The White House unveiled a program on August 12 that will allow vetted American companies to conduct offensive cyber operations against foreign criminal networks under federal supervision, marking a significant shift in how the U.S. government approaches cybercrime enforcement.
President Donald Trump signed a National Security Presidential Memorandum establishing the initiative inside the National Coordination Center of the Homeland Security Task Force. The program authorizes two categories of operations: “Cyber Surveillance Operations,” which permit companies to access target systems without owner permission to gather intelligence, and “Cyber Effect Operations,” which allow manipulation, disruption, denial of service, degradation, or destruction of information systems and the physical or virtual infrastructure they control.
The administration framed the move as a necessary escalation against ransomware, phishing, financial fraud, and sextortion schemes operating from abroad. “By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” the memorandum states.
How the program works
Two executive directors, one each from the Department of Justice and the Department of Homeland Security, will run the program. Companies seeking to participate must clear a rigorous vetting process covering technical capability, operational track record, facility security, and personnel screening. They must also post a bond or escrow of at least $1 million, which can be forfeited for contract violations.
The operational flow requires a company to gather threat information from other businesses or state and local agencies, then propose operations to the National Coordination Center. Nothing proceeds until the executive directors review each package and issue written approval and direction. The government retains operational control throughout; companies act only on explicit authorization.
Targets are limited to “cyber-enabled transnational criminal organizations” that threaten U.S. government entities, American citizens, or U.S. interests. Organizations that are part of a foreign government, or under its complete direction, are excluded. Operations that could cause loss of life or serious injury, or that would constitute “use of force” or “armed attack” under international law, fall outside standard approval authority. Any operation that hits a U.S. person or U.S.-based system must stop immediately, with minimization procedures triggered.
The targeting rules themselves sit in a classified annex, leaving public guardrails thin on operational detail. The Justice and Homeland Security departments have 60 days to develop implementation guidance. The administration also said it will establish criteria allowing smaller firms with niche operational specialties to participate, not just large cybersecurity companies. Reporting requirements mandate updates to the president’s advisers and the national cyber director within 180 days of program launch, then annually thereafter.
The White House justified the scale of the program by citing the costs of cybercrime. Crypto scams alone drained an estimated $80.7 billion from Americans in 2025, according to figures cited in the administration’s materials. North Korean hackers have developed increasingly sophisticated laundering methods for stolen cryptocurrency, and the government has already seized more than $25 million in crypto tied to investment and romance scams.
Privateering parallels and historical skepticism
The concept draws immediate parallels to letters of marque, documents from the Age of Sail that extended official protection to private vessels authorized to attack pirates and enemy ships. That practice, known as privateering, was a regulated form of piracy that faded from use as professional navies expanded.
Modern cybersecurity policy circles have long treated the idea with suspicion. In 2019, the concept of “hacking back” attracted the moniker of “worst idea in cybersecurity” among policy experts, who pointed out that accurately identifying perpetrators is notoriously difficult and that misattribution could spark damaging crossfire between governments and private actors.
Even Trump’s own officials have publicly distanced themselves from the concept. In March 2026, Thomas Lind, then a senior adviser at the Office of the National Cyber Director, told a conference the administration was “not interested in fighting pirates with pirates.” National Cyber Director Sean Cairncross told attendees at a Washington security summit around the same time that private offensive cyber operations were “not what we’re talking about” when seeking more help from industry.
Those statements reflected concerns that remain unresolved. Cyber attackers routinely obfuscate their origins and exploit information asymmetry. Threat actors are often less coherent organizations than overlapping, temporary associations between cybercriminals, a landscape further complicated by the growth of the cybercrime-as-a-service economy and the emergence of supergroups like “Scattered Lapsus$ Hunters.” The potential for tit-for-tat retaliatory cycles, as witnessed in the ongoing cyber conflict between Ukraine and Russia, adds another layer of risk.
A shifting federal posture
The program arrives against a backdrop of tension between the White House and the Cybersecurity and Infrastructure Security Agency (CISA), the federal body responsible for coordinating threat intelligence sharing and defense during cyber incidents. The administration has aggressively cut CISA’s budget and personnel, stemming from a grudge over the agency’s refusal to support Trump’s efforts to overturn the 2020 presidential election results. The new program shifts offensive capability toward private firms at a moment when the primary federal defensive coordinator operates with diminished capacity.
Currently, most offensive cyber operations are conducted by military units like U.S. Cyber Command, intelligence agencies, or their proxies. Private companies have generally limited themselves to “active defense” tactics such as seeking court orders to dismantle hacker infrastructure or setting up honeypots, wary of liability exposure and the legal ambiguity surrounding more aggressive measures.
The new framework attempts to resolve that tension by placing private capabilities under explicit federal authority. The White House said the program is not intended as a permanent license for companies to “hack back” on their own initiative, but rather a mechanism to combine government legal authority with private-sector technical speed. Whether that distinction holds in practice will depend heavily on the operational procedures the Justice and Homeland Security departments develop over the next two months.
Click Here For The Original Source.
