The Volokh Conspiracy

Mostly law professors | Sometimes contrarian | Often libertarian | Always independent

Trump Administration Announces New "Hacking Back" Program

But does it legalize hacking under the CFAA?

|

The Trump Administration announced a new program on hacking back last week, allowing United States companies to hack back in some circumstances in cooperation with United States officials.  The program is premised on some interesting theories about the scope of the Computer Fraud and Abuse Act, and I think it raises a lot of complicated issues under that statute.

In this post, I wanted to take a look at some of them.

First, here's the language from the Trump Administration's announcement:

. . . . The National Coordination Center (NCC), established pursuant to section 6(d) of Executive Order 14159 of January 20, 2025 (Protecting the American People Against Invasion), shall create, manage, and maintain a Program to authorize Participating Companies, as defined in section 4(f) of this memorandum, to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government.  As part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement, this Program shall:

(i)    be overseen by co-Executive Directors, one from the Department of Justice, designated by the Attorney General, and one from the Department of Homeland Security, designated by the Secretary of Homeland Security (Program Executive Directors).  The Program Executive Directors shall be delegated authority to approve, after coordination with each other, cyber operations conducted within the Program by personnel of their respective departments, except that they may not approve operations resulting in Critical Outcomes, as defined in section 4(b) of this memorandum.  Cyber operations shall only be approved after coordination between the Program Executive Directors, and any resulting operational action will be exclusively conducted on behalf of and under the supervision of the Federal Government pursuant to the Federal Government's lawful authorities;

(ii)   require Participating Companies to enter into contractual agreements with the Department of Justice or the Department of Homeland Security, which shall ensure that Participating Companies undergo rigorous vetting and that their performance adheres to the strict operational procedures outlined in the implementation guidance directed in section 3 of this memorandum; and

(iii)  permit Participating Companies to enter into commercial agreements with:

(A)  private sector entities, from which the Participating Companies may receive for the purpose of proposing responsive cyber operations to the NCC any threat information collected in the course of those entities' normal business activities; and

(B)  Federal, State, local, tribal, and territorial agencies, which will identify CE-TCO threats to the Participating Companies in a manner that enables them to propose cyber operations to the NCC that address those threats.

(b)  The NCC shall conduct all Program activities in accordance with the Constitution and all other applicable laws and international obligations of the United States, including section 1030 of title 18, United States Code, thereby ensuring that Participating Companies are acting under the control and oversight of the United States Government.

Sec. 3.  Implementing Guidance.  (a)  Within 60 days of the date of this memorandum, the Program Executive Directors shall, in coordination with the Homeland Security Council, establish consensus operating procedures for the Program that ensure the Federal Government's complete oversight and control of Participating Companies' performance.  No operation may be approved unless it complies with these operating procedures.  The procedures shall:

(i)     establish minimum standards that Participating Companies must meet in order to take part in the Program, which shall include appropriate levels of technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors that the Program Executive Directors, in coordination with the Homeland Security Council, determine are relevant or necessary for guaranteeing high confidence in a Participating Company's ability to perform successfully in the Program;

(ii)    ensure that the Program's eligibility criteria enable participation by both large companies, which provide critical capacity, and smaller, more agile companies, which may be better suited for specialized or discrete tasks;

(iii)   mandate that Participating Companies disclose to the NCC all contractual relationships entered into pursuant to section 2(a)(iii) of this memorandum;

(iv)    authorize the Department of Justice and the Department of Homeland Security to mandate as a condition of their contractual agreements with Participating Companies under section 2(a)(ii) of this memorandum that such companies maintain a bond or escrow in an amount not less than $1 million, to be forfeited should the Participating Company enter non‑compliance with its contractual agreement described in section 2(a)(ii) of this memorandum;

(v)     in conformance with the classified annex to this memorandum, set forth the operational workflow of the Program, which shall include operational deconfliction across Federal law enforcement, the Department of State, the Department of the Treasury, the Department of War, the Department of Justice, and the United States Intelligence Community;

(vi)    in conformance with the classified annex to this memorandum, provide an adjudicatory framework to ensure operational activity targets only CE-TCOs and accounts for other United States Government equities;

(vii)   set forth standardized rubrics and templates for target identification and the creation and processing of Cyber Surveillance and Cyber Effects Operations packages;

(viii)  include reporting requirements for Participating Companies that will advance a greater understanding of the activities and impact of foreign CE-TCOs, especially as they relate to the American people and economy, and that will ensure the NCC is fully apprised of the Participating Companies' operational activities;

(ix)    include procedures, including a review by the Department of Justice, that ensure any Program activity that is directed at a United States person or otherwise implicates the United States Government's obligations under the Constitution, Federal law, or international law receives any necessary authorization, judicial or otherwise, prior to approval of the operation;

. . . .

