Representative · R-TN
The bill empowers private-sector cyber operations and asset seizures to disrupt crypto-enabled crime and recover funds more quickly, but does so by expanding private authority and immunity in ways that heighten risks to privacy, accountability, legal remedies, taxpayers, and international stability.
Tech firms, financial institutions, small businesses, and other victims of cybercrime gain authorization for private-sector cyber operations to disrupt foreign command-and-control and stop attacks faster.
Victims (consumers, small businesses, and financial institutions) can see stolen digital assets seized or returned and recovered funds routed to victim services or compensation mechanisms.
Federal government and private operators get clearer legal authority, definitions, and eligibility rules for authorized cyber operations, reducing uncertainty for operators and encouraging lawful digital-asset innovation.
Everyday Americans and U.S. infrastructure face increased risk of accidental harm, collateral damage, and international escalation because private actors may conduct offensive or extraterritorial cyber operations.
People harmed by authorized operations may lose legal remedies and accountability — immunity and private commissions create gaps that make it harder for victims to obtain redress for wrongful intrusions or seizures.
Expanding private cyber activity and broad authorities increases privacy and surveillance risks for the public and retention of sensitive logs/records, potentially exposing personal and proprietary data.
Based on analysis of 7 sections of legislative text.
Authorizes the President to commission private entities to conduct offensive cyber operations and seize digital assets from designated foreign cyberthreats, with bond, recordkeeping, bounty, and immunity rules.
Official title: To authorize the President of the United States to issue cyber letters of marque and reprisal, and for other purposes.
Introduced July 15, 2026 by Timothy Burchett · Last progress July 15, 2026
Authorizes the President to commission private persons and companies — via "cyber letters of marque and reprisal" — to conduct limited extraterritorial cyber operations against designated foreign cyberthreats, including disrupting infrastructure, seizing and repatriating digital assets, and using offensive cyber tools. It requires bonds, logging and forfeiture rules, permits a portion of recovered assets to fund bounties and victim restitution, and bars civil suits for acts expressly authorized by a letter. Sets definitions for covered cybercrimes and designated threats, allows cyber holders to operate in other domains only if Congress later authorizes traditional letters of marque, and gives the President authority to issue implementing guidance and set operational limits and security requirements.