Summary

  • On August 12, Trump enacted a National Security Presidential Memorandum to enable private companies to disrupt foreign cybercriminal organizations.
  • In this initiative, participating firms will operate under the guidance of the DOJ and DHS, post a minimum bond of $1 million, and undergo yearly evaluations.
  • According to the White House, Americans reported losses exceeding $20.8 billion due to cyber-enabled crimes in 2025.

President Donald Trump has signed a memorandum that allows the federal government to engage select U.S. companies in proactive cyber operations targeting foreign criminal networks. This National Security Presidential Memorandum, issued on August 12, establishes a program within the National Coordination Center of the Homeland Security Task Force.

In the White House's words, "This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector," referring specifically to transnational criminal organizations.

“By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” the memorandum states.

The initiative will be overseen by two executive directors, one each from the Department of Justice and the Department of Homeland Security. Private firms that collaborate with either agency will have the opportunity to propose and execute operations aimed at accessing, surveilling, disrupting, or dismantling systems associated with these foreign criminal networks.

The operational process involves a company applying for the program, passing a vetting procedure, and securing a bond or escrow of at least $1 million, which would be forfeited if the company violates any rules. These firms will collect threat intelligence from other businesses or local agencies and then present their operational proposals to the NCC at Homeland Security. No action can be taken until the executive directors review and approve the proposal. The government retains operational authority, and firms can only act with governmental approval.

Authorized Activities for Firms

The memorandum permits "Cyber Surveillance Operations," which include accessing systems without the owner's consent or exceeding authorized access, along with broader offensive measures against networks responsible for ransomware, phishing, financial fraud, and sextortion. Any operations that could result in "Critical Outcomes" are prohibited, and any actions affecting a U.S. individual or a U.S.-based system must cease immediately and follow minimization procedures.

The memorandum emphasizes that "it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime." The scale of the cyber threat justifies this initiative.

Crypto scams alone reportedly cost Americans around $80.7 billion in 2025. North Korean hackers are reportedly utilizing more advanced strategies to launder stolen cryptocurrency, and the government has already seized over $25 million in cryptocurrency linked to investment and romance scams. This new program aims to leverage private sector involvement to enhance these efforts.

Details regarding the program's targeting rules are classified, leaving public information scant. Companies will have 60 days to prepare before implementation guidelines are released.

Daily Debrief Newsletter

Stay updated with the latest news stories, original features, podcasts, and videos every day.