Commentary
In the first half of 2026, North Korea-linked groups accounted for 99 documented advanced persistent threat incidents. Russia’s activity rose by 30 percent and spread beyond Ukraine. Chinese clusters kept pre-positioning inside Western critical infrastructure. Iranian operations surged with the regional war. These are not isolated crimes.
The actors filling this space are hacker groups—sometimes criminal, sometimes hybrid, often working with tacit or explicit state support. They deliver strategic effect cheaply and with deniability. That is the privateer bargain. The main practitioners are the regimes of China, Russia, North Korea, and Iran.
China runs the most institutionalized dual-use system. State groups such as Volt Typhoon and Salt Typhoon focus on long-term collection and infrastructure pre-positioning. A contractor ecosystem blurs the lines between official tasking and profit.
Researchers describe a “Premier Pass-as-a-Service” model: one cluster establishes live access and hands it to another. Intelligence remains the priority; financial crime is secondary.
Russia offers sanctuary and selective tasking. Ransomware groups enjoy near-impunity if they spare Russian targets. Some receive intelligence support; others simply use the safe harbor. The result is high-volume, continuous pressure on the West.
Iran is more reactive. Operations mix sabotage, influence, and proxy networks that surge with kinetic events—useful for signaling, less reliable for sustained collection.
North Korea runs the purest revenue model. Lazarus and related clusters treat cryptocurrency theft as a form of regime finance. In 2025, they stole more than $2 billion in digital assets—about 59 percent of all crypto theft that year—including the $1.5 billion Bybit heist. The state gets the needed hard currency. The operators get protection that can be withdrawn when they become too noisy.
Specialization has now become structural: Access brokers compromise and hand off, collectors dwell and extract, revenue groups steal, and disruptive specialists target industrial systems. This enables the tempo of activities to rise and individual risk to fall.
Cooperation is visible, if incomplete. In mid-2025, infrastructure used by Russia’s Gamaredon hosted malware linked to North Korea’s Lazarus Group. Chinese groups share access internally. North Korean operators share tools with ransomware crews. These are pragmatic exchanges, not mergers.
Russia and North Korea have deepened their political-military ties; cybercollaboration appears to follow suit. Deep Chinese–Russian fusion remains limited. National cyberprograms are no longer fully siloed. Of course, this is just what we know from open sources.
The state captures the most value: deniability, lower cost, and continuous pressure. Operators absorb legal risk and receive unreliable protection. This pattern is similar to how selected Russian criminal groups have long received sanctuary or tasking, or Chinese triad networks sometimes operate for the regime at home or overseas while remaining formally criminal.
For the West, the costs are already visible: attrition against infrastructure and intellectual property, tradecraft leaking into criminal markets, imperfect attribution, and high cumulative defense costs.
An Old Tradition
The instrument is not new. States have historically used private actors when they needed force without the full burden of official armies. Letters of marque authorized privately owned ships to attack enemy commerce. The privateer kept a share of the prizes; the state gained disruption, intelligence, and deniability. The line between privateer and pirate was thin.
The model worked because private actors brought capabilities that states could not always maintain at scale. Profit-aligned incentives, deniability, reduced political exposure, and commissions could be issued or revoked. Specialization emerged naturally: scouting, boarding, long-range disruption.
The same logic reappeared more recently in private military companies. Blackwater, for example, provided surge capacity and political distance in conflict zones. Wagner was a more extreme, less constrained version—tightly linked to Russian interests, formally deniable.
But there is Western reluctance with deep roots. The 1856 Declaration of Paris abolished privateering by most major European powers of the time because licensed private forces proved destabilizing and difficult to control at sea. (The United States declined to formally sign it at the time, although it adhered to its principles in practice.) Liberal democracies have preferred a clearer monopoly on the use of force. The common perception of the post-9/11 contractor experience has reinforced that instinct.
Cyberprivateering inherits the old logic and amplifies it. Barriers to entry are lower, as the prize is data, access, disruption, or stolen cryptocurrency rather than cargo, while attribution is imperfect by design. Operations scale with less friction. Specialization is already here, as noted above.
There are differences, as well. Effects can cascade through shared infrastructure. Cloud providers and third-party systems sit in the path of almost any serious operation. At the same time, decision cycles compress. Tools leak quickly from state-linked groups into criminal markets, making the line between authorized action and predation more porous than it was at sea.
The result is an asymmetry, as authoritarian systems have refined the model in cyberspace, while liberal democracies have mostly absorbed the cost of defense rather than licensing private offensive capacity. That choice is now under increasing pressure.
The West Adapts
Western governments still prefer a state monopoly on force, but the scale of the threat is nonetheless forcing experiments in controlled outsourcing.
The most concrete step is American. On Aug. 12, the White House issued a national security presidential memorandum directing a program under which vetted U.S. companies may conduct cybersurveillance and run operations against foreign cyber-enabled transnational criminal organizations—groups that are not explicitly part of foreign governments.
Operations require written approval from the Department of Justice and Department of Homeland Security, a forfeitable escrow, rigorous vetting, and federal supervision. Actions producing loss of life or use of force are prohibited. Companies act as government agents, not independent operators.
This is the first formal U.S. authorization of private-sector offensive cyberoperations of this kind, and it is deliberately narrower than classical privateering.
A more expansive model sits in the proposed legislation. The Cyber Letters of Marque and Reprisal Act, from Sen. Mike Lee (R-Utah), would allow the U.S. president to commission private entities to target designated foreign cyberthreats, require bonds, and permit asset recovery and limited sharing of recoveries, including bounty funding. It is closer to the historical instrument. As of late August, it remains in the early stages, with limited momentum, although it could surface in a larger bill.
In Britain, the debate is still analytical. RUSI papers have explored “deputisation”: time-limited, narrowly scoped disruption by vetted firms against serious cybercrime, under continuous government authorization and legal indemnity, with the state able to halt activity at any moment.
Singapore offers the only existing statute. Under Section 23 of its Cybersecurity Act, a minister may certify a person or firm to counter threats to computer systems. The process is opaque, and its actual use is unclear. Other European states have so far hesitated, at least publicly.
Is the Pendulum Swinging Back?
Authoritarian systems have never fully abandoned this modus operandi. For the West, the cost of continuous attrition has become harder to ignore. Traditional tools have not closed the gap, and private technical capacity already exceeds that of the government in many niches. It seems like there is a momentum to concede that some controlled private capacity may be necessary.
But the lessons of 1856 still matter: Licensed private force is hard to restrain. Attribution, escalation through shared infrastructure, and rapid leakage into criminal markets all argue for caution. This is not a full return to privateering, but it is a change. One set of states has normalized the instrument, and now another is testing supervised versions under pressure. How far the experiments travel is still an open question.
Views expressed in this article are the opinions of the author and do not necessarily reflect the views of The Epoch Times.





















