Trump Permits US Private Companies to Conduct Cyberattacks on Foreign Criminal Networks
President Donald Trump has issued a National Security Presidential Memorandum enabling approved American corporations to conduct offensive cyber operations against foreign criminal organisations, marking a significant shift in U.S. policy.
Key Details of the Memorandum
President Donald Trump has issued a National Security Presidential Memorandum enabling approved American corporations to conduct offensive cyber operations against foreign criminal organisations, marking a significant shift in U.S. policy. The directive, signed on August 12, allows vetted firms to engage in hacking and sabotage activities targeting ransomware, phishing, and sextortion networks that threaten U.S. citizens. This represents the first official framework for private-sector “hack-back” operations, a practice previously restricted by federal laws.
Regulated Process and Oversight
The memorandum explicitly states that private entities do not have unrestricted authority to retaliate against cyber threats. Instead, it establishes a regulated process requiring written approval from federal officials for each operation. Unauthorized actions remain subject to legal consequences under the Computer Fraud and Abuse Act. The program will be overseen by the Homeland Security Task Force’s National Coordination Center, with joint leadership from the Attorney General and Secretary of Homeland Security. Participating companies are permitted to conduct surveillance, deploy spyware, and execute disruptive measures against criminal infrastructure, but must halt operations immediately upon federal directive and report all activities.
Legal and Expert Concerns
Legal experts have raised concerns about unresolved questions within the framework. The memorandum does not clarify liability for collateral damage caused by authorised operations, nor does it address the legal status of employees carrying out state-directed actions abroad. Cybersecurity analyst Robert Graham noted the policy effectively delegates authority to law enforcement to define permissible private-sector activities, with any recovered assets likely transferred to the government.
Cybersecurity analyst Robert Graham noted the policy effectively delegates authority to law enforcement to define permissible private-sector activities, with any recovered assets likely transferred to the government.
Implications and Future Outlook
The cybersecurity community remains divided. Proponents argue that private firms possess advanced capabilities that could enhance efforts to counter persistent threats, particularly amid reported reductions in federal cybersecurity staffing. Critics, however, warn of heightened risks of retaliation from foreign entities and potential escalation in cyber conflicts. The policy’s implementation will face scrutiny from international partners, as authorised operations may intersect with foreign infrastructure, raising jurisdictional and diplomatic challenges. The memorandum builds on an earlier executive order from March 2026 addressing cybercrime and fraud, aligning with a broader national strategy that hinted at expanded private-sector involvement in offensive cyber operations. The initiative underscores a growing emphasis on leveraging corporate resources to combat transnational criminal networks, though its long-term impact on cybersecurity dynamics remains uncertain.
