US President Donald Trump has authorized a new program that will allow vetted private companies to conduct limited offensive cyber operations against foreign criminal organizations under federal supervision. The policy marks a major shift in the US government’s approach to cybercrime, bringing private-sector cybersecurity capabilities into operations that have traditionally been handled by government agencies.

A national security presidential memorandum signed by Trump directs the Department of Justice and Department of Homeland Security to establish a framework for participating companies. The program is intended to target transnational criminal organizations involved in ransomware, financial fraud, sextortion and other cyber-enabled crimes affecting Americans and US interests. Companies will require government approval for individual operations and will operate under federal oversight.

Trump Opens Offensive Cyber Operations to Private Companies

The new policy creates a formal pathway for selected private companies to participate in offensive cyber operations against foreign criminal groups.

Under the program, participating firms could conduct cyber surveillance to gather intelligence and, with government authorization, carry out operations designed to disrupt, manipulate or destroy information systems used by criminal organizations.

This represents a significant departure from the traditional position that private companies can defend their own networks but generally cannot launch offensive cyber operations against attackers.

Key DetailInformation
US presidentDonald Trump
PolicyNational security presidential memorandum
TargetForeign transnational criminal organizations
Private-sector roleCyber surveillance and cyber effects operations
Government oversightDepartment of Justice and Department of Homeland Security
Geographic focusForeign jurisdictions
Target crimesRansomware, fraud, sextortion and other cybercrime
Minimum financial safeguard$1 million bond or escrow
Individual approvalRequired
Program rulesExpected within 60 days

The policy does not give companies unlimited permission to hack anyone they believe is responsible for an attack.

Companies Must Receive Government Approval

Private firms participating in the program will not have independent authority to launch attacks.

Each operation will have to go through a government approval process, with federal agencies reviewing proposed activities before they are carried out.

The companies will operate under government supervision rather than acting as independent cyber forces.

Approval Process

Private cybersecurity firm

Identifies criminal infrastructure

Develops proposed operation

Submits operation to federal authorities

Justice Department + Homeland Security review

Approval

Government-supervised operation

This structure is designed to keep offensive activity within a government-controlled framework.

The Program Targets Foreign Criminal Organizations

The memorandum focuses on transnational criminal organizations operating from outside the United States.

These groups may target American businesses, citizens or government institutions through ransomware, online fraud and other cybercrime.

The policy specifically distinguishes criminal organizations from foreign governments.

Companies are not being given permission to independently conduct offensive operations against state actors.

Targeting Framework

Foreign criminal organization

Targets US interests

Government identifies threat

Vetted private company

Approved cyber operation

The distinction is important because incorrectly identifying a criminal group could create diplomatic or national-security consequences.

Ransomware Is a Major Target

Ransomware groups are among the most important potential targets of the new program.

These organizations typically compromise computer systems, encrypt data and demand payment from victims.

Private cybersecurity companies often have extensive intelligence about ransomware infrastructure because they investigate attacks and track criminal networks.

Ransomware Response

Ransomware group

Compromises victim

Security company tracks infrastructure

Criminal servers identified

Government review

Approved disruption

Criminal infrastructure weakened

The new framework could allow companies to go beyond simply warning customers and instead participate in government-authorized disruption operations.

Financial Fraud Is Also Included

The memorandum also addresses cyber-enabled financial fraud.

Online criminal organizations can use stolen credentials, malware, phishing infrastructure and compromised systems to steal money from individuals and businesses.

Private-sector cybersecurity firms often have visibility into these networks.

The new program could allow that intelligence to support offensive operations aimed at disrupting the infrastructure behind fraud schemes.

Sextortion and Other Cybercrimes Are Covered

The policy is broader than ransomware and financial fraud.

It also covers other forms of cyber-enabled criminal activity, including sextortion and predatory schemes targeting Americans.

This gives the government flexibility to use private-sector capabilities against a range of international criminal networks.

The Policy Marks a Major Shift in US Cyber Strategy

Historically, offensive cyber operations have largely been conducted by government agencies such as the military, intelligence community and federal law enforcement.

Private companies generally have been limited to defensive actions.

The new program changes that division.

Traditional Model

Cybercriminal attack

Private company defends

Collects evidence

Reports threat

Government investigates

New Model

Cybercriminal attack

Private company investigates

Government authorizes operation

Private company participates in offensive activity

Criminal infrastructure disrupted

The change could significantly expand the number of organizations involved in US cyber operations.

Why the Trump Administration Wants Private-Sector Capabilities

The administration argues that American cybersecurity companies have capabilities and intelligence that are not being fully used in the fight against international cybercrime.

Private companies constantly monitor malicious infrastructure, ransomware gangs and hacking campaigns.

They can sometimes identify criminal activity faster than government agencies because they are already operating across global networks.

