Donald Trump has signed a Presidential Memorandum directing the formation of a new program to oversee offensive cyber operations carried out by companies in the private sector targeting cyber criminal networks and their infrastructure.
The memorandum, ‘Expanding Capabilities to Combat Transnational Cyber-Enabled Crime’, was published on August 12 and aims to target what the Trump administration calls Transnational Criminal Organisations.
“The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States,” the memorandum says.
“Yet, American businesses’ innovative capabilities have historically been underutilised in efforts to identify and disrupt criminal networks operating in cyberspace. Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime. By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.”
The program will operate under the auspices of the National Coordination Center, which was established in 2025, overseen by co-Executive Directors from the Department of Justice and Department of Homeland Security, with both the US Attorney General and Secretary of Homeland Security acting as Program Executive Directors.
According to the memorandum, “Cyber operations shall only be approved after coordination between the Program Executive Directors, and any resulting operational action will be exclusively conducted on behalf of and under the supervision of the Federal Government pursuant to the Federal Government’s lawful authorities”.
Companies participating in the program will be required to enter into contractual agreements with the DoJ or DoHS to undergo a “rigorous” vetting process to ensure that all operations take place under the appropriate oversight and approval.
Chris Wysopal, Chief Security Evangelist at application security firm Veracode, called the move a “pretty big shift in US cyber policy.”
“The White House is setting up a program that would let private cybersecurity companies conduct government-authorised operations against foreign cybercriminal groups, including surveillance and disruption of their infrastructure,” Wysopal said in a post to X.
“Not exactly ‘hack back,’ but definitely a major expansion of the private sector’s role in offensive cyber operations.”
The idea of letting private companies target criminals in offensive cyber operations is not a new one. Congressman David Schweikert proposed a ‘Letter of Marque’ for such operations in a 2025 proposal to Congress.
Schweikert’s idea was that Congress still has the power to issue letters of marque under Article I, section 8 of the US Constitution. These letters, which essentially legitimised piracy as long as it was undertaken against foreign belligerents, were issued during the French and Indian War between 1754 and 1763 and the American Revolution between 1765 and 1783.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.