Thursday, 13 August 2026 Newsarchy UK live index
NewsarchyUKUK
Every UK story. Mapped, sourced, and explained where it matters.
World

Donald Trump signs memo letting private firms launch cyber attacks on criminal groups

President Donald Trump signed a national security presidential memorandum allowing vetted U.S. companies to carry out offensive cyber operations against foreign-based transnational criminal organisations.

Donald Trump signs memo letting private firms launch cyber attacks on criminal groups
Donald Trump signs memo letting private firms launch cyber attacks on criminal groups

President Donald Trump signed a national security presidential memorandum on Wednesday that formally authorises vetted U.S. Companies to carry out offensive cyber operations against foreign-based transnational criminal organisations. According to the White House, the policy shifts a role traditionally reserved for government agencies onto the private sector, essentially deputising companies in the online fight against crime.

The memorandum directs the Department of Homeland Security’s National Coordination Center, working alongside the Department of Justice, to create a programme that will vet, contract and oversee participating firms. Under the direction, control and authority of the U.S. Government, those firms may conduct cyber surveillance operations and cyber-effects operations. The memo defines cyber-effects operations as potentially involving the manipulation, disruption, denial, degradation or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, and any information resident thereon.

Media additions

Image via nextgov.com
Image via nextgov.com
Image via sana.sy
Image via sana.sy

The White House cited ransomware attacks, financial frauds and other crimes run by foreign-based criminal organisations. The framework encourages private sector companies to enter into agreements with other private entities, as well as federal, state, local, tribal and territorial agencies, to gather threat information on transnational criminal organisations and propose cyber operations to address those threats.

Industry reaction and expert perspectives

The policy change follows a national cybersecurity policy released in March that stated the government would create incentives to unleash the private sector against foreign adversaries. Mike Centrella, head of public policy at SecurityScorecard, welcomed the move in a statement reported by Nextgov.

"The memorandum recognizes that addressing cybercrime also requires identifying and disrupting the infrastructure and networks that allow criminal organisations to operate."

Mike Centrella, head of public policy, SecurityScorecard, via Nextgov

Centrella added that the guidance signals an evolution in public-private cybersecurity collaboration, moving from primarily sharing information about threats toward combining government authorities with private-sector intelligence and capabilities to more actively disrupt them. These plans have faced questions from legal experts on what sort of risks companies could face as they enmesh themselves in international digital conflicts. The idea of private sector firms participating in cyber operations against criminal and other targets is not new but has encountered controversy in the past over fears of escalation, inadvertent consequences and inter-agency coordination issues.

How the programme is expected to work

Additionally, participating companies will be required to maintain a bond or escrow of at least $1 million, according to the memorandum.

  • Vetting process: Program executive directors from the departments of Homeland Security and Justice — in coordination with the Homeland Security Council — will draft screening standards within 60 days of the memo's signing. Criteria will include technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence and reliability. The group will ensure that program participation criteria enable involvement from large and small companies, and that operations target only transnational criminal organizations.
  • Authorization limits: Program executive directors from the departments of Homeland Security and Justice will have the authority to greenlight companies’ cyber operations unless the authorization would result in a loss of life, serious injury or “rise to the level of use of forced or armed attack under international law.”
  • Oversight: The federal government would vet and conduct oversight of authorized companies, which would need to enter into contractual agreements with either DHS or Justice. the program executive directors will produce a report on the initiative’s status and submit it to the National Cyber Director and Assistant to the President and Deputy Chief of Staff for Policy and Homeland Security Advisor.

Timeline of key steps

EventDate
President signs national security presidential memorandumWednesday
Department of Homeland Security and Justice task-force to draft screening standardsWithin 60 days of the memo’s signing

International concern over cyber-attacks has grown after the release of increasingly powerful artificial intelligence models, which have shown that they can hack into outdated security systems. In the US, hackers targeted critical infrastructure systems in several states earlier this year, resulting in disruptions at water facilities.

The DHS and the White House did not immediately respond to requests for additional details about the program.

Related stories