US authorizes private security firms to hack overseas cybercriminals

The Trump administration authorizes private security firms to conduct offensive hacking operations against overseas criminal networks targeting American victims.

By Central
A new program allows private firms to conduct cyber operations against foreign criminals under government oversight.
Highlights
  • Private security firms will be authorized to conduct offensive cyber operations against foreign criminal networks.
  • The program targets ransomware, sextortion, phishing, and other cyber-enabled crimes.
  • A National Security Presidential Memorandum issued Thursday directs the formation of the program.

The Trump administration has moved to enlist private security firms as government-authorized cyber warriors, granting them the power to conduct offensive hacking operations against overseas criminal networks that target American victims. A National Security Presidential Memorandum issued Thursday directs the National Coordination Center (NCC), operating under the Homeland Security Task Force, to develop a formal program that would allow private-sector companies to carry out what the memo terms “Cyber Surveillance Operations and Cyber Effects Operations” against foreign transnational criminal organizations. The Departments of Justice and Homeland Security will provide oversight, but the lynchpin of the program represents a fundamental departure from decades of federal policy: for the first time, the United States government will authorize private companies to go on the cyber offensive against foreign hackers.

The National Security Presidential Memorandum: What It Actually Authorizes

The memorandum, formally titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” establishes a framework for the NCC to recruit and deploy private security firms in operations that have historically been the exclusive domain of military and intelligence agencies. The program targets what the memo defines as “cyber-enabled” transnational criminal organizations (TCOs) — any foreign group that conducts cyber-enabled crime against the US government, a US person, or US interests, provided the group is not an institutional part of a foreign government or wholly operated under a foreign government’s direction.

The fact sheet accompanying the memorandum lists specific criminal activities eligible for private-sector targeting: ransomware attacks, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams. These are the bread-and-butter operations of the cybercriminal underground, responsible for billions of dollars in losses annually and affecting millions of American individuals and businesses.

The scope of authorized operations is notably broad. The memo does not rule out using encryption to lock targets out of their own networks, conducting distributed denial-of-service (DDoS) attacks, deploying spyware, or launching offensive attacks intended to destroy TCO data or systems. This latitude represents the most significant expansion of private-sector cyber authority in American history.

Breaking the Government Monopoly on Offensive Cyber Operations

Until now, the federal government has maintained a strict prohibition against private sector entities conducting offensive cyber operations without court-authorized approval. The rationale has been straightforward: offensive cyber operations carry immense risks of escalation, collateral damage, and unintended consequences. A company that penetrates a foreign criminal server could inadvertently disrupt critical infrastructure, escalate tensions with foreign governments, or violate international laws governing state-sponsored cyber activities.

The new program explicitly overrides these longstanding constraints by creating a legal and operational framework under which private security firms can act as government-authorized agents. Companies participating in the program will operate under the direction of the NCC, with oversight from DOJ and DHS, but the actual hacking will be done by private-sector personnel using private-sector tools and infrastructure.

This represents a significant outsourcing of state power. The government is effectively deputizing private security firms to conduct operations that, if conducted by the firms independently, would constitute federal crimes under the Computer Fraud and Abuse Act, the Wiretap Act, and other laws. The memorandum provides the legal authorization necessary to shield participating companies from prosecution, but the operational risks remain substantial.

How the Program Will Work: The NCC and the Private Sector

The National Coordination Center, an agency within the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA), will serve as the operational hub for the new program. The NCC currently coordinates cyber incident response across federal agencies and private sector partners, but its mandate has never included authorizing offensive operations. The memorandum expands the NCC’s role dramatically, tasking it with developing the program’s rules of engagement, vetting private security firms for participation, and overseeing ongoing operations.

The Departments of Justice and Homeland Security will provide what the memo calls “oversight,” though the specific mechanisms remain undefined. The fact sheet offers no details on how the government will verify that private companies comply with operational restrictions, how it will prevent mission creep, or what happens when a private contractor violates the rules of engagement. The “devil will be in the still-undefined details,” as one reading of the memo suggests, and those details will determine whether the program remains a targeted tool against criminal networks or becomes a source of uncontrolled cyber escalation.

Private security firms that choose to participate will need to meet unspecified qualification standards, maintain appropriate insurance and liability protections, and accept the operational direction of the NCC. The memorandum does not specify whether firms will be compensated for their participation, whether they will be indemnified against legal claims arising from their operations, or what happens to their personnel if they are captured or targeted by foreign governments.

