New tools, old bonds

The privateers are back. This time, they carry federal contracts.

August 19, 2026

The memorandum, “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” directs the National Coordination Center (NCC) to run a program in which vetted “Participating Companies” conduct surveillance operations and cyber effects operations against foreign Cyber-Enabled Transnational Criminal Organizations. The NCC sits inside the interagency Homeland Security Task Force, established by a January 2025 immigration executive order. Two co-Executive Directors, one from the Department of Justice and another from the Department of Homeland Security, must approve every operation in writing. Operations likely to produce what the directive calls “Critical Outcomes,” defined as loss of life, serious injury, or effects rising to a use of force or armed attack under international law, sit beyond their authority to approve. The program extends a March executive order aimed at the fraud networks preying on American citizens.

Last December I argued in these pages–and within Aspen Digital’s Playing Offense series–against reviving letters of marque and reprisal for cyberspace. The proposal on the table then was a House bill authorizing the President to commission private actors to strike back at cybercriminals. I wrote that privatized cyber retaliation fractures the state’s monopoly on force, collapses on attribution, and hands our adversaries license to keep doing the same. Kemba Walden opened the series by arguing that offensive cyber operations need shared first principles before new authorities. The new White House memo provides a workaround.

Rather than ask Congress for letters of marque, it builds the bureaucratic machinery those letters once provided–the license, the rules, the bond–and issues the direction from the Oval Office. The Administration has not formally revived letters of marque. It has revived the governing logic behind them: use private capacity to close a public-force gap, authorize coercive action through a legal instrument, and manage the distance between the state and the operator through rules and a bond. That is a mistake twice over. The workaround inherits every defect of the idea it routes around, and it adds a constitutional defect of its own.

The bond is the tell. Governments command their agents. They bond their licensees. Federal contractors post performance bonds all the time, but a performance bond guarantees the government receives what it paid for. This bond does the letter of marque’s job. It polices conduct in the exercise of delegated force, which is why the Continental Congress demanded bonds of $5,000 ($10,000 for larger vessels) within days of formalizing privateering in the spring of 1776, and why Congress’s privateering act of June 26, 1812, renewed the requirement. The bond covered the distance the license created between the state and the operator. The memorandum’s $1 million bond answers the same distance. If a program needs the privateer’s bond, it is running the privateer’s model.

The Administration’s legal theory should be met on its own terms. On that theory, “Participating Companies” are not privateers at all but government contractors–agents of federal law enforcement, no different in kind from the contractors embedded across federal law enforcement and intelligence work today. In the same Playing Offense series, John Carlin traced the legal contours of hacking back, with the Computer Fraud and Abuse Act (CFAA) blocking the private actor’s sway at nearly every turn. The memorandum frames every action as part of “lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement,” language drafted carefully to fit the CFAA’s exception for authorized law enforcement and intelligence activity.

Companies, under this memo’s construct, take no prizes. They propose operations; the government approves them in writing, one package at a time. A letter of marque was a general license to hunt. This is a leash.

But a leash is only as good as the hand that holds it, and a signature at the start of an operation is not the same as oversight. Cyber effects unfold at machine speed across infrastructure that no approving official controls. The memorandum concedes as much. It anticipates that a company may discover, mid-operation, that it has struck a U.S. person or a computer sitting on American soil. It directs the company to stop, run “minimization procedures” on itself, and report to the government immediately. Every action in the sequence belongs to the contractor. The same is true when the stakes are highest. It is the company who must decide whether its own operation is about to cause loss of life or amount to an armed attack, and then say so. Approval is paperwork. Supervision is capability. The gap between them is where the privateer lives.

The Constitution places the power to grant letters of marque and reprisal with Congress, in the same clause as the power to declare war. It is a legislative power, and it has been one since the Continental Congress issued the first American commissions in 1776. Representative David Schweikert asked Congress to revive that power for cyberspace. His bill proposing cyber letters of marque has sat in committee since August 2025. It has not moved, and in December 2025, I argued it should not.

A national security presidential memorandum now accomplishes by directive what the legislature has not. The document’s legal weight rests on a single clause, the assurance that operations are “exclusively conducted on behalf of and under the supervision of the Federal Government pursuant to…lawful authorities.” If a court, a foreign government, or a future administration decides these firms are licensed hunters rather than supervised agents, that foundation gives way, and the companies holding the bonds are the ones left exposed.

The existing–and lawful–playbook already works. The multinational takedowns of Emotet, Hive, and LockBit dismantled criminal infrastructure with warrants, allies, and private-sector expertise inside government operations. U.S. Cyber Command’s defend-forward posture disrupts adversaries with state accountability attached. Microsoft’s Digital Crimes Unit takes down botnets through civil process. These models deliver what the privateer promises, at a fraction of the risk.

The task is to scale this existing playbook, and scaling starts with how America builds its cyber forces. Each military service today recruits, trains, and equips cyber operators in its own way, and U.S. Cyber Command inherits the uneven results. In this series, Mark Montgomery argued the only durable fix is a dedicated U.S. Cyber Force. The CSIS Commission on U.S. Cyber Force Generation, where he served with retired four-star officers, NSA veterans, and industry leaders, spent ten months on the harder question of how to build one. Its June 2026 report laid out the service in detail. The direction matters more than the organizational chart. A nation serious about state capacity invests in generating its own force, so it never again faces a choice between mission gaps and licensed proxies.

Congress has other tools. Reauthorize the Cybersecurity Information Sharing Act of 2015 for the long term rather than the current stopgap, and expand it for new technologies and participants. Fund the joint task forces that made the multinational takedowns work. And draw the line the memorandum blurred. Federal procurement policy already reserves functions as inherently government work “so intimately related to the public interest” that only federal employees may perform them. Offensive cyber operations belong on that list, performed by the government’s own hands, and with contractor support that stops short of pulling the trigger.

In the early Republic, the bond governed a workaround for a state whose public force could not meet the mission. The durable answer was to build that force. The bond is back. The excuse for it is not.

The views represented herein are those of the author(s) and do not necessarily reflect the views of the Aspen Institute, its programs, staff, volunteers, participants, or its trustees.

Devin Lynch's headshot.

Devin Lynch is a Senior Director at the Paladin Global Institute and a Lecturer at the George Washington University’s Elliott School of International Affairs. He is a former director for cyber policy at the Office of the National Cyber Director, a veteran of the conflicts in Iraq and Afghanistan, and served two tours of duty on Capitol Hill. The views expressed are the author’s and do not reflect those of any government organization or entity, including but not limited to the Department of War and Department of Navy.