President Donald Trump has cleared the way for private American companies to fight foreign cybercriminals with the same tools once reserved for spies and soldiers. On Wednesday, Trump signed a national security presidential memorandum directing federal agencies to build a program that lets vetted firms surveil, disrupt and even dismantle the digital infrastructure of transnational criminal organizations operating overseas.
It sounds like something out of a heist movie: government-blessed hackers, working for private paychecks, going after scam networks on the other side of the world. But the memo is real, and it marks one of the most significant shifts in U.S. cyber policy in years — handing offensive capabilities that used to belong exclusively to the military, intelligence community and federal law enforcement to companies willing to sign up.
The White House frames the move as overdue. Ransomware gangs, phishing rings, sextortion schemes and financial fraud operations based abroad have drained billions of dollars from Americans, and officials argue the government alone can't keep pace. So now, corporate cyber talent gets deputized — under close supervision, at least on paper.
"It is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime.
— National Security Presidential Memorandum, Aug. 12, 2026
The memorandum directs the Homeland Security Task Force's National Coordination Center to stand up the program within 60 days. Two executive directors — one from the Department of Justice, one from the Department of Homeland Security — will run it jointly, deciding which companies get in and which operations get approved.
Once cleared, participating firms fall into two categories of work. The first is cyber surveillance: quietly infiltrating a criminal group's systems to gather intelligence without their knowledge. The second, more aggressive track is what the memo calls cyber effects operations — actively disrupting, degrading or even destroying the servers and networks that keep a criminal enterprise running.
Officials insist the target list is limited to foreign criminal syndicates, not foreign governments — a distinction meant to keep the program from being read as an act of state-on-state cyber warfare.
The Price of Admission
Getting into the program won't be simple or cheap. Companies must clear a vetting process built around technical skill, past performance, staff background checks, facility security and general reliability — standards that a coordinating council is expected to finalize within two months of the memo's signing.
There's also a financial catch: participating firms have to post a bond or hold funds in escrow of at least $1 million, a cushion meant to cover liability if something goes wrong. And plenty could go wrong. Any operation touching a U.S. person triggers extra legal review, including sign-off from the Justice Department, and approvals are barred if an operation risks loss of life, serious injury, or actions that could be read as an armed attack under international law.
Not Exactly a New Idea — and Not Without Critics
Letting private companies hack back at criminals isn't a new debate in Washington. Versions of the idea have circulated for years, always running into the same objection: what happens when a private operation goes sideways? Security researchers are already raising that question about this program.
What worries the experts
Chris Wysopal, co-founder of the cybersecurity firm Veracode, told reporters the more organized federal structure could help, but he also flagged the risk of collateral damage — for instance, an operation targeting a scam center's shared data center that ends up knocking out a hospital's systems in the process. He also noted that employees of participating companies could become targets for detention or questioning if they travel to the countries where their operations took place.
A former U.S. Cyber Command official, Jason Kikta, separately pointed out that the memo doesn't spell out a clear process for protecting the civil liberties of American citizens who might get swept up in an operation aimed at foreign targets.
✓ Risk of unintended damage to unrelated systems, like hospitals or utilities, sharing infrastructure with criminal targets
✓ Legal exposure for company employees traveling to countries where operations occurred
✓ Unclear safeguards for the civil liberties of U.S. citizens incidentally affected
None of that has stopped the administration from moving forward. Officials describe the initiative as a natural extension of a fraud-focused executive order issued earlier this year, part of a broader effort to treat cyber-enabled financial crime as a national priority rather than a background nuisance.
What Happens Next
For now, the program exists on paper. The real test comes over the next 60 days, as the coordination center works out vetting standards and the two overseeing departments decide which companies — and which targets — actually make the cut.
Supporters see an untapped resource finally being put to use. U.S. companies, the administration argues, already have the technical edge; this just gives them legal cover to use it against criminal networks that federal agencies don't have the bandwidth to chase down one by one.
Skeptics see a harder-to-control experiment. Offensive hacking, even when authorized and supervised, carries a track record of unpredictable consequences — and outsourcing it to companies motivated in part by contracts adds a layer of uncertainty that government-run operations don't have.
There's a gloves-off mentality now.— Jon Bateman, Carnegie Endowment for International Peace
The White House has not detailed which companies might apply or how quickly operations could begin once the program is up and running. What's clear is that a line the U.S. government has held for decades — that offensive hacking stays in the hands of the state — has just been redrawn, and Washington is betting the private sector can be trusted to stay inside it.







