On August 12, U.S. President Donald Trump signed a memorandum that will allow certified private companies to engage in cyber operations against foreign criminal organizations under federal oversight.
The initiative targets transnational criminal groups involved in ransomware, financial fraud, and other illegal activities in the digital realm. Contractors will be enabled to gather intelligence on these groups' infrastructure and propose targets for precision interventions to authorities.
In addition to gathering intelligence, certified firms will have the authority to carry out impactful actions on information systems, including blocking, disrupting, or destroying hardware and the data contained within.
Program Operations
The National Coordination Center at the Department of Homeland Security will manage the operations, with oversight also provided by the Department of Justice. Private companies will operate “under the guidance, control, and authority of the U.S. government,” and they will not be permitted to independently select targets.
To participate in the program, contractors must undergo a certification process. This includes demonstrating technical competence, proven experience in such operations, and securing their own infrastructures. They must also place a bond or funds in an escrow account of at least $1 million, which can be forfeited for non-compliance.
The list of permissible targets is strictly defined. Companies can only act against foreign criminal entities that are not part of any government and are not under its direct control.
The White House began laying the groundwork for this new approach earlier in the spring. In a March 6 executive order, Trump directed the development of a strategy to combat foreign scam centers and other transnational groups. The order explicitly called for establishing an operational cell within the National Coordination Center and involving the private sector in combating online criminal activities.
At that time, the Department of Justice and the Department of Homeland Security were instructed to leverage technical advancements, intelligence, and practical expertise from commercial cybersecurity firms to identify perpetrators, track their movements, and disrupt their infrastructures.
This new memorandum transforms this directive into a separate program, allowing private contractors to directly participate in government-sanctioned offensive actions.
Involvement of Major Tech Firms
U.S. authorities had previously collaborated with the tech sector, but businesses had only operated within the confines of their services.
In May, the Scam Center Strike Force conducted its first large-scale Disruption Week, which included participation from Apple, Coinbase, Google, Meta, Microsoft, SpaceX, TRM Labs, and others, as reported by the Department of Justice.
Law enforcement provided partners with data regarding specific fraudulent networks from Southeast Asia, enabling the companies to identify accounts and infrastructure elements that violated their platform regulations.
During the operation, over 1.4 million social media and email accounts were blocked, malicious traffic was disrupted, and servers and hosting services for fraudsters were shut down.
As a result of the data provided by authorities, participants froze over $3.8 million in cryptocurrency used for laundering. In Thailand, seven individuals suspected of cyber crimes were arrested following this joint effort.
However, the involvement of the private sector in offensive online actions remains a contentious practice. Reuters journalists noted potential risks, including possible retaliatory aggression, accidental harm to innocents, and coordination challenges between agencies.
It is worth noting that in July, the United Nations Office on Drugs and Crime released a report estimating that by 2025, losses from scam operations in East and Southeast Asia, Australia, and New Zealand could reach as high as $114.1 billion.
