US President Donald Trump has signed a national security presidential memorandum (NSPM) that permits vetted private companies to conduct offensive cyber operations against foreign transnational criminal organizations. The memorandum directs the administration to leverage private sector innovation to perform these operations under the direction, control, and authority of the US government.

The program is designed to target criminal entities involved in ransomware, phishing, financial fraud, sextortion, and identity theft or impersonation scams. These organizations are defined as foreign groups conducting cyber-enabled crime against US interests that are not an institutional part of a foreign government or wholly operated under a foreign government's direction.

The US Department of Justice (DOJ) and the US Department of Homeland Security (DHS) will oversee the program. Specifically, the DHS National Coordination Center (NCC) is tasked with establishing, managing, and monitoring the initiative.

Operational scope and limitations

The memorandum authorizes both 'Cyber Surveillance Operations' and 'Cyber Effects Operations.' According to the White House, Cyber Effects Operations may include the manipulation, disruption, denial of access, degradation, or destruction of information systems, networks, and physical or virtual infrastructures.

The policy does not grant unlimited hacking abilities, but rather authorizes limited operations directed by the government. These operations are not intended to result in outcomes that reach the level of use of force or armed attack under international law, or result in loss of life or serious injury.

Participating companies are required to deposit a bond or escrow of at least $1 million, which is forfeited if they fail to comply with government direction or contractual agreements. Furthermore, companies must immediately stop operations and notify the NCC if they encounter activity exceeding approved limits, such as the unintended targeting of US citizens or US-based systems.

20.8 billion

USD lost by US consumers to cyber-enabled crime in 2025.

Expert reaction and legal concerns

The move marks a significant shift from previous US federal laws that broadly prohibit private companies from conducting cyberattacks without court-authorized approval. This follows advocacy from the US cybersecurity lobby for 'cyber letters of marque' to allow private entities to conduct counter-attacks in cyberspace.

Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas.
— Jake Williams, Vice President of Research and Development at Hunter Strategy
Anyone conducting these operations is doing so at substantial personal legal risk.
— Jason Healey, Senior Cyber Conflict Researcher at Columbia University
It is a major expansion of the private sector's role in offensive cyber operations.
— Chris Wysopal, Veracode co-founder

Critics have raised concerns regarding the technical and legal complexities of such strikes. Ben Bernstein of Huntress noted that threat actors often route traffic through innocent, compromised infrastructure, making it difficult to target criminals without affecting bystanders. Additionally, Jason Kikta, former Cyber National Mission Force leader, described the policy as 'a perpetual motion machine for billable threats.'

Regarding the broader US cyber posture, former CISA director Chris Krebs stated that the strategy lacks clarity while capabilities and staffing have been reduced.

Economic impact and implementation

The initiative comes as US consumers reported losing over $20.8 billion to cyber-enabled crime in 2025. The US government has previously seized more than $25 million in cryptocurrency linked to romance and investment scams.

The US government intends to issue implementation guidance outlining specific requirements for participating companies within the next 60 days.