White House Authorizes Private Firms to Launch Offensive Cyberattacks on Criminal Networks
A new presidential memorandum lets vetted US companies conduct government-supervised surveillance and disruption operations against foreign cybercrime networks, reversing decades of policy that...
The White House will for the first time let vetted private American companies carry out offensive cyber operations against foreign criminal networks, reversing a policy that has held across multiple administrations. President Trump signed a National Security Presidential Memorandum titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime” on Wednesday, August 12, 2026, directing federal agencies to bring private-sector firms into government-supervised hacking operations, according to the text published on WhiteHouse.gov and reporting from TechCrunch.
Table Of Content
What the Memorandum Authorizes
The memorandum states it is now U.S. policy “to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime,” according to the official text. Under the program, vetted companies can conduct two categories of operations against foreign transnational criminal organizations: “Cyber Surveillance Operations,” meaning covert access to systems to collect intelligence, and “Cyber Effects Operations,” meaning disrupting, degrading, or destroying an adversary’s data or systems, TechCrunch and SecurityWeek both reported.
The targets are the criminal groups behind ransomware, phishing, financial fraud, and sextortion schemes that the administration says have largely operated beyond the reach of law enforcement. Notably, TechCrunch reported that the memorandum “stops short of allowing companies to ‘hack back’ any cyber threats” on their own initiative: it does not hand breached companies blanket authority to retaliate. Every operation still needs specific, written government approval before it can proceed.
Oversight, Approval, and a $1 Million Bond
The program runs through a new National Coordination Center, co-led by executive directors designated by the attorney general and the secretary of homeland security, according to the memorandum text, CyberScoop, and SecurityWeek. Every operation requires written sign-off from both executive directors, and anything that could produce a “Critical Outcome” (defined in the memorandum as an action likely to cause loss of life, serious injury, or that would constitute a use of force under international law) needs a higher level of approval, SecurityWeek reported. Proposed operations also go through multi-agency deconfliction involving the State Department, Treasury, the Department of War, the Justice Department, and the intelligence community, per the memorandum text and SecurityWeek’s reporting. CyberScoop reported that operations must comply with the Computer Fraud and Abuse Act and existing law.
Participating companies must sign contracts with the Justice Department or the Department of Homeland Security and undergo what CyberScoop described as “rigorous vetting,” repeated annually. They must also maintain a bond or escrow of at least $1 million, which the government can forfeit if a company breaks the rules: a detail confirmed independently by the memorandum text, TechCrunch, and BleepingComputer. If a company’s operation accidentally touches a U.S. person or a domestic system, it must immediately stop and report the incident. The rules also presume a foreign target is independent of any government unless there’s evidence otherwise, and they bar operations from targeting anything inside the United States, SecurityWeek reported. Separately, TechCrunch reported that participating companies must notify the government if they discover an imminent cyberattack against critical U.S. infrastructure, such as power grids or water providers, while conducting an authorized operation.
Industry Reaction Is Split
Security industry veterans offered starkly different takes on the announcement. Veracode co-founder Chris Wysopal told CyberScoop the move was “a pretty big shift in U.S. cyber policy,” while noting it remains less expansive than some alternative proposals for private-sector offensive action. Josh Steinman, co-founder of Galvanick and a senior White House cyber official during Trump’s first term, voiced support for the plan, CyberScoop reported.
Others were more skeptical. Jason Kikta, Automox’s chief technology officer and a former U.S. Cyber Command official, called the program “a perpetual motion machine for billable threats,” a characterization reported independently by both CyberScoop and BleepingComputer. Jake Williams, vice president of research and development at cybersecurity company Hunter Strategy, told TechCrunch the policy is “half-baked” and warned it could expose American contractors to real legal risk overseas. “Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas,” Williams said, adding that a foreign government does not need the allegation to be true to use it as a pretext: “The administration’s policy alone creates cover for a foreign government to make such accusations.”
A Reversal Decades in the Making
Private companies in the United States have long been barred from launching cyberattacks or offensive operations without a court order, regardless of who attacked them first. Every administration to date has held the line that the private sector may defend its own networks but may not go on the offensive, TechCrunch reported. Wednesday’s memorandum builds on Executive Order 14390, “Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens,” which Trump signed on March 6, 2026, and which had already directed federal agencies to draft plans for cracking down on the scam centers and cybercrime networks targeting Americans.
The White House’s justification leans heavily on scale: Americans reported losing more than $20.8 billion to cyber-enabled crime in 2025, according to the administration’s own fact sheet on the order, a figure independently reported by BleepingComputer. The government now has 60 days to publish detailed operating procedures for the program, and participating companies will be vetted annually. A White House spokesperson did not answer TechCrunch’s questions about whether any private companies are already taking part.
The timing lands against a backdrop of active state-level incidents: TechCrunch reported that officials in over a dozen states, including Michigan, Minnesota, and Georgia, have reported intrusions into local water providers, intrusions that U.S. intelligence officials have reportedly linked privately to Iranian government-backed hackers. The new program’s rules explicitly bar companies from operating against anything inside the United States, and every operation still requires the government’s own sign-off before a single packet gets sent.








No Comment! Be the first one.