
The White House has authorized private U.S. companies to conduct offensive cyber operations against foreign criminal networks.
President Trump signed a National Security Presidential Memorandum on August 12, allowing vetted firms to target transnational criminal organizations behind ransomware, phishing, and sextortion schemes. These operations will be under the control and oversight of the US government.
Private sector gains offensive role in cybersecurity
The memorandum states that American businesses have advanced technological capabilities that could help disrupt cybercrime. “The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States,” the White House said.
Under the new policy, companies can propose and execute two types of operations. Cyber Surveillance Operations involve accessing a target’s systems without authorization, with intent to remain undetected, for the purpose of collecting information or intelligence. Cyber Effects Operations result in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, or infrastructure. Both require written approval and direction from the program’s Executive Directors—one designated by the Attorney General from the Department of Justice and one designated by the Secretary of Homeland Security.
Some actions will not be allowed. Operations that could cause loss of life, serious injury, or rise to the level of use of force or armed attack under international law—classified as Critical Outcomes—cannot be approved by the Executive Directors.
Related: Android malware steals card details in real time
Oversight and financial safeguards in place
The program will be managed by the Homeland Security Task Force’s National Coordination Center. Participating companies must maintain a bond or escrow of at least $1 million as a condition of taking part, forfeited if they fall into non-compliance with their contract. They also face at least annual review to remain in the program.
If a company discovers it has unintentionally targeted a US person, a system residing in the US, or a system under the control of a US person, it must cease the operation, run minimization procedures, and immediately notify the National Coordination Center. Any activity directed at a US person requires prior authorization before an operation can be approved.
In 2025, American consumers reported losing more than $20.8 billion to cyber-enabled crime, according to the White House. The memorandum builds on an earlier executive order Trump signed in March 2026 addressing cybercrime and fraud targeting American citizens.
Firms are encouraged to form agreements with other private entities and with federal, state, local, tribal, and territorial agencies to gather intelligence on criminal networks and propose operations against them. The memorandum confirms that implementation will be consistent with applicable law and subject to the availability of appropriations.
