Constitutional experts warn executive memo revives 18th-century practice without legislative consent, risking unaccountable warfare and geopolitical escalation
President Donald Trump signed a national security memorandum Wednesday authorizing select private companies to conduct government-sponsored cyberattacks against foreign criminal networks — effectively reviving the age‑old practice of privateering for the digital era while sidestepping the constitutional authority explicitly reserved for Congress.
The memo directs the Justice Department and the Department of Homeland Security to create a program under which vetted U.S. firms may surveil, manipulate, disrupt or destroy foreign computer systems and infrastructure.
While the order bars operations that cause “loss of life” or “serious injury,” and prohibits targeting foreign governments, critics say the distinction between criminal syndicates and state‑backed hackers is dangerously blurred in practice — and that the president has overstepped his constitutional bounds.
Constitutional power grab
Under the U.S. Constitution, Article I, Section 8, Clause 11 grants Congress — not the president — the exclusive power to grant letters of marque and reprisal.
These formal licenses historically allowed private ship owners to legally attack and capture enemy vessels during declared wars, transforming civilian sailors into lawful combatants subject to military law and admiralty prize courts.
Article I, Section 10 strictly forbids individual states from granting any such letters, underscoring that the federal power belongs solely to the legislative branch.
Trump’s cyber memo, issued unilaterally by executive fiat, bypasses that constitutional lane entirely.
“The Founders deliberately placed the power to authorize private warfare in the legislative branch, alongside the power to declare war,” said a former Pentagon general counsel who spoke on condition of anonymity to discuss constitutional concerns. “By acting alone, the president is effectively rewriting the Constitution’s war powers for the digital age.”
The memorandum evokes the privateers of the 18th and 19th centuries — private ship owners and sailors who received government licenses to attack and capture enemy merchant ships during wartime, keeping a portion of the profits from seized cargo while disrupting enemy supply lines.
Nations with small official navies, like the United States during the American Revolution and the War of 1812, relied heavily on privateers to fight larger foes like the British Royal Navy.
The practice ended internationally with the 1856 Declaration of Paris, though the U.S. never formally signed it and has abided by its prohibition for more than a century and a half.
Trump’s directive effectively revives the practice — just in cyberspace. But the operational mechanics diverge dramatically.
Historical privateers carried explicit commissions naming specific enemy nations, operated only during wartime, and were required to bring captured vessels to admiralty courts for legal adjudication of prize money.
Trump’s contractors may target “cyber-enabled transnational criminal organizations” without a declared war, and the memo’s oversight mechanism — a joint Justice Department and Homeland Security coordination center — lacks the judicial transparency of prize courts.
“Privateers had to prove their captures in a court of law,” said legal historian Sarah Milner of Georgetown University. “Here, a company’s destruction of foreign servers or infrastructure will be reviewed by political appointees behind closed doors. There is no public accounting and no clear victim compensation.”
Escalation risks and legal ambiguity
For decades, the U.S. government barred private firms from “hacking back” against attackers for fear of geopolitical blowback. That restraint is now discarded.
The administration says it needs private-sector speed and innovation to combat a surge of ransomware and fraud. But former officials warn the move creates a new class of unaccountable actors.
“What if a company carries out an operation against what it thinks is an Iranian or Russian criminal group, but that group is actually controlled, influenced or protected by Tehran or Moscow?” said Matt Curtis, former White House senior director for cyber policy under President Joe Biden. “Suddenly, what was intended as an operation against criminals could be viewed as a U.S.-authorized cyber operation against a nation-state actor … and potentially trigger retaliation or escalation.”

The memo contains a classified annex describing coordination with the military and intelligence agencies, a process known as deconfliction. But critics question whether private firms can reliably avoid collateral damage.
“The real risk is that you end up with a bunch of cyber privateers running around without any clear coordination or direction at the federal level,” said Andrew Schoka, a former Army officer at U.S. Cyber Command. Deconflicting cyber operations “is already a major challenge for federal agencies, but now you’re adding in the complexity of private sector firms with a lot more capability and speed,” he told CNN.
Jason Kikta, a former Cyber Command operator, now chief technology officer at cybersecurity firm Automox, said using contractors to perform government work “makes us no better than China and Iran,” where industry has conducted ransomware operations and carried out cyberspying. “The U.S. has fought against such abuses for years, and this now makes us look hypocritical.”
Legal experts also question whether the Computer Fraud and Abuse Act — the main federal anti‑hacking statute — would still apply to companies acting as government agents.
