Trump authorizes vetted US firms to conduct cyber ops against foreign criminal groups

The machinery that will make it work is still being built.
Operating procedures for the new cyber program remain under development, with rules due within 60 days.
Mark

Why does the government need private companies to do this? Doesn't the military or NSA already have cyber capabilities?

Mimi

They do, but this is different. Private companies often have specialized expertise in particular criminal networks or technologies. They can move faster, and they're not bound by the same bureaucratic constraints. The government is essentially outsourcing to tap into skills it may not have in-house.

Mark

What stops a company from just hacking whoever they want and claiming it was approved?

Mimi

The $1 million bond, the contracts, the annual re-evaluation, and the requirement for written approval before every operation. If a company goes rogue, it loses the money and its contract. But you're right to worry—it depends on how closely the government actually watches.

Mark

What happens if an operation accidentally hits an American's computer?

Mimi

The company has to stop immediately, notify the government, and follow minimization procedures. But "immediately" is doing a lot of work in that sentence. By the time they notice and report it, damage may already be done.

Mark

Can these companies target anyone they think is a criminal?

Mimi

No. The targets have to be foreign criminal organizations—not just suspected criminals, but groups that meet a specific definition. And they can't be part of a foreign government. That's actually a meaningful constraint, though it took a lot of legal language to draw that line.

Mark

What's the biggest risk here?

Mimi

Mission creep. You start with foreign ransomware gangs, and five years later you're disrupting systems in countries the government has a political disagreement with. The safeguards look good on paper, but they only work if people enforce them.

  • Foreign criminal networks are draining $21 billion from Americans each year, and AI is making their ransomware, fraud, and impersonation schemes increasingly indistinguishable from legitimate communications.
  • The memorandum creates two categories of authorized action—covert intelligence gathering inside foreign systems and active disruption or destruction of criminal digital infrastructure—neither of which is defensive in nature.
  • Strict guardrails attempt to contain the risk: companies must pass rigorous vetting, post a $1 million bond, and obtain written federal approval for every single operation before it can proceed.
  • A hard boundary protects American persons and systems—if an operation accidentally touches U.S. targets, it must stop immediately and trigger a mandatory notification chain up to the Justice Department.
  • The framework exists on paper, but the actual operating rules are still being written over the next 60 days, meaning the program's integrity depends entirely on standards not yet finalized.

In a significant reconfiguration of how sovereign power meets private enterprise, President Trump signed a memorandum in August 2026 authorizing vetted American companies to conduct offensive cyber operations against foreign criminal organizations—under direct federal oversight and approval. The move acknowledges what governments worldwide have quietly understood: that the speed and sophistication of digital crime has outpaced the capacity of public institutions alone to answer it. With cybercrime costing Americans nearly $21 billion annually, the framework represents a calculated wager that private capability, carefully leashed, can extend the reach of justice into corners the state cannot easily enter. Whether this expansion of sanctioned force into private hands strengthens security or quietly erodes the boundaries that once contained it remains the deeper question.

In mid-August 2026, President Trump signed a national security memorandum reshaping how the United States confronts foreign cybercriminals—extending the authority to conduct offensive cyber operations beyond federal agencies and into the hands of vetted private American companies. The decision is rooted in a sobering reality: the FBI logged over one million cybercrime complaints last year, with losses approaching $21 billion, a 26 percent increase from the prior year. As artificial intelligence sharpens criminal tools, attacks grow harder to detect and victims find themselves targeted repeatedly as stolen data circulates through criminal networks for years.

The memorandum authorizes two categories of private action. A Cyber Surveillance Operation permits companies to covertly access foreign systems to gather intelligence. A Cyber Effects Operation allows them to manipulate, disrupt, degrade, or destroy criminal digital infrastructure. These are offensive measures conducted on foreign soil—not passive defenses.

The framework is built around substantial oversight. Companies must undergo rigorous vetting of their technical capability, personnel, and security practices, then sign contracts with either the DOJ or DHS. Every operation requires written approval from executive directors at those agencies before it begins. A bond or escrow account of at least $1 million is forfeitable upon any violation. Targets are limited to foreign criminal organizations not affiliated with or directed by any foreign government. If an operation accidentally reaches a U.S. person or system, it must halt immediately and trigger a mandatory notification chain reaching the Justice Department. Operations risking loss of life or constituting an act of war under international law are explicitly prohibited.

