TodayFriday, August 14, 2026

Trump Authorizes Private Firms to Hack Foreign Criminal Networks

The White House memo creates the first licensed offensive cyber program in US history, with a $1M bond required and DOJ-DHS approval needed for every operation.
August 14, 2026
Cybersecurity ransomware attack computer screen showing encrypted files
Angelo Martino convicted for conspiring with BlackCat/ALPHV ransomware gang to extort US companies. [Image Source: Getty Images via TechCrunch]

WASHINGTON – Three days after it was signed, the memo sits in peculiar administrative limbo: public, specific, and precedent-setting, yet almost entirely without operational detail. The White House released the presidential memorandum on August 12 under the title “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.” What it establishes is the first formal program in American peacetime history authorizing private companies to conduct offensive cyberattacks on behalf of the federal government.

The document, signed by President Trump and posted to the White House presidential actions page, creates two categories of authorized operations. “Cyber Surveillance Operations” covers covert information gathering from foreign computer systems designed to remain undetected. “Cyber Effects Operations” authorizes actions that manipulate, disrupt, deny, or destroy the networks of designated criminal organizations operating overseas. Both describe conduct that would constitute federal crimes under Title 18 of the U.S. Code, unless the companies carrying them out have been authorized under the program the memo establishes.

The historical parallel that lawyers and security policy analysts reached for immediately is the Letter of Marque and Reprisal, a constitutional instrument under Article I, Section 8, by which Congress commissioned private ship captains to attack enemy vessels. The United States last issued Letters of Marque during the War of 1812. The Trump administration has not revived the statutory instrument, which would require an act of Congress, but the memo achieves a functionally similar outcome by citing executive authority, existing criminal law, and two earlier Trump executive orders to carve out space for licensed private offensive operations.

Oversight of the program sits with a newly created National Coordination Center, co-directed by officials from the Department of Justice and the Department of Homeland Security. Every cyber operations package must receive written approval from both directors before any action is taken. Companies are explicitly prohibited from pursuing what the memo classifies as “Critical Outcomes,” defined as operations likely to cause loss of life, serious physical injury, or conduct that would rise to the level of an armed attack under international law.

To participate, a company must maintain a bond or escrow account of not less than $1 million, forfeitable upon violation of program rules. The memo frames this as a threshold low enough to attract smaller firms, stating a preference for including “both large companies, which provide critical capacity, and smaller, more agile companies.” In practice, the requirement may concentrate participation among established defense contractors and large commercial security firms. Most independent threat intelligence operations and boutique firms fall below the capitalization level needed to sustain a seven-figure escrow.

Private US firms authorized offensive cyberattacks foreign criminal networks Trump presidential memorandum
Trump’s presidential memorandum creates the first formal U.S. government program licensing private companies to conduct offensive cyberattacks against foreign criminal networks. [Image Source: Getty Images via Atlantic Council]

The targets the program authorizes are designated “Cyber-Enabled Transnational Criminal Organizations,” or CE-TCOs: foreign entities conducting cyber-enabled crime against U.S. interests that are “not an institutional part of a foreign government” unless intelligence establishes otherwise. That carve-out matters. Ransomware gangs operating with state tolerance in Russia, North Korea-affiliated cryptocurrency theft groups, and Iranian proxy cyber units all inhabit the gray space between independent criminal networks and state-sponsored operations. The memo does not specify which body makes the CE-TCO designation, what evidentiary standard applies, or how the distinction would be adjudicated if challenged.

The Justice Department’s most recent annual cybercrime assessment cited ransomware losses to U.S. organizations exceeding $17 billion in 2025, with North Korean state-affiliated hackers accounting for more than a third of global cryptocurrency thefts. Iranian-linked groups are currently under FBI investigation for attacks on water treatment systems across seven U.S. states, the kind of critical infrastructure intrusion the memo’s authors cited as justification for expanding private sector offensive capacity.

The legal foundation the memo rests on includes 18 U.S.C. § 1030, the Computer Fraud and Abuse Act, alongside Executive Order 14390 from March 6, 2026, and Executive Order 14159 from the first day of Trump’s second term. The CFAA has historically been interpreted broadly to criminalize unauthorized computer access; the memo effectively creates a government-issued authorization exempting enrolled companies from its reach for approved operations abroad. The question of whether U.S. law can authorize operations against systems in jurisdictions with their own cybercrime statutes is not addressed in the public-facing text.

Apple warned this week that users in 110 countries had been targeted by mercenary spyware, the commercial hacking tools that governments and well-funded private actors deploy to penetrate mobile devices. The Trump memo implicitly positions licensed American private hackers as a counterweight to that ecosystem, directing their offensive capacity against the criminal networks that fund and operate much of it. What distinguishes an authorized U.S. government contractor conducting a cyber effects operation from a mercenary spyware firm conducting a client-directed intrusion is a question the memo does not resolve.

Coordination with U.S. allies and intelligence partners is addressed in a classified annex covering operational deconfliction across the State Department, Treasury, Defense, the Intelligence Community, and federal law enforcement. The annex’s existence signals that the administration anticipates conflicts, including scenarios where a licensed company’s approved target overlaps with an ongoing intelligence operation, or where a designated CE-TCO has ties to a country with which the United States maintains intelligence-sharing arrangements.

AI agents that broke containment last month and compromised external systems demonstrated how rapidly authorized digital operations can exceed their intended scope. The memo requires participating companies to cease operations that exceed approved parameters and immediately notify program directors. Neither the minimization procedures nor the annual review process can fully account for a scenario in which a targeted criminal organization detects the intrusion, traces it to a licensed U.S. firm, and escalates in ways that neither the company nor its government overseers anticipated.

Which companies have already enrolled, whether any operations are under way, and the operational contents of the classified annex are not public. The Justice Department and Department of Homeland Security had not issued guidance on enrollment procedures as of Thursday. The National Coordination Center’s staffing, location, and budget remain undisclosed. What is certain is that as of August 12, the legal landscape for private offensive cyber operations in the United States acquired a formal structure it did not previously have, built not on new legislation, but on executive authority and a statute written for an era that did not anticipate licensed contractors hacking criminal networks overseas.

Akihito Muranaka

Akihito Muranaka

Akihito Muranaka is a Senior Correspondent at The Eastern Herald covering geopolitics, international security, and investigative affairs across Asia, Europe, and the Middle East, with reporting in English and Japanese.

Leave a Reply

Don't Miss