White House Memo Lets Vetted Firms Run Offensive Cyber Ops Against Foreign Crime Groups

White House memorandum authorizing private firms to run offensive cyber operations against foreign criminal organizations

Written by

in

A national security presidential memorandum signed on August 12, 2026 directs the National Coordination Center (NCC), a component of the Homeland Security Task Force, to stand up a program allowing vetted private security companies to conduct cyber operations against foreign criminal organizations under U.S. government authority. The framework is intended to disrupt ransomware, phishing, financial fraud, sextortion and impersonation schemes run by transnational criminal organizations (TCOs), which the administration says cost U.S. consumers more than $20.8 billion in 2025.

What the memo authorizes

Under the memorandum, the NCC will create, manage and maintain a program to authorize participating companies to run “Cyber Surveillance Operations and Cyber Effects Operations” against foreign Cyber-Enabled Transnational Criminal Organizations. The program will be jointly overseen by two Executive Directors, one designated by the Attorney General at the Department of Justice and one designated by the Secretary of Homeland Security, according to a White House fact sheet released the same day as the memo.

Operations carried out under the program must comply with the U.S. Constitution, federal law and applicable international agreements. Cyber operations can only be approved after coordination between the two Program Executive Directors, and any resulting operational action will be conducted exclusively on behalf of and under the supervision of the federal government.

How private firms can participate

Companies that want to take part must enter into contractual agreements with either the Department of Justice or the Department of Homeland Security. Each participating company will undergo rigorous vetting before the contract is signed and must operate under the strict procedures laid out in the implementation guidance called for by the memo.

The framework also lets participating companies enter into separate commercial agreements with:

  • Other private-sector entities, which can share threat information collected in the normal course of their business so that the participating company can propose responsive cyber operations to the NCC.
  • Federal, state, local, tribal and territorial agencies, which can identify CE-TCO threats and let participating companies propose operations to address them.

The White House fact sheet describes the program as one that “leverages the capability and innovation of the private sector to help conduct these cyber operations under the direction, control, and authority of the U.S. Government.”

Compliance requirements and safeguards

Companies accepted into the program will have to post a bond or maintain an escrow of at least $1 million that is forfeited if they fail to comply with contractual terms. The memo also requires participating companies to immediately halt any operation if they discover activity that exceeds approved limits, including unintended targeting of U.S. citizens or U.S.-based systems, and to notify the National Coordination Center.

The memorandum, according to the fact sheet, also directs the Program Executive Directors and the Homeland Security Council to build “rigorous procedures for the review and conduct of these limited cyber operations.” The Executive Directors may not approve operations that produce “Critical Outcomes,” a defined term in the memo that covers the most consequential effects.

Why the policy is shifting now

The White House frames the program as a response to the scale and reach of foreign-based organized crime. According to the fact sheet, 73% of U.S. adults have experienced some kind of online scam or attack, and 98% of Americans believe scams pose a threat to individuals in the U.S., with two-thirds rating it a “major” threat. The fact sheet also notes that one in seven young people who experienced sextortion as a minor reported harming themselves in response to the abuse.

The memo builds on Executive Order 14390, signed on March 6, 2026, titled “Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens,” which directed the federal government to take a range of actions against cyber-enabled crime. Earlier actions cited in the fact sheet include the May 2025 TAKE IT DOWN Act, championed by First Lady Melania Trump, which targets non-consensual distribution of intimate images and deepfake abuse; an April 2026 conviction under that act; a June 2025 executive order on critical infrastructure cybersecurity; a September 2025 notice to help financial institutions detect and disrupt financially motivated sextortion; and a June 2026 NSPM strengthening the cybersecurity of National Security Systems.

Reactions from the security industry

Veracode co-founder Chris Wysopal characterized the memo as a “pretty big shift in US cyber policy” and a “major expansion of the private sector’s role in offensive cyber operations.” Jason Kikta, former head of the Cyber National Mission Force (CNMF) and chief technology officer at Automox, described the program as “a perpetual motion machine for billable threats.” Both comments reflect a long-running debate about hack-back activity by U.S. companies and how strictly it can be scoped, supervised and terminated when something goes wrong.

Wysopal, whose title and affiliation are noted in the public reaction to the memo, is the only individual explicitly identified as the named author of a company; the other quoted figure is identified by prior government role and current employer. Industry reaction captured in the initial reporting focused on how the new framework handles liability, oversight and the practical risk that offensive actions will reach beyond intended targets.

What’s still unclear

The memo directs the Executive Directors and the Homeland Security Council to write the procedural guidance that will actually govern who is approved, how operations are reviewed, what counts as a Critical Outcome that cannot be approved at the Executive Director level, and how violations are adjudicated. Until that implementation guidance is published, the practical scope of the program, including the number of firms that will be vetted in the first cohort and the specific categories of criminal infrastructure the U.S. government plans to target first, remains undefined.

The $1 million bond figure is the only public dollar threshold in the memo, and it is framed as a minimum. The memorandum does not, in the text released, specify how long contracts will last, how operations will be audited after the fact, or what recourse victims of mistaken targeting would have.

FAQ

What does the White House memo actually allow private companies to do?

It allows vetted U.S. private security companies to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations under contracts with the Department of Justice or the Department of Homeland Security, with the operations run under federal supervision and reviewed by co-Executive Directors from each department.

Who oversees the program?

Two Program Executive Directors, one designated by the Attorney General and one by the Secretary of Homeland Security, jointly oversee the program. They must coordinate before approving any operation and cannot approve operations that produce “Critical Outcomes” as defined in the memorandum.

What safeguards apply if a private firm hits the wrong target?

Participating companies must stop operations immediately upon discovering activity beyond approved limits, including unintended targeting of U.S. citizens or U.S.-based systems, and notify the National Coordination Center. They must also maintain a bond or escrow of at least $1 million that is forfeited for noncompliance with contractual terms, and all operations must comply with the Constitution, federal law and applicable international agreements.

Related coverage


This article summarizes reporting from bleepingcomputer.com.