7-minute read | 1,600 words
What to know this week
The private sector is now allowed to hack cybercriminals.
President Trump has signed a new memo that encourages American companies to launch their own cyberattacks.
States seek $200 billion in damages from Meta.
Numerous states have accused Meta of harming children and addicting minors to its social media.
This week's full stories
President Trump allows for private companies to hack cybercriminals.
THE NEWS
Last Thursday, President Trump signed a new national security memorandum that permits select companies to work with the Justice Department and Homeland Security to strike foreign cybercriminal groups.
The memorandum, titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” specifically allows approved private companies to launch attacks that would enable surveillance of criminal networks and specific types of hacking operations. These operations include efforts that could lead to disruption, manipulation, or destruction of information systems and networks.
Notably, the document did specify that these attacks will be limited to transnational criminal organizations that are considered separate from a foreign government.
When approving and launching these attacks, the administration stated that operations would be launched “based on intelligence.”
Amanda Naylor, the director of cybersecurity at the National Security Council, wrote:
This memo gives “the United States new tools to protect Americans from cybercrime and fraud.”
THE KNOWLEDGE
Though this latest memorandum is certainly the most decisive and clear effort by the Trump administration to approve of private sector offensive cyber operations, this is not the first time the administration has signaled it was interested in this path.
Earlier this year, in March 2026, the administration released a new National Cybersecurity Strategy. At the time, the strategy called for increased participation of private companies in offensive cyber operations. Specifically, the strategy wanted private support in operations targeting “sophisticated military, intelligence, and criminal adversaries.” Targets included ransomware groups and cyber criminals.
This effort came after the administration was able to provision an additional $1 billion for offensive cyber operations in the Big Beautiful Bill in 2025. Notably, that same bill also cut roughly $1.2 billion for defensive cyber operations.
This latest memorandum is the next iteration of a new cybersecurity policy that has been formulating for over a year and sees offensive operations as the most effective way to counter malicious actors. Further, this new approach is not unique to the US.
Alongside the US, the United Kingdom (UK) has also established similar priorities. In April, the UK published its guiding principles for offensive cyber operations. Additionally, the publication noted that the UK has already sanctioned operations that:
- Protected military assets overseas.
- Disrupted terrorist operations.
- Countered state-backed disinformation campaigns.
- Countered stealthy, sophisticated cyberthreats.
Joining the US and UK, Germany drafted similar legislation.
Each of these nations pivoting their respective approaches to cyber operations demonstrates that governments are no longer confident that defensive cyber operations are solely effective at stopping malicious activities.
THE IMPACT
The biggest change from this memorandum is not that the US is willing to conduct offensive cyber operations. Rather, it is the decision to bring private companies directly into these operations.
For years, governments have relied on cybersecurity companies to identify, investigate, and defend against cyber attacks. Now that select companies will have the authority to participate in offensive cyber operations, that relationship is changing. Private companies could be permitted to take part in efforts to infiltrate or disrupt targets sanctioned by the US government.
The memorandum represents the next step in a broader shift for how the US government is looking to address cyber threats. Rather than relying on organizations for defense, governments are looking to go on the offensive, disrupting adversaries before they can cause harm. If effective, this approach will likely continue to be adopted globally, fundamentally changing the cybersecurity landscape.
States start lawsuit against Meta.
THE NEWS
On Tuesday, a lawsuit involving several states and Meta began, with the states seeking roughly $200 billion in damages alongside forcing platform technology changes. The lawsuit, brought by California, Colorado, Kentucky, and New Jersey, alleges that Meta harmed children on its platform by intentionally creating addictive features.
California’s attorney general, Rob Bonta, commented on the suit, stating:
“Meta designed a dangerous product for young users, knew it to be dangerous and then lied to children, families and the community about how dangerous it was.”
Kentucky Attorney General Russell Coleman echoed these sentiments:
“AGs are in the perfect position to get this done. We did it with the Tobacco Settlement in the 1990s. We did it with the companies behind the opioid crisis. We’ll do it again with Meta.”
Meta plans to argue that it put appropriate safeguards in place to protect young users and that it was truthful to consumers.
