Trump Authorises Government-Directed Offensive Cyber Operations Against Foreign Criminal Networks
• A new National Security Presidential Memorandum creates a framework for vetted private cybersecurity companies to conduct surveillance and disruptive cyber operations against foreign cyber-enabled...
• A new National Security Presidential Memorandum creates a framework for vetted private cybersecurity companies to conduct surveillance and disruptive cyber operations against foreign cyber-enabled transnational criminal organisations under federal oversight.
Meat of the Story
US President Donald Trump has signed a National Security Presidential Memorandum directing the federal government to establish a programme allowing vetted private-sector cybersecurity companies to participate in offensive cyber operations against foreign cyber-enabled transnational criminal organisations.
Signed on August 12, 2026, the memorandum, titled Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, directs the National Coordination Center to establish a framework through which approved private companies can conduct cyber surveillance and cyber effects operations against designated criminal networks under government direction and oversight.
The move represents a significant shift in the US approach to cybercrime enforcement. Rather than relying exclusively on conventional investigation, prosecution and disruption by government agencies, Washington intends to harness private-sector capabilities to identify, track and disrupt foreign criminal infrastructure.
Analysis
The memorandum builds on the administration’s earlier cybercrime strategy. In March, Trump directed federal agencies to develop an action plan targeting transnational criminal organisations involved in ransomware, fraud, malware, phishing and other cyber-enabled schemes against Americans. The order specifically called for greater use of commercial cybersecurity expertise to improve attribution, tracking and disruption of malicious infrastructure.
The August memorandum takes that approach further by establishing a mechanism for vetted private companies to participate directly in government-authorised cyber operations.
The programme distinguishes between cyber surveillance operations, which are designed to gather intelligence about criminal networks and their infrastructure, and cyber effects operations, which can involve disrupting, manipulating or damaging foreign information systems. The activities are intended to be conducted under federal supervision rather than as independent private-sector “hack back” campaigns.
The National Coordination Center will oversee the programme, while the Departments of Justice and Homeland Security are expected to establish the operational framework and safeguards. Participating companies will undergo vetting and require government approval for operations.
The programme is therefore not an unrestricted authorisation for US companies to attack suspected criminals. It establishes a government-controlled mechanism through which selected private entities can provide capabilities that would otherwise remain within government cyber operations.
Compliance Implications
The initiative creates a new category of legal and operational risk for cybersecurity companies considering participation.
Private firms involved in the programme will need robust governance around authorisation, attribution, target identification, operational scope, evidence preservation and escalation. A mistaken attribution could result in operations against an innocent company, compromised infrastructure or an entity with no connection to the criminal organisation being investigated.
Cross-border operations create additional complications. Cyber infrastructure frequently spans multiple jurisdictions, meaning an operation directed at a criminal network could affect servers, cloud services, telecommunications systems or data belonging to legitimate organisations in third countries.
For companies outside the United States, the development also reinforces the importance of maintaining accurate cyber asset inventories and incident response capabilities. Organisations whose infrastructure is compromised by criminal groups could potentially become collateral participants in government-directed disruption operations.
Cybersecurity firms should also review contractual arrangements, liability provisions, data handling requirements and government information-sharing obligations before participating in any such programme.
Why the Update Matters
The memorandum marks a significant evolution in the US government’s response to transnational cybercrime.
For decades, private companies have generally been expected to defend their own networks and report criminal activity to law enforcement. The new framework moves towards a more integrated model in which selected private-sector actors can potentially participate in offensive disruption operations conducted under government authority.
That creates both opportunities and risks.
Supporters argue that private cybersecurity companies possess specialised technical capabilities, threat intelligence and visibility into criminal infrastructure that can complement government resources. Critics have raised questions about accountability, legal authority, attribution and the possibility that offensive operations could unintentionally escalate international disputes.
The distinction between cybercrime groups and state-sponsored actors is also important. The programme is directed at foreign cyber-enabled transnational criminal organisations, but determining whether a criminal network is genuinely independent of a foreign government can be difficult.
For multinational businesses, this makes cyber attribution an increasingly important compliance issue. A company may face consequences not only from the criminal group attacking it, but also from government action against the infrastructure used in that attack.
Compliance Takeaway
The new US framework signals that cybercrime enforcement is moving beyond passive defence and conventional prosecution towards government-directed disruption of criminal infrastructure.
Cybersecurity companies operating in or with the United States should monitor the programme’s implementing rules closely, particularly requirements governing authorisation, attribution, operational limits, data handling and liability.
Businesses should likewise strengthen asset inventories, third-party cyber-risk assessments, incident response and threat-intelligence capabilities. Where critical infrastructure is hosted or operated through third parties, organisations should understand how a government-led cyber operation against criminal infrastructure could affect legitimate systems and data.
The central compliance lesson is clear. Cybersecurity risk is increasingly becoming a national security and law-enforcement issue, with private-sector technology providers potentially moving from defenders and witnesses to authorised participants in government cyber operations



No Comment! Be the first one.