World

The US Is Letting Private Companies Hack Back at Cybercriminals — Under Federal Supervision

Elena MarquezPublished 16h ago6 min readBased on 6 sources
Reading level
The US Is Letting Private Companies Hack Back at Cybercriminals — Under Federal Supervision
Photo by Shealeah Craighead / Public domain

On August 12, 2026, President Donald Trump signed a national security memorandum authorizing private companies to carry out offensive cyber operations against foreign-based criminal groups, under US government direction. The memorandum, titled "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," appeared on the White House presidential-actions page alongside a fact sheet describing the initiative as an expansion of federal law enforcement's authority to use cyber tools to disrupt cybercrime (White House).

The memorandum directs the administration to "leverage the capability and innovation of the private sector to help conduct these cyber operations under the direction, control and authority of the US government," according to the White House (The Guardian). The authority is scoped to "limited cyber operations at the direction of the US government," not open-ended hacking licenses for private firms.

The fact sheet identifies ransomware attacks, financial frauds, and other crimes run by foreign-based criminal organizations as the targets. The memorandum refers to these groups as "transnational criminal organizations," or TCOs — criminal networks that operate across national borders, often beyond the reach of any single country's law enforcement (The Guardian).

Operationally, the memo creates a framework encouraging private sector companies to enter into agreements with other private entities and with federal, state, local, tribal, and territorial agencies to gather threat information on TCOs and propose cyber operations. It directs the Department of Homeland Security (DHS), through the homeland security taskforce's national coordination center, to establish a program "to conduct specific cyber operations that disrupt foreign TCOs," with oversight jointly provided by DHS and the Department of Justice (DOJ) (The Guardian).

Under federal supervision, vetted participating companies will carry out two categories of activity: "cyber surveillance operations" and "cyber effects operations" against specified targets. "Cyber effects" is defined broadly in the memorandum to include "potential manipulation, disruption, denial, degradation or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon." In plain terms, that means everything from spying on a criminal network's communications to disabling or destroying the computer systems and physical facilities those systems control. Participating companies must maintain a bond or escrow of at least $1 million (The Guardian).

This memorandum builds on a March 2026 presidential action titled "Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens," which laid out an action plan identifying the TCOs responsible for scam centers and cybercrime (White House). The Trump administration also released a national cybersecurity policy in March 2026 stating the government would create incentives to "unleash the private sector" against foreign adversaries. The December 2025 National Security Strategy similarly references the American private sector's role in maintaining surveillance of persistent threats to US networks, including critical infrastructure, and acknowledges offensive cyber operations (White House.

The broader context here is a deliberate sequencing across three documents over roughly eight months, each escalating the role of private actors in national cyber operations. The December 2025 National Security Strategy established the strategic rationale. The March 2026 cyber policy and cybercrime action plan translated that rationale into an announced intent to incentivize private-sector engagement. The August 2026 memorandum now supplies an operational framework with defined authorities, oversight structures, and financial requirements. Whether this represents a genuinely new delegation of authority or a formalization of practices already occurring under less explicit arrangements is a question worth tracking. The DOJ-DHS dual oversight structure and the $1 million bond requirement suggest an attempt to impose accountability guardrails, though the memorandum's text defines the scope of "cyber effects" broadly enough to encompass destructive action against information systems and the physical infrastructure they control.

Several practical questions follow. The vetting criteria for participating companies are not detailed in the available materials, nor are the specific mechanisms by which DHS and DOJ will coordinate target selection and operational approval. The bond or escrow requirement sets a relatively low financial barrier for entry, which may be designed to encourage participation rather than to serve as a meaningful deterrent against operational misconduct. The requirement that companies operate under federal "direction, control and authority" places this framework within a command-relationship model rather than a standalone licensing regime, but the practical boundaries between government-directed operations and private-sector initiative remain to be tested.

The memorandum also raises questions about how this domestic framework interacts with international law and the sovereignty of states where TCOs operate. Offensive cyber operations conducted against infrastructure physically located in third countries, even when targeting criminal rather than state actors, can implicate norms around territorial sovereignty and the prohibition on intervention. The available documents do not address how the US government plans to navigate these constraints or whether participating companies will receive any form of legal protection for operations conducted abroad.

The fact sheet and memorandum frame the initiative narrowly around transnational criminal organizations. But the December 2025 National Security Strategy references offensive cyber operations and private-sector surveillance of "persistent threats" in broader terms, including critical infrastructure protection. Whether the TCO-focused framework established this week becomes a precedent or template for expanding private-sector offensive operations against state-aligned actors is an open question that will depend on how the program is implemented and whether future presidential actions broaden its scope.