
President Donald Trump signed a National Security Presidential Memorandum on August 12, 2025, establishing a comprehensive program that allows private companies under federal oversight to conduct offensive cyber operations against criminal groups targeting Americans. According to the latest White House Fact Sheet, this marks a significant expansion of the US cybersecurity framework, where such operations are usually conducted by government agencies. The program will be run by the Department of Homeland Security and coordinated with the Justice Department, with two Executive Directors from both departments overseeing operations. As reported by multiple sources, the memo represents a significant shift for the US, where such operations are usually carried out by the government, and for months the Trump administration has been laying the groundwork for private-sector firms to legally conduct offensive cyber operations. The initiative was announced late Wednesday and represents a sharp pivot from decades of cybersecurity policy that generally prioritized improving corporate defenses and confined offensive cyberoperations to the US military and intelligence agencies.
The updated memorandum provides enhanced capabilities for private sector participation, allowing companies to conduct 'cyber surveillance operations' and 'cyber effects operations' against approved targets. According to the White House Fact Sheet, cyber effects operations include the 'manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon'. To qualify for the program, companies must maintain a bond or escrow of at least $1 million that will be forfeited if they don't comply with contractual agreements. The initiative will be overseen jointly by DHS and the Department of Justice, with the Homeland Security Task Force's National Coordination Center establishing procedures for review and conduct of these limited cyber operations. The memo specifically directs the administration to 'leverage the capability and innovation of the private sector to help conduct these cyber operations under the direction, control, and authority of the U.S. Government'. Participating companies must first be vetted to be included in the program, sign a contract with the government that includes $1 million fines for violations, and receive written approval from officials at the Justice and Homeland Security Departments before proceeding with an attack.
The initiative addresses a massive financial threat, with American consumers reporting losses exceeding $20.8 billion to cyber-enabled crime in 2025. According to the White House Fact Sheet, 73% of U.S. adults have experienced some kind of online scam or attack, while 98% of Americans believe scams pose a threat to individuals in the U.S., with two-thirds saying it is a 'major' threat. The program specifically targets ransomware attacks, phishing campaigns, financial frauds, sextortion schemes, and impersonation scams that are often coordinated by sophisticated transnational criminal organisations based outside the United States. The memo specifically cites ransomware attacks, financial frauds and other crimes run by foreign-based criminal organizations, referred to as 'transnational criminal organizations' in the document. The Trump administration did not brief reporters on the order ahead of its release, with the White House stating that operations would be 'based on intelligence'.
The program establishes a framework where private sector companies that willingly participate are encouraged to enter into agreements with other private entities as well as Federal, State, Local, Tribal, and Territorial agencies to gather TCO threat information and propose cyber operations that address those threats. As reported by the White House Fact Sheet, the program directs the Homeland Security Task Force's National Coordination Center (NCC) to create rigorous procedures for review and conduct of these limited cyber operations, ensuring strict compliance with the U.S. Constitution and laws, as well as applicable international agreements. The memo creates a framework that encourages private sector companies to 'enter into agreements with other private entities, as well as federal, state, local, tribal, and territorial agencies to gather threat information on transnational criminal organizations and propose cyber operations to address those threats'. The initiative is highly polarising due to fears that such activities could lead to unintended consequences and escalation, though advocates argue that tapping a larger pool of professionals would expand the country's ability to counter cyber threats. Amanda Naylor, director of cyberpolicy at the National Security Council, said in a LinkedIn post that the memo would 'give the United States new tools to protect Americans from cybercrime and fraud'.
The new memorandum does not directly address many concerns about liability and international legal exposure for US firms, though it states that the policy is meant to tap into the 'ingenuity of the private sector' to stem the rising costs of cyberattacks. Nick Carr, threat intelligence lead at Microsoft and a former cybersecurity official, expressed concern about 'just how difficult attribution in criminal operations is, and how few organizations can repeatably do it right'. Michael Garcia, who served as associate chief of policy at the Cybersecurity and Infrastructure Security Agency until departing in June, noted that while attribution had improved over the years, 'obfuscation is still a hell of a tactic'. The Trump administration did not respond to questions about the memorandum other than to say operations would be 'based on intelligence'. Vanessa Le, a partner at Latham & Watkins who advises companies on geopolitical risk, said the approach presents 'novel questions for publicly traded companies in the sector' regarding operational risk and disclosure requirements. The memo also contains a classified annex laying out a process to deconflict private-sector hacking with the federal government's own operations, and specifies that attacks will be limited to transnational criminal organizations that are considered separate from a foreign government unless clear intelligence exists establishing such connection.