Wireva

Trump signs memorandum letting US firms conduct cyber operations against foreign crime groups

President Donald Trump signed a National Security Presidential Memorandum creating a framework for vetted private U.S. companies to conduct cyber operations against foreign criminal organizations, with federal oversight.

This item was produced with AI assistance under the editorial responsibility of Haydamax OÜ.

President Donald Trump has signed a National Security Presidential Memorandum that establishes a framework for vetted private U.S. companies to conduct cyber operations against certain foreign criminal organizations, according to the document released earlier this month. The federal government would direct and oversee those operations, marking a new approach in the fight against cyber-enabled crime that costs Americans billions of dollars each year.

The memorandum permits two broad types of activity. Companies could secretly collect intelligence from targeted computer systems, and with federal approval, they could also manipulate, disrupt, deny access to, degrade or destroy systems and digital infrastructure that targeted criminal organizations control. The program is designed to give the federal government another way to pursue foreign groups responsible for sophisticated campaigns involving ransomware, phishing, financial fraud and impersonation scams targeting Americans and U.S. interests.

Cybercrime continues to impose staggering costs on Americans. The FBI's Internet Crime Complaint Center received 1,008,597 complaints in 2025, with reported losses reaching $20.877 billion, up 26% from 2024. The White House says foreign-based criminal organizations are behind many of these attacks, and technology is making some of them increasingly difficult to recognize, with AI helping criminals create more convincing impersonation scams and other cyberattacks.

The memorandum establishes two types of operations that participating companies could conduct under federal authority. A Cyber Surveillance Operation can involve secretly accessing targeted computer systems to collect information or intelligence, carried out with the intent to remain undetected and potentially accessing systems without authorization from the owner or operator. A Cyber Effects Operation can manipulate or disrupt information systems, deny access, degrade systems or destroy information and infrastructure controlled through those systems.

This does not give private companies permission to start hacking suspected criminals on their own. Companies participating in the program must be accepted by the government and enter into contractual agreements with either the Department of Justice or Department of Homeland Security. Operations must happen on behalf of the federal government and under its supervision, with DOJ and DHS executive directors required to review cyber operations packages and provide written approval and direction before a participating company can act.

Companies will face vetting requirements that can examine technical proficiency, past cyber operations, facility security, personnel vetting and reliability. The rules must allow both large companies and smaller companies that may be better suited for specialized operations to participate. DOJ or DHS may also require a participating company to maintain a bond or escrow account of at least $1 million, which could be forfeited if the company violates its contractual agreement.

The memorandum does not identify any companies that will participate. The program's targets are defined as Cyber-Enabled Transnational Criminal Organizations, or CE-TCOs, which are foreign groups that conduct cyber-enabled crimes against the U.S. government, Americans or U.S. interests. The definition excludes organizations that are an institutional part of a foreign government or wholly operated under a foreign government's direction.

The memorandum includes safeguards for operations that accidentally move outside their approved boundaries. If a participating company discovers that an operation has unintentionally targeted a U.S. person, a system located in the United States or a system controlled by a U.S. person, it must stop the operation, carry out required minimization procedures and immediately notify the National Coordination Center, which must notify the Justice Department.

Same event, other desks

Story file →