Clear reporting on the stories that matter
DP
Daily Pulse · August 22, 2026
Tech

U.S. Government Authorizes Private Firms for Cyber Operations Against Foreign Criminal Organizations

A new presidential memorandum establishes a framework for vetted American companies to conduct federally directed cyber operations targeting foreign criminal groups responsible for cyber-enabled crimes.

U.S. Government Authorizes Private Firms for Cyber Operations Against Foreign Criminal Organizations

The United States government is moving to confront foreign criminal organizations responsible for cyber-enabled crimes by involving private sector expertise. Earlier this month, President Donald Trump signed a National Security Presidential Memorandum creating a framework that permits vetted U.S. companies to undertake cyber operations against specific foreign criminal groups, all under federal direction and supervision.

This memorandum outlines two primary categories of permitted activity. Participating companies could covertly gather intelligence from targeted computer systems. With explicit federal approval, they could also manipulate, disrupt, deny access to, degrade, or destroy systems and digital infrastructure controlled by these targeted criminal organizations.

Rising Tide of Cybercrime and Advanced Threats

Cybercrime continues to inflict substantial financial damage on Americans. The FBI's Internet Crime Complaint Center recorded 1,008,597 complaints in 2025, with reported losses reaching an alarming $20.877 billion. This figure represents a 26% increase from 2024. According to the White House, sophisticated campaigns involving ransomware, phishing, financial fraud, and impersonation scams targeting American citizens and U.S. interests are largely attributed to foreign-based criminal organizations.

Advancements in technology are making some of these attacks increasingly difficult to detect. Artificial intelligence (AI), for instance, is being utilized by criminals to craft more convincing impersonation scams and other types of cyberattacks. Furthermore, stolen personal information often continues to circulate long after the initial crime, contributing to repeat victimizations, particularly in identity theft cases. The new government initiative is designed to provide an additional avenue for federal authorities to pursue certain foreign criminal organizations engaged in cyber-enabled illicit activities.

Defining Permitted Operations and Oversight

The memorandum establishes two distinct types of operations that participating companies can undertake under federal authority:

  • Cyber Surveillance Operation: This involves surreptitiously accessing targeted computer systems to collect information or intelligence. These operations are intended to remain undetected and may involve accessing systems without the explicit authorization of the owner or operator.
  • Cyber Effects Operation: These operations are designed to manipulate or disrupt information systems. They can also involve denying access, degrading systems, or destroying information and infrastructure controlled through those systems. It is crucial to note that this framework does not grant private companies unilateral permission to engage in hacking against suspected criminals.

Companies wishing to participate in this program must gain government acceptance and enter into contractual agreements with either the Department of Justice (DOJ) or the Department of Homeland Security (DHS). All operations conducted through the program must be carried out on behalf of the federal government and under its direct supervision.

The executive directors from the DOJ and DHS overseeing the program are required to review each cyber operation package and provide written approval and specific direction before any participating company can proceed. Companies will also undergo stringent vetting, which may assess their technical proficiency, history in cyber operations, facility security, personnel vetting, and overall reliability. The program's rules are designed to allow participation from both large corporations and smaller, specialized companies.

Furthermore, the DOJ or DHS may mandate that a participating company maintain a bond or escrow account of at least $1 million. This money could be forfeited if the company breaches its contractual agreement. The public memorandum does not disclose which companies will be participating in the program.

Targeting, Safeguards, and Future Development

The program is specifically designed to target

cybercrimeforeign criminal organizationscyber operationsU.S. governmentprivate cybersecurity firmsnational securitycyber surveillancecyber effects

The latest