Trump’s Cybersecurity Memo: Private Firms Authorized for Offensive Actions Against Foreign Threats
Trump Memo Lets Private Firms Hack Back at Foreign Cybercriminals for the First Time
President Donald Trump signed a landmark National Security Presidential Memorandum on August 12, 2026, authorizing vetted U.S. private companies to conduct offensive cyber operations against foreign criminal organizations under direct federal oversight.
The move represents a seismic shift in how the United States battles cybercrime. For decades, private companies have been legally barred from striking back against hackers under the Computer Fraud and Abuse Act — but this memorandum rewrites those rules in a significant and unprecedented way. With Americans losing more than $20.8 billion to cyber-enabled crime in 2025 alone, the White House is signaling that defense alone is no longer enough.
What the Memorandum Actually Authorizes
The memorandum — titled Expanding Capabilities to Combat Transnational Cyber-Enabled Crime — directs the U.S. National Coordination Center (NCC) to establish a formal program allowing what it calls "Participating Companies" to run offensive cyber operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs).
Two categories of operations are permitted under the new framework:
- Cyber Surveillance Operations, aimed at covertly collecting intelligence on criminal networks
- Cyber Effects Operations, which can manipulate, disrupt, degrade, or outright destroy an adversary's systems
Every operation requires joint approval from two Program Executive Directors — one designated by the Attorney General and one by the Secretary of Homeland Security. Neither director can authorize any action classified as a "Critical Outcome," defined as conduct likely to result in loss of life, serious injury, or actions rising to the level of use of force or armed attack under international law.
The NCC itself was originally established under a January 2025 executive order focused on immigration enforcement. It has since been repurposed as the government's primary cybercrime coordination hub — a transformation that reflects how rapidly the administration's priorities have evolved in this space.
Why This Matters Beyond the Headlines
The scale of the criminal ecosystem driving these losses is worth understanding in context. Ransomware, business email compromise, and large-scale phishing operations are no longer the work of isolated individuals — they are industrialized services, often sold and distributed through sophisticated criminal networks. Understanding how crime-as-a-service models operate and threaten businesses is essential context for grasping why the administration concluded that passive defense had reached its limits. This memorandum is a direct policy response to that industrialization of cybercrime.
How Companies Qualify and What They Must Do
Not every cybersecurity firm will be handed offensive capabilities overnight. Participating Companies must enter into direct contractual agreements with either the Department of Justice (DOJ) or the Department of Homeland Security (DHS) and undergo rigorous vetting before being accepted into the program.
The Vetting and Eligibility Process
That vetting process covers technical proficiency, facility security, personnel screening, and operational reliability. The Program Executive Directors have 60 days from the memo's signing to finalize those standards. Eligibility criteria are specifically designed to accommodate both large firms with broad capacity and smaller specialized companies — a detail that could open the door to boutique threat intelligence and incident response firms.
Once accepted, companies face ongoing accountability measures:
- They must maintain a bond or escrow of at least $1 million, forfeitable for non-compliance
- Annual re-evaluation is required to remain in the program
This structure closely mirrors government contractor frameworks in the defense industry — a model with established precedent for managing private-sector actors in sensitive national security roles, carrying real financial stakes attached.
The framework also allows Participating Companies to enter commercial agreements with other private-sector entities and with federal, state, local, tribal, and territorial agencies. These agreements can involve sharing threat intelligence gathered through normal business activity and proposing responsive cyber operations to the NCC for consideration.
What This Means for Cybersecurity Firms Specifically
For firms already operating in offensive security, this represents a formalized pathway that has never previously existed. Those with existing capabilities in ethical hacking and authorized penetration testing methodologies are likely to be among the most competitive candidates for program participation. The skills, tooling, and operational discipline developed in that space translate directly to what the NCC will be evaluating.
Guardrails, Legal Questions, and What Comes Next
Oversight Mechanisms Built Into the Framework
The administration has built several oversight mechanisms into the program to address concerns about unchecked private-sector aggression. A DOJ review is required for any activity directed at a U.S. person or that implicates constitutional, statutory, or international-law obligations.
Minimization procedures are also mandatory. If a company discovers it has exceeded the parameters of an approved operation — including unintentionally targeting a U.S. person or a domestic information system — it must immediately notify the NCC. The same immediate notification requirement applies if a company discovers an imminent attack on U.S. critical infrastructure.
A classified annex addresses operational deconfliction across the Departments of State, Treasury, War, Justice, and the intelligence community. The Program Executive Directors must deliver a status report to the White House within 180 days of the memo's signing and annually thereafter.
The Policy Timeline and Escalating Losses
The memorandum builds directly on Executive Order 14390, signed in March 2026, which directed a government-wide review of tools available to combat cyber-enabled fraud. When that earlier order was signed, the cited loss figure stood at $12.5 billion. The jump to $20.8 billion in reported losses by 2025 — driven by ransomware, phishing, financial fraud, sextortion, and impersonation scams — underscores the urgency behind this escalation.
Effective cyber threat intelligence strategies for identifying and tracking criminal actors will almost certainly form the operational backbone of how Participating Companies build their cases for NCC-approved actions. The intelligence-gathering phase — before any offensive operation is ever approved — is where much of the real work will occur.
Unresolved Legal Tensions
Legal and cybersecurity experts have already begun raising questions about how the tension between the new framework and the existing Computer Fraud and Abuse Act will be managed in practice. Those questions are unlikely to be resolved until the Program Executive Directors finalize implementing guidance in the months ahead. For further context on the broader legal and policy landscape, the Cybersecurity and Infrastructure Security Agency (CISA) provides ongoing regulatory guidance that organizations should monitor closely alongside DOJ and DHS developments.
The hack-back debate has long divided the cybersecurity community — and this memorandum will not end that conversation. It will intensify it.
How Readers Can Use This Information
- Cybersecurity professionals and firms should begin assessing whether their organizations meet the emerging eligibility criteria and monitor DOJ and DHS guidance expected within 60 days of August 12, 2026.
- Business leaders and risk managers should review their cyber insurance policies and incident response plans in light of a threat landscape where criminal organizations may now face active offensive countermeasures.
- Legal and compliance teams should track how regulators reconcile this memorandum with existing Computer Fraud and Abuse Act obligations to avoid inadvertent liability during any cooperative operations.