President Donald Trump has opened the door for vetted private U.S. companies to hack foreign cybercrime groups under a new White House programme designed to disrupt criminal networks targeting Americans.
- President Donald Trump has opened the door for vetted private U.S. companies to hack foreign cybercrime groups under a new White House programme designed to disrupt criminal networks targeting Americans.
- Justice Department and Homeland Security contracts can require participating companies to maintain a bond or escrow of at least $1 million, which can be forfeited if a company fails to comply with its agreement.
- Cyber surveillance would involve accessing computer systems without authorization to gather information while attempting to remain undetected, while cyber effects operations could manipulate, disrupt, deny, degrade or destroy information systems and data.
A presidential memorandum signed on August 12 directs the National Coordination Center to establish a programme allowing participating companies to conduct covert cyber surveillance and operations capable of disrupting, degrading or destroying foreign criminal infrastructure. The companies will operate under federal control, with every operation requiring written approval from senior officials at the Justice Department and Department of Homeland Security.
Private Firms Could Go On The Offensive
The memorandum marks a shift from relying solely on government agencies to conduct offensive cyber operations against foreign criminal groups. It calls for vetted private companies to be brought into federal operations targeting what the White House calls cyber-enabled transnational criminal organizations, or CE-TCOs.
The companies would be able to conduct two broad types of operation. Cyber surveillance would involve accessing computer systems without authorization to gather information while attempting to remain undetected, while cyber effects operations could manipulate, disrupt, deny, degrade or destroy information systems and data.
The policy does not give companies an unrestricted right to hack targets on their own. The memorandum says operations will be conducted on behalf of and under the supervision of the federal government, using the government’s legal authorities.
Have a development worth tracking?
Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.
→ Submit a Press ReleaseEvery Operation Requires Approval
The programme will be overseen by two executive directors, one designated by the attorney general and the other by the secretary of Homeland Security. They must coordinate before approving cyber operations, with the memorandum requiring written approval and direction before a participating company can act.
Participating companies will also have to sign contracts with the Justice Department or Homeland Security. Those agreements will require rigorous vetting and compliance with operating procedures that the administration must establish within 60 days of the memorandum.
The companies will have to meet minimum standards covering technical capability, previous cyber operations, facility security, personnel vetting and reliability. The rules are intended to allow both large cybersecurity companies and smaller firms with specialised capabilities to participate.
Foreign Criminal Groups Are The Target
The programme is limited to foreign cyber-enabled transnational criminal organizations. The memorandum defines those groups as foreign organisations conducting cyber-enabled crime against the U.S. government, U.S. persons or U.S. interests that are not institutional parts of a foreign government or wholly directed by one.
The distinction is important because the programme is not framed as a general authorization for private companies to conduct cyberattacks against foreign states. It is aimed at criminal organizations operating across borders, particularly networks involved in cybercrime, fraud and other schemes targeting Americans.
The memorandum also sets procedures for cases in which an operation could unintentionally reach a U.S. person or an information system located in the United States. Companies would be required to stop the operation, take minimization measures and immediately notify the National Coordination Center and Justice Department.
Companies Could Face $1 Million Bond
The White House has also built a financial penalty into the programme. Justice Department and Homeland Security contracts can require participating companies to maintain a bond or escrow of at least $1 million, which can be forfeited if a company fails to comply with its agreement.
The memorandum requires the government to review participating companies at least annually. It also calls for procedures covering coordination among federal law enforcement, the State Department, Treasury, the Defense Department and the intelligence community.
The government will retain control over the operations even when private companies supply the technical expertise. The memorandum says any activity authorized through the programme must remain subject to U.S. government oversight, operational control and legal authority.
Programme Still Being Built
The new system is not yet an open operating licence for cybersecurity companies. The White House has given the programme’s executive directors 60 days to establish operating procedures, including standards for participation, target identification and the approval of cyber operations.
The memorandum also requires a report on the programme within 180 days and annual reports thereafter. No participating companies are identified in the presidential memorandum.
The policy expands the federal government’s cyber response beyond traditional government agencies while keeping operational authority with Washington. Private companies may supply the technical capability, but the government retains the final say over which operations can proceed and how they are conducted.
Activate Terminal Layer
Structural analysis of the systems, pressures, and stakeholders behind this story.





