Senate advances bill allowing contractors to conduct military hacking for US government

2 weeks ago 17

The Senate Armed Services Committee has greenlit a provision that would, for the first time, formally authorize private contractors to conduct cyber operations on behalf of the US military. The measure, tucked inside the National Defense Authorization Act for Fiscal Year 2027, would create a pilot program letting civilian firms generate and maintain access to foreign computer networks under the watchful eye of US Cyber Command.

The SASC advanced the provision on June 23, 2026, during its markup of the FY2027 NDAA. Under the proposed framework, contractors would use their own infrastructure to carry out access generation and maintenance operations. These are the tedious, resource-intensive tasks of finding pathways into target networks and keeping those pathways viable over time.

The scope is deliberately narrow. Operations would be restricted exclusively to access-related activities. No offensive capabilities, meaning no disrupting enemy systems, no destroying data, no shutting down infrastructure. Contractors would operate under the command and supervision of CYBERCOM, with Department of Defense approval required.

The China math problem

The driving force behind this proposal is a numbers game the US is losing badly. China’s cyber workforce reportedly outnumbers America’s by a ratio of roughly 10 to 1. That gap isn’t just about headcount. It translates directly into operational capacity, because maintaining access to adversary networks is one of the most labor-intensive tasks in cyber operations.

Establishing a foothold in a foreign network can take months or even years of patient, methodical work. Losing that access because there aren’t enough trained operators to maintain it means starting the clock over from zero. Proponents of the provision argue that contractors can fill this capacity gap, freeing up military cyber operators to focus on higher-priority missions while private firms handle the persistent, grinding work of keeping digital doors open.

The case against outsourcing access

Critics of the provision haven’t been shy about flagging those risks. The concerns cluster around three main areas: liability, oversight, and international norms.

On liability, the question is straightforward but legally messy. If a contractor accidentally or deliberately causes damage to civilian infrastructure while generating access, who bears responsibility? Military personnel operate under the Uniform Code of Military Justice and clear chains of command. Contractors exist in a murkier legal space, as the US learned painfully during the Iraq War era when private security firms operated in conflict zones with limited accountability.

Oversight presents its own challenges. CYBERCOM would maintain command authority, but monitoring contractor activities in cyberspace is inherently more difficult than supervising physical operations.

Then there’s the international dimension. A growing body of international norms aims to protect civilian infrastructure from cyber operations and to maintain clear distinctions between governmental and private cyber activities. Authorizing contractors to conduct military cyber operations, even limited ones, could blur those lines in ways that undermine US credibility when it calls out other nations for similar behavior.

What comes next

The provision has cleared its first hurdle but faces a long road to becoming law. It still needs full Senate approval, then must survive House-Senate reconciliation, where the House’s own version of the NDAA could modify or strip the language entirely. After that, presidential signature would be required for enactment.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article