President Donald Trump signed a national security memorandum this week that clears vetted U.S. private companies to conduct offensive cyber operations against foreign criminal networks. The five-section document, released Wednesday night, marks a sharp break from long-standing policy that barred businesses from launching their own digital attacks.
Transnational criminal organizations pose a growing threat. They drained American consumers of $20.8 billion in cyber-enabled crime last year alone. The White House fact sheet accompanying the memo drives the point home. Seventy-three percent of U.S. adults have fallen victim to online scams or attacks. Ninety-eight percent view such scams as a national threat. And one in seven young people targeted by sextortion reported self-harm.
The memorandum directs the creation of a National Coordination Center to run the program. Two Program Executive Directors—one chosen by the Attorney General, the other by the Secretary of Homeland Security—will oversee day-to-day operations. Within 60 days they must draft detailed procedures. No strikes can launch until those rules exist. An initial report lands in 180 days.
Companies that qualify gain permission for two types of missions. Cyber Surveillance Operations let them slip into systems undetected to gather intelligence. Cyber Effects Operations go further. They allow manipulation, disruption, denial, degradation or outright destruction of criminal networks and infrastructure. Spyware fits inside the surveillance bucket, according to reporting by TechCrunch.
Targets remain tightly defined. Only foreign cyber-enabled transnational criminal organizations qualify. The memo explicitly bars operations against groups that form an institutional part of a foreign government or operate wholly under its direction. That carve-out spares North Korean state hackers and raises questions about Russian-linked gangs that enjoy tacit tolerance in Eastern Europe. Politico highlighted those gray zones in its coverage published yesterday.
But this isn’t the freewheeling hack-back some outlets first suggested. Victims cannot simply lash out at whoever hit them. Every operation requires prior written approval from the executive directors. Companies must disclose all their contracts, post a $1 million bond or escrow, submit to annual reviews and meet strict standards on technical skill, security clearances and personnel vetting. Smaller agile firms sit alongside industry giants in the eligibility pool.
Strict red lines govern what counts as off-limits. No operation may produce “critical outcomes”—anything likely to cause loss of life, serious injury, or actions that rise to the level of use of force under international law. Activity touching U.S. persons demands extra judicial or other authorizations first. Mistakes trigger immediate cease-and-desist, data minimization and notification requirements. Companies must also flag imminent threats to domestic critical infrastructure.
The memo creates no new enforceable legal rights. It changes nothing about the Computer Fraud and Abuse Act, which still criminalizes unauthorized access. Lawyers have flagged the uncertainty. Writing for Lawfare in March, partners from Jenner & Block noted that no court has tested whether the CFAA’s government-activity exception shields private contractors performing these missions. A Skadden analysis from the same period reached similar conclusions. Further legislation or regulation likely lies ahead.
Industry voices greeted the move with enthusiasm. “For years we’ve called the American technology industry a strategic asset but left it on the cyber sidelines,” said Joe Lin, CEO of Twenty, a startup that builds offensive tools for government clients. His quote appeared in both The Next Web and Politico coverage.
Mike Centrella, head of public policy at SecurityScorecard, described the memo as an important shift. Public-private cooperation, he told Nextgov, moves beyond simple threat sharing toward joint disruption of criminal networks using government authorities and private capabilities.
Critics struck a more cautious tone. Jake Williams, vice president of research and development at Hunter Strategy, warned of serious personal risk. “Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas,” he told TechCrunch. He added that allegations of involvement need not be true to create problems. Williams called the policy half-baked and expressed doubt it could resist abuse. He also pointed to a classified addendum that presumably details target selection.
The timing feels deliberate. The memorandum arrives against a backdrop of proposed budget cuts at the Cybersecurity and Infrastructure Security Agency. A further $707 million reduction sits in the 2027 request. At the same time, ransomware groups, phishing rings and sextortion operations continue to evolve. Iranian hackers have hit water utilities across more than a dozen states. AI-driven campaigns can now compromise government networks in days rather than months.
The Legal and Operational Tightrope
Private firms now stand on uncertain ground. They must propose operations, await federal sign-off, execute under supervision and accept liability if something goes wrong. Annual reviews could yank their participation without much notice. The $1 million financial guarantee adds real skin in the game. Yet the potential rewards loom large. Successful contractors could gain privileged access to intelligence, shape future targeting and build capabilities the government itself lacks.
Deconfliction questions remain unanswered in public. How will these private strikes avoid stepping on ongoing intelligence or military operations? What happens when a criminal group shares infrastructure with a state actor? The memo’s exclusions try to draw lines. Reality often blurs them. Chinese and Iranian hackers have moonlighted as criminals before. Eastern European ransomware crews frequently enjoy safe harbor.
Analysts compare the arrangement to historical letters of marque that let private ships attack enemy vessels on behalf of the crown. The analogy fits the spirit if not the technology. Both deputize commercial actors for state ends while trying to keep them on a short leash. Whether modern cyber equivalents can stay leashed is the open bet.
Recent coverage underscores the stakes. Help Net Security reported yesterday that the memo builds directly on an earlier executive order directing aggressive action against cybercrime. CyberScoop detailed how the National Coordination Center will vet companies and approve each package of operations. InsideCyberSecurity noted the 60-day clock for procedures and the emphasis on both large and small participants.
Legal experts continue to caution that a memorandum alone cannot rewrite criminal statutes. The path forward may require Congress to pass enabling legislation or agencies to issue new regulations that explicitly shield participating firms. Until then, companies will weigh the business opportunity against potential CFAA exposure, foreign prosecution and personal safety risks for employees who travel.
Supporters argue the private sector brings speed, scale and creativity that government alone cannot match. They point to the $20.8 billion annual loss figure and the human toll on victims. Detractors counter that outsourcing digital combat invites mission creep, escalation and unintended international incidents. The classified annex likely holds answers to some of those fears. The public will see only the results.
Sixty days from now the operating procedures drop. One hundred eighty days after that comes the first report. Between those milestones the real test begins. Which firms sign up? How aggressively do they propose targets? And can the government maintain control without stifling the very innovation it seeks to harness?
The memo itself ends on a familiar bureaucratic note. It creates no right or benefit enforceable at law or in equity. Translation: don’t sue us if this goes sideways. That disclaimer may prove the most important sentence in the entire document.
White House Memo Hands Private Firms License to Strike Foreign Hackers first appeared on Web and IT News.
