US President Donald Trump has authorized a new program that will allow vetted private companies to conduct limited offensive cyber operations against foreign criminal organizations under federal supervision. The policy marks a major shift in the US government’s approach to cybercrime, bringing private-sector cybersecurity capabilities into operations that have traditionally been handled by government agencies.
A national security presidential memorandum signed by Trump directs the Department of Justice and Department of Homeland Security to establish a framework for participating companies. The program is intended to target transnational criminal organizations involved in ransomware, financial fraud, sextortion and other cyber-enabled crimes affecting Americans and US interests. Companies will require government approval for individual operations and will operate under federal oversight.
Trump Opens Offensive Cyber Operations to Private Companies
The new policy creates a formal pathway for selected private companies to participate in offensive cyber operations against foreign criminal groups.
Under the program, participating firms could conduct cyber surveillance to gather intelligence and, with government authorization, carry out operations designed to disrupt, manipulate or destroy information systems used by criminal organizations.
This represents a significant departure from the traditional position that private companies can defend their own networks but generally cannot launch offensive cyber operations against attackers.
| Key Detail | Information |
|---|---|
| US president | Donald Trump |
| Policy | National security presidential memorandum |
| Target | Foreign transnational criminal organizations |
| Private-sector role | Cyber surveillance and cyber effects operations |
| Government oversight | Department of Justice and Department of Homeland Security |
| Geographic focus | Foreign jurisdictions |
| Target crimes | Ransomware, fraud, sextortion and other cybercrime |
| Minimum financial safeguard | $1 million bond or escrow |
| Individual approval | Required |
| Program rules | Expected within 60 days |
The policy does not give companies unlimited permission to hack anyone they believe is responsible for an attack.
Companies Must Receive Government Approval
Private firms participating in the program will not have independent authority to launch attacks.
Each operation will have to go through a government approval process, with federal agencies reviewing proposed activities before they are carried out.
The companies will operate under government supervision rather than acting as independent cyber forces.
Approval Process
Private cybersecurity firm
↓
Identifies criminal infrastructure
↓
Develops proposed operation
↓
Submits operation to federal authorities
↓
Justice Department + Homeland Security review
↓
Approval
↓
Government-supervised operation
This structure is designed to keep offensive activity within a government-controlled framework.
The Program Targets Foreign Criminal Organizations
The memorandum focuses on transnational criminal organizations operating from outside the United States.
These groups may target American businesses, citizens or government institutions through ransomware, online fraud and other cybercrime.
The policy specifically distinguishes criminal organizations from foreign governments.
Companies are not being given permission to independently conduct offensive operations against state actors.
Targeting Framework
Foreign criminal organization
↓
Targets US interests
↓
Government identifies threat
↓
Vetted private company
↓
Approved cyber operation
The distinction is important because incorrectly identifying a criminal group could create diplomatic or national-security consequences.
Ransomware Is a Major Target
Ransomware groups are among the most important potential targets of the new program.
These organizations typically compromise computer systems, encrypt data and demand payment from victims.
Private cybersecurity companies often have extensive intelligence about ransomware infrastructure because they investigate attacks and track criminal networks.
Ransomware Response
Ransomware group
↓
Compromises victim
↓
Security company tracks infrastructure
↓
Criminal servers identified
↓
Government review
↓
Approved disruption
↓
Criminal infrastructure weakened
The new framework could allow companies to go beyond simply warning customers and instead participate in government-authorized disruption operations.
Financial Fraud Is Also Included
The memorandum also addresses cyber-enabled financial fraud.
Online criminal organizations can use stolen credentials, malware, phishing infrastructure and compromised systems to steal money from individuals and businesses.
Private-sector cybersecurity firms often have visibility into these networks.
The new program could allow that intelligence to support offensive operations aimed at disrupting the infrastructure behind fraud schemes.
Sextortion and Other Cybercrimes Are Covered
The policy is broader than ransomware and financial fraud.
It also covers other forms of cyber-enabled criminal activity, including sextortion and predatory schemes targeting Americans.
This gives the government flexibility to use private-sector capabilities against a range of international criminal networks.
