Private Cyber Letters of Marque

Full Title:
Cyber Letters of Marque and Reprisal Act

Summary#

This bill would let the President issue "cyber letters of marque and reprisal" that commission private people or companies to carry out specified cyber operations against named foreign cyberthreats. The main change is to authorize private actors to use offensive cyber tools (including malware) and to seize digital assets outside U.S. territory, under conditions the President sets. The stated policy goals are to deter and disrupt cybercrime, recover stolen digital assets for U.S. victims, and use private capacity to act faster than traditional enforcement.

Important points:

  • Main change: Creates a federal commission (a cyber letter of marque) authorizing private entities to conduct limited offensive cyber operations against designated foreign targets.
  • Targets and geography: Operations are limited to designated foreign individuals/groups/entities and to assets or infrastructure located outside U.S. territory.
  • Types of action allowed: Intelligence collection, data recovery, asset seizure (including cryptocurrencies), disruption of malicious infrastructure, and other actions to disrupt or degrade targeted systems.
  • Compensation and funding: The President may require up to 15% of recovered assets be forfeited to fund a bounty program; non-letter holders who help may get up to 5% of recovered assets.
  • Conditions and checks: Letter holders must post a security bond, keep activity logs for at least 5 years, and are prohibited from knowingly targeting U.S. persons or entities.
  • Legal immunity: Holders are immune from lawsuits for acts expressly authorized by their letter.

What it means for you#

  • Private cybersecurity firms and contractors

    • Could apply for and, if selected, carry out government-authorized offensive cyber missions under a letter of marque.
    • Must post a security bond and keep logs of operations and assets seized for at least 5 years.
    • May receive a portion of recovered assets or bounties as payment, subject to program rules.
  • People and businesses that custody digital assets (exchanges, custodians)

    • May be asked to cooperate with recovery or seizure operations targeting assets stored by or routed through them.
    • Could see increased operational interaction with private actors authorized to seize assets.
  • Victims of cyber-enabled theft

    • The bill aims to help return stolen assets to American victims by authorizing private recovery efforts and funneling some recovered funds into a victim-related fund.
    • Recoveries would be shared: up to 15% may be retained to fund the bounty program; remaining recovered funds may go to victims or the Crime Victims Fund per the bill’s instructions.
  • Designated foreign targets and foreign infrastructure

    • Foreign individuals, groups, or entities the President lists as "designated cyberthreats" could be subject to offensive cyber operations and asset seizure by private actors.
    • The bill requires such targets to be listed in a public registry "in accordance with applicable law."
  • U.S. courts and legal remedies

    • The bill bars lawsuits against letter holders for acts the letter expressly authorizes. People harmed by such authorized acts may have limited legal recourse in U.S. courts.
  • Federal government & agencies

    • The President (or a senior designee) decides who receives letters, the bond amounts, and program guidance. The bill allows the President to issue guidance on qualifications and the scope of operations.

Expenses#

No publicly available information.

Possible cost or financial effects the bill itself creates:

  • The bill allows recovered assets to fund a bounty program (up to 15% of each recovery required), and unused recovered funds to be deposited into the Crime Victims Fund.
  • The federal government may incur administrative costs to manage the program: maintaining the public registry, setting and enforcing bond rules, overseeing operations, and handling seized assets.
  • There could be indirect costs from diplomatic, legal, or incident-response demands if actions trigger foreign disputes or unintended damage. The bill does not provide a budget or cost estimate.

Proponents' View#

  • The bill appears intended to speed up disruption of cybercrime by using private-sector capacity to act in real time, since digital-asset crimes move very fast.
  • It appears intended to recover stolen digital assets and return value to American victims, using a private incentive model (payments from recovered funds).
  • The bill appears intended to deter and disrupt foreign cyber actors by allowing direct offensive actions against their infrastructure and assets.
  • It models historic privateering (letters of marque) adapted to the digital domain, giving private firms a clear legal commission to act.
  • The bond and recordkeeping requirements could be seen as safeguards to encourage compliance and accountability by letter holders.

Opponents' View#

  • One concern is that the bill gives broad immunity from lawsuits for authorized actions, which may leave harmed third parties with limited legal remedies.
  • One concern is lack of detailed oversight: the President largely sets who qualifies, how big bonds are, and what checks apply. The bill does not specify independent review, judicial oversight, or congressional approval for specific letters.
  • One concern is the risk of escalation or diplomatic conflict if private offensive actions harm foreign states or civilians. The bill authorizes operations against foreign infrastructure but does not detail how international law or foreign consequences are handled.
  • One concern is attribution and error: cyber operations can affect systems beyond intended targets, and the bill does not specify liability or remediation for collateral harm outside the scope of an authorized letter.
  • One concern is operational risk from authorizing private parties to use malware and offensive tools—this may create security or misuse risks if tools escape control or are used improperly.
  • It is unclear how the public registry of designated cyberthreats will work, what legal standards will apply, and how transparency and due process for listed entities will be ensured.