Trump signs memorandum allowing vetted U.S. firms to conduct cyber operations against foreign cybercriminals

·

President Donald Trump has signed a National Security Presidential Memorandum creating a federal program that would allow vetted U.S. private companies, under Justice Department and Department of Homeland Security oversight, to carry out surveillance and disruptive cyber operations against foreign cybercriminal groups targeting Americans.

The Aug. 12 memorandum, published by the White House on Wednesday and signed “DONALD J. TRUMP,” marks a substantive shift in U.S. cyber policy because it formalizes a private-sector operational role in offensive cyber activity under government supervision. In a fact sheet, the White House said American consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025. The memorandum says, “Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime.”

The directive orders the National Coordination Center, or NCC, to “create, manage, and maintain” a program authorizing participating companies to conduct cyber operations against foreign Cyber-Enabled Transnational Criminal Organizations, or CE-TCOs. The memo places the program inside the NCC structure created by Executive Order 14159 on Jan. 20, 2025.

The memorandum defines CE-TCOs as foreign groups conducting cyber-enabled crime against the U.S. government, U.S. persons or U.S. interests that are not institutional parts of a foreign government or wholly operated under a foreign government’s direction. Absent intelligence to the contrary, the memo says, such groups will be presumed not to be government-run.

Under the program, companies could be authorized to conduct two kinds of operations. The first, “Cyber Surveillance Operations,” is defined as covert information collection or unauthorized access intended to remain undetected. The second, “Cyber Effects Operations,” covers actions that manipulate, disrupt, deny, degrade or destroy information systems or infrastructure.

Oversight is split between two Program Executive Directors, one designated by the attorney general and one by the homeland security secretary. Those officials can approve operations, but the memorandum bars them from approving operations expected to produce “Critical Outcomes.” The memo defines those outcomes as operations likely to cause death or serious injury, or likely to “rise to the level of use of force or armed attack under international law.”

The White House framed the arrangement as a way to expand law enforcement’s reach while keeping companies under federal control. “By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” the memorandum says. A White House fact sheet described the action this way: “Today, President Donald J. Trump signed a National Security Presidential Memorandum (NSPM) empowering U.S. Federal law enforcement to use cyber tools to disrupt transnational criminal organizations (TCOs) that operate in foreign jurisdictions to attack Americans.”

The memorandum says the program must operate “in accordance with the Constitution and all other applicable laws and international obligations of the United States, including section 1030 of title 18,” a reference to the Computer Fraud and Abuse Act, the main U.S. anti-hacking law. Participating companies must sign contracts with DOJ or DHS and may be required to post a bond or escrow of at least $1 million, which could be forfeited for contractual noncompliance.

The companies also must disclose commercial agreements entered into under the program and immediately notify the NCC and DOJ if they discover an imminent cyberattack, unintentionally target a U.S. person or system, or exceed approved operating parameters.

Within 60 days, DOJ and DHS program leaders, coordinating with the Homeland Security Council, must establish operating procedures covering eligibility standards, oversight, reporting, deconfliction, adjudication and minimization. Within 180 days of the memorandum, and annually after that, the program leaders must submit a status report to senior White House officials and the national cyber director. The memorandum repeatedly refers to a classified annex governing operational workflow and adjudicatory frameworks, but that annex was not published.

The move builds on Executive Order 14390, issued March 6, 2026, which directed agencies to review authorities and develop tools to combat transnational cybercrime, fraud and predatory schemes targeting Americans. It also lands in a long-running debate over “hack back,” shorthand for private-sector offensive cyber action that U.S. law has generally not allowed companies to conduct on their own.

What is new here is not the idea of government cyber disruption itself; U.S. agencies already conduct authorized technical operations against criminal infrastructure. The change is that the administration is creating a formal mechanism for private companies to take part under federal direction. The memorandum’s explicit reference to the Computer Fraud and Abuse Act also underscores a key legal question for implementation: how participating firms will be protected from liability while operating under government authority.

Tags: #cybersecurity, #cybercrime, #whitehouse, #nationalsecurity