```html ```
top of page

We Spent Nine Months Arguing That 'Legal Recon' and 'Hostile Recon' Are the Same Packets. On August 12 the White House Made That Distinction Federal Policy, With a $1 Million Bond.

  • Writer: Patrick Duggan
    Patrick Duggan
  • 1 minute ago
  • 5 min read

On August 12, 2026, the President signed a National Security Presidential Memorandum authorising vetted private companies to conduct offensive cyber operations against foreign criminal organisations. It is the first formal US program of its kind.


We have been circling this exact question since December 2025, from the other direction, and we want to lay out the argument we already made before the policy existed — because it turns out to have been a question about consent all along.



What the memo actually authorises


Firms that clear vetting become Participating Companies, contractually bound to the Department of Justice or the Department of Homeland Security, posting a bond of at least one million dollars, subject to annual review. The program is run out of the National Coordination Center — a body created under the January 2025 immigration enforcement order and since repurposed as the government's cybercrime coordination hub — jointly supervised by two executive directors, one from DOJ and one from DHS.


Targets are foreign Cyber-Enabled Transnational Criminal Organizations: ransomware crews, phishing operations, financial fraud, sextortion, impersonation scams.


Two categories of operation are authorised. Cyber Surveillance Operations covers covert intelligence gathering from computer systems, networks, telecommunications infrastructure and embedded devices — including, in the memo's own framing, unauthorised access that must remain undetected. Cyber Effects Operations goes further: manipulation, disruption, denial, degradation, or destruction of information systems.


The justification is not made up. US consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025. That is a real number attached to real people, and anyone dismissing this memo as pure adventurism has to answer it.



The argument we already made


In December 2025 the question that started this for us was small and specific: Palo Alto was scanning infrastructure without consent.


The observation that came out of it was that the packets are identical. A security vendor enumerating your attack surface and a criminal enumerating your attack surface send the same probes to the same ports and build the same map. What separates them is not the traffic. It is who is holding the keyboard, and whether we have decided in advance to call that party legitimate.


We called it consensual reconnaissance, and the conclusion was uncomfortable then and is more uncomfortable now: legal is not the same as ethical, and the consent model is broken. Not broken in a way that makes the scanners villains. Broken in a way where the same action is prosecutable or laudable depending on the letterhead, and nobody can articulate the technical difference because there isn't one.


August 12 did not resolve that. It codified it. There is now a formal process by which a company gets a letterhead that converts unauthorised access into authorised access, and the conversion costs a million-dollar bond and a vetting review. The distinction that was previously informal and unexamined is now a licence with a price on it.


That is, at minimum, more honest than the status quo. It is also the first time the thing has been written down where the rest of us can read it.





The Slap Shot problem


There is a 1977 film about this and it is not subtle.


In Slap Shot, Paul Newman's player-coach announces a bounty on an opposing player. It works. The crowds get bigger, the team starts winning, and the Hanson Brothers become the main attraction. The film's actual subject is not whether the violence is effective ��� it plainly is — but what the franchise turns into once the violence is what sells tickets.


The memo is not a bounty program. It authorises operations and requires a bond rather than paying per scalp, and that distinction matters. But the dynamic it creates rhymes hard, because the incentive structure now has a commercial actor on the ice.


A Participating Company has posted a million dollars, cleared a vetting process, and built a capability. That capability is a cost centre until it is used. Its annual review will ask what it did. Nobody in the history of institutions has ever built an offensive team, staffed it, and then reported that the correct number of operations this year was zero.


That is not cynicism about the people involved — it is the ordinary physics of a funded capability seeking justification. The question is not whether these firms will act in bad faith. It is what happens to the definition of a valid target when a well-run company with a bond and a review date needs a productive year.


Anyone who has watched a security vendor's threat-intel output expand to match its marketing calendar knows the shape of this. Now the output is operations.



Four things practitioners should actually watch


Attribution is the whole risk, and it is the weakest link in every offensive operation. Everything in this program depends on correctly identifying that the box you are degrading belongs to a foreign criminal organisation. We publish attribution corrections regularly because attribution is genuinely hard — we did one this week, noting that researchers said "Chinese-language operator" while outlets upgraded it to state linkage. Criminal infrastructure sits on shared hosting, on compromised third parties, on residential proxies built from hijacked televisions. A Cyber Effects Operation against a wrongly-attributed host is destruction of somebody else's property, and the bond suggests the drafters know it.


"Must remain undetected" is a demanding requirement. Covert access that has to stay covert is a high bar even for well-resourced state teams. A Participating Company that gets caught mid-operation creates an incident in a foreign jurisdiction with a US government contract behind it.


Escalation runs both ways. The crews being targeted are the same ones running ransomware against hospitals and water utilities. Degrading their infrastructure is not a consequence-free act against an opponent with no options.


The legal basis is untested. No court has ruled on this framing. "Acting under the control and oversight of the United States Government" is the sentence carrying all the weight, and it has not been tried anywhere.



The part that decides whether this is good


We are not going to pretend to a confident verdict on a memo signed yesterday. Here is the honest position.


The problem is real and the current answer is failing. $20.8 billion in consumer losses, takedowns that put infrastructure back up in weeks, and jurisdictions that will never extradite. Doing nothing has a body count too. If you have watched a ransomware crew hit a hospital and then watched the takedown, you understand the appeal of reaching out and breaking their stuff.


What will decide this is whether the oversight is real or ceremonial. A million-dollar bond and annual review are meaningful if there is genuine adjudication behind them, and theatre if there is not. The details that matter have not been published: who adjudicates a wrongly-attributed strike, what the victim of a mistaken Cyber Effects Operation can do about it, and whether any of this is ever disclosed.


Ask for those three answers before forming a view. We are going to keep asking for them.



Why we care about this one specifically


Because this is the pattern we have been describing all year, arriving in policy form.


The same technique is either an attack or a service depending on who performs it. We wrote it about vulnerability scanning, about the honeypots that exist to get hit, about security vendors becoming attack surface, and about the researchers who get named "anonymous" when their bug finally gets a CVE. Every one of those is a question about who is permitted to do the thing.


There is now a federal answer, and it is: whoever posts the bond.


Ninety-five percent, as always. This is a memo, not an outcome, and if the oversight turns out to be substantive we will say so as loudly as we are raising the question now.




Search the Epstein archive yourself

400,000+ DOJ documents, OCR’d and cross-indexed. Search by name, place, or connection — free.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=we-spent-nine-months-arguing-that-legal-recon-and-hostile-recon-are-the-same-packets-on-august



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page