Private US companies can now run cyber operations abroad. State-backed hackers are excluded

A presidential memorandum lets vetted private companies run offensive cyber operations against foreign criminal groups, under federal direction. Groups that are part of a foreign government, or working wholly at its direction, are excluded.


Private US companies can now run cyber operations abroad. State-backed hackers are excluded
Image Credits Credit: The White House

Donald Trump signed the memorandum on 12 August and the White House published it that night.

It runs to five sections. A National Coordination Center creates and manages the programme. Two Program Executive Directors oversee it. The Attorney General designates one, and the Secretary of Homeland Security designates the other.

What the White House says it is for

Section 1 sets out the reasoning. Transnational criminal organisations “pose a growing threat to American citizens, businesses, and national security”, the memorandum states.

It declares a policy of using all instruments of national power, “including the innovative capabilities of the private sector”. It also says American businesses’ capabilities “have historically been underutilized” in disrupting criminal networks.

The accompanying fact sheet puts figures to it. American consumers lost $20.8bn to cyber-enabled crime in 2025.

It states that 73% of US adults have experienced online scams or attacks. It puts at 98% the share who consider scams a threat to the country. One in seven young sextortion victims reported self-harm.

The administration says these campaigns target seniors, children and low-income families through ransomware, phishing, fraud and sextortion.

What the memorandum authorises

Section 4 defines two kinds of operation. A Cyber Surveillance Operation collects information or intelligence. It involves accessing systems without authorisation, with “the intent to remain undetected”.

A Cyber Effects Operation is activity that results in “the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure”.

TechCrunch reports that surveillance may include the use of spyware.

Who can be targeted, and who cannot

The memorandum defines its target as a cyber-enabled transnational criminal organisation. That means “any foreign group that conducts cyber-enabled crime” against the US government, a US person or US interests.

The definition then excludes two categories. A group that is an institutional part of a foreign government does not qualify. Nor does one wholly operated under a foreign government’s direction.

Several outlets note what that leaves out. North Korean hackers work at state direction, Politico reported. The desk has covered how they build their own AI tools.

Politico also reports on the grey areas. Many Eastern European gangs are thought to operate with the tacit consent of the Russian government. Chinese and Iranian state hackers sometimes moonlight as criminals.

It is not hack-back

Several outlets described the memorandum as a licence to hack back. TechCrunch, whose security editor read the document, reports that it stops short of that.

Hacking back describes a victim striking at whoever attacked it, on its own initiative. Under this programme, companies act under contract, against approved targets, supervised by the federal government.

TechCrunch also notes the longstanding US position. Held across administrations, it is that private firms may defend against attacks but not launch them.

The desk covered the signing as a cyber memo aimed at transnational crime groups.

What companies have to do

Section 3 gives the Program Executive Directors 60 days to establish operating procedures. An initial report is due within 180 days.

Minimum standards will cover technical proficiency, experience of cyber operations, facility security, personnel vetting and reliability. Eligibility must accommodate both large companies and “smaller, more agile companies”.

Companies must disclose all contractual relationships to the National Coordination Center. They must also maintain a bond or escrow of “not less than $1 million” against non-compliance.

Each company faces review of its continued participation at least annually. The Program Executive Directors must review every cyber operations package and give written approval before anything happens.

The limits the memorandum sets

Operations may not produce what the document calls Critical Outcomes. Those are actions likely to result in loss of life or serious injury. They also include anything rising to the level of use of force or armed attack under international law.

Activity directed at a US person must receive “any necessary authorization, judicial or otherwise, prior to approval”.

One clause covers mistakes. It applies to unintentional targeting of a US person, a system in the United States, or a system controlled by a US person. The company must cease, conduct minimisation and notify immediately.

Companies must also alert the government to imminent attacks on US critical infrastructure. Section 5 states that the memorandum creates “no right or benefit, substantive or procedural, enforceable at law or in equity”.

What supporters say

Industry figures have welcomed it. Joe Lin is chief executive of Twenty, which builds offensive tools for the government. “For years we’ve called the American technology industry a strategic asset but left it on the cyber sidelines,” he said.

Mike Centrella is head of public policy at SecurityScorecard. He told Nextgov the memorandum “represents an important shift in how the United States approaches cyber threats originating overseas”.

He described a change of method. Public-private work moves from sharing threat information towards using government authorities and private capabilities to disrupt criminal networks.

What critics say

Jake Williams, vice-president of research and development at Hunter Strategy, raised a risk to individuals. “Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas,” he told TechCrunch.

He added that “the allegations that an American participated in these ops need not be true”. Williams described the policy as half-baked and said he was not convinced it would resist abuse.

He also said the memorandum has a classified addendum, which he expects addresses how targets are chosen.

TechCrunch reports that the policy is likely to face legal challenges. It also asked the White House whether any companies are already participating. A spokesperson did not answer.

The legal question

The Computer Fraud and Abuse Act prohibits unauthorised access, and a memorandum does not amend a statute.

Lawyers at Jenner & Block, writing for Lawfare, pointed to section 1030(f). It exempts lawfully authorised investigative, protective or intelligence activity by a government agency.

Their conclusion was reported by The Register. “No court has addressed whether this exception provides any protection for private-sector entities engaged to perform these activities on behalf of the US government,” they wrote.

Skadden lawyers reached a similar view in March. Involving the private sector in offensive cyber operations would likely require further legal and regulatory change, they wrote.

The context reported around it

TechCrunch notes that the memorandum arrives after cuts and layoffs at the Cybersecurity and Infrastructure Security Agency since January 2025. Gizmodo reports that the proposed 2027 budget would cut the agency by a further $707m.

California announced its own AI Cyber Defense Program on 10 August. It puts an AI cybersecurity officer in each state agency, with a plan due within 120 days.

TechCrunch also reports intrusions at local water providers in more than a dozen states. Intelligence officials privately attribute those to Iranian government hackers.

Attacks are becoming faster as well. Taiwan says an AI-driven campaign compromised its government in four days. A vishing campaign reached Blackstone and KKR by telephone.

Security firms have had a strong year. CrowdStrike and Palo Alto Networks hit record highs this month.

What happens next

The operating procedures are due within 60 days, and no operation can be approved before they exist. The first report follows at 180 days.

Three questions remain open. Which companies will take part. What the classified addendum contains. And whether Congress or the courts will test the legal basis.

Get the TNW newsletter

Get the most important tech news in your inbox each week.