Private-Sector Advantage

Security companies

Monitor threats continuously

Track criminal infrastructure

Identify emerging campaigns

Collect technical intelligence

Potentially support government operations

The administration wants to convert some of that private-sector intelligence into operational capability.

Cybersecurity Firms Already Track Criminal Networks

Large cybersecurity companies routinely investigate cybercrime.

They may identify command-and-control servers, malicious domains, compromised infrastructure and other technical indicators connected to criminal groups.

However, finding criminal infrastructure does not automatically give a private company the legal authority to access or disrupt it.

The new program is intended to create a government-approved pathway for such actions.

The Policy Does Not Legalize Independent Hacking Back

One important distinction is that the memorandum does not simply legalize “hacking back.”

US federal law continues to restrict unauthorized access to computer systems.

A company cannot independently decide that another organization attacked it and then launch a retaliatory cyberattack.

Instead, participating companies must enter the government program and receive authorization for specific operations.

What Changes

Unauthorized hacking back

Still prohibited

BUT

Government-approved operation

Permitted within program

Federal oversight

This distinction is central to the policy.

Companies Must Be Vetted

Not every cybersecurity company will be eligible to participate.

The government is expected to establish requirements covering technical capability, security standards, personnel and operational procedures.

The goal is to ensure that only trusted organizations can access the program.

Vetting Process

Private company

Technical evaluation

Security assessment

Government vetting

Program participation

Individual operation approval

This additional layer is intended to reduce the risk of companies misusing offensive capabilities.

Companies Must Post a $1 Million Bond

Participating firms will be required to maintain at least $1 million in bond or escrow.

The financial requirement is designed to create accountability.

If a company violates the program’s rules, the government could potentially forfeit the financial guarantee.

Financial Safeguard

Company joins program

$1 million minimum bond or escrow

Company conducts approved operation

Compliance monitored

Rules followed

OR

Violation

Financial penalty

The requirement also creates an additional cost for companies considering participation.

Operations Must Avoid Americans and US Systems

The program includes restrictions designed to prevent participating companies from targeting Americans or systems located in the United States.

This is intended to reduce the possibility that offensive operations could accidentally affect domestic infrastructure.

Geographic Safeguard

Foreign criminal target

Approved operation

US systems excluded

+

US persons excluded

Foreign infrastructure targeted

However, cyber infrastructure is often distributed across multiple countries, making geographic boundaries difficult to enforce perfectly.

Criminals Often Use Compromised Infrastructure

One of the biggest operational challenges is that cybercriminals frequently use systems belonging to innocent third parties.

A criminal group may compromise cloud servers, routers, websites or computers belonging to unrelated individuals and use them to launch attacks.

Disrupting that infrastructure could therefore affect people who have no connection to the criminal operation.

Potential Collateral Damage

Criminal group

Compromises innocent server

Uses server for attack

Private company identifies infrastructure

Government authorizes operation

Operation affects server

Potential impact on innocent owner

This creates significant technical and legal challenges.

Attribution Is Another Major Risk

Determining who is actually behind a cyberattack can be difficult.

Criminal groups may operate anonymously, use proxy infrastructure or deliberately create false indicators to make investigators believe another organization is responsible.

Some criminal organizations may also have relationships with foreign governments.

Attribution Problem

Cyberattack

Technical evidence

Multiple layers of infrastructure

Possible criminal group

Possible state connection

Uncertainty

If attribution is wrong, an operation intended to target criminals could potentially affect a foreign government or another unrelated organization.

State and Criminal Cyber Activity Can Overlap

The distinction between cybercriminals and state-backed hackers is not always straightforward.

Some criminal groups operate independently but may cooperate with governments.

Others can receive indirect protection or financial support from state actors.

This creates the possibility that a private company could unintentionally become involved in a geopolitical conflict.

Potential Escalation

Private company targets criminal group

Criminal group has hidden state connection

Operation affects state-linked infrastructure

Foreign government responds

Diplomatic or cyber escalation

This is one of the main concerns surrounding the new policy.

Government Agencies Will Review Operations

The memorandum calls for coordination across multiple parts of the US government.

Federal law enforcement, intelligence agencies and other departments may need to ensure that private-sector operations do not interfere with existing investigations or intelligence activities.

This process is commonly referred to as deconfliction.

Deconfliction

Private company proposes operation

Government checks existing operations

Law enforcement investigation

+

Intelligence activity

+

Military operations

+

Diplomatic considerations

Conflicts identified

Operation modified or rejected

Approved operation proceeds

The process is designed to prevent multiple US agencies from unknowingly operating against the same target in conflicting ways.

Why Deconfliction Matters

A private company could identify infrastructure that a government agency is already monitoring.

If the company disrupts that infrastructure, it could destroy intelligence that authorities have been collecting.

It could also alert criminals that they are being watched.

Government review is therefore intended to prevent private operations from interfering with sensitive investigations.