Defining the Target: What Qualifies as a Transnational Criminal Organization

The memorandum’s definition of a “cyber-enabled” TCO is both carefully crafted and potentially expansive. To qualify for targeting, a group must be foreign, must conduct cyber-enabled crime against US persons, organizations, or government entities, and must not be an institutional part of a foreign government or wholly operated under a foreign government’s direction.

The last exclusion is critical. It means the US government cannot use this program to authorize private firms to hack into state-sponsored hacking groups that operate under the control of foreign governments. Groups like those linked to the Chinese Ministry of State Security, Russia’s GRU or SVR, North Korea’s Reconnaissance General Bureau, or Iran’s Islamic Revolutionary Guard Corps would fall outside the program’s scope, even if they conduct cybercrime as a cover for state operations.

In practice, however, the distinction between state-sponsored and criminal groups is often blurry. Many ransomware gangs operate from within states that tolerate or tacitly support their activities. The Conti group, for example, had documented ties to Russian security services before it fragmented. The LockBit operation operated with apparent impunity from Russia. The memorandum’s exclusion of groups “wholly operated under a foreign government’s direction” leaves room for interpretation, and that ambiguity will create challenges for firms attempting to determine whether a particular target qualifies.

Operations Permitted: Cyber Surveillance and Cyber Effects

The memorandum authorizes two categories of operations: Cyber Surveillance Operations and Cyber Effects Operations. Cyber Surveillance Operations involve monitoring, intercepting, or collecting data from target systems without altering or destroying them. These operations are intelligence-gathering missions designed to map criminal networks, identify key personnel, track financial flows, and understand operational infrastructure.

Cyber Effects Operations go further. They authorize actions that alter, disrupt, degrade, or destroy target systems or data. This category includes launching encryption software to lock criminal servers, conducting DDoS attacks to take criminal websites offline, deleting stolen data from criminal servers, and deploying tools to wipe or corrupt criminal infrastructure. The memo does not exclude any specific type of effect operation, suggesting that the full range of offensive cyber capabilities is available to private firms operating under the program.

The absence of specific prohibitions is notable. Previous US government cyber operations have operated under strict rules of engagement that limit collateral damage, require minimization of harm to innocent third parties, and mandate careful target validation. The memorandum does not specify whether private firms will operate under equivalent restrictions, nor does it address how the government will ensure that private contractors meet the same standards of precision and restraint that apply to military and intelligence operations.

Historical Context: How Previous Administrations Approached Private-Sector Cyber Offense

The decision to authorize private security firms to conduct offensive cyber operations represents a sharp departure from the policies of both previous administrations. The Obama administration took a cautious approach to private-sector cyber involvement, focusing on information sharing and voluntary cybersecurity standards. The first Trump administration expanded cyber authorities for military and intelligence agencies but did not extend them to the private sector. The Biden administration pursued diplomatic and law enforcement approaches to combating ransomware, including the seizure of criminal infrastructure and the arrest of key individuals, but maintained the prohibition on private-sector offensive operations.

The shift reflects a growing frustration with the limitations of traditional law enforcement and military responses to cybercrime. Criminal organizations operate from jurisdictions that refuse to cooperate with US investigations. They use infrastructure hosted in countries with weak cybercrime laws. They leverage anonymity tools and cryptocurrencies to obscure their identities and financial flows. Law enforcement actions, while occasionally successful, have not stemmed the rising tide of ransomware attacks, business email compromise schemes, and other forms of cyber-enabled financial crime.

The new program attempts to address these limitations by unleashing the private sector’s capabilities. Private security firms have deep expertise in offensive cyber operations, often gained through legitimate penetration testing and vulnerability research. They have tools, techniques, and personnel that rival those of government agencies. And they are not constrained by the bureaucratic processes, interagency coordination requirements, and political considerations that slow government operations.

At the same time, the program introduces risks that previous administrations sought to avoid. Private firms operate on commercial incentives. They may cut corners, take excessive risks, or prioritize speed over precision. They may be more susceptible to foreign intelligence operations aimed at compromising their capabilities. And their personnel, unlike military or intelligence personnel, do not operate under the Uniform Code of Military Justice or equivalent standards of conduct.

Industry Implications: How Security Firms Are Likely to Respond

The cybersecurity industry has already begun to assess the implications of the memorandum. Major firms with established relationships with the US government, including those that currently provide incident response, threat intelligence, and penetration testing services, are the most likely candidates for participation. These firms already hold security clearances, maintain secure facilities, and have experience operating under government direction.