The architecture is in place, but the detailed operating procedures—covering eligibility, targeting, legal review, and oversight—are still being written, with program leaders given 60 days to complete them. For most Americans, the immediate effect is invisible. The real test will unfold in the shadows: whether the operations disrupt criminal networks, whether intelligence gathered serves law enforcement, and whether federal supervision remains rigorous enough to prevent the framework from becoming something harder to control than the threat it was designed to answer.

In mid-August, President Trump signed a national security memorandum that fundamentally shifts how the U.S. government fights foreign cybercriminals. Rather than limiting offensive cyber work to federal agencies alone, the new framework authorizes vetted private American companies to conduct cyber operations against foreign criminal organizations—but only under direct federal supervision and approval.

The scale of the problem the government is trying to address is staggering. Last year, the FBI's Internet Crime Complaint Center logged over one million complaints from Americans, with reported losses totaling nearly $21 billion—a 26 percent jump from the year before. Foreign-based criminal groups orchestrate sophisticated ransomware campaigns, phishing schemes, financial fraud, and impersonation scams that target both individual Americans and U.S. institutions. As artificial intelligence becomes more sophisticated, these attacks grow harder to detect and distinguish from legitimate communications. Stolen personal data circulates through criminal networks for years, meaning victims often find themselves targeted repeatedly.

The memorandum creates two distinct categories of operations that approved private companies could execute. The first, called a Cyber Surveillance Operation, allows companies to secretly access targeted computer systems to gather intelligence—potentially without the system owner's knowledge or permission. The second, a Cyber Effects Operation, permits companies to manipulate, disrupt, deny access to, degrade, or destroy digital infrastructure and systems controlled by criminal organizations. These are not passive defensive measures. They are offensive actions conducted on foreign soil against foreign actors.

But the framework includes substantial guardrails. Participating companies must pass rigorous vetting that examines technical capability, prior cyber operations experience, facility security, and personnel reliability. They must sign contracts with either the Department of Justice or the Department of Homeland Security. Every operation requires written approval and direction from executive directors at those agencies before it can proceed. The government may also require companies to maintain a bond or escrow account of at least $1 million, forfeitable if they violate their agreements. The memorandum does not name any companies that will participate, and the government has deliberately structured the rules to allow both large firms and smaller specialized operators to qualify.

The targets are narrowly defined as Cyber-Enabled Transnational Criminal Organizations—foreign groups conducting cyber crimes against the U.S. government, American citizens, or U.S. interests. Critically, the definition excludes organizations that are part of a foreign government or operate under its direction. This boundary matters because the operations authorized are deeply intrusive. If a company discovers that an operation has accidentally targeted a U.S. person, a system in the United States, or a system controlled by an American, it must immediately halt the operation, follow minimization procedures, and notify the National Coordination Center, which then alerts the Justice Department. Operations that could result in loss of life, serious injury, or constitute an armed attack under international law are explicitly prohibited from approval.

The memorandum establishes the framework, but the actual operating procedures remain under development. Program leaders have 60 days from mid-August to write the detailed rules governing company eligibility, targeting decisions, legal review processes, reporting requirements, and federal oversight mechanisms. Participating companies will face annual re-evaluation. Within 180 days, officials must deliver a status report to the White House, with additional reports required annually thereafter. The structure is in place. The machinery that will make it work is still being built.

For ordinary Americans, the immediate impact is invisible. No one needs to change settings or take action. The real consequence plays out in the shadows—whether approved operations successfully disrupt criminal infrastructure, whether the intelligence gathered helps law enforcement, and whether federal supervision remains tight enough to prevent overreach. The memorandum attempts to give the government a new tool against foreign cybercriminals while building in legal review, operational safeguards, and financial accountability. Whether those safeguards prove sufficient depends entirely on the rules now being written and how strictly federal officials enforce them once operations begin.

The government is attempting to put more pressure on foreign criminal organizations carrying out cyber attacks, potentially adding another layer to defensive steps Americans already take.
— Kurt Knutsson, CyberGuy
Quieres la nota completa? Lee el original en Fox News ↗
Contáctanos FAQ