If the states were able to successfully seek damages equating to $2 billion dollars, that would be equivalent to roughly 14% of the company’s stock value.
The court case will be heard in the U.S. District Court for the Northern District of California, and the trial is expected to last six to eight weeks with Judge Gonzalez Rogers overseeing the trial.
Additionally, the states plan to call Mark Zuckerberg to the witness stand and use internal documents and interviews from current and former company employees to demonstrate their case.
THE KNOWLEDGE
This latest case joins dozens of similar ones filed by both states and individuals alike. However, unlike the other cases, this suit represents one of the largest to date. Outside of seeking roughly $2 billion in damages, the states are also looking to force Meta to adopt substantial platform changes. These changes include:
- Remove autoplay of video content.
- Remove image filters related to changing one’s appearance.
- End disappearing or “ephemeral” posts, such as Stories.
- Change its “dopamine-manipulating recommendation algorithms”
- Disable “likes” for minors.
Given both the financial scope and the significant platform changes, this lawsuit has the potential to set a precedent for not only similar cases but for how social media platforms are designed. While many of these platforms have unique features, there are numerous commonalities found across all of these platforms such as infinite scroll, autoplay, likes, and stories. Removing any of, or all, of these design features could fundamentally change how social media platforms are designed and how users engage with them.
Outside of this case, dozens of other lawsuits have been filed against Meta and similar social media platforms, such as YouTube, Snapchat, and TikTok. One of the most high-profile cases involved a woman suing both Meta and Google for several million dollars. In the case, a jury ruled that the two companies were to blame for her depression and anxiety.
Since that case, another lawsuit in New Mexico also concluded, which resulted in the court ordering Meta to pay $567 million. In that case, the court found that Meta had failed to properly warn the public about the dangers of its platforms to minors. The funds from the fine will be used to support a minor's mental health treatments for those the platforms caused harm to and will also go towards stronger awareness and prevention efforts.
THE IMPACT
While it is impossible to predict how this trial will be ruled, the suit itself reflects a growing trend of holding social media companies accountable not for the content they host, but for how they have designed their platforms. This distinction could have significant implications for the broader technology industry if courts determine that certain design choices can constitute a form of consumer harm.
The potential remedies to these suits could be significant. While financial penalties would create a direct cost, requirements that impose design changes could force companies to reconsider how they maximize engagement. If these changes are imposed across multiple platforms, they could ultimately influence how social media products are designed and how companies balance user engagement with safety.
As governments and plaintiffs look for ways to better address the potential harms associated with social media, companies will likely face greater scrutiny over not only what their platforms show, but how their products are engineered.
This Week's Caveat Podcast: When companies can hack back.
Dave Bittner and Ben Yelin dive deeper into the Trump administration’s decision to allow private companies to hack foreign cybercriminals. Additionally, the two look at the emerging trend of AI companies publishing their own “AI constitutions” and how these documents define the values and behaviors that respective models should be following.
OTHER NOTEWORTHY STORIES
California mandates a new AI cybersecurity role.
What: California mandates a new AI cybersecurity role for state agencies.
Why: On Friday, California Governor Gavin Newsom announced a new directive that tasks state agencies with creating new AI cybersecurity roles. This new role will be tasked with assisting respective agencies with using AI to improve vulnerability detection, network hardening, and incident response efforts.
Additionally, Governor Newsom has also called for state governments and critical infrastructure providers to increase access to stronger and more advanced cybersecurity capabilities.
AUGUST 14, 2026 | Source: State Scoop
French taxpayers’ data stolen.
What: A malicious actor successfully targeted the French Finance Ministry, stealing both individual and professional data.
Why: On Friday, the French Finance Ministry disclosed that the agency was successfully breached after a malicious actor announced the attack several days before. The attack was able to successfully extract taxpayer data for over 678,000 users.
In a statement, the ministry emphasized:
“Users concerned will receive individual information specifying the data that may have been consulted or extracted and, where applicable, the precautionary measures to be adopted.”
AUGUST 14, 2026 | Source: Reuters
