Sunday, August 30, 2026

Trump Memo Would Let Companies Hack Foreign Cybercriminals

Valyrian News Network 7 min read

Trump Memo Would Let Companies Hack Foreign Cybercriminals

WASHINGTON — President Donald Trump has signed a national security memorandum that would authorize private U.S. companies to conduct offensive cyber operations against foreign cybercriminal organizations, marking the first time the federal government has sanctioned private-sector hacking of overseas adversaries. The presidential memorandum, issued August 12, directs the National Coordination Center to create a program allowing vetted private companies to conduct “Cyber Surveillance Operations” and “Cyber Effects Operations” against foreign “Cyber-Enabled Transnational Criminal Organizations” (CE-TCOs).

The policy represents a dramatic departure from the way America’s private sector has traditionally operated in cyberspace. In the past, work involving spying on or disrupting foreign criminal networks has been performed exclusively by government agencies. Under the new framework, participating companies would be contracted with the Department of Justice or the Department of Homeland Security, undergo “rigorous vetting,” and maintain a bond or escrow of at least $1 million that can be forfeited for non-compliance.

Context: A Growing Cybercrime Threat

The memorandum arrives amid escalating cyber threats against American infrastructure and citizens. According to the White House fact sheet, Americans reported losing more than $20.8 billion to cyber-enabled crime in 2025. The memo cites ransomware attacks, phishing campaigns, financial frauds, sextortion schemes, and impersonation scams as coordinated campaigns run by sophisticated transnational criminal organizations based outside the United States.

The policy shift also follows a series of recent attacks on U.S. critical infrastructure. In late July, a coordinated cyberattack targeted operational technology at more than 30 water systems in Minnesota, with the FBI confirming that at least seven states suffered similar attacks on water and wastewater facilities. U.S. intelligence links these attacks to Iran, with one cybersecurity expert telling NPR there’s intelligence connecting the activity to the Iranian Revolutionary Guard Corps.

How the Program Would Work

Under the memorandum, the National Coordination Center — established under the Homeland Security Task Force — would manage a program overseen by two co-Executive Directors, one from the Department of Justice and one from the Department of Homeland Security. Participating companies would be permitted to enter into commercial agreements with other private entities to receive threat information, and with federal, state, local, tribal, and territorial agencies to identify CE-TCO threats.

The memo does not change U.S. anti-hacking laws, specifically the Computer Fraud and Abuse Act (18 U.S.C. Sec. 1030), but mandates that any participating company be contracted with the federal government. Operations that would result in “Critical Outcomes” — defined as loss of life, serious injury, or actions rising to the level of use of force under international law — are prohibited.

The memorandum gives DOJ and DHS 60 days to establish consensus operating procedures, including minimum standards for participating companies, an adjudicatory framework for target selection, and procedures to halt operations if a participating company unintentionally targets a U.S. person or an information system under U.S. control.

Supporters: A Necessary Step for Parity

Supporters argue the program leverages the private sector’s innovation and speed to counter adversaries who already operate this way at scale. Joshua Steinman, who served as senior director for cyber policy on the National Security Council during Trump’s first term, told NPR that “there’s a range of potential targets… like organized crime… people doing money laundering or other criminal activity.”

“The Chinese and the Russians do this at scale, and I guarantee you they have very few limiting tools when they do it,” Steinman told CyberScoop. “It opens up an entire workforce that allows us to go out and achieve strategic objectives.”

Ari Redbord, global head of policy at TRM Labs, praised the memo as “a huge step toward empowering the private sector at a critical moment.” He noted that “scammers are using AI to move with unprecedented speed and scale, stealing billions in life savings from average Americans and small businesses. The private sector holds the data. The public sector holds the authorities. This [memo] puts them together.”

Critics raise significant concerns about the program’s legal implications, targeting risks, and potential for collateral damage. Paul Rosenzweig, former deputy assistant homeland security secretary for policy under George W. Bush, was blunt in his assessment: “It’s not an incomparably bad idea, but it’s a bad idea.”

“Anything that our new cyber-enabled private sector actors do overseas will assuredly be against the domestic law of a host of countries wherein they act,” Rosenzweig said. “The internet is not bounded in by sovereign borders in the same way that physical space is.”

Chris Wysopal, co-founder of the security firm Veracode, warned about the risk of unintended consequences. “You don’t want to have collateral damage when your blast radius is too big at the data center you were trying to take down, and you took down a transportation company or hospital’s servers,” he told NPR.

Security consultant Davi Ottenheimer was even more critical, calling the memo “an embarrassment to America.” He expressed concern about political targeting, noting that the memo authorizes attacking “criminals” without clear definitions. “Left-wing opposition, liberals, anti-fascists — they’re all criminals to him,” Ottenheimer told CyberScoop. “So to authorize attacking criminals under this means private organizations can go hack people that he designates as criminals.”

Michael Garcia, a former top official at the Cybersecurity and Infrastructure Security Agency, called the memo “a massive shift in the cyber policy community” and “a philosophical shift.” He worried about attribution risks: “It comes down to attribution, and if you make a risky bet on who we’re attributing [attacks] to, that’s where things can get dicey.”

The ‘Cyber Privateers’ Debate

The memorandum has revived discussion of “cyber privateers,” a concept drawing from 16th-century naval warfare where private ships were authorized via “letters of marque” to attack enemy vessels. Senator Mike Lee (R-UT) introduced the Cyber Letters of Marque and Reprisal Act in July 2026, which would grant the President explicit statutory authority to authorize private entities to conduct cyber operations against foreign threats. The Trump memorandum does not go as far as the Lee bill — it does not create a “privateer” system but rather a government-contracted program with strict oversight.

Independent security researcher Kevin Beaumont offered a cautiously supportive view, telling Ars Technica that “there’s definitely merit in the idea of hacking ransomware groups and it does already in fact happen.” But he added a caution: “The biggest problem I’ve had with fighting ransomware over the past 5 years is private cyber companies basically lobbying for nothing to change. A lot of companies have made a lot of money, so putting them in charge of stopping it seems optimistic.”

What’s Next

The 60-day implementation window will be critical in determining how the program takes shape. Will Barker, cybersecurity adviser at Huntress, noted that “the 60-day implementing guidance is where the real substance lives. Minimum standards, operational procedures, the adjudicatory framework for target selection.”

Several key questions remain unanswered: Which companies will participate? How will targets be selected and attributed? What legal protections will the government provide to participating companies? And how will foreign governments react to U.S. private companies conducting offensive operations?

Even if the legal and technical issues are resolved, some question whether offensive operations will actually solve the growing threat of cybercrime. As Wysopal put it: “I don’t think you can sort of offense your way to security. There’s always going to be yet another threat actor… the idea that this is going to solve the problem seems really foolish.”

Steinman, however, remains optimistic about the program’s potential. “The point of this is to get started,” he said. “And I trust that the people that are running it are going to be very measured in their initial efforts to try and build out this capability.”

As the program moves forward, the tension between leveraging private-sector innovation and maintaining appropriate government oversight will likely define the debate over this unprecedented shift in U.S. cybersecurity policy.