WeVote

Bill

Bill

S 5000

Cyber Letters of Marque and Reprisal Act

119th Congress Introduced by Mike Lee

The bill would let the President grant private actors cyber letters of marque to target foreign cyberthreats, enabling funded, limited operations with liability protections.

Introduced in Senate
0
WeVote Research Nonpartisan
Bill Summary · S 5000

Overview

  • Bill: S. 5000 (119th Congress, 2nd Session)
  • Title: Cyber Letters of Marque and Reprisal Act
  • Purpose: Authorize the President to issue cyber letters of marque and reprisal to private individuals or entities to conduct limited cyberspace operations against designated cyber threats, with mechanisms for funding, accountability, and limited liability protection.

Main purpose and intent

  • Enable the President to commission private actors to carry out targeted cyber operations against designated foreign cyberthreats.
  • Deter and disrupt cyber-enabled attacks against the United States, U.S. persons, or U.S. assets.
  • Modernize a concept rooted in historic privateering to address rapid, cross-border cybercrime and asset theft.
  • Facilitate return of stolen funds to American victims and support growth of lawful digital asset innovation with safety measures.

Key provisions and changes

  • Sec. 4 – Definitions
    • Cyber Letter of Marque and Reprisal: Federal commission authorizing a private entity to conduct specified cyber operations under Presidentially issued conditions.
    • Cyber Operation: Broadly includes intelligence gathering, data recovery, information operations, asset seizure (including digital assets/cryptocurrency), disruption of malicious infrastructure, support for government operations, combating cybercrime, and proactive disruption of threats.
    • Designated Cyberthreat: Foreign individual/group/entity identified by the President as responsible for or sponsoring cyberattacks against U.S. persons/assets, listed publicly.
  • Sec. 5 – Issuance of Letters
    • The President (or designated senior official) may commission privately equipped persons/entities with letters of marque to conduct cyber operations targeting designated cyberthreats outside U.S. borders.
    • Security Bonds: Recipients must post a security bond; forfeiture can occur for violations.
    • Restrictions: Recipients may not knowingly target U.S. citizens or entities.
    • Recordkeeping: Recipients must maintain a 5-year activity/assets log.
    • Recovered Assets: President may require up to 15% of total recovered assets to fund a bounty program for future operations.
    • Bounties:
    • The President may establish bounties funded by recovered assets for holders of letters.
    • Non-letter recipients may receive up to 5% of recovered assets as a reward for information leading to recovery.
    • Unexpended funds go to the Crime Victims Fund.
  • Sec. 6 – Reciprocal Invocation
    • If Congress authorizes traditional letters of marque and reprisal for maritime/land/air/space, cyber letter holders may conduct parallel operations to the extent allowed by the President.
  • Sec. 7 – Requirements and Qualifications
    • The President may issue guidance on eligibility and on the scope/extent of operations at sea/land/air/space for letter holders.
  • Sec. 8 – Protection from Liability
    • No civil liability against a letter holder for acts expressly authorized by the letter.

Who would be affected

  • Private individuals and entities could be commissioned as cyber operators under a presidentially issued letter.
  • Designated cyberthreat actors (foreign individuals/groups/entities listed in the registry) would be the intended targets.
  • The United States government would oversee issuance, monitoring, and enforcement, including bonds, logs, and potential asset forfeiture.
  • Victims of cybercrime could benefit from asset recovery and possible victim fund allocations.

Procedural and timing aspects

  • Introduced in Senate on July 15, 2026 by Senator Mike Lee (co-sponsor), referred to the Committee on Foreign Relations.
  • The bill outlines processes for issuance, monitoring, and liability protection, but it is not clear from the text whether or when this may become law without further legislative action (e.g., committee amendments, votes, conference).

Potential impact and considerations

  • Deterrence and disruption of sophisticated cyber threats through private-sector participation.
  • Escalation risk: Private actors operating internationally could raise concerns about sovereignty, escalation, collateral impact, and accountability.
  • Legal and ethical questions around due process, rules of engagement in cyberspace, and potential misuses.
  • Financial mechanisms (bonds, bounties, and forfeit provisions) create incentives and funding streams for ongoing cyber operations.
  • Protections for rightful targets and the need for clear guardrails to prevent abuses or unintended harm.

Compiled from official sources — confirm details with the bill’s official record.

Sign in to ask a question.