The Trump administration has approved a new framework that allows selected U.S. companies to participate in government-directed offensive cyber operations against foreign transnational criminal groups, marking one of the clearest moves yet to formalize a private-sector role in the nation’s cyber arsenal.[2][4][11]
The authority comes through a National Security Presidential Memorandum issued on August 12, which directs a National Coordination Center to create and oversee a program for “Participating Companies” authorized to conduct cyber surveillance and cyber effects operations against foreign cyber-enabled transnational criminal organizations.[11] The accompanying White House fact sheet says the initiative is intended to “leverage the capability and innovation of the private sector” and encourages companies in the program to enter into agreements with other private entities and all levels of government to gather threat intelligence and propose operations against transnational groups.[2] Officials describe the effort as part of a broader campaign to disrupt global ransomware crews, large-scale fraud rings, and other cyber-enabled criminal networks that target Americans.[2][6][12][14]
This memorandum builds on the administration’s national cyber strategy released earlier this year, which for the first time explicitly envisioned an expanded role for private companies in offensive operations.[1][5][7][10] That strategy pledged to deploy the “full suite” of U.S. defensive and offensive cyber capabilities against adversaries and said the government would create incentives for businesses to help identify and disrupt adversary networks, signaling a shift from a purely government-run offensive posture toward a more integrated public–private approach.[1][5][7][12] Policy analysts noted at the time that the language left open questions about how far private-sector entities might go beyond intelligence sharing to more direct operational support.[1][7][10]
Legal experts and civil liberties advocates are now warning that formalizing corporate participation in offensive cyber operations raises complex questions under existing computer crime and surveillance laws, as well as international norms around sovereignty and the use of force in cyberspace.[1][7][8][10] Commentators on national security law point out that there is no federal statute that clearly authorizes companies to conduct independent “hack back” activities, and that multiple laws instead restrict private entities from accessing or damaging others’ systems without authorization.[1][7][8] As a result, any corporate role is likely to be tightly constrained to actions clearly conducted under U.S. government direction and control, with companies operating more like contractors or deputized agents than autonomous cyber combatants.[1][4][11]
Officials have sought to downplay fears that the administration is unleashing freewheeling corporate cyber offense, emphasizing instead the value of private-sector visibility into malicious activity.[9][13] The national cyber director has said the strategy is not about companies running their own offensive campaigns, but about using their technical telemetry to help the government “illuminate the battlefield” and get ahead of threats.[13] Nonetheless, the new memorandum goes further than previous statements by explicitly authorizing accepted firms to carry out cyber operations themselves under federal supervision, blurring the line between traditional government capabilities and outsourced or co-sourced action in the digital domain.[4][11]
For defenders, the announcement does not introduce any new software vulnerabilities or CVE-tracked flaws; instead, it reshapes the policy and operational environment in which incident response and threat hunting occur.[1][2][11] Security leaders at organizations that may be approached to join the program will need to weigh the potential intelligence and disruption benefits against legal exposure, customer trust issues, and the risk of being drawn into cross-border operations where attribution and escalation dynamics are highly sensitive.[1][4][7][10] Companies outside the program should closely monitor how the initiative evolves, watch for any regulatory changes or guidance, and ensure their own incident response policies clearly prohibit unsanctioned “hack back” activity while preserving avenues to share threat data with government partners and industry peers.[1][7][8][13]
Internationally, the move is likely to be scrutinized by allies and rivals who are already wary of the growing use of offensive cyber tools in counterterrorism and anti-crime campaigns.[6][15] Targeting transnational criminal organizations whose infrastructure and victims are scattered across jurisdictions heightens the risk of unintended diplomatic fallout, misattribution, or collateral impact on third countries’ networks.[6][12][15] How transparently the United States communicates about the program, and how rigorously it controls and audits corporate participation, will shape whether this experiment in public–private cyber offense is viewed as a responsible evolution of policy or a dangerous outsourcing of state power in the digital domain.[1][4][6]
References
- Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations
- Fact Sheet: President Donald J. Trump Expands Capabilities to Combat Transnational Cyber-Enabled Crime
- Trump Enlists Private Sector to Boost Cyber-Offensive Arsenal
- White House Unveils President Trump’s Cyber Strategy for …
- White House formally adds offensive cyberattacks to US …
- Trump Administration Releases Cyber Strategy – Skadden
- New Trump Cyber Strategy Prompts Companies to Mull Legal Limits
- Private-Sector Role Clarified in Offensive U.S. Cyber Strategy
- The Trump Administration’s Cyber Strategy
- Expanding Capabilities to Combat Transnational Cyber-Enabled …
- Trump releases cyberstrategy that is more aggressive than ever
- Trump administration isn’t pushing companies to conduct cyber offense …
- Trump unveils 2026 Cyber Strategy targeting hackers and global …
- [PDF] U.S. Cyber Operations Policy (TOP SECRET/NOFORN)