The Policy Marks a Major Shift in US Cyber Strategy
Historically, offensive cyber operations have largely been conducted by government agencies such as the military, intelligence community and federal law enforcement.
Private companies generally have been limited to defensive actions.
The new program changes that division.
Traditional Model
Cybercriminal attack
↓
Private company defends
↓
Collects evidence
↓
Reports threat
↓
Government investigates
New Model
Cybercriminal attack
↓
Private company investigates
↓
Government authorizes operation
↓
Private company participates in offensive activity
↓
Criminal infrastructure disrupted
The change could significantly expand the number of organizations involved in US cyber operations.
Why the Trump Administration Wants Private-Sector Capabilities
The administration argues that American cybersecurity companies have capabilities and intelligence that are not being fully used in the fight against international cybercrime.
Private companies constantly monitor malicious infrastructure, ransomware gangs and hacking campaigns.
They can sometimes identify criminal activity faster than government agencies because they are already operating across global networks.
Private-Sector Advantage
Security companies
↓
Monitor threats continuously
↓
Track criminal infrastructure
↓
Identify emerging campaigns
↓
Collect technical intelligence
↓
Potentially support government operations
The administration wants to convert some of that private-sector intelligence into operational capability.
Cybersecurity Firms Already Track Criminal Networks
Large cybersecurity companies routinely investigate cybercrime.
They may identify command-and-control servers, malicious domains, compromised infrastructure and other technical indicators connected to criminal groups.
However, finding criminal infrastructure does not automatically give a private company the legal authority to access or disrupt it.
The new program is intended to create a government-approved pathway for such actions.
The Policy Does Not Legalize Independent Hacking Back
One important distinction is that the memorandum does not simply legalize “hacking back.”
US federal law continues to restrict unauthorized access to computer systems.
A company cannot independently decide that another organization attacked it and then launch a retaliatory cyberattack.
Instead, participating companies must enter the government program and receive authorization for specific operations.
What Changes
Unauthorized hacking back
↓
Still prohibited
BUT
Government-approved operation
↓
Permitted within program
↓
Federal oversight
This distinction is central to the policy.
Companies Must Be Vetted
Not every cybersecurity company will be eligible to participate.
The government is expected to establish requirements covering technical capability, security standards, personnel and operational procedures.
The goal is to ensure that only trusted organizations can access the program.
Vetting Process
Private company
↓
Technical evaluation
↓
Security assessment
↓
Government vetting
↓
Program participation
↓
Individual operation approval
This additional layer is intended to reduce the risk of companies misusing offensive capabilities.
Companies Must Post a $1 Million Bond
Participating firms will be required to maintain at least $1 million in bond or escrow.
The financial requirement is designed to create accountability.
If a company violates the program’s rules, the government could potentially forfeit the financial guarantee.
Financial Safeguard
Company joins program
↓
$1 million minimum bond or escrow
↓
Company conducts approved operation
↓
Compliance monitored
↓
Rules followed
OR
↓
Violation
↓
Financial penalty
The requirement also creates an additional cost for companies considering participation.
Operations Must Avoid Americans and US Systems
The program includes restrictions designed to prevent participating companies from targeting Americans or systems located in the United States.
This is intended to reduce the possibility that offensive operations could accidentally affect domestic infrastructure.
Geographic Safeguard
Foreign criminal target
↓
Approved operation
↓
US systems excluded
+
US persons excluded
↓
Foreign infrastructure targeted
However, cyber infrastructure is often distributed across multiple countries, making geographic boundaries difficult to enforce perfectly.
Criminals Often Use Compromised Infrastructure
One of the biggest operational challenges is that cybercriminals frequently use systems belonging to innocent third parties.
A criminal group may compromise cloud servers, routers, websites or computers belonging to unrelated individuals and use them to launch attacks.
Disrupting that infrastructure could therefore affect people who have no connection to the criminal operation.
Potential Collateral Damage
Criminal group
↓
Compromises innocent server
↓
Uses server for attack
↓
Private company identifies infrastructure
↓
Government authorizes operation
↓
Operation affects server
↓
Potential impact on innocent owner
This creates significant technical and legal challenges.
