President Trump last week signed a national security presidential memorandum directing federal law enforcement to create a program that would allow vetted private companies to conduct cyber operations against foreign criminal groups, a move the White House described as a major expansion of U.S. capabilities to fight transnational cyber-enabled crime.
The memorandum directs the Homeland Security Task Force’s National Coordination Center to establish the program, overseen by co-executive directors appointed by the Attorney General and the Secretary of Homeland Security. Participating firms would be authorized to carry out two categories of activity: cyber surveillance operations to covertly access systems and gather intelligence, and cyber effects operations to disrupt, degrade, or destroy the information systems and infrastructure used by foreign criminal organizations.
To take part, companies must undergo vetting and sign contracts with the Justice Department and the Department of Homeland Security. The agreements may require a bond or escrow of at least $1 million, which is forfeited if a company violates operational requirements. Companies would need written approval from the executive directors before acting, and proposed operations would go through multi-agency deconfliction involving law enforcement, the State, Treasury, and War Departments, the Justice Department, and the intelligence community.
The memorandum sets limits on what companies can do. It bars operations likely to cause loss of life, serious injury, or actions that rise to the level of a use of force or armed attack under international law. Targeting is restricted to foreign criminal groups that are not part of, or wholly directed by, a foreign government, with entities presumed independent unless clear intelligence establishes a state connection. If a company finds that an operation has breached a U.S. person or domestic system, it must immediately halt and notify the government.
The action does not change the Computer Fraud and Abuse Act, the federal anti-hacking law, and does not authorize companies to “hack back” against attackers on their own. The Justice Department and Homeland Security have 60 days to draft rules governing participation, targeting, approvals, and operations.
The White House said Americans reported losing more than $20.8 billion to cyber-enabled crime in 2025, and that 73% of adults have experienced an online scam or attack. “By partnering with vetted U.S. companies, we will enhance our ability to counter [transnational criminal organization] threats,” the White House said in a fact sheet.
The memorandum drew skepticism from some former officials. “It’s not an incomparably bad idea, but it’s a bad idea,” Paul Rosenzweig, a former Bush administration homeland security official, told NPR
.




