3 min read
President Donald Trump signed a memorandum on Tuesday directing the federal government to enlist vetted U.S. companies in offensive cyber operations against foreign criminal networks. The National Security Presidential Memorandum, dated Aug. 12, stands up a program inside the National Coordination Center of the Homeland Security Task Force.
"This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector," the White House wrote in the order's purpose section, referring to transnational criminal organizations.
Myriad: When will OpenAI release GPT-6? Click to make your prediction.
“By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.”
Two executive directors, one each from the Department of Justice and the Department of Homeland Security, would run the program. Private firms that contract with either agency could propose and carry out operations to access, surveil, disrupt, or destroy systems tied to those networks operating abroad.
Here's how it actually works: A company applies, clears a vetting process, and posts a bond or escrow of at least $1 million, forfeited if it breaks the rules. It gathers threat information from other businesses or from state and local agencies, then proposes operations to the NCC at Homeland Security. Nothing moves until the program's executive directors review the package and give written approval and direction. The government keeps operational control. The company pulls the trigger only on the government's say-so.
The memo authorizes "Cyber Surveillance Operations" (accessing systems without the owner's permission or by exceeding authorized access) and broader offensive action against the networks behind ransomware, phishing, financial fraud, and sextortion schemes. Operations that would cause "Critical Outcomes," are barred, and any hit on a U.S. person or a U.S.-based system must stop immediately with minimization procedures.
Per the memorandum, "it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime." The scale is the stated justification.
Crypto scams alone cost Americans an estimated $80.7 billion in 2025. North Korean hackers now have more sophisticated and complex ways to launder stolen crypto, and the government has already seized more than $25 million in crypto tied to investment and romance scams. This program would scale that model with private hands.
The program's targeting rules sit in a classified annex, so the public guardrails are thin on detail. The memo gives companies 60 days before implementation guidance is due.
Decrypt-a-cookie
This website or its third-party tools use cookies. Cookie policy By clicking the accept button, you agree to the use of cookies.