Smaller boutique firms with specialized offensive capabilities may also seek to participate, particularly if the program offers financial incentives or preferential treatment in government contracting. The memorandum does not specify how firms will be selected or what qualifications they must meet, creating uncertainty about the program’s accessibility and the criteria for participation.

Firms that choose to participate will face significant operational and legal challenges. They will need to develop rules of engagement that satisfy government oversight requirements while preserving operational flexibility. They will need to implement robust mechanisms for target validation, collateral damage assessment, and post-operation reporting. They will need to protect their personnel from retaliation by criminal organizations and foreign governments. And they will need to manage the reputational risks associated with being publicly identified as government-authorized hackers.

The program also raises questions about liability. If a private firm’s operation causes collateral damage to critical infrastructure in a foreign country, who bears responsibility? If the firm’s tools are captured and repurposed by criminal organizations, what recourse do victims have? If the firm’s personnel are arrested or detained by foreign authorities, will the US government intervene on their behalf? The memorandum provides no answers to these questions, leaving participating firms to navigate significant legal and operational uncertainties.

How does the new authorization differ from existing private sector cyber operations? The existing model allows private security firms to conduct defensive and intelligence-gathering operations, such as monitoring criminal forums, tracking infrastructure, and alerting victims, but it prohibits them from taking offensive action against criminal systems. The new program removes that prohibition for participating firms, allowing them to hack back, disrupt, and destroy criminal infrastructure under government authorization. This is the key distinction: authorized offensive operations replace prohibited self-help.

Risks of Escalation and Unintended Consequences

The most significant concerns about the new program center on the risks of escalation and unintended consequences. Offensive cyber operations are inherently imprecise. Tools designed to target criminal servers can spread to adjacent systems. Encryption deployed against criminal infrastructure can lock out legitimate users. DDoS attacks designed to take down criminal websites can disrupt internet services for entire regions. The risk of collateral damage increases when operations are conducted by private firms that may lack the government’s experience with target validation and damage assessment.

Criminal organizations may respond to private-sector attacks by escalating their own operations. A group whose infrastructure is destroyed by a private security firm may retaliate directly against the firm, its employees, or its clients. Criminal groups with ties to state actors may seek support from their government sponsors, escalating a law enforcement operation into a state-level confrontation. The memorandum does not address how the government will protect private firms from retaliation or how it will respond if criminal groups target US critical infrastructure in reprisal.

There is also the risk of misidentification. Criminal groups frequently mimic each other’s tactics, use false flags to misdirect attribution, and operate through compromised infrastructure owned by innocent third parties. A private firm acting on imperfect intelligence could attack the wrong target, disrupting legitimate businesses or government operations and creating diplomatic incidents. The memorandum does not specify what due diligence private firms must conduct before launching operations, nor does it address what happens when operations go wrong.

The program also raises concerns about the privatization of state power. By authorizing private companies to conduct offensive cyber operations, the government is delegating a core function of national security to entities that are not subject to the same constitutional constraints, congressional oversight, or public accountability as government agencies. Private firms are not required to comply with the same reporting requirements, they are not subject to the same restrictions on targeting and collection, and they do not have the same institutional safeguards against abuse and mission creep.

The memorandum raises significant legal and constitutional questions that are likely to be tested in court. The Authorization for Use of Military Force (AUMF) passed after the September 11 attacks provides a legal framework for some offensive operations against terrorist groups, but cybercriminal organizations are not covered by that authorization. The memorandum relies on the President’s inherent constitutional authority as Commander in Chief, combined with statutory authorities under the Homeland Security Act and other laws, but the legal foundation for authorizing private companies to conduct offensive cyber operations is untested.

Civil liberties advocates are likely to challenge the program on Fourth Amendment grounds. The Fourth Amendment’s prohibition on unreasonable searches and seizures applies to government actions, but its application to private actors operating under government authorization is legally complex. The memorandum does not address how the program will comply with constitutional requirements for warrants, probable cause, and individualized suspicion. Nor does it address how the government will ensure that private firms do not collect or retain information about US persons that falls outside the scope of authorized operations.

