Key Takeaways: The White House is turning to private companies to conduct offensive cyber operations against foreign criminal groups, a first-of-its-kind expansion of the public-private security partnership.
Key Takeaways: The White House is turning to private companies to conduct offensive cyber operations against foreign criminal groups, a first-of-its-kind expansion of the public-private security partnership.

President Trump signed a national security memorandum Wednesday authorizing vetted private-sector firms to conduct offensive cyber operations against transnational criminal organizations, citing $20.8 billion in reported consumer losses to cyber-enabled crime in 2025.
"Not exactly 'hack back,' but definitely a major expansion of the private sector's role in offensive cyber operations," said Chris Wysopal, co-founder at Veracode, a software security firm.
The National Security Presidential Memorandum, signed Aug. 12, directs the Department of Homeland Security's National Coordination Center to establish a program overseeing the operations, with executive directors from DHS and the Department of Justice. Participating companies must maintain a bond or escrow of at least $1 million and will conduct "cyber surveillance operations" and "cyber effects operations" — defined as manipulation, disruption, denial, degradation, or destruction of information systems — under federal direction and control.
The memo builds on a March executive order directing agencies to take "rigorous actions" against cyber-enabled crime. With 73 percent of U.S. adults reporting exposure to online scams or attacks, the administration argues the private sector's scale and speed give the United States a "critical offensive cyber advantage" — but critics warn the approach risks misattribution and escalation.
Nick Carr, technical director at Microsoft Threat Intelligence Center and former chief technical analyst at CISA, said attribution in criminal cyber operations is exceptionally difficult. "People are regularly and willingly wrong on pretty important incidents," he wrote on X, adding that few organizations can "repeatably do it right."
Dr. Lukasz Olejnik, an independent cybersecurity and privacy researcher, warned that authorizing private firms to destroy cyber-controlled infrastructure could impact state-linked systems, raising the risk of interstate escalation and conflict. The concern is not purely theoretical: criminal groups frequently operate from jurisdictions with weak enforcement, and infrastructure used for ransomware campaigns often overlaps with systems tied to state actors.
The concerns echo debates that have surrounded private-sector cyber action for years. Successive administrations have increasingly relied on the private sector to strengthen cybersecurity capabilities, though authorizing companies to carry out government-directed offensive operations marks a significant expansion of that relationship. The White House acknowledged the risks, stating that "rigorous procedures" will govern the review and conduct of "limited" cyber operations, which will only be conducted under the direction of the U.S. government.
The United Kingdom has moved in a similar direction, creating the National Cyber Force in 2020 to disrupt and deter cybercriminal groups. In 2023, the UK government published principles emphasizing it would "rarely deploy" offensive capabilities where other responses are better suited. The UK model has been cited by U.S. officials as a reference point for balancing offensive capability with legal and diplomatic constraints.
The program will ensure compliance with the U.S. Constitution, federal laws, and relevant international agreements, according to the White House. The memorandum also establishes a framework in which private sector companies can enter into agreements with other firms as well as federal, state, local, tribal, and territorial agencies to gather threat intelligence on transnational cybercrime groups.
For cybersecurity companies and defense contractors, the memo could open new government contracting opportunities. The $1 million bond requirement indicates the administration expects meaningful participation from established firms rather than small startups. The program's structure — with oversight from both DHS and DOJ — suggests the administration is attempting to address inter-agency coordination concerns that have historically complicated such efforts.
The policy shift comes as ransomware attacks and financial fraud continue to escalate. American consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025, according to White House figures, and the administration argues that "every available tool" should be deployed against transnational cyber threats. The question now is whether the private sector's offensive capabilities can be effectively directed without triggering unintended consequences — a concern that will likely shape the program's implementation in the coming months.
This article is for informational purposes only and does not constitute investment advice.