On August 12, 2026, President Donald Trump signed a National Security Presidential Memorandum authorizing federal law enforcement and approved private sector companies to use cyber tools to disrupt foreign-based transnational criminal organizations targeting Americans [1, 2, 3, 4]. The program is led by the Department of Homeland Security's National Coordination Center with oversight from DHS and the Department of Justice, conducting offensive cyber operations such as disruption, denial, degradation, and destruction of criminal information systems and infrastructure [1, 2, 5, 6, 4].
Private firms participating must operate under U.S. government control and direction. They will conduct cyber surveillance and effects operations under strict contractual agreements and vetting. Companies must maintain a bond or escrow of at least $1 million that can be forfeited for non-compliance [1, 2, 5, 7, 8, 4, 9]. Offensive actions that could cause death, serious injury, or constitute use of force under international law are explicitly excluded [10, 7, 6, 11, 9]. The policy also excludes operational targeting of organizations that are components of foreign governments unless there is clear evidence of criminal ties [10, 8, 9].
The framework encourages collaboration between private companies and federal, state, local, tribal, and territorial agencies to collect threat intelligence and propose operations against transnational criminal organizations (TCOs) [1, 2, 3, 4]. The memo cites ransomware, financial fraud, sextortion, phishing, and impersonation scams as key criminal activities this program aims to combat, with ransomware and online fraud costing Americans an estimated $20 billion in 2025 [1, 2, 7, 6].
This policy marks a significant shift from previous U.S. cybersecurity strategies that restricted offensive cyber actions largely to military and intelligence agencies [12, 10, 11]. Amanda Naylor, National Security Council cyber policy chief, said the memorandum "will provide new tools for the United States to protect Americans from cybercrime and fraud." Ari Redbord of TRM Labs added, "The private sector holds the data. The public sector holds the authorities," and the new memorandum "puts them together." [12, 7]
Private companies will require approval from DOJ and DHS officials before launching offensive cyber operations. Specific companies participating have not yet been announced, as program criteria and agreements are still being developed [12, 10, 8, 11, 4, 9]. Experts like Microsoft's Nick Carr warn that cyberattack attribution is highly challenging, with few able to accurately assign responsibility consistently. Critics also caution the approach poses risks including legal liability for companies, potential escalation of cyber conflicts, and coordination difficulties between government and private actors [12, 10, 7, 8, 11, 9].
Some have compared the program to historical letters of marque or privateering, which authorized private parties to conduct government-sanctioned attacks. However, concerns remain about control and accountability, given the controversial history of privateering [5, 7].
The new program represents a novel public-private partnership in offensive cyber operations against transnational criminal organizations. The government will soon begin vetting and contracting private companies to participate under strict oversight. Additional details on participating firms and operational scope are expected in the coming months [1, 2, 10, 8, 4].