The memo does not directly address Fourth Amendment protections requiring warrants for domestic hacks, nor does it spell out liability for collateral damage. Chris Wysopal, co‑founder of cybersecurity firm Veracode, warned that a government‑sanctioned operation could inadvertently affect hospitals or other critical infrastructure, and that employees of participating companies who travel abroad could become legitimate targets for detention by foreign governments.
The memorandum’s prohibition on targeting foreign governments is particularly fraught.
As former officials note, criminal syndicates frequently operate with state protection or control, making the distinction illusory. That ambiguity mirrors a core risk of historical privateering: commissions were often ignored, and privateers frequently crossed into outright piracy when profits beckoned.
Captured privateers were historically treated as normal prisoners of war, while pirates were hanged as common criminals. Under Trump’s order, the legal status of a contractor captured or detained overseas remains entirely undefined — raising the specter that American citizens could face prosecution as unlawful combatants or common cybercriminals in foreign courts.
The White House defended the order as a necessary evolution.
“President Trump is unleashing every available tool to stop foreign-based organized criminal organizations that exploit Americans in cyberspace,” said a White House fact sheet.
The memo establishes a national coordination center run by the Justice Department and DHS to vet companies, which face fines up to $1 million for contract violations.
But critics say the fine is negligible, and the oversight structure remains opaque. “There is no clear oversight or review process on the determinations that will be made by unnamed political appointees,” Kikta said.
Constitutional shipwreck
The United States last issued letters of marque during the War of 1812. Occasional debates have floated reviving the concept for cyber warfare or asset seizure, but none have been enacted — precisely because the constitutional text is unequivocal.
By bypassing Capitol Hill, Trump’s memo invites a separation-of-powers clash that legal experts say could render the entire program legally indefensible.
Trump launched an unprovoked war against Iran in conjunction with Israel that has received tacit approval from Congress but not any legal authorization.
Congressman Josh Gottheimer proposed a package of federal actions to bolster American critical infrastructure following a wave of attacks that targeted New Jersey municipal water systems and others in at least a dozen states across the country.
“Every morning, folks in this town wake up, turn on the faucet, and clean water comes out. You flip a switch and your lights come on. Nobody thinks twice about it. Nobody should have to,” said Gottheimer, who has been called Trump’s favorite Democrat in Congress. “I’m standing here because in towns just like this one, all over the country, that deal we have with our utility companies has been put in real jeopardy, and if we don’t get out ahead of it, it could mean a disaster.”
Gottheimer said in recent weeks, hackers have targeted water systems in New Jersey and at least a dozen other states.
In Cape May County, two municipal systems were hit, forcing operators to manually turn valves and run pumps after the digital controls they rely on every day were wrenched away from them.
The Federal Bureau of Investigation (FBI) is investigating incidents in at least seven states, and the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency (EPA), and the FBI issued a joint advisory urging the entire water sector to immediately lock down its systems. Investigators have pointed to Iranian-affiliated actors, while examining whether other adversaries are copying the same playbook.
There are roughly 150,000 public water systems in the country, and 97 percent of them serve small communities such as Park Ridge, often with just a handful of employees and no full-time cybersecurity team. Many were built decades ago for reliability, not for cybersecurity, leaving older controllers and outdated software exposed to anyone who knows where to look.
Gottheimer generally supports Trump’s war mongering in the Middle East, but he has not committed to the latest policy.
“This isn’t just privateering,” said a former Cyber Command lawyer. “It’s executive privateering — with no congressional declaration of war, no statutory authorization and no independent court to oversee the spoils. That makes it a constitutional shipwreck waiting to happen.”
The order comes as the FBI and Google recently disrupted a botnet used by hackers from China, Iran and Russia.
Yet by outsourcing offensive operations to corporate militias without legislative consent, experts argue, the Trump administration is trading strategic clarity for short‑term expediency — and risking a future where digital warfare is fought by profit‑driven mercenaries with no direct accountability to the American people or their elected representatives.
“The United States just revived privateering for the digital age,” said Jeff Gray, who led training for DHS’s emergency response team. “The government is authorizing private actors to conduct offensive cyber operations on its behalf, under its control. That’s privateering — except this time, the letter of marque bears only one signature, not the consent of the people’s representatives.”
The White House did not respond to a request for comment on the constitutional questions.
Discover more from NJTODAY.NET
Subscribe to get the latest posts sent to your email.
