US Authorizes Private Firms for Government-Supervised Cyber Operations Against Foreign Criminals
A new presidential memorandum allows private companies to conduct government-directed cyber surveillance and disruption operations against foreign criminal groups.

President Donald Trump has signed a significant presidential memorandum that establishes a framework for private companies to engage in government-supervised cyber operations targeting foreign criminal organizations. This policy aims to combat cyber-enabled transnational criminal organizations (CE-TCOs) that perpetrate online crimes impacting Americans and businesses.
The memorandum designates the National Coordination Center (NCC) as the entity responsible for establishing and managing this new program. Under this initiative, approved private firms will be authorized to conduct two primary types of operations: cyber surveillance and cyber effects operations. Crucially, these activities will be conducted strictly under the direction, control, and oversight of the federal government, with joint supervision provided by the Department of Justice and the Department of Homeland Security through designated program executive directors.
Cyber surveillance operations are defined as covert activities designed to gather intelligence from computer systems, networks, telecommunications infrastructure, or embedded devices. This includes unauthorized access or exceeding authorized access to remain undetected while collecting information that could support future operations. The goal is to proactively identify and understand the operations of foreign criminal groups.
Cyber effects operations, on the other hand, are more active in nature. They are designed to manipulate, disrupt, deny, degrade, or destroy information, systems, networks, or infrastructure managed through information technology. However, the memorandum explicitly prohibits operations that are likely to cause death, serious injury, or effects that amount to a use of force or armed attack under international law. These critical outcomes are beyond the scope of what program executive directors can approve.
This policy is not a carte blanche for companies to engage in "hack-back" activities. Every proposed operation must undergo a rigorous review process and receive explicit written approval and direction before any action can be taken. Companies will operate as government agents, acting under the lawful authority of the United States. The NCC will also be responsible for coordinating these operations across various federal agencies, including law enforcement, intelligence, foreign policy, treasury, and defense departments, to ensure alignment and prevent conflicts.
To participate in the program, companies must enter into contracts with either the Justice Department or Homeland Security. They will be subjected to thorough vetting processes covering their technical capabilities, security protocols, and personnel. The program aims to accommodate both large technology providers and smaller, specialized firms, ensuring a diverse range of expertise can be leveraged. Participating companies may also be required to maintain a financial bond or escrow of at least $1 million as a safeguard against non-compliance.
Stringent protocols are in place for accidental targeting. Companies must immediately halt operations, minimize data collection, and notify the NCC if they inadvertently target a U.S. person or system. Furthermore, any operation that might implicate constitutional, federal, or international law obligations requires review and potential legal or judicial authorization before approval.
The memorandum mandates that program executive directors establish detailed operating procedures within 60 days, in coordination with the Homeland Security Council. The program's effectiveness and implementation will be reported on within 180 days and annually thereafter. For the cybersecurity community, this initiative could formalize channels for sharing threat intelligence and proposing government-backed disruptions of criminal infrastructure, though its ultimate practical impact will hinge on the classified workflows, target selection, and legal review processes.
This new memorandum from President Trump significantly expands upon the previous directive by authorizing private sector companies to actively conduct offensive cyber operations, including surveillance and effects operations, against transnational criminal organizations. While the existing story notes the authorization for government-supervised cyber operations, this article details the specific mechanism of private sector involvement, including contractual agreements, rigorous vetting, and adherence to existing laws like the Computer Fraud and Abuse Act, marking a substantial policy shift.