Attribution Is Another Major Risk
Determining who is actually behind a cyberattack can be difficult.
Criminal groups may operate anonymously, use proxy infrastructure or deliberately create false indicators to make investigators believe another organization is responsible.
Some criminal organizations may also have relationships with foreign governments.
Attribution Problem
Cyberattack
↓
Technical evidence
↓
Multiple layers of infrastructure
↓
Possible criminal group
↓
Possible state connection
↓
Uncertainty
If attribution is wrong, an operation intended to target criminals could potentially affect a foreign government or another unrelated organization.
State and Criminal Cyber Activity Can Overlap
The distinction between cybercriminals and state-backed hackers is not always straightforward.
Some criminal groups operate independently but may cooperate with governments.
Others can receive indirect protection or financial support from state actors.
This creates the possibility that a private company could unintentionally become involved in a geopolitical conflict.
Potential Escalation
Private company targets criminal group
↓
Criminal group has hidden state connection
↓
Operation affects state-linked infrastructure
↓
Foreign government responds
↓
Diplomatic or cyber escalation
This is one of the main concerns surrounding the new policy.
Government Agencies Will Review Operations
The memorandum calls for coordination across multiple parts of the US government.
Federal law enforcement, intelligence agencies and other departments may need to ensure that private-sector operations do not interfere with existing investigations or intelligence activities.
This process is commonly referred to as deconfliction.
Deconfliction
Private company proposes operation
↓
Government checks existing operations
↓
Law enforcement investigation
+
Intelligence activity
+
Military operations
+
Diplomatic considerations
↓
Conflicts identified
↓
Operation modified or rejected
↓
Approved operation proceeds
The process is designed to prevent multiple US agencies from unknowingly operating against the same target in conflicting ways.
Why Deconfliction Matters
A private company could identify infrastructure that a government agency is already monitoring.
If the company disrupts that infrastructure, it could destroy intelligence that authorities have been collecting.
It could also alert criminals that they are being watched.
Government review is therefore intended to prevent private operations from interfering with sensitive investigations.
Private Firms Could Gain New Capabilities
For cybersecurity companies, the program could provide an opportunity to move beyond defensive cybersecurity services.
A company could potentially use its technical expertise to actively disrupt criminal infrastructure under government authority.
This could create a new category of government cybersecurity contracts and services.
New Business Model
Cybersecurity intelligence
↓
Threat detection
↓
Criminal infrastructure identified
↓
Government partnership
↓
Authorized offensive operation
↓
Government contract or mission
The commercial potential could attract both large cybersecurity firms and specialized smaller companies.
Participation Could Also Be Risky for Companies
Taking part in offensive cyber operations could expose companies to significant risks.
Criminal organizations could retaliate against participating firms through ransomware, distributed denial-of-service attacks, data theft or other forms of cyber aggression.
Companies could therefore become more attractive targets.
Retaliation Risk
Private company
↓
Participates in offensive operation
↓
Criminal infrastructure disrupted
↓
Criminal group retaliates
↓
Company becomes target
↓
Potential financial and operational damage
The risks could make some companies reluctant to participate even if they have the technical capabilities.
The $1 Million Bond May Not Cover All Risks
The financial guarantee creates accountability, but the potential costs of a major cyber incident could far exceed $1 million.
A participating company could face legal expenses, operational disruptions, reputational damage and retaliation.
The financial requirement therefore provides only one layer of protection.
Companies May Need New Legal Protections
Another unresolved question is how participating companies will be protected from lawsuits and other legal consequences resulting from authorized operations.
Even government-approved cyber activity could potentially affect third parties.
Companies may therefore seek clear legal protections before agreeing to participate.
Legal Questions
Government authorization
↓
Operation approved
↓
Third-party system affected
↓
Who is responsible?
↓
Private company?
↓
Government?
↓
Third-party claims?
The program’s detailed rules will need to address these questions.
The Government Has 60 Days to Develop the Framework
The presidential memorandum establishes the policy but does not provide every operational detail.
The Justice Department and Department of Homeland Security are expected to develop the rules governing participation, targeting, approvals and operations within 60 days.
