
Trump authorizes private companies to conduct offensive cyber operations against foreign criminals
President Donald Trump signed a memorandum on August 12 authorizing vetted private companies to conduct offensive cyber operations against foreign criminal groups, the first time the US government has delegated such authority to the private sector.
Policy shift
President Donald Trump signed a national security presidential memorandum on Wednesday, August 12, authorizing private companies to conduct offensive cyber operations against foreign transnational criminal organizations (TCOs) for the first time. The memo directs the National Coordination Center (NCC), operating under the Homeland Security Task Force, to develop a program enabling vetted private-sector firms to carry out cyber surveillance and cyber effects operations against criminal groups based overseas. The Departments of Justice and Homeland Security will provide oversight, with co-executive directors from both agencies managing the effort.
The fact sheet accompanying the memo lists ransomware, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams as eligible targets. TCOs are defined as foreign groups conducting cyber-enabled crime against the United States Government, US persons, or US interests, that are not an institutional part of a foreign government or wholly operated under a foreign government's direction. The memo permits participating companies to use spyware for intelligence collection and to launch attacks intended to disrupt, manipulate, or destroy criminal networks' data and systems, including virtual and physical infrastructure.
Safeguards and requirements
Companies seeking to participate must undergo what the memo describes as "rigorous vetting" and meet minimum standards for technical proficiency, proven performance of cyber operations, and facility security. They must sign contracts with both DOJ and DHS and post a $1 million bond or escrow, forfeited if they fail to comply with government direction. No operations may proceed without written approval from officials at both departments, and no operations will be approved until executive directors at DOJ and DHS establish "consensus procedures" with the White House Homeland Security Council guaranteeing "complete oversight and control of Participating Companies' performance." Those procedures are to be drafted within 60 days.
The policy explicitly prohibits operations likely to result in loss of life, serious injury, or actions that rise to the level of use of force or armed attack under international law. The memo also directs the government to create procedures preventing any operation from targeting Americans or US-based systems. Guidance issued within the next two months will outline requirements for companies of all sizes, including smaller firms that may be better suited for specialized operations.
- DOJ announces it will no longer prosecute white-hat hackers conducting hacks for security research
- National cybersecurity policy released, pledging to 'unleash the private sector' against foreign adversaries
- Trump signs presidential memorandum authorizing private companies to conduct offensive cyber operations against foreign TCOs
- DOJ and DHS executive directors must draft consensus procedures for oversight and control of participating companies
Expert concerns
Several cybersecurity experts raised concerns about the program's risks. Jason Healey, a senior cyber conflict researcher at Columbia University, said that anyone conducting these operations faces substantial personal legal risk. Jake Williams, vice president of research and development at Hunter Strategy, warned that Americans participating could be classified as non-uniformed combatants while traveling overseas.
Ben Bernstein, a manager for the cybersecurity advisors team at Huntress, pointed to the practical difficulty of targeting criminals who route traffic through compromised innocent infrastructure, such as a vulnerable router at an Ohio dental office or a hospital network.
That makes it practically impossible to 'strike back' without taking out innocent bystanders.
Political context
The memo builds on a national cybersecurity policy released in March that pledged to "unleash the private sector" against foreign adversaries. It also comes as the Trump administration has reduced the size of the Cybersecurity and Infrastructure Security Agency (CISA), prompting intelligence community members to argue for enlisting more private-sector capacity, including AI companies. Utah senator Mike Lee introduced legislation last year to revive "letters of marque and reprisal," the historic constitutional practice of authorizing civilian actors to attack enemy targets. Jeffrey Gray, a CISA veteran, said the memo does something that has not been done in centuries.
The United States just revived privateering for the digital age.
The memo was signed in the aftermath of cyberattacks on water facilities in Minnesota and Michigan linked to Iran. Some US tech groups, including those run by Trump donors, have privately supported the initiative and stand to benefit from lucrative contracts. Others, including Google and Microsoft, have touted their readiness to help the government fight cyber crime, though some companies remain reluctant, fearing they lack legal protections and could face retaliation from nation states.