Private Firms Could Gain New Capabilities

For cybersecurity companies, the program could provide an opportunity to move beyond defensive cybersecurity services.

A company could potentially use its technical expertise to actively disrupt criminal infrastructure under government authority.

This could create a new category of government cybersecurity contracts and services.

New Business Model

Cybersecurity intelligence

Threat detection

Criminal infrastructure identified

Government partnership

Authorized offensive operation

Government contract or mission

The commercial potential could attract both large cybersecurity firms and specialized smaller companies.

Participation Could Also Be Risky for Companies

Taking part in offensive cyber operations could expose companies to significant risks.

Criminal organizations could retaliate against participating firms through ransomware, distributed denial-of-service attacks, data theft or other forms of cyber aggression.

Companies could therefore become more attractive targets.

Retaliation Risk

Private company

Participates in offensive operation

Criminal infrastructure disrupted

Criminal group retaliates

Company becomes target

Potential financial and operational damage

The risks could make some companies reluctant to participate even if they have the technical capabilities.

The $1 Million Bond May Not Cover All Risks

The financial guarantee creates accountability, but the potential costs of a major cyber incident could far exceed $1 million.

A participating company could face legal expenses, operational disruptions, reputational damage and retaliation.

The financial requirement therefore provides only one layer of protection.

Companies May Need New Legal Protections

Another unresolved question is how participating companies will be protected from lawsuits and other legal consequences resulting from authorized operations.

Even government-approved cyber activity could potentially affect third parties.

Companies may therefore seek clear legal protections before agreeing to participate.

Legal Questions

Government authorization

Operation approved

Third-party system affected

Who is responsible?

Private company?

Government?

Third-party claims?

The program’s detailed rules will need to address these questions.

The Government Has 60 Days to Develop the Framework

The presidential memorandum establishes the policy but does not provide every operational detail.

The Justice Department and Department of Homeland Security are expected to develop the rules governing participation, targeting, approvals and operations within 60 days.

This means the program remains in its early stages.

Implementation Timeline

Trump signs memorandum

Program announced

Government develops rules

Company vetting framework created

Operational approval process established

Private firms participate

The final rules will determine how broadly the program can actually operate.

Large and Small Companies Could Participate

The administration has indicated that the program could involve companies of different sizes.

This is significant because specialized cybersecurity firms may possess capabilities that larger technology companies do not.

A smaller company focused on a particular threat or technology could potentially contribute to specific operations.

Potential Participants

Large technology companies

+

Cybersecurity firms

+

Threat-intelligence companies

+

Specialized security startups

Government-vetted pool

Mission-specific operations

The structure could create a broader private-sector cyber capability.

The Policy Could Strengthen Public-Private Cybersecurity

The US government already relies heavily on private companies for cybersecurity intelligence.

Cloud providers, internet companies and security firms frequently identify malicious activity and share information with government agencies.

The new program extends that relationship from intelligence sharing toward operational cooperation.

Public-Private Model

Private sector

Threat intelligence

Government

Target analysis

Approved operation

Private-sector technical capability

Cyber threat disruption

The model could become a more important component of US cyber strategy.

But Critics Warn of Escalation

Cybersecurity experts and policy critics have raised concerns about giving private companies a role in offensive cyber operations.

One concern is that companies may not have the same accountability mechanisms as government agencies.

Another is that an operation could escalate unexpectedly if a target turns out to have state connections.

Escalation Risk

Cyber operation

Unexpected target

State connection

Foreign response

Cyber escalation

Potential geopolitical consequences

These risks make strong government oversight essential.

The Policy Could Change the Role of Cybersecurity Companies

Cybersecurity companies have traditionally been hired to protect networks, investigate breaches and respond to incidents.

The new program could expand that role into active disruption.

This would blur the line between private cybersecurity and national-security operations.

Changing Industry Role

Defensive cybersecurity

Threat intelligence

Incident response

Government collaboration

Offensive cyber operations

The shift could create new opportunities but also new responsibilities for the industry.

AI Could Strengthen Private Cyber Operations

Artificial intelligence is increasingly being used by cybersecurity companies to identify threats, analyze large volumes of data and automate defensive responses.

The same technologies could potentially help authorized operators analyze criminal infrastructure and develop operational plans.

However, AI systems would still need to operate within strict legal and government controls.

AI-Enabled Cybersecurity

Large volumes of threat data

AI analysis

Threat identification

Human validation

Government authorization

Controlled operation

AI could therefore become another important capability within the emerging public-private cyber model.

The Policy Reflects a More Aggressive Cybersecurity Posture

Trump’s administration has increasingly emphasized proactive disruption of cyber threats rather than relying primarily on defensive measures.

The new memorandum follows that broader strategy.

Instead of waiting for criminal groups to attack and then responding, the government wants to identify and disrupt their infrastructure before or during attacks.

