U.S. Authorizes Private Companies for Offensive Cyber Operations Against Criminals
On August 12-13, 2026, President Trump signed a presidential memorandum creating a program that allows vetted U.S. private companies to conduct offensive cyber operations, including surveillance and system disruption, against transnational criminal organizations, particularly ransomware groups. Overseen by DHS and DOJ, the program requires firms to meet security standards, post escrow, and obtain approval for each operation. Operations risking loss of life or armed attack are prohibited, though a classified annex allows exceptions. This marks a shift from information-sharing to active disruption.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection
Cross-source coverage
Wire timeline
White House Authorizes Private Companies to Conduct Offensive Cyber Operations Against Foreign Cybercriminals
President Donald Trump signed a presidential memorandum on August 12 establishing the first U.S. program that allows vetted private companies to conduct offensive cyber operations, including data and system destruction, against foreign cybercrime organizations. Participating firms must post at least $1 million in escrow and obtain written approval from the Department of Justice and Department of Homeland Security for each operation. The program authorizes two categories: Cyber Surveillance Operations (unauthorized access for intelligence) and Cyber Effects Operations (disruption or destruction). Targets include ransomware crews operating with state tolerance but not formal state control, such as many Russia-based groups. Operations likely to cause loss of life or rise to an armed attack require approval from a classified annex. The policy reverses the administration's public stance from March 2025, when officials ruled out private offensive operations. Experts warn that Americans involved could be classified as non-uniformed combatants overseas.
White House Authorizes Private Companies to Conduct Offensive Cyber Operations Against Foreign Cybercriminals
President Donald Trump signed a presidential memorandum on August 12 establishing the first U.S. program that allows vetted private companies to conduct offensive cyber operations, including data destruction and system disruption, against foreign cybercrime organizations. The program, managed by a National Coordination Center, authorizes two types of activity: 'Cyber Surveillance Operations' (unauthorized access for intelligence gathering) and 'Cyber Effects Operations' (disruption or destruction of systems). Participating firms must post at least $1 million in escrow and obtain written approval from the Department of Justice and Department of Homeland Security for each operation. The policy reverses the administration's earlier stance, as senior officials had publicly ruled out such measures in March. Targets include ransomware groups operating with state tolerance but not formal state control, such as many Russia-based cybercriminal organizations. Operations likely to cause loss of life or rise to an armed attack under international law are prohibited, though a classified annex retains approval authority for such cases. Experts warn that American participants could be classified as non-uniformed combatants while traveling overseas.
U.S. Government to Authorize Private Companies to Conduct Cyber Operations Against Transnational Criminals
The White House announced a new program, created by a presidential memorandum signed by President Donald Trump, that will allow vetted U.S. private companies to conduct cyber operations against transnational criminal organizations under federal direction. The program, overseen by the Departments of Homeland Security and Justice, authorizes companies to disrupt criminal infrastructure and networks. Participating firms must meet technical and security standards, enter contractual agreements, and will be subject to government oversight. Operations are prohibited if they risk loss of life, serious injury, or constitute an armed attack under international law. The initiative builds on a March executive order and a national security strategy emphasizing offensive cyber responses. Experts describe it as a shift from information-sharing to active public-private disruption of cyber threats.
Show 2 older updatesHide older updates
U.S. Government to Authorize Private Companies for Cyber Operations Against Transnational Criminals
President Donald Trump signed a memorandum on August 13, 2026, creating a program under the National Coordination Center that allows vetted U.S. private companies to conduct cyber operations against transnational criminal organizations at the direction of the federal government. The Departments of Homeland Security and Justice will oversee the program, with program executive directors authorized to greenlight operations unless they risk loss of life, serious injury, or constitute an armed attack under international law. Participating companies must enter contractual agreements with DHS or Justice and meet technical proficiency, security, and reliability standards. The initiative aims to shift public-private cybersecurity collaboration from information sharing to active disruption of criminal infrastructure. A report on the program's status will be submitted to the National Cyber Director and other senior officials.
U.S. Government to Authorize Private Companies for Cyber Operations Against Transnational Criminals
President Donald Trump signed a memorandum on August 13, 2026, creating a program under the National Coordination Center that allows vetted U.S. private companies to conduct cyber operations against transnational criminal organizations at the direction of the federal government. The program, overseen by the Departments of Homeland Security and Justice, requires companies to enter contractual agreements and meet standards including technical proficiency, personnel vetting, and reliability. Operations are prohibited if they would cause loss of life, serious injury, or constitute an armed attack under international law. The initiative builds on a March 2026 executive order and national security strategy, marking a shift from information-sharing to active disruption of criminal cyber infrastructure. Program executive directors will draft screening standards within 60 days and report progress to the National Cyber Director.