
The Trump administration is preparing to let private security firms take part in government-authorized offensive cyber operations against overseas criminal groups, a major shift that could give vetted companies a formal role in disrupting ransomware gangs, phishing crews, financial fraud networks and similar threats aimed at the United States.
White House memo opens the door to private offensive cyber work
In a National Security Presidential Memorandum issued Thursday, President Donald Trump directed the National Coordination Center, which operates under the Homeland Security Task Force, to build a program for conducting specific cyber operations against foreign transnational criminal organizations, or TCOs. The Departments of Justice and Homeland Security will oversee the effort, but the memo makes clear that private-sector participation is intended to be the core of the program.
According to the accompanying fact sheet, the types of activity that could be targeted include ransomware, sextortion schemes, phishing campaigns, financial fraud and impersonation scams. The memo says participating firms could conduct “Cyber Surveillance Operations and Cyber Effects Operations” against “cyber-enabled” TCOs.
The administration defines those groups as foreign organizations that commit cyber-enabled crime against the United States government, a U.S. person or U.S. interests, and that are not part of a foreign government or acting wholly under one. In practice, that wording appears aimed at overseas criminal networks that operate outside the state apparatus of another country.
A first for federal authorization
The policy stands out because it would be the first time the federal government has authorized private companies to conduct offensive cyber operations against overseas hackers. Until now, private security firms have generally been constrained to defensive work, incident response, attribution research and cooperation with law enforcement rather than direct retaliation.
The memo appears broad enough to allow participating firms to use spyware or launch attacks intended to damage criminal systems or data. It also does not rule out some of the more aggressive tactics associated with offensive cyber operations, including attacks that could lock targets out of their own networks with encryption or disrupt systems through distributed denial-of-service techniques. Up to now, such actions have not been permitted for the private sector without court-authorized approval.
That possibility is likely to make the details of the program just as important as the announcement itself. The memo sketches the framework, but the administration has not yet released the rules that will determine what companies can actually do, how far they can go, and how closely each operation will be supervised.
What private firms would be allowed to target under the program
The fact sheet attached to the memorandum identifies several categories of crime that could fall under the new authority. Those include:
- Ransomware operations
- Sextortion schemes
- Phishing campaigns
- Financial fraud
- Impersonation scams
These are all familiar threats, but the policy would move the government’s response into new territory by allowing approved private companies to participate in offensive actions rather than simply advising or defending. In effect, the administration is trying to formalize a capability that has long existed in a gray area: the desire among some security professionals to actively interfere with criminal infrastructure overseas.
Independent security researcher Kevin Beamont reacted to the memo by saying, “There’s definitely merit in the idea of hacking ransomware groups and it does already in fact happen (don’t ask me how I know),” while adding that “the correct incentives have gotta be there.”
Beamont also criticized the current incentive structure in the broader ransomware-fighting ecosystem. “The biggest problem I’ve had with fighting ransomware over the past 5 years is private cyber companies basically lobbying for nothing to change,” he said. “A lot of companies have made a lot of money, so putting them in charge of stopping it seems optimistic.”
Limits, oversight and eligibility requirements
The memorandum does not give companies a blank check. It says private firms must first be approved after vetting by the Justice and Homeland Security departments. The two agencies will also provide oversight of the program as it is developed and implemented.
There are also explicit restrictions on the outcomes these operations can produce. Cyber Effects Operations and Cyber Surveillance Operations may not result in “Critical Outcomes,” which the memo defines as outcomes causing loss of life, serious injury or anything that rises to the level of use of force or armed attack under international law.
That language matters because it suggests the administration wants to distinguish cyber operations against criminals from actions that could create broader conflict or violate international norms. The line between disruptive digital operations and actions that could be viewed as force under international law is often disputed, so that boundary will likely be one of the most closely watched parts of the rollout.
The memo also sets out minimum standards for participating companies. Those firms must demonstrate appropriate technical proficiency, proven performance in cyber operations, facility security, personnel vetting, competence and reliability, along with other factors that the program’s executive directors, in coordination with the Homeland Security Council, decide are necessary.
In addition, each participating company must deposit $1 million into an escrow account. That money would be forfeited if the company violates its contractual agreement under the program. The escrow requirement appears designed to create a financial penalty for noncompliance and to reinforce the seriousness of the authorization.
Big questions remain about how the program will work
Even with the headline-grabbing authority in place, the most important operational questions are still unanswered. The memo directs the Justice and Homeland Security departments to provide the specifics within 60 days, which means the practical rules, scope limitations and approval process are still being written.
Those forthcoming details will likely determine whether the program becomes a tightly controlled tool for disrupting overseas cybercriminals or a broader policy shift that gives private companies unusually wide latitude to act in the government’s name. The difference will matter not just for participating firms, but for victims, investigators and any foreign governments whose territory may be involved when these operations are launched.
There is also an obvious policy tension at the center of the plan. On one hand, ransomware and related crimes have inflicted enormous damage on U.S. businesses, institutions and individuals, and many security professionals have long argued that more aggressive disruption is needed. On the other hand, giving private companies access to offensive capabilities raises concerns about accountability, escalation and the possibility of overreach.
For now, the administration has signaled that it wants to harness private-sector expertise in a way that goes beyond passive defense. Whether the final rules produce effective disruption or create a new set of risks will depend on how carefully the program is structured and enforced over the next two months.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: August 14, 2026 at 1:51 am
0 views

