
For the first time in US history, the federal government is opening the door for private security companies to conduct offensive cyber operations — including hacking and surveillance — against foreign criminal organizations targeting American citizens, businesses, and government entities. A National Security Presidential Memorandum signed by President Donald Trump on August 12, 2026, formally authorizes this unprecedented public-private arrangement, raising fundamental questions about accountability, oversight, and the blurring of lines between corporate interests and state-sanctioned cyber warfare.
What the Memorandum Actually Says
The memo, titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” directs the National Coordination Center (NCC) — operating under the Homeland Security Task Force — to build and manage a program authorizing vetted private companies to conduct what the document calls “Cyber Surveillance Operations” and “Cyber Effects Operations” against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs).
The memorandum defines eligible targets as “any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government’s direction.” Eligible crime types listed in an accompanying White House fact sheet include ransomware, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams.
The program will be jointly overseen by co-Executive Directors — one designated by the Attorney General from the Department of Justice, and one from the Department of Homeland Security designated by the Secretary of Homeland Security. All cyber operations must be approved through coordination between these two directors before any action is taken.
A Historic Shift in Offensive Cyber Policy
Until now, the US government has prohibited private sector entities from engaging in offensive cyber operations without specific court authorization. This memorandum represents the first time the federal government will formally authorize private companies to conduct such operations, effectively deputizing commercial security firms as instruments of national cyber power.
The memo does not appear to rule out aggressive tactics. According to reporting by Ars Technica, the program appears to permit participating companies to deploy spyware or launch attacks designed to destroy TCO data or systems. Notably, the memo does not explicitly prohibit techniques such as using encryption to lock targets out of their own networks or conducting distributed denial-of-service attacks against criminal infrastructure.
The White House framed the rationale directly in the memo’s opening section: “The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States. Yet, American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace.”
The Guardrails — And Their Gaps
The memorandum does establish specific constraints on what participating companies can do. Operations may not result in what the document terms “Critical Outcomes” — defined as actions resulting in loss of life, serious injury, or actions that “rise to the level of use of force or armed attack under international law.” The Program Executive Directors are explicitly prohibited from approving operations meeting that threshold.
Companies wishing to participate must pass a rigorous vetting process conducted by the Departments of Justice and Homeland Security. Minimum standards include demonstrated technical proficiency, proven performance in cyber operations, facility security, personnel vetting, and reliability assessments. Each participating company must also deposit $1 million into an escrow account, which will be forfeited if the company enters non-compliance with its contractual agreement.
Participating companies must enter formal contractual agreements with either the Department of Justice or the Department of Homeland Security. The memo also permits these companies to enter commercial agreements with private sector entities to receive threat intelligence collected during normal business operations — intelligence that can then be used to propose responsive cyber operations to the NCC.
However, as Ars Technica noted, many of the most consequential specifics remain undefined. The Departments of Justice and Homeland Security have been given 60 days from the memo’s issuance to deliver detailed implementation guidance. Those yet-to-be-written details will determine the practical scope and limits of the program.
Industry Observers Flag Structural Concerns
Not everyone in the cybersecurity community is greeting this development with uncritical enthusiasm. Independent security researcher Kevin Beaumont, commenting publicly on the memo, acknowledged that there is “definitely merit in the idea of hacking ransomware groups” and noted that such activities already occur in practice. But he raised pointed concerns about who stands to benefit from the new arrangement.
“The biggest problem I’ve had with fighting ransomware over the past 5 years is private cyber companies basically lobbying for nothing to change,” Beaumont wrote. “A lot of companies have made a lot of money, so putting them in charge of stopping it seems optimistic.”
His observation cuts to the structural tension at the heart of this program: the firms being recruited to disrupt cybercrime ecosystems are often the same firms that have built profitable businesses responding to, remediating, and insuring against those very attacks. The financial incentive architecture matters enormously when calibrating how aggressively any private actor will pursue the elimination — rather than the perpetuation — of the threats they are paid to manage.
The Broader Policy Context
This memorandum does not exist in isolation. It builds explicitly on Executive Order 14390, signed on March 6, 2026, which directed federal agencies to take actions combating cyber-enabled crime harming American citizens. The new memo frames itself as an expansion of that earlier order, specifically by incorporating private sector capabilities into what had previously been a purely government-led effort.
The NCC itself was established under Executive Order 14159 from January 20, 2025. Its elevation to program manager for this new offensive cyber initiative marks a significant expansion of its role within the national security apparatus.
The memorandum was addressed to a wide range of senior officials, including the Vice President, the Secretaries of State, Treasury, Commerce, Energy, and Homeland Security, the Attorney General, the Directors of National Intelligence and the CIA, the NSA Director, the Chairman of the Joint Chiefs of Staff, and the National Cyber Director — signaling the cross-agency reach the administration intends for this initiative.
What Remains Unknown
The 60-day implementation window leaves critical questions unanswered. How will the government ensure that private firms, operating under contract, do not exceed their authorized scope — intentionally or otherwise? What legal frameworks govern liability if a sanctioned operation causes unintended collateral damage to third-party systems? How will the government verify that intelligence provided by participating companies is accurate enough to justify offensive action against a named target? And how will the program handle the inherent conflict of interest when commercial entities profit both from threat intelligence sales and from the ongoing existence of the threats they are contracted to disrupt?
These are not abstract concerns. Offensive cyber operations, by their nature, carry escalation risks. Misidentified targets, infrastructure shared between criminal and civilian users, and the potential for foreign governments to view private US corporate hacking as a state action all represent scenarios that the current memo’s language does not fully address.
A New Frontier — With Uncertain Boundaries
The Trump administration’s decision to formalize and authorize private-sector offensive cyber operations marks a genuine inflection point in how the United States approaches cybersecurity threats. Whether this program becomes a precision instrument against criminal networks or an accountability gap waiting to be exploited will depend almost entirely on the implementation details that have yet to be written.
What is clear is that the boundary between private commercial interest and government-sanctioned offensive action has now been formally, deliberately, and historically crossed. The 60-day clock is running.
This article draws on reporting from Ars Technica, the White House National Security Presidential Memorandum, and SiliconAngle.



