Trump Memo Lets Private Firms Hack Back at Cybercriminals
4:57
Mon | Aug 17, 2026 | 8:43 AM PDT

President Donald Trump signed a National Security Presidential Memorandum (NSPM) on August 12, 2026, authorizing vetted U.S. private companies to conduct offensive cyber operations against foreign criminal organizations for the first time, provided the operations remain under direct federal government control and oversight.

The memorandum, titled Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, directs the U.S. National Coordination Center (NCC) to establish a formal program permitting "Participating Companies" to run two categories of operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs): Cyber Surveillance Operations, aimed at covertly collecting intelligence, and Cyber Effects Operations, which can manipulate, disrupt, degrade, or destroy an adversary's systems. The NCC was originally established under a January 2025 executive order on immigration enforcement and has since been repurposed as the government's cybercrime coordination hub.

How the program is structured

Every operation under the new program requires joint sign-off from two Program Executive Directors—one designated by the Attorney General and one by the Secretary of Homeland Security. Those directors coordinate approvals but cannot authorize any operation that would generate a "Critical Outcome," which the memo defines as an action likely to result in loss of life, serious injury, or conduct rising to the level of use of force or armed attack under international law.

Participating Companies must enter into direct contractual agreements with the Department of Justice (DOJ) or the Department of Homeland Security (DHS) and undergo vetting against standards the memo directs the Program Executive Directors to finalize within 60 days, covering technical proficiency, facility security, personnel vetting, and operational reliability. Eligibility criteria are meant to accommodate both large firms with broad capacity and smaller, more specialized companies. Once accepted, companies must maintain a bond or escrow of at least $1 million, forfeitable for non-compliance, and face annual re-evaluation to remain in the program.

The framework also lets Participating Companies enter commercial agreements with other private-sector entities and with federal, state, local, tribal, and territorial agencies, both to receive threat information collected through normal business activity and to propose responsive cyber operations to the NCC.

Built-in guardrails

The implementing guidance directed under the memo includes several oversight mechanisms: a DOJ review for any activity directed at a U.S. person or that otherwise implicates constitutional, statutory, or international-law obligations; minimization procedures and mandatory NCC notification if a company discovers it has exceeded the parameters of an approved operation, including unintentional targeting of a U.S. person or a domestic information system; and immediate notification requirements if a company discovers an imminent attack on U.S. critical infrastructure.

A classified annex addresses operational deconfliction across the Departments of State, Treasury, War, Justice, and the intelligence community, as well as the adjudicatory framework meant to confirm that operations target only CE-TCOs.

The Program Executive Directors must deliver a status report to the White House within 180 days of the memo's signing and annually thereafter.

Part of a broader policy push

The memorandum builds directly on Executive Order 14390, signed in March 2026, which directed a government-wide review of tools available to combat cyber-enabled fraud and established a dedicated operational cell within the NCC.

The accompanying White House fact sheet frames this latest action as a response to escalating losses: Americans reported more than $20.8 billion in losses to cyber-enabled crime in 2025, up from the $12.5 billion figure cited when the March order was signed, with ransomware, phishing, financial fraud, sextortion, and impersonation scams named as primary drivers.

The move marks a notable expansion of the private sector's role in offensive cyber activity. Existing federal law, including the Computer Fraud and Abuse Act, has generally barred private companies from conducting cyberattacks or disruption operations without court authorization—a restriction that has kept so-called "hack-back" operations largely off-limits to industry.

Legal and cybersecurity experts have already begun raising questions about how that tension will be managed under the new framework, a debate SecureWorld News will continue to track as the Program Executive Directors finalize implementing guidance over the coming months.

[RELATED: The Ransomware Victim that Hacked Back]

Comments