Trump authorizes private companies to conduct government cyberattacks against foreign criminal networks

2 hours ago 30

The US government just handed a select group of private companies something that used to be reserved for intelligence agencies and military units: the ability to hack back.

President Trump signed a National Security Presidential Memorandum on August 12 titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.” The order authorizes vetted private US companies to conduct limited offensive cyber operations against foreign Cyber-Enabled Transnational Criminal Organizations, or CE-TCOs in the government’s ever-growing acronym library.

What the memorandum actually allows

The program creates two categories of authorized activity. “Cyber Surveillance Operations” involve undetected intelligence collection against foreign criminal networks. “Cyber Effects Operations” go further, aiming to disrupt or degrade the systems those criminal groups rely on.

The program is managed by the National Coordination Center, which was established under Executive Order 14159 on January 20, 2025. Day-to-day oversight falls to the Department of Justice and the Department of Homeland Security.

Every single operation requires written approval from federal authorities before it can proceed. The memorandum also explicitly prohibits any operation that could result in loss of life, serious injury, or escalation to armed conflict.

Participating firms must post a minimum $1 million bond or escrow and face penalties of up to $1 million for noncompliance.

Why now

In 2025, losses from cyber-enabled crimes surpassed $20.8 billion, a figure that reflects everything from ransomware attacks on hospitals to sophisticated fraud operations targeting financial institutions.

The focus on transnational criminal organizations rather than nation-state actors is deliberate. By limiting the scope to criminal groups, the administration avoids the thorniest geopolitical complications, at least on paper.

Market and industry implications

The vetting requirements and compliance infrastructure needed to participate will likely favor larger, established players over startups. The $1 million bond requirement alone puts a floor on who can play.

The implications for digital asset security are worth considering. Many of the transnational criminal organizations targeted by this memorandum are the same groups responsible for cryptocurrency exchange hacks, DeFi exploits, and ransomware campaigns that demand payment in Bitcoin or privacy coins. North Korea-linked groups like Lazarus, for example, have stolen billions in crypto assets over the past several years.

The memorandum does not mention cryptocurrency or digital assets specifically. Any benefit to the crypto ecosystem would come as a byproduct of disrupting criminal operations that happen to target it.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article