President Donald Trump signs memo letting US agencies hack transnational crime groups abroad

A new presidential memorandum authorises American law enforcement to go on the cyber offensive against foreign criminal networks, and to bring private contractors along for the ride.


President Donald Trump signs memo letting US agencies hack transnational crime groups abroad
Image Credits Credit: The White House

President Donald Trump has signed a National Security Presidential Memorandum authorising US federal law enforcement to conduct offensive cyber operations against transnational criminal organisations operating abroad.

Washington, in short, is giving itself formal permission to hack the hackers, and it is roughly as consequential as that sounds.

The memorandum takes aim at foreign criminal groups that harm Americans through ransomware, phishing, financial fraud, sextortion and the sort of AI-assisted impersonation scams that have exploded over the past year.

The stated aim is to disrupt those operations at source, rather than wait for the money and the harm to reach American shores.

The numbers behind the order are genuinely grim. The White House cites $20.8bn in reported cybercrime losses in 2025, and says 73% of US adults have experienced online scams.

More soberingly, it notes that one in seven young victims of sextortion reported self-harm, a reminder that the human cost of these networks is not measured in dollars alone.

On paper, the programme comes with scaffolding. A new National Coordination Center, sitting under a Homeland Security Task Force and co-directed by the Department of Justice and the Department of Homeland Security, will oversee operations.

The Homeland Security Council is tasked with setting procedures, and the memorandum mandates “rigorous procedures” for review and for compliance with the Constitution, US law and international agreements.

The most eyebrow-raising clause concerns the private sector. The coordination centre is directed to “leverage the capability and innovation of the private sector” to carry out operations under government direction and control.

In other words, private firms could be enlisted to help the state break into criminal infrastructure abroad, a line many governments have been careful never to cross out loud.

That is where the European reader’s eyebrow tends to stay raised. Offensive hacking sanctioned by a state, even against unambiguously nasty targets, is a capability that does not switch off cleanly once it is switched on.

The obvious worry is escalation: criminal groups often share infrastructure with legitimate services, and disrupting one can knock over the other.

Attribution is the second problem. Cyber operations are notoriously hard to trace, which is precisely why criminals like them, and that same murkiness cuts both ways when a government is the one holding the exploit.

A takedown that goes wrong, or lands on the wrong server in the wrong country, is not easily walked back or credibly denied.

Then there is the collateral damage question. The people who run these networks are experts at hiding among ordinary users, so an operation aimed at a scam compound or a ransomware crew risks catching innocent bystanders, foreign businesses or even allied infrastructure in the blast radius, as botnet takedowns have repeatedly shown.

The private-contractor element sharpens all of it. Handing offensive tooling to commercial firms, however tightly the memo insists on “direction and control”, blurs the line between public accountability and private incentive.

Europe has spent years trying to rein in the commercial spyware market for exactly this reason, and watching Washington invite contractors into government cyber-offensives will not go unnoticed in Brussels.

To be fair, the threat is real and the current approach is clearly not working. Ransomware gangs and scam networks have grown fat on the gap between where they operate and where their victims live, and traditional law enforcement, bound by borders, has struggled to keep up with the deepfake-fuelled fraud and fraud economy.

The question is whether the guardrails hold. “Rigorous procedures” and constitutional compliance sound reassuring in a fact sheet, but the real test will come the first time an operation misfires, the first time a contractor oversteps, or the first time an allied government asks who, exactly, authorised the code running on a server in its jurisdiction.

Get the TNW newsletter

Get the most important tech news in your inbox each week.