Reported by 1 source

The short version

  • The Trump administration has issued a National Security Presidential Memorandum allowing vetted private sector firms to conduct offensive cyber operations against foreign transnational criminal organizations.
  • Participating companies must meet strict technical and security standards, including a one-million-dollar escrow deposit, while operations are prohibited from causing loss of life or rising to the level of armed attack.
  • Security experts express skepticism regarding the incentives for private firms, noting that many have profited from the current threat landscape and may lack motivation to disrupt it aggressively.

The federal government has formally authorized private security companies to execute offensive cyber operations against foreign criminal organizations, marking a significant departure from previous restrictions on non-state actors in digital warfare. President Donald Trump issued a National Security Presidential Memorandum directing the National Coordination Center, which functions under the Homeland Security Task Force, to establish a framework for these activities. The initiative aims to combat transnational criminal groups that engage in cyber-enabled crimes targeting United States persons, government entities, or broader national interests.

Under the new directive, private firms will be permitted to conduct both cyber surveillance and cyber effects operations. These actions are specifically targeted at organizations involved in ransomware attacks, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams. The memorandum defines eligible targets as foreign groups that are not institutional parts of a foreign government nor wholly operated under its direction. This distinction ensures the program focuses on criminal enterprises rather than state-sponsored actors, although the line between independent criminals and state-aligned proxies often remains blurred in practice.

News Journal

This policy represents the first instance in which the federal government has explicitly permitted private sector entities to perform offensive cyber attacks without requiring individual court-authorized approvals for each action. Previously, such activities were prohibited unless sanctioned through specific judicial processes. The new framework allows participating companies to utilize spyware or launch attacks designed to destroy data or systems belonging to these criminal groups. The memorandum does not exclude certain aggressive tactics, including the use of encryption to lock targets out of their networks or the execution of distributed denial-of-service attacks.

Oversight of the program will be shared between the Departments of Justice and Homeland Security. These agencies are responsible for vetting private companies before they can participate in the initiative. The memorandum outlines minimum standards that firms must satisfy, including demonstrated technical proficiency, a history of successful cyber operations, robust facility security, thorough personnel vetting, and overall reliability. Program executive directors, in coordination with the Homeland Security Council, will determine additional factors necessary to guarantee high confidence in a company’s ability to perform successfully.

Financial accountability is also built into the structure of the program. Participating companies are required to deposit one million dollars into an escrow account. This sum serves as a bond that will be forfeited if the company fails to comply with its contractual obligations as described in the memorandum. This mechanism is intended to ensure that firms adhere strictly to the rules of engagement and do not exceed their authorized scope of operations.

Strict limitations are placed on the potential outcomes of these cyber operations. The memorandum explicitly prohibits actions that result in critical outcomes, defined as those leading to loss of life or serious injury. Furthermore, operations must not rise to the level of use of force or armed attack under international law. These constraints aim to prevent private actors from escalating conflicts into kinetic warfare or causing unintended physical harm while conducting digital operations against criminal infrastructure.

Many details regarding the implementation of this policy remain undefined. The Justice and Homeland Security departments have been directed to deliver specific particulars within the next sixty days. These upcoming guidelines will be crucial in determining how effectively and judiciously the program operates. Questions remain about how oversight will be conducted in real-time, how targets will be selected, and how the government will verify that operations stay within legal and ethical boundaries.

Independent security researchers have expressed caution regarding the new approach. Kevin Beamont, an independent researcher, acknowledged that hacking ransomware groups has merit and already occurs to some extent. However, he emphasized that correct incentives must be in place for the program to succeed. Beamont noted that many private cyber companies have lobbied against significant changes to the status quo because they have profited substantially from the existing threat landscape. He suggested that placing these same companies in charge of stopping the threats may be overly optimistic.

The broader implications of this policy shift extend beyond immediate tactical gains. By outsourcing offensive capabilities to the private sector, the government is altering the traditional monopoly on cyber warfare held by state actors. This move could lead to a more aggressive posture against foreign criminal networks but also raises concerns about accountability and potential misuse. As the details are finalized over the coming months, stakeholders will be watching closely to see how this new model balances effectiveness with the need for strict legal and ethical compliance.

The success of this initiative will likely depend on the rigor of the vetting process and the clarity of the operational guidelines. If private firms are motivated primarily by profit rather than public safety, there is a risk that they may prioritize low-risk targets or engage in activities that generate revenue rather than dismantle criminal infrastructure. Conversely, if properly managed, the program could provide a powerful new tool for disrupting the financial and operational capabilities of transnational criminal organizations that have long evaded traditional law enforcement efforts.

Sources behind this briefing

Go to the original reporting

  • Ars Technica↗Private security firms will soon be allowed to hack overseas cybercriminals