US Firms Tapped for Covert Cyber Operations Against Foreign Criminals

The U.S. government is launching a new initiative to combat foreign cybercrime by enlisting the help of vetted private American companies. President Donald Trump signed a National Security Presidential Memorandum earlier this month, establishing a framework that allows these companies, under strict federal direction and oversight, to conduct offensive cyber operations against specific foreign criminal organizations. This marks a significant shift, moving beyond individual defense strategies to a more proactive, government-sanctioned approach targeting the infrastructure of cybercriminals.

A New Front in the Cyber War

The escalating cost of cybercrime in the United States has prompted this novel strategy. The FBI’s Internet Crime Complaint Center (IC3) reported a staggering 1,008,597 complaints in 2025, with reported losses soaring to $20.877 billion – a 26% jump from the previous year. White House officials attribute a substantial portion of these sophisticated attacks, including ransomware, phishing, and elaborate impersonation scams, to foreign-based criminal syndicates. The increasing sophistication of these attacks, often amplified by artificial intelligence, makes them harder for both individuals and law enforcement to detect and combat.

This new memorandum aims to equip the federal government with additional tools to pursue these elusive foreign criminal groups. It allows for two primary types of operations that private companies can undertake with explicit federal authorization:

Strict Oversight and Vetting

Despite the offensive nature of these operations, the program is not a free-for-all for private companies to engage in unauthorized hacking. Participation is contingent upon rigorous government vetting and contractual agreements with either the Department of Justice (DOJ) or the Department of Homeland Security (DHS). Every proposed cyber operation must undergo a thorough review and receive written approval and direction from executive directors within the DOJ and DHS.

The vetting process for participating companies is designed to be comprehensive, examining their technical capabilities, past performance in cyber operations, facility security, and personnel reliability. To ensure accountability, companies may be required to maintain a bond or escrow account of at least $1 million, which could be forfeited in the event of a contractual violation.

Defining the Targets: Beyond Individual Hackers

The memorandum specifically defines its targets not as individual hackers, but as Cyber-Enabled Transnational Criminal Organizations (CE-TCOs). These are foreign entities that perpetrate cyber-enabled crimes against the U.S. government, its citizens, or its interests. Crucially, the program explicitly excludes organizations that are integral parts of foreign governments or operate directly under their command. This distinction is vital, given the intrusive nature of the authorized operations.

Safeguards and Limitations

Recognizing the potential for unintended consequences, the memorandum incorporates safeguards. If an operation inadvertently targets a U.S. person, a system within the United States, or a system controlled by a U.S. entity, the company must immediately halt the operation, implement minimization procedures, and notify the National Coordination Center. Any operation involving U.S. persons or raising constitutional, federal, or international law concerns requires a separate DOJ review and authorization.

Furthermore, operations deemed to have a Critical Outcome – those likely to result in loss of life, serious injury, or constitute an armed attack under international law – are strictly prohibited from approval by DOJ and DHS officials overseeing the program.

Developing the Operational Framework

While the National Security Presidential Memorandum establishes the foundational framework, many detailed operating procedures are still under development. Program leaders have a 60-day window from August 12 to draft rules governing company eligibility, targeting protocols, legal review processes, reporting requirements, and federal oversight mechanisms. Participating companies will also face annual evaluations to ensure continued suitability.

Within 180 days, a status report is due to the White House homeland security adviser and the National Cyber Director, with subsequent annual reports to follow. This phased approach ensures that the program’s implementation is carefully managed.

What This Means for the Public

For the average American, this new policy does not require any immediate changes to personal cybersecurity habits. The impact of this initiative will largely occur behind the scenes, as government-sanctioned cyber operations are conducted against foreign criminal networks. The program offers the federal government a new avenue to pursue cybercriminals, potentially disrupting their operations and gathering valuable intelligence.

However, the effectiveness and safety of these operations will hinge on the meticulous development of the detailed rules and the rigor of federal supervision. As with any powerful new tool, the potential for unintended consequences remains, underscoring the importance of robust oversight and accountability. While this initiative represents a proactive step in combating cybercrime, maintaining strong personal cybersecurity practices continues to be essential for individual protection.

Key Takeaways:

The success of this program will depend on how effectively these detailed rules are implemented and how diligently federal officials oversee the participating companies. It introduces a complex, behind-the-scenes layer to the ongoing fight against cyber threats, complementing, rather than replacing, individual vigilance.

Exit mobile version