The federal government is opening a door that has been shut for decades: letting private companies fight back against hackers on offense, not just defense. Under a new policy from the Trump administration, vetted security firms could soon be authorized to launch US private cyber operations against foreign criminal networks that target Americans online, a shift that upends decades of policy barring private actors from taking offensive action without a court’s blessing.
Key takeaways
- A National Security Presidential Memorandum, dated Aug. 13, 2026, directs the National Coordination Center (NCC) to build a program letting vetted private firms conduct offensive cyber operations against foreign cybercriminals.
- Eligible targets include ransomware gangs, sextortion schemes, phishing campaigns, financial fraud rings, and impersonation scams tied to transnational criminal organizations.
- Participating companies must be approved by the Departments of Justice and Homeland Security, meet strict technical and vetting standards, and post a $1 million escrow deposit that is forfeited for non-compliance.
- Operations may include spyware deployment, encryption-based lockouts, and distributed denial-of-service attacks, but cannot cause loss of life, serious injury, or rise to the level of “use of force” under international law.
- The Justice and Homeland Security Departments have 60 days to spell out how the program will actually work.
U.S. Government Authorizes Private Sector Offensive Cyber Operations
For the first time, Washington is inviting private companies to strike back against overseas hackers under federal authorization, rather than confining them strictly to defense. The memorandum, signed by President Donald Trump, instructs the National Coordination Center, which sits under the Homeland Security Task Force, to build out a formal program for these operations, with oversight split between the Departments of Justice and Homeland Security.
The policy is aimed squarely at transnational criminal organizations, groups the memo defines as foreign entities that commit cyber-enabled crimes against the US government, US persons, or US interests without being an official arm of another government. A fact sheet released alongside the order names ransomware operators, sextortion schemes, phishing campaigns, financial fraud rings, and impersonation scams as fair game for participating firms. According to figures cited in the White House fact sheet, US consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025 alone, a number that underscores why officials are looking beyond traditional law enforcement tools.
Why does this matter beyond the policy language? It marks a structural change in how the US confronts cybercrime that crosses borders. Rather than relying solely on FBI investigations, sanctions, or diplomatic pressure, the government is now positioning private-sector expertise as a frontline weapon against criminal networks that have often operated with near impunity from jurisdictions the US cannot easily reach.
Participation Requirements and Operational Constraints
Not just any security vendor can sign up. Firms hoping to take part must clear a vetting process run jointly by the Departments of Justice and Homeland Security before entering into a formal contract, and the bar for entry is deliberately high.
Vetting, Standards and the $1 Million Escrow
The memo lays out minimum standards that participating companies must meet, including technical proficiency, a proven track record in cyber operations, facility security, personnel vetting, competence, and reliability. Program executive directors, working with the Homeland Security Council, will determine exactly what “high confidence” in a firm’s ability looks like before approving it.
Financially, the stakes are real too. Companies must deposit at least $1 million in an escrow account**, money that gets forfeited if they violate the terms of their contractual agreement. Firms are also required to immediately halt operations and notify the NCC if they detect activity exceeding approved limits, including any accidental targeting of US citizens or US-based systems. That safeguard is meant to prevent friendly-fire scenarios where an offensive operation strays into domestic networks.
Permitted Cyber Operations and Legal Boundaries
The program draws a firm line between aggressive digital tactics and anything that could cause real-world harm. Approved firms will be allowed to conduct what the memo calls Cyber Surveillance Operations and Cyber Effects Operations, terminology that leaves room for a fairly broad offensive toolkit.
What’s Allowed and What’s Off-Limits
Based on the memo’s language, companies could deploy spyware, use encryption to lock criminal groups out of their own systems, or launch distributed denial-of-service attacks designed to disrupt a target’s infrastructure. Until now, the government has generally barred the private sector from taking these kinds of offensive actions without court-authorized approval, which makes this shift notable.
There is, however, a hard ceiling on what’s permitted. Operations cannot produce what the memo terms “Critical Outcomes,” meaning no loss of life, no serious injury, and nothing that would qualify as a use of force or armed attack under international law. That constraint is meant to keep hack-back operations from escalating into something resembling armed conflict, even as it hands private actors tools previously reserved for government agencies.
What Happens Next
The framework exists on paper, but the operational reality is still being written. The Departments of Justice and Homeland Security have 60 days to define the specifics of how the program will function day to day, including how contracts are structured and how oversight will actually be enforced.
Expert Skepticism Over Incentives
Independent security researcher Kevin Beamont welcomed part of the concept but flagged a real concern about how it plays out in practice. “There’s definitely merit in the idea of hacking ransomware groups and it does already in fact happen (don’t ask me how I know),” he said, adding that “the correct incentives have gotta be there.”
Beamont went further, pointing to a pattern he’s observed in the industry: “The biggest problem I’ve had with fighting ransomware over the past 5 years is private cyber companies basically lobbying for nothing to change. A lot of companies have made a lot of money, so putting them in charge of stopping it seems optimistic.”
That tension gets at the core question hanging over this whole initiative. Handing offensive capabilities to companies that profit from the persistence of cybercrime could create a program that looks tough on paper but struggles to deliver results if the underlying incentives don’t shift. Whether the Justice and Homeland Security Departments build in enough accountability when they finalize the rules in the coming weeks will likely determine whether this new chapter of US private cyber operations becomes a meaningful disruption to transnational hacking networks or just another layer of contracted bureaucracy.
FAQ
What types of cybercriminal groups can private firms target under the new program?
Private firms may target foreign transnational criminal organizations involved in ransomware, sextortion, phishing, financial fraud, and impersonation scams.
What restrictions are placed on the cyber operations conducted by private security firms?
Operations must not cause loss of life, serious injury, or qualify as use of force under international law, and must comply with U.S. laws and oversight.
How are private security firms selected for participation in the offensive cyber program?
Firms must be vetted and approved by the Departments of Justice and Homeland Security, meet technical and security standards, and deposit a $1 million escrow.
When will detailed operational procedures for this program be published?
The Departments of Justice and Homeland Security are required to define program specifics within 60 days from the date of the memorandum.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.