White House lets US companies hack foreign cybercrime groups — with a catch

The Trump administration has launched a new program that will allow vetted U.S. companies to conduct cyber surveillance and offensive cyber operations against foreign transnational criminal organizations. A presidential memorandum signed on August 12 directs the National Coordination Center to establish and manage the initiative, expanding the government's fight against cybercrime by tapping the technical capabilities of the private sector.
The move builds on a March executive order that called for greater private-sector involvement, but goes significantly further by establishing a formal operational framework. The White House argues that American companies possess a "critical offensive cyber advantage" whose capabilities have "historically been underutilized" in efforts to identify and disrupt criminal networks operating online.
The program defines two broad categories of authorized activity. "Cyber Surveillance Operations" can involve secretly accessing foreign information systems without authorization to gather intelligence, including information that could later be used for offensive operations. "Cyber Effects Operations," meanwhile, can result in the "manipulation, disruption, denial, degradation, or destruction" of information systems, networks, or infrastructure.
Companies will not be free to launch their own operations, however. The memorandum requires program officials to "review every cyber operations package and provide written approval and direction" before a participating company can act. Operations that could cause death or serious injury, or that fall into other sensitive categories, will require additional levels of clearance and oversight.
The program reflects a broader shift toward leveraging private-sector expertise in national security, but also raises questions about accountability, escalation, and the legal boundaries of corporate participation in offensive cyber activities. The White House frames the initiative as a necessary adaptation to the growing scale and sophistication of transnational cybercrime, which increasingly operates across borders and beyond the reach of traditional law enforcement.
Details on how companies will be vetted, how operations will be deconflicted with intelligence agencies, and what legal protections participants will receive have not yet been fully disclosed. The National Coordination Center is expected to publish implementation guidelines in the coming months as the program moves from policy to practice.