International law presents another set of challenges. The United Nations Charter prohibits states from using force against other states, and customary international law prohibits states from conducting operations that violate the sovereignty of other states. The US government has traditionally argued that cyber operations that do not cause physical damage or casualties do not constitute uses of force, but this position is contested. The memorandum’s authorization of private firms to conduct operations that cause data destruction and system disruption could be viewed by other states as violations of their sovereignty, potentially triggering diplomatic protests, economic retaliation, or even military responses.

The memorandum also implicates the Law of Armed Conflict, which governs the conduct of hostilities during armed conflict. If private firms conduct operations that rise to the level of armed attack, they could be classified as combatants under international law, making them legitimate targets for military action by foreign states. The memorandum does not address how the government will ensure that operations stay within the bounds of peacetime law enforcement rather than crossing into the realm of armed conflict.

Operational Practicalities and the Challenge of Attribution

For the program to succeed, private security firms will need reliable attribution intelligence. Knowing who is behind a criminal operation, where their infrastructure is located, and what systems they control is a prerequisite for any offensive operation. Attribution is notoriously difficult in the cyber domain, where attackers routinely use proxies, VPNs, anonymization tools, and compromised infrastructure to obscure their identities and locations.

The government, through agencies like the NSA, CIA, and FBI, has attribution capabilities that far exceed anything available to the private sector. The memorandum does not specify what intelligence support the government will provide to participating firms, nor does it address how the government will validate firms’ attribution assessments before authorizing operations. If participating firms rely on their own attribution methodologies, the risk of misidentification increases significantly.

Even with good intelligence, the operational challenges are substantial. Criminal infrastructure is often hosted in countries with weak rule of law, limited technical capabilities, and hostile relationships with the United States. Conducting operations against servers in Russia, China, Iran, or North Korea creates legal and practical obstacles that are qualitatively different from operations against servers in allied countries. The memorandum does not address how the program will handle operations in countries where the US government has limited diplomatic leverage or where the risk of escalation is highest.

Comparison with International Approaches

The United States is not the first country to explore private-sector offensive cyber operations. The United Kingdom has developed a framework for government-authorized cyber operations conducted by private contractors, though the scope is more limited and the oversight mechanisms more developed. Israel has a mature ecosystem of private cyber security firms that work closely with government agencies, though the legal framework differs substantially. Several European countries have considered similar programs but have not implemented them, citing concerns about legal clarity, operational control, and international norms.

The US program goes further than any previous national effort in the scope of operations authorized, the degree of autonomy granted to private firms, and the absence of specific operational restrictions. This creates the risk that the program will set a precedent that other countries will follow, potentially leading to a proliferation of private-sector offensive cyber capabilities that operate under uncertain legal frameworks and minimal oversight.

The timing of the memorandum, issued in August 2026, places it in the context of an evolving international debate about norms of responsible state behavior in cyberspace. The United States has been a leading voice in advocating for international norms that prohibit cyber operations targeting critical infrastructure, that require states to prevent their territory from being used for cybercrime, and that promote cooperation in investigating and prosecuting cybercriminals. The new program could be seen as undercutting these norms by authorizing private companies to conduct operations that would violate the sovereignty of other states if conducted by government agencies.

The National Security Presidential Memorandum issued Thursday authorizes private security firms to conduct offensive cyber operations against foreign criminal organizations, marking the first time the US government has formally delegated this authority to the private sector. The program, to be developed by the National Coordination Center under Homeland Security Task Force direction, will allow participating firms to conduct Cyber Surveillance Operations and Cyber Effects Operations against groups engaged in ransomware, sextortion, phishing, financial fraud, and impersonation scams, as long as those groups are not wholly operated under foreign government direction. The Departments of Justice and Homeland Security will provide oversight, but the operational details, qualification requirements, liability protections, and rules of engagement remain undefined, creating significant uncertainty for the firms that will be asked to carry out the operations.

The success or failure of the program will depend on the details that remain to be written. If the government can develop robust oversight mechanisms, clear rules of engagement, reliable attribution intelligence, and effective protection for participating firms, the program could provide a powerful new tool for combating the criminal networks that have caused hundreds of billions of dollars in losses and disrupted critical services across the United States. If the details are inadequate, the program risks unleashing a wave of private-sector cyber operations that cause collateral damage, provoke escalation, undermine international norms, and ultimately leave Americans less secure than they were before. The distinction between a targeted law enforcement tool and a source of uncontrolled cyber conflict will be determined not by the memorandum itself, but by the choices the NCC and its oversight agencies make in the months ahead as they translate the memo’s broad authorizations into operational reality.

Share This Article