Washington: US President Donald Trump has signed a national security memorandum allowing the American government to work with vetted private-sector technology companies on cyber operations against foreign-based transnational criminal organisations. The move marks a significant expansion of the private sector’s role in US offensive cyber operations.
The memorandum, signed on August 12, 2026, is aimed at criminal networks involved in ransomware, financial fraud and other cyber-enabled crimes targeting Americans. Under the new framework, private companies can work with federal authorities to identify threats and propose cyber operations, but the activities remain under government direction and control.
Private companies to join US cyber operations
The new policy expands the US government’s cyber capabilities by bringing private-sector expertise into operations traditionally handled by government agencies.
According to the White House, the memorandum directs the Department of Homeland Security’s Homeland Security Task Force National Coordination Center to establish a programme for working with private companies.
Participating firms can collaborate with federal, state, local, tribal and territorial authorities to gather information about foreign criminal organisations and develop proposals for cyber operations against them.
The objective is to use the technical capabilities of private companies to disrupt criminal networks operating beyond US borders.
What kind of groups can be targeted?
The policy focuses on transnational cyber-enabled criminal organisations, rather than foreign governments.
These groups can include networks involved in ransomware attacks, online financial fraud and other forms of cybercrime that operate across international borders.
The White House said such organisations pose a growing threat to American citizens and businesses.
The memorandum is an expansion of an earlier executive order signed by Trump in March 2026 that directed the federal government to strengthen its response to cybercrime, fraud and predatory schemes targeting Americans.
Cyber operations could disrupt foreign systems
The programme allows authorised operations to go beyond simply monitoring criminal activity.
According to reporting on the memorandum, permitted activities can include cyber surveillance and cyber effects operations, potentially involving the manipulation, disruption or destruction of information systems associated with targeted criminal organisations. (Reuters)
However, private companies will not receive unrestricted authority to conduct cyber warfare independently.
The operations are intended to take place under the direction, control and authority of the US government.
Why Trump is turning to private cyber firms
Private technology companies possess significant cybersecurity capabilities and often have access to technical information that government agencies may not have.
Cybersecurity companies routinely monitor malicious infrastructure, ransomware groups and suspicious online activity around the world.
The Trump administration says bringing these capabilities into government-led operations could make it easier to identify and disrupt criminal networks before they can cause further damage.
The White House described private-sector expertise as an underused resource in the fight against transnational cybercrime.
$1 million financial safeguard
The new arrangement also includes financial safeguards for companies participating in the programme.
Reports say participating firms must maintain a minimum $1 million bond or escrow. The measure is intended to provide accountability if a company violates the conditions governing authorised cyber operations.
The requirement is significant because private companies operating in cyberspace could potentially cause unintended consequences if an operation affects systems belonging to innocent third parties.
Concerns over escalation
The policy has already raised questions among cybersecurity experts and policymakers.
Cyber operations can be difficult to contain because criminal groups frequently use compromised computers, servers and other infrastructure belonging to innocent individuals or organisations.
An operation targeting a criminal network could therefore unintentionally disrupt unrelated systems.
There are also concerns about international escalation. A cyber operation conducted against infrastructure located in another country could create diplomatic complications, particularly if the targeted network has links to government institutions or state-backed actors.
Distinguishing criminals from foreign governments
One of the major challenges will be determining exactly who qualifies as a criminal target.
Cybercrime networks can operate from countries where governments have limited control over online criminal activity. In some cases, criminal groups may also have alleged relationships with government officials or state-linked organisations.
The memorandum is focused on transnational criminal organisations rather than foreign governments, but determining those boundaries in real-world cyber operations could be complicated.
Experts have warned that incorrectly identifying a target could create legal and geopolitical consequences.
A major shift in US cybersecurity policy
Historically, offensive cyber operations have largely been associated with government agencies and national security organisations.
Trump’s new framework represents a move towards a more extensive public-private cyber partnership, allowing commercial firms to contribute directly to government-authorised offensive operations.
The administration argues that this approach can bring faster innovation and specialised technical expertise into the fight against cybercrime.
Critics, however, are likely to question whether commercial companies should have a role in operations that can potentially disrupt or destroy computer systems in foreign countries.
Ransomware and financial fraud in focus
Ransomware and financial fraud are among the major threats driving the initiative.
Ransomware groups can target businesses, hospitals and public institutions, encrypting their data and demanding payments.
International fraud networks have also increasingly used digital platforms to target American victims.
By targeting the infrastructure supporting such criminal operations, US authorities hope to make it more difficult for these organisations to operate.
The administration’s strategy therefore combines law enforcement, intelligence gathering and offensive cyber capabilities.
Government retains control
Despite the expanded role for private companies, the memorandum does not simply give businesses a free hand to launch cyberattacks.
The White House says private-sector operations will occur under federal oversight.
The National Coordination Center will play a central role in coordinating the programme, while the Department of Justice and Department of Homeland Security are expected to oversee implementation.
This distinction is important because it places ultimate responsibility for authorised operations with the US government rather than individual companies.
International implications
The initiative could have implications beyond America’s fight against cybercrime.
Foreign governments may closely monitor how US-linked companies conduct cyber operations against criminal infrastructure located within their borders.
Questions could arise over jurisdiction, sovereignty and responsibility if an operation affects infrastructure hosted in another country.
The policy could also encourage other governments to consider similar partnerships with private cybersecurity companies.
That could lead to a broader shift in how nations conduct cyber operations against criminal networks.
A controversial new era for cyber warfare
The decision reflects the growing importance of cyberspace in national security.
As criminal organisations become more sophisticated, governments are increasingly seeking technological capabilities from the private sector.
Trump’s memorandum formalises a relationship in which private companies can contribute not just defensive cybersecurity services but also government-authorised offensive cyber capabilities.
The challenge will be ensuring that these capabilities are used within clearly defined legal and operational boundaries.
Conclusion
Donald Trump has authorised a new framework allowing vetted US private-sector technology companies to participate in government-directed cyber operations against foreign transnational criminal organisations. The programme will focus on threats including ransomware and financial fraud and will operate under federal oversight.
The move could significantly strengthen America’s ability to disrupt international cybercrime networks by combining government authority with private-sector technical expertise. However, the policy also raises concerns over accountability, unintended damage and the possibility of international escalation.
As the programme takes shape, its success will depend on how effectively US authorities balance the need for aggressive action against cybercriminals with the legal and diplomatic risks of allowing private companies to participate in offensive cyber operations.
