The US Government Now Lets Private Companies Hack Back at Foreign Cybercriminals

On August 12, 2026, President Donald Trump signed a memo that lets private companies carry out cyberattacks against foreign criminal groups, but only when the US government tells them to. The memo, called "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," was posted on the White House website with a fact sheet describing the plan as a way to give federal law enforcement more tools to fight cybercrime (White House).
The White House says the memo directs the government to "leverage the capability and innovation of the private sector" to carry out "limited cyber operations at the direction of the US government" (The Guardian). This is not a free pass for companies to hack anyone they want. They can only act when the government directs them to.
The targets are foreign-based criminal groups that carry out ransomware attacks and financial fraud. The memo calls them "transnational criminal organizations," or TCOs. These are criminal networks that operate across multiple countries, which makes them hard for any single government to stop (The Guardian).
Here is how it would work. Private companies can team up with other companies and with government agencies at the federal, state, local, and tribal levels to gather information about these criminal groups and suggest cyber operations. The Department of Homeland Security (DHS) is directed to set up a program to carry out specific cyber operations that disrupt foreign criminal groups. Two agencies, DHS and the Department of Justice (DOJ), oversee the whole program together (The Guardian).
Companies that pass a vetting process can do two types of activity. The first is "cyber surveillance operations," which means watching or gathering information from the criminals' computer systems. The second is "cyber effects operations," which means actually interfering with those systems. The memo defines "cyber effects" to include "manipulation, disruption, denial, degradation or destruction" of information systems, networks, or even physical facilities those systems control. Think of it as the difference between listening in on a criminal's phone calls and cutting the power to their hideout. Companies that participate must keep at least $1 million in a bond or escrow account, which is money set aside in case something goes wrong (The Guardian).
This memo did not come out of nowhere. In March 2026, Trump signed an action plan to fight cybercrime that identified the criminal groups behind scam centers and online fraud (White House). Also in March 2026, the administration released a cybersecurity policy saying it wanted to "unleash the private sector" against foreign adversaries. Before that, the December 2025 National Security Strategy mentioned the private sector's role in watching for threats to US networks, including critical infrastructure, and acknowledged offensive cyber operations (White House.
The broader context here is that these three documents, spread across about eight months, each step up the role of private companies in national cyber operations. The December 2025 strategy set the big-picture goal. The March 2026 policies said the government wanted to get private companies involved. The August 2026 memo now gives the actual rules, oversight structure, and financial requirements. Whether this is truly new or just makes official something that was already happening quietly is worth watching. The joint DHS-DOJ oversight and the $1 million bond suggest an attempt to build in accountability. But the memo's definition of "cyber effects" is broad enough to include destroying computer systems and the physical infrastructure they control.
Several practical questions remain. The available documents do not explain how companies will be vetted or how DHS and DOJ will decide on targets and approve operations. The $1 million bond requirement sets a relatively low bar, which may be meant to encourage companies to join rather than to seriously punish misconduct. Companies must operate under government "direction, control and authority," which sounds like the government is in charge. But the line between a government-directed operation and a company acting on its own initiative has not been tested yet.
The memo also raises questions about international law. Cyber operations against computer systems in other countries, even when targeting criminals rather than governments, can violate those countries' sovereignty, meaning their right to control what happens within their borders. The documents do not say how the US plans to handle this or whether companies will get legal protection for operations carried out abroad.
The memo is framed narrowly around criminal groups. But the December 2025 National Security Strategy talked about offensive cyber operations and private-sector surveillance of threats in broader terms, including protecting critical infrastructure. Whether this program stays focused on criminals or becomes a model for letting private companies go after government-linked hackers is an open question. The answer will depend on how the program is run and whether future presidential actions expand its scope.


