Private cybersecurity firms get a license to strike foreign criminal networks under new US program

President Donald Trump has signed a national security presidential memorandum that lets private cybersecurity firms conduct offensive operations against foreign criminal networks, moving a function long reserved for the federal government into commercial hands. The memorandum, first reported by Bloomberg, directs the National Coordination Center to establish a program in which vetted US companies can carry out cyber surveillance and cyber effects operations against foreign transnational criminal organizations that target American citizens, businesses, and critical infrastructure.

Participating firms operate under the control and oversight of the federal government. Oversight is split between the Department of Justice and the Department of Homeland Security: two program executive directors, one named by the attorney general and one by the homeland security secretary, must coordinate before any operation is approved. The directors cannot approve operations expected to cause loss of life, serious injury, or conduct that amounts to a use of force or armed attack under international law.

To qualify, companies must demonstrate technical proficiency, a proven record of running cyber operations, facility security, and vetted personnel. They must also post a bond or escrow of at least $1 million, forfeited if they fall out of compliance with their government contract. Targets are limited to groups that are not an institutional part of a foreign government and not wholly operated under a foreign government’s direction, with a presumption that any criminal group is unaffiliated unless clear intelligence establishes otherwise. Participating companies must disclose any outside contractual relationships tied to the program. Operating procedures are to be finalized within 60 days in consultation with the Homeland Security Council, and each operation requires written approval from the program’s executive directors, with annual reviews of every participant.

The memo treats the private sector as an underused asset. It declares US policy to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime, and it allows participating companies to strike commercial agreements with private entities and with federal, state, local, tribal, and territorial agencies to gather threat information and propose responsive operations to the coordination center.

Support evidence-based journalism. At 1ban.news, every article is built on careful research, multiple sources, and a commitment to accuracy over sensationalism. If you value independent reporting, please consider supporting our work.

Become a supporter

The move culminates a policy thread that has run through the administration for months. Bloomberg reported in December that the Office of the National Cyber Director was preparing to lean on private firms for offensive work. A March executive order aimed at cybercrime, fraud, and predatory schemes against American citizens laid groundwork, and the administration’s National Cybersecurity Strategy, released in March, floated the idea of enlisting companies to disrupt adversary networks. A June memorandum reestablished the Committee on National Security Systems as part of the same push.

Lawyers and researchers have flagged serious concerns. Attorneys at Jenner & Block, writing in Lawfare, warned that no federal framework currently authorizes private companies to conduct offensive cyber operations, and that the Computer Fraud and Abuse Act, along with a patchwork of state and foreign hacking laws, broadly criminalizes exactly the conduct the strategy envisions. Until Congress acts, they argued, companies in technology, defense, and cybersecurity face real legal exposure.

The attribution problem compounds the risk. Jason Healey, a senior cyber conflict researcher at Columbia University, told Cybersecurity Dive that anyone conducting these operations does so at substantial personal legal risk, because it can be hard to determine which criminal groups are backed by foreign governments. Jake Williams, vice president of research and development at Hunter Strategy, voiced similar concerns. If a contractor misreads a target’s government ties, the operation could ignite a geopolitical incident or expose the company to prosecution under US or foreign law, even with federal authorization in hand.

The program raises a deeper question about accountability. Offensive cyber operations have traditionally been the province of agencies like the National Security Agency and US Cyber Command, which operate under classified authorities and congressional oversight. Contracting that work out, even under DOJ and DHS supervision, distributes the authority to act in cyberspace to companies whose employees face personal liability in ways federal operators largely do not. The exclusion of operations likely to cause serious harm narrows the risk, but the line between disruption and damage in cyberspace is hard to draw in advance.

For the cybersecurity industry, the program is both an opportunity and a trap. It opens a new revenue line for firms with offensive capabilities, but it also puts their staff in the crosshairs of foreign governments that will treat them as legitimate targets. Whether enough companies accept that exposure, and whether the 60-day rulemaking window produces procedures that satisfy both the industry and the lawyers, will determine whether the program becomes a durable instrument of US policy or a short-lived experiment.

Sources: Trump Enlists Private Sector to Boost Cyber-Offensive Arsenal (Bloomberg, Aug 13, 2026); The Trump admin will start letting private firms launch international cyberattacks (The Verge, Aug 13, 2026); Presidential Memo Seeks to Expand Private Sector’s Role in Fighting Transnational Cybercrime (ExecutiveGov, Aug 13, 2026); Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations (Lawfare, Mar 2026)

Scroll to Top