S5000119th CongressWALLET

Cyber Letters of Marque and Reprisal Act

Sponsored By: Senator Lee, Mike [R-UT]

Introduced

Summary

Authorizes the President to commission private cyber operators to disrupt foreign cyber threats and recover stolen digital assets. The Cyber Letters of Marque and Reprisal Act would let the President issue "cyber letters" that permit private individuals or companies to carry out limited offensive cyber operations abroad, seize digital assets, and return funds to American victims while funding future bounty programs.

Show full summary
  • Private operators: Would be allowed to run offensive cyber actions outside U.S. territory, including malware and asset seizures, after meeting qualifications and posting security bonds set by the President. Bond forfeiture can occur if holders violate the letter's terms.
  • Victims and rewards: Recovered assets may be returned to U.S. victims and up to 15% of each holder's recovered assets can be forfeited to a federal bounty program. Non-holding informants may receive up to 5% of recovered assets for information that leads to recovery.
  • Oversight and limits: Letters cannot authorize operations against U.S. citizens or entities and require holders to keep records of activities and seizures for at least five years. The bill shields holders from civil suits for acts the letter expressly authorizes.

Personalized for You

How does this bill affect your finances?

Personalize government policy and PRIA will tell you what this bill means for your household, plus every other piece of legislation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.

Bill Overview

Analyzed Economic Effects

3 provisions identified: 0 benefits, 0 costs, 3 mixed.

Authority to hire private cyber teams

If enacted, the President would be able to issue cyber letters that hire private teams to run offensive cyber operations outside U.S. borders. Holders would be allowed to use tools like malware to disrupt or seize foreign digital assets against designated cyberthreats. The bill would forbid knowingly targeting any U.S. citizen or U.S. entity. The bill would also limit civil lawsuits for acts the letter expressly authorizes and would define key terms such as "cyber operation" and "designated cyberthreat."

New rules for cyber-letter holders

If enacted, the President would issue guidance on who may get a cyber letter and where holders may operate. The President would require recipients to post a security bond the President sets before issuing a letter. The bill would permit forfeiture of some or all of the bond if the holder violates the letter. Holders would also have to keep logs of activities and seized assets for at least five years. Holders could act in sea, land, air, or space only if Congress first authorizes traditional letters of marque and reprisal.

Recovered cyber assets fund bounties

If enacted, recovered assets from authorized cyber operations would help fund a federal bounty program. The President could require up to 15% of assets recovered by a letter-holder be forfeited to the United States to fund bounties. A person without a letter who provides information leading to recovery could receive up to 5% of recovered assets as a reward. Any recovered funds not spent on bounties or rewards would be deposited into the Crime Victims Fund.

Sponsors & CoSponsors

Sponsor

Lee, Mike [R-UT]

UT • R

Cosponsors

There are no cosponsors for this bill.

Roll Call Votes

No roll call votes available for this bill.

View on Congress.gov
Back to Legislation