This means the program remains in its early stages.
Implementation Timeline
Trump signs memorandum
↓
Program announced
↓
Government develops rules
↓
Company vetting framework created
↓
Operational approval process established
↓
Private firms participate
The final rules will determine how broadly the program can actually operate.
Large and Small Companies Could Participate
The administration has indicated that the program could involve companies of different sizes.
This is significant because specialized cybersecurity firms may possess capabilities that larger technology companies do not.
A smaller company focused on a particular threat or technology could potentially contribute to specific operations.
Potential Participants
Large technology companies
+
Cybersecurity firms
+
Threat-intelligence companies
+
Specialized security startups
↓
Government-vetted pool
↓
Mission-specific operations
The structure could create a broader private-sector cyber capability.
The Policy Could Strengthen Public-Private Cybersecurity
The US government already relies heavily on private companies for cybersecurity intelligence.
Cloud providers, internet companies and security firms frequently identify malicious activity and share information with government agencies.
The new program extends that relationship from intelligence sharing toward operational cooperation.
Public-Private Model
Private sector
↓
Threat intelligence
↓
Government
↓
Target analysis
↓
Approved operation
↓
Private-sector technical capability
↓
Cyber threat disruption
The model could become a more important component of US cyber strategy.
But Critics Warn of Escalation
Cybersecurity experts and policy critics have raised concerns about giving private companies a role in offensive cyber operations.
One concern is that companies may not have the same accountability mechanisms as government agencies.
Another is that an operation could escalate unexpectedly if a target turns out to have state connections.
Escalation Risk
Cyber operation
↓
Unexpected target
↓
State connection
↓
Foreign response
↓
Cyber escalation
↓
Potential geopolitical consequences
These risks make strong government oversight essential.
The Policy Could Change the Role of Cybersecurity Companies
Cybersecurity companies have traditionally been hired to protect networks, investigate breaches and respond to incidents.
The new program could expand that role into active disruption.
This would blur the line between private cybersecurity and national-security operations.
Changing Industry Role
Defensive cybersecurity
↓
Threat intelligence
↓
Incident response
↓
Government collaboration
↓
Offensive cyber operations
The shift could create new opportunities but also new responsibilities for the industry.
AI Could Strengthen Private Cyber Operations
Artificial intelligence is increasingly being used by cybersecurity companies to identify threats, analyze large volumes of data and automate defensive responses.
The same technologies could potentially help authorized operators analyze criminal infrastructure and develop operational plans.
However, AI systems would still need to operate within strict legal and government controls.
AI-Enabled Cybersecurity
Large volumes of threat data
↓
AI analysis
↓
Threat identification
↓
Human validation
↓
Government authorization
↓
Controlled operation
AI could therefore become another important capability within the emerging public-private cyber model.
The Policy Reflects a More Aggressive Cybersecurity Posture
Trump’s administration has increasingly emphasized proactive disruption of cyber threats rather than relying primarily on defensive measures.
The new memorandum follows that broader strategy.
Instead of waiting for criminal groups to attack and then responding, the government wants to identify and disrupt their infrastructure before or during attacks.
Defensive vs Offensive
Traditional cybersecurity
↓
Detect
↓
Defend
↓
Recover
New approach
↓
Detect
↓
Identify attacker
↓
Disrupt infrastructure
↓
Reduce threat capability
The policy therefore represents a broader shift toward proactive cyber operations.
What It Means for Cybersecurity Companies
The new program could create opportunities for companies with advanced threat intelligence, penetration testing, malware analysis and offensive-security capabilities.
However, participation would come with substantial compliance and operational requirements.
Companies would need to develop stronger governance systems and ensure that employees follow government-approved procedures.
What It Means for the US Government
For the government, the initiative could expand its operational capabilities without requiring every technical function to be performed internally.
Private companies already have extensive visibility into cybercriminal infrastructure.
The government could potentially combine that visibility with its legal authority and intelligence capabilities.
What It Means for Cybercriminals
The policy could increase the cost and risk of operating international cybercrime infrastructure.
