these actions will be neglected.
It doesn’t seem likely that we’ll face any major problems in the near term. After all, this is still very new. However, in the medium and long term, this could become an issue that both governments and other companies will have to grapple with.

