The U.S. government will now permit private security firms to conduct offensive cyber operations against overseas criminal groups. President Donald Trump signed a national security memorandum on August 12, directing the Departments of Justice and Homeland Security to create a program for this purpose. This policy marks a significant expansion of the private sector's role in offensive cyber activities, blurring the lines between government foreign policy and commercial enterprise.

The initiative aims to harness the "innovative capabilities" of American businesses to counter transnational criminal organizations (TCOs) that perpetrate cybercrime, fraud, and other schemes against U.S. citizens. The White House stated that American consumers reported over $20.8 billion in losses from cyber-enabled crime in 2025, with 73% of U.S. adults experiencing some form of online scam. The program will allow vetted companies to conduct "cyber surveillance operations" and "cyber effects operations," which can include manipulating, disrupting, denying, degrading, or destroying digital infrastructure, information systems, and hardware controlled by targeted organizations.

The program will be managed by the Homeland Security Task Force's National Coordination Center (NCC) and overseen by co-Executive Directors from the Department of Justice and the Department of Homeland Security. Participating companies must undergo rigorous vetting and will enter into contractual agreements with federal agencies. These companies can also form agreements with other private entities and government agencies at federal, state, local, tribal, and territorial levels to gather threat intelligence and propose cyber operations. The memorandum specifies that companies can only target foreign criminal groups that are not directly part of a foreign government or wholly operated under its direction, though a group will be assumed to meet these conditions unless clear intelligence indicates otherwise. Furthermore, operations that could result in death or serious injury, or constitute an armed attack under international law, are prohibited.

The Departments of Justice and Homeland Security have 60 days to establish operating procedures for the program. These procedures will include standards for company participation, methods for deconflicting operations with military and intelligence communities, and requirements for reporting acquired information on criminal gangs' activities. Companies will also be required to set aside bonds of at least $1 million, which would be forfeited if they violate program rules. Both large and small companies may be eligible to participate if they meet the program's standards.

While the administration views this as a necessary step to combat sophisticated adversaries, some cybersecurity experts have expressed reservations. Concerns include potential escalation risks, the possibility of exposing private companies to foreign retaliation, and the difficulty of vetting targets to ensure they are unaffiliated with foreign governments. Gary Corn, a former staff judge advocate at U.S. Cyber Command, noted that foreign governments often utilize non-state entities, making clear distinctions problematic. He also pointed out that under international law, the U.S. government remains accountable for any cyberattack conducted by a private company, even if it violates program rules. Chris Wysopal, co-founder at Veracode, described the policy as a "big shift" in U.S. cyber policy, representing a major expansion of the private sector's role in offensive cyber operations. U.S. Cyber Command already engages with the private sector through programs like "Under Advisement" to share information on foreign threats, but this new directive authorizes direct participation in offensive actions.