Defensive vs Offensive

Traditional cybersecurity

Detect

Defend

Recover

New approach

Detect

Identify attacker

Disrupt infrastructure

Reduce threat capability

The policy therefore represents a broader shift toward proactive cyber operations.

What It Means for Cybersecurity Companies

The new program could create opportunities for companies with advanced threat intelligence, penetration testing, malware analysis and offensive-security capabilities.

However, participation would come with substantial compliance and operational requirements.

Companies would need to develop stronger governance systems and ensure that employees follow government-approved procedures.

What It Means for the US Government

For the government, the initiative could expand its operational capabilities without requiring every technical function to be performed internally.

Private companies already have extensive visibility into cybercriminal infrastructure.

The government could potentially combine that visibility with its legal authority and intelligence capabilities.

What It Means for Cybercriminals

The policy could increase the cost and risk of operating international cybercrime infrastructure.

Criminal groups may face not only traditional law enforcement investigations but also government-authorized technical disruption.

This could force criminal organizations to change how they host infrastructure and communicate.

Criminal Adaptation

More offensive operations

Criminal infrastructure disrupted

Groups move infrastructure

Use more compromised systems

Increase anonymity

More complex cybercrime ecosystem

The result could be a continuing cycle between attackers and defenders.

What It Means for Businesses

Businesses could potentially benefit if the program successfully reduces ransomware and other cybercrime.

However, companies may also face new risks if offensive operations create retaliation campaigns.

Organizations involved in cybersecurity may need to prepare for increasingly aggressive responses from criminal groups.

What Investors Should Watch

Investors should watch how the government implements the program and whether major cybersecurity companies participate.

Key indicators include:

  • Final program rules
  • Number of approved companies
  • Government contracts
  • Cybersecurity company participation
  • Number of authorized operations
  • Ransomware disruption activity
  • Legal challenges
  • International reactions
  • Cybercriminal retaliation
  • Security incidents involving participants

The success of the program will depend heavily on whether the government can combine private-sector agility with effective oversight.

Key Facts at a Glance

MetricDetail
US presidentDonald Trump
AnnouncementAugust 2026
Policy instrumentNational security presidential memorandum
Target organizationsForeign transnational criminal organizations
OperationsCyber surveillance and cyber effects
Examples of targetsRansomware, fraud and sextortion networks
Private companiesVetted participants
Government controlRequired
Individual operation approvalRequired
Minimum bond/escrow$1 million
Implementation period60 days for detailed rules
Domestic targetsIntended to be excluded

Infographic: Trump’s New Private Cyber Operations Program

TRUMP ADMINISTRATION

NATIONAL SECURITY MEMORANDUM

VETTED PRIVATE COMPANIES

THREAT INTELLIGENCE

FOREIGN CRIMINAL ORGANIZATION IDENTIFIED

OPERATION PROPOSED

FEDERAL REVIEW

JUSTICE DEPARTMENT

+

HOMELAND SECURITY

+

OTHER AGENCIES

APPROVAL

GOVERNMENT-SUPERVISED OPERATION

SURVEILLANCE

OR

DISRUPTION

OR

DESTRUCTION OF CRIMINAL SYSTEMS

The Bigger Picture

The Trump administration’s decision to allow vetted private companies to participate in government-authorized offensive cyber operations marks a major change in the relationship between the US government and the cybersecurity industry. Private firms have long played a critical role in detecting ransomware, tracking criminal infrastructure and protecting businesses, but their role has traditionally been defensive. The new program creates a formal pathway for those companies to use their capabilities in offensive operations against foreign criminal organizations under federal supervision.

The policy could provide the US government with additional technical resources and speed in the fight against ransomware, fraud and other cybercrime. However, it also introduces significant risks. Cybercriminals often use compromised infrastructure belonging to innocent parties, while attribution can be difficult and criminal groups may have hidden links to foreign governments. A mistake could therefore result in collateral damage, legal disputes or international escalation. The success of the program will depend on how carefully the government defines its rules and supervises participating companies.

Looking Ahead

The immediate next step is for the Justice Department and Department of Homeland Security to develop the detailed rules governing the program. Those rules will determine which companies can participate, how targets are identified, how individual operations are approved and what safeguards will prevent attacks from affecting Americans or US-based systems. The government will also need to establish clear procedures for coordinating operations with intelligence, military and law-enforcement activities.

Over the longer term, the program could reshape the cybersecurity industry by creating a new category of government-authorized offensive services. Companies may gain access to opportunities that were previously reserved for government agencies, but they will also face greater legal, operational and security risks. If the initiative succeeds in disrupting major criminal networks without causing significant collateral damage or geopolitical escalation, it could become a model for deeper public-private cooperation in cybersecurity. If those safeguards fail, however, the program could face legal challenges and resistance from both technology companies and policymakers.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.