US Cybercrime Losses Hit $20.8bn as White House Moves to Operationalise Offensive Cyber Programme
• The Trump administration says Americans reported more than $20.8 billion in cyber-enabled crime losses in 2025, as federal agencies receive 60 days to establish procedures for a new programme...
• The Trump administration says Americans reported more than $20.8 billion in cyber-enabled crime losses in 2025, as federal agencies receive 60 days to establish procedures for a new programme targeting foreign cybercrime networks.
Meat of the Story…
The Trump administration has cited more than $20.8 billion in losses reported by American consumers to cyber-enabled crime in 2025, as it moves to expand the US government’s response to ransomware, phishing, financial fraud and impersonation schemes.
The figure forms part of the White House’s justification for a new National Security Presidential Memorandum directing the National Coordination Center to establish a programme allowing vetted US companies to participate in government-directed cyber surveillance and disruptive operations against foreign transnational criminal organisations.
The memorandum gives the relevant federal authorities 60 days to establish the operational framework, including procedures for approving participating companies and proposed cyber operations.
Analysis
The financial losses cited by the administration demonstrate the scale of the threat Washington is attempting to address. The White House says cyber-enabled criminal organisations are targeting Americans through ransomware, malware, phishing, financial fraud, sextortion and impersonation schemes. It has also pointed to the growing use of technology to industrialise scams against individuals and businesses.
The new programme represents a significant escalation because it moves beyond conventional law enforcement responses. Under the memorandum, vetted private-sector companies could, with government approval, conduct cyber surveillance operations and cyber effects operations against qualifying foreign criminal organisations.
Cyber surveillance operations can involve accessing sensitive information without authorisation from the owner or operator, while cyber effects operations may involve disrupting, denying, degrading or destroying information systems, networks or infrastructure.
The programme is nevertheless subject to government control. Participating companies must be vetted and approved, while operations require authorisation and must remain within specified parameters.
The memorandum also places limits on operations that could cause death or serious physical injury or constitute a use of force under international law. Firms must stop operations that exceed their approved parameters and report incidents involving US persons or US-controlled systems.
Compliance Implication
The 60-day implementation period makes governance and operational controls a central issue.
For participating cybersecurity companies, the eventual framework will need to establish clear rules around target identification, attribution, authorisation, evidence handling, data access, operational boundaries and incident escalation.
Attribution presents a particularly difficult compliance challenge. Criminal infrastructure can be routed through compromised servers, cloud platforms, routers and other systems belonging to innocent third parties. An operation directed at a criminal network could therefore inadvertently affect legitimate organisations.
The programme also creates significant third-party and jurisdictional risks. Cybercriminal organisations frequently operate across multiple countries, meaning infrastructure targeted in an approved US operation could be located outside the United States and potentially controlled or hosted by an unrelated organisation.
For businesses, maintaining accurate inventories of internet-facing assets, cloud infrastructure and critical suppliers will therefore become increasingly important. Organisations should also maintain robust incident response procedures capable of distinguishing between criminal activity and potentially disruptive government or law enforcement operations.
Financial institutions and fintech companies should pay particular attention to the financial component of the programme. Ransomware, phishing, impersonation and other cyber-enabled crimes frequently generate proceeds that move through payment processors, banks, cryptocurrency platforms and other financial intermediaries.
Why the Update Matters
The $20.8 billion loss figure provides the economic backdrop for a major change in US cyber policy. Washington is effectively arguing that the scale and sophistication of transnational cybercrime justify a more aggressive model of disruption.
The programme also illustrates the convergence of cybersecurity, financial crime and national security.
Ransomware groups may require hosting infrastructure, cryptocurrency wallets and money-laundering networks. Phishing operations can depend on domain registrars, compromised servers and payment channels. Impersonation scams increasingly exploit artificial intelligence to create convincing voices, images and communications.
This interconnected structure means that enforcement increasingly targets the infrastructure and financial ecosystem supporting cybercrime, rather than focusing exclusively on individual perpetrators.
The 60-day deadline is therefore significant. It creates a near-term regulatory and governance milestone that will determine how private-sector participation operates in practice and what safeguards will govern offensive cyber activity
Compliance Takeaway
The emerging US framework reinforces the need for organisations to treat cyber risk as a broader financial, operational and regulatory issue.
Companies should strengthen asset inventories, third-party risk assessments, incident response capabilities and threat-intelligence processes. Financial institutions and digital asset businesses should also continue monitoring ransomware and fraud-related transactions for indicators of illicit proceeds.
For cybersecurity firms considering participation in the federal programme, the critical compliance questions will centre on authorisation, attribution, proportionality, data protection, jurisdiction, liability and operational oversight.
The broader lesson is clear.With cybercrime losses reaching tens of billions of dollars, Washington is moving from a predominantly defensive model towards government-directed disruption of the criminal infrastructure behind the attacks.



No Comment! Be the first one.