Criminal groups may face not only traditional law enforcement investigations but also government-authorized technical disruption.
This could force criminal organizations to change how they host infrastructure and communicate.
Criminal Adaptation
More offensive operations
↓
Criminal infrastructure disrupted
↓
Groups move infrastructure
↓
Use more compromised systems
↓
Increase anonymity
↓
More complex cybercrime ecosystem
The result could be a continuing cycle between attackers and defenders.
What It Means for Businesses
Businesses could potentially benefit if the program successfully reduces ransomware and other cybercrime.
However, companies may also face new risks if offensive operations create retaliation campaigns.
Organizations involved in cybersecurity may need to prepare for increasingly aggressive responses from criminal groups.
What Investors Should Watch
Investors should watch how the government implements the program and whether major cybersecurity companies participate.
Key indicators include:
- Final program rules
- Number of approved companies
- Government contracts
- Cybersecurity company participation
- Number of authorized operations
- Ransomware disruption activity
- Legal challenges
- International reactions
- Cybercriminal retaliation
- Security incidents involving participants
The success of the program will depend heavily on whether the government can combine private-sector agility with effective oversight.
Key Facts at a Glance
| Metric | Detail |
|---|---|
| US president | Donald Trump |
| Announcement | August 2026 |
| Policy instrument | National security presidential memorandum |
| Target organizations | Foreign transnational criminal organizations |
| Operations | Cyber surveillance and cyber effects |
| Examples of targets | Ransomware, fraud and sextortion networks |
| Private companies | Vetted participants |
| Government control | Required |
| Individual operation approval | Required |
| Minimum bond/escrow | $1 million |
| Implementation period | 60 days for detailed rules |
| Domestic targets | Intended to be excluded |
Infographic: Trump’s New Private Cyber Operations Program
TRUMP ADMINISTRATION
↓
NATIONAL SECURITY MEMORANDUM
↓
VETTED PRIVATE COMPANIES
↓
THREAT INTELLIGENCE
↓
FOREIGN CRIMINAL ORGANIZATION IDENTIFIED
↓
OPERATION PROPOSED
↓
FEDERAL REVIEW
↓
JUSTICE DEPARTMENT
+
HOMELAND SECURITY
+
OTHER AGENCIES
↓
APPROVAL
↓
GOVERNMENT-SUPERVISED OPERATION
↓
SURVEILLANCE
OR
DISRUPTION
OR
DESTRUCTION OF CRIMINAL SYSTEMS
The Bigger Picture
The Trump administration’s decision to allow vetted private companies to participate in government-authorized offensive cyber operations marks a major change in the relationship between the US government and the cybersecurity industry. Private firms have long played a critical role in detecting ransomware, tracking criminal infrastructure and protecting businesses, but their role has traditionally been defensive. The new program creates a formal pathway for those companies to use their capabilities in offensive operations against foreign criminal organizations under federal supervision.
The policy could provide the US government with additional technical resources and speed in the fight against ransomware, fraud and other cybercrime. However, it also introduces significant risks. Cybercriminals often use compromised infrastructure belonging to innocent parties, while attribution can be difficult and criminal groups may have hidden links to foreign governments. A mistake could therefore result in collateral damage, legal disputes or international escalation. The success of the program will depend on how carefully the government defines its rules and supervises participating companies.
Looking Ahead
The immediate next step is for the Justice Department and Department of Homeland Security to develop the detailed rules governing the program. Those rules will determine which companies can participate, how targets are identified, how individual operations are approved and what safeguards will prevent attacks from affecting Americans or US-based systems. The government will also need to establish clear procedures for coordinating operations with intelligence, military and law-enforcement activities.
Over the longer term, the program could reshape the cybersecurity industry by creating a new category of government-authorized offensive services. Companies may gain access to opportunities that were previously reserved for government agencies, but they will also face greater legal, operational and security risks. If the initiative succeeds in disrupting major criminal networks without causing significant collateral damage or geopolitical escalation, it could become a model for deeper public-private cooperation in cybersecurity. If those safeguards fail, however, the program could face legal challenges and resistance from both technology companies and policymakers.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.
