WASHINGTON — President Donald Trump on Aug. 12 signed a National Security Presidential Memorandum allowing qualified U.S. cybersecurity companies to conduct offensive cyber operations against overseas transnational criminal organizations under federal authorization and oversight.
The move marks a significant expansion of the role private companies can play in the U.S. government's fight against cybercrime.
According to the White House, Americans lost more than $20.8 billion to online scams, ransomware and sextortion in 2025. Officials have argued that increasingly sophisticated criminal groups, including those using artificial intelligence to improve their attacks, are placing growing demands on the government's existing cyber capabilities.
Under the new policy, approved companies may monitor criminal networks and, with government authorization, disrupt or disable digital infrastructure used by those groups. Companies will not be allowed to choose targets or launch operations on their own.
Participating firms must undergo security, technical and personnel screening and sign agreements with the federal government. They must also post a minimum $1 million bond, which can be forfeited for violations, along with possible additional administrative penalties.
Each operation will require a written proposal and approval from senior officials overseeing a national coordination process involving the Justice Department and Department of Homeland Security. The policy prohibits operations that could cause death or serious physical harm or that could meet the threshold of an armed attack under international law.
The policy has already sparked debate among cybersecurity experts and legal scholars.
Supporters say bringing private-sector expertise into the fight could give U.S. authorities more flexibility in responding to ransomware and other cross-border crimes. Critics, however, warn that identifying the real source of a cyberattack is notoriously difficult. Criminal groups can hide behind compromised servers and third-party infrastructure, raising the risk that a counterattack could hit innocent systems or trigger an international dispute.
Some security experts have compared the policy to historical “letters of marque,” under which governments authorized private actors to attack enemy vessels.
The Justice Department and Homeland Security Department have 60 days to develop detailed rules for implementing the policy. How the new system will balance aggressive action against cybercrime with the risks of escalation remains to be seen.