Sec. 4.  Definitions.  For purposes of this memorandum:

(a)  "Cyber Effects Operation" means activity conducted in or through the interdependent network of information technology infrastructure that includes the Internet, telecommunications networks, computers, information systems, industrial control systems, networks, and embedded processors and controllers that results in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon.

There's a lot going on here—many policy issues, and many legal issues.  In this post, I wanted to focus on a legal question: Does hacking back pursuant to this program violate federal law, and specifically 18 U.S.C. § 1030, the Computer Fraud and Abuse Act (CFAA)?

The concern, I take it, is more civil liability than criminal prosecution. Can a company hacking under this provision be subject to a civil suit, either by the entity targeted for hacking or someone whose data was affected by the hacking even if they were not the target?

The issue is partly the result of the global reach of the CFAA.  Over the years, the CFAA has expanded in scope so that it now covers computers all around the world.  Basically, if the foreign commerce clause allows Congress to protect it, the CFAA protects it—and given that the foreign commerce clause is thought to be almost plenary, that means computers all around the world are covered.

There are three interrelated legal provisions, it seems to me.  First, governments are exempt from liability under § 1030(f) for their "lawfully authorized" activity:

This section does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States, a State, or a political subdivision of a State, or of an intelligence agency of the United States.

Second, the CFAA prohibits unauthorized access (in § 1030(a)(2), for example) and damage without authorization (in § 1030(a)(5)(A)).  What makes the access or damage authorized versus unauthorized is of course one of the great longstanding issues in interpreting the CFAA.

Finally, there's a requied mens rea for liability.  To trigger liability, an unauthorized access or damage without authorization must be intentional.

So how does this play out?  I think there are three questions.

The first question is whether the executive branch's blessing is enough to trigger § 1030(f). If a company has entered an agreement with the government, and the government pre-approves the hacking back, is that the exempt "activity of a law enforcement agency . . . or of an intelligence agency of the United States"?

I doubt it.  This is a voluntary program, in which companies go to the U.S. government and get permission to hack back.  Even if the U.S. government is approving the hacking, it's still the company deciding to participate and instigating the hacking.  I would think this is the company's activity, not the government's.

The second question is whether executive branch blessing makes the access or damage authorized, or, if so, whether judicial blessing does so.

On one hand, it seems clear to me that executive-branch permission alone can't "authorize" the hacking as a statutory matter.  Think of a physical analogy.  If I want to break into people's homes and steal things, getting the permission of the local police chief doesn't mean that I'm actually allowed to do it as a matter of law.  Maybe I have an estoppel argument against prosecution (and maybe some kind of necessity defense allowing the breaking in could at least be considered), but it doesn't negate liability under the elements of the criminal statutes of trespass or burglary.  In the CFAA setting, the existence of § 1030(f) tends to confirm this, I think. The provision wouldn't be needed if police could just legally authorize hacking themselves.

On the other hand, I think a judicial warrant could authorize hacking under the CFAA.  I have suggested this in the past.  The way to have legal hacking back, I think, is to have the government go to a judge and get a warrant authorizing the search of the computer to be hacked and the seizure of data there.  If that seems odd, I'd suggest it's not all that far to the original use of warrants in the physical world back in the common law era.   If the farmer next door stole your sheep, you'd get a judicial warrant giving you permission to enter the neighbor's farm and take your sheep back. The warrant was your judicial authorization to enter and seize that made the acts legal.

Applying that concept to the digital realm also raises several other interesting legal questions, though.  Among them, does Rule 41 authorize a warrant to hack back?  Lower courts have held that the warrant requirement doesn't apply outside the United States, so there's not much in Rule 41 that focuses on that sort of thing. But the 2018 amendments to Rule 41(b)(6)(B) might plausibly fit to authorize the warrant to be issued.

Finally, there's the mens rea question: If the government says you can hack, and you hack incorrectly thinking that the executive branch blessing might render the hacking legal, is it intentional unauthorized access?  (Again, an estopped principle might apply to prevent prosecution, but that wouldn't apply civilly.)  That raises some very interesting issues about the intent requirement, see my article Norms of Computer Trespass in the last section.

There's certainly lots to think about for the companies that are considering whether to get involved in this program.

One last thought, not really substantive, but I gotta say it: It's too bad our colleague Stewart Baker isn't around to see this.  As our years-ago debate on hacking back made clear, Stewart would have loved this.

Note: I have fiddled a bit with this after posting to improve a few sentences and correct typos.