Private cyber operations authorization

Full Title:
Cyber Letters of Marque and Reprisal Act

Summary#

This bill would let the President issue "cyber letters of marque and reprisal" that commission private persons or companies to carry out specified cyber operations against named foreign cyber threats. The main change is to create a federal authorization, with limits and conditions, for private actors to recover assets, disrupt malicious cyber infrastructure, and perform offensive actions (including malware) outside U.S. territory. The stated goal is to deter cybercrime, recover stolen digital assets for American victims, and use private-sector capacity to act faster than traditional law enforcement.

Key changes:

  • Creates a new federal commission called a cyber letter of marque and reprisal authorizing private entities to carry out specified cyber operations.
  • Defines covered actions broadly to include intelligence collection, data recovery, asset seizure (including cryptocurrencies), disruption of malicious systems, and limited offensive tools (including malware).
  • Limits operations to targets designated by the President and located outside U.S. territory; operations against U.S. persons or entities are forbidden.
  • Requires a security bond from each letter holder and keeps a log of activities and seized assets for at least 5 years.
  • Provides immunity: holders may not be sued in U.S. courts for acts expressly authorized by their letter.
  • Money rules: up to 15% of recovered assets can be forfeited to fund a bounty program; non-holders who provide useful information may receive up to 5% of recovered assets; leftover funds go to the Crime Victims Fund.

What it means for you#

  • Private cybersecurity companies and individuals

    • Could be commissioned by the President to carry out cyber operations against designated foreign threats.
    • Must post a security bond and keep detailed logs for at least 5 years.
    • Could use offensive cyber tools, including malware, if authorized.
    • Would be immune from civil suits in U.S. courts for acts expressly authorized by the letter.
  • Victims of crypto-enabled theft or cybercrime

    • This could mean more private capacity aimed at recovering stolen digital assets and returning funds to victims.
    • A portion of recovered funds may be used to pay bounties or go to the Crime Victims Fund.
  • Entities handling digital assets (exchanges, wallet providers)

    • May be asked to cooperate with private actors operating under a letter; the bill allows seizure and recovery of digital assets outside U.S. territory.
  • Foreign individuals, groups, or entities

    • Could be designated as “designated cyberthreats” and become targets of private cyber operations conducted under these letters.
  • General public / taxpayers

    • The bill allows part of recovered funds to fund operations, but it does not include an explicit budget or cost estimate.
  • Government agencies

    • The President may issue guidance on qualifications and limits for letter holders. The bill does not detail which agencies will run oversight, enforcement, or how the public registry of designated threats will work.

Expenses#

No publicly available information.

  • The bill requires private holders to post security bonds. That is a private cost and could be forfeited if terms are violated.
  • Up to 15% of recovered assets may be forfeited to the United States to fund a bounty program; up to 5% may be paid to informational helpers without a letter.
  • The bill does not include a fiscal note estimating government administrative or enforcement costs, nor does it state whether agencies need extra staff or technology to run the program.

Proponents' View#

  • The bill appears intended to expand tools to deter and disrupt cybercrime quickly by using private-sector capacity.
  • Supporters may argue this could help recover stolen digital assets and return funds to American victims faster than traditional investigations.
  • It could be seen as adapting an old legal power (letters of marque) to modern cyber threats and to the speed at which digital asset crime unfolds.
  • The security bond and forfeiture rules are framed as safeguards and as a way to fund a sustained bounty program.

Opponents' View#

  • One concern is that the bill allows private actors to carry out offensive cyber operations and use malware outside U.S. territory, while giving them immunity from civil suits; oversight and accountability rules in the bill are minimal.
  • The bill does not clearly explain how the President will designate targets, what public notification or review will occur, or how errors or misuse will be corrected.
  • It is unclear how the program would comply with international law or how it would affect diplomatic relations when private actors operate abroad.
  • The immunity from court claims for authorized acts may limit victims’ remedies if operations cause unintended harm to third parties.
  • The guidance, qualifications, and operational limits are left to unspecified presidential guidance, leaving implementation details uncertain.