$20.8 billion lost to cyber-enabled crime in one year. Trump’s answer: let vetted American companies hack back at the people responsible, with the Justice Department and Homeland Security signing off. Congress wasn’t consulted. Neither was anyone who’ll have to sort out the legal mess this creates.
President Trump signed a National Security Presidential Memorandum on August 12 authorizing vetted private US companies to conduct offensive cyber operations against foreign criminal networks, under government oversight but with businesses doing the actual hacking. “American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace,” the White House said. “Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime.” The Department of Justice and Department of Homeland Security will jointly run the program through a new National Coordination Center.
What’s Happening & Why It Matters
What Companies Get to Do

The memorandum targets transnational criminal organizations running ransomware, phishing, and sextortion campaigns against Americans from abroad. Vetted companies that opt in can gather intelligence on these networks, propose specific operations, and — with government sign-off — actually execute them: spying on criminal infrastructure or sabotaging it directly. The program builds on an earlier March 2026 executive order that first floated greater private-sector involvement, but this memo goes considerably further, establishing an actual operational framework rather than just a policy direction.
The Homeland Security Task Force‘s National Coordination Center will manage the whole thing, led by two executive directors — one appointed by the Attorney General from DOJ, one appointed by the Secretary of Homeland Security. Companies are encouraged to team up with each other and with federal, state, local, tribal, and territorial agencies to build out intelligence on their targets before proposing an operation.
The Number Driving the Policy
American consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025, according to the White House’s own figures. That’s the justification underpinning the entire memo — a scale of loss the administration argues government resources alone haven’t been able to stop, and a case for tapping private-sector technical capability the White House describes as sitting mostly idle on the sidelines of this specific fight.
Whether that capability actually exists at the scale needed is a separate question the memo doesn’t answer. Plenty of US cybersecurity firms already run defensive operations — detecting intrusions, patching vulnerabilities, responding to breaches. Offensive operations, actually hacking into someone else’s infrastructure to disrupt it, is a fundamentally different skill set, one that’s historically been reserved for intelligence agencies and military cyber commands precisely because it carries legal and diplomatic risk that a private company’s shareholders don’t typically want on the balance sheet.
The Legal Line Nobody’s Drawn Yet

Cybersecurity Dive’s framing of the policy captures the real concern: it “significantly blurs the line between the government’s foreign policy activities and businesses’ commercial activities.” A private company hacking a criminal network in another country isn’t just a cybersecurity operation — it’s an action with foreign policy consequences, potentially violating the target country’s own laws, regardless of what US law authorizes. Nobody in this memo has explained what happens if a vetted company’s operation goes wrong, hits the wrong target, or triggers a diplomatic incident with a country that doesn’t recognize Washington’s authorization as covering anything.
Congressman Bennie Thompson (D-MS) raised exactly that concern following the announcement, though the White House hasn’t detailed a specific liability framework for companies operating under this authorization. That’s the gap worth watching most closely as the program actually starts approving operations, not just accepting applications.
TF Summary: What’s Next
The National Coordination Center is standing up its application and vetting process, with no confirmed timeline for when the first company-run operations might actually begin. No specific legal liability framework has been published for companies operating under this authorization. Congressional response beyond Thompson’s initial concern remains limited as of this writing.
MY FORECAST: Expect the vetting process to move slower than the administration’s public framing suggests — genuine offensive cyber capability, executed lawfully enough to survive scrutiny, is a narrower pool of companies than the White House’s “underutilized” framing implies. Watch for the first real controversy to arrive within a year, once an approved operation produces an unintended consequence: a wrong target, a foreign government’s formal objection, or a company overstepping its authorized scope. That incident, whenever it lands, will be the actual test of whether this framework holds up, not the memo’s signing.
Related Stories
- GOLD EAGLE: White House Launches an AI Cybersecurity Clearinghouse
- FBI: Hackers Targeted Water Utilities in at Least 7 States
- FortiBleed: Credential Leak Hits Oracle, Lenovo, NATO, and 74,000 Fortinet Firewalls
