№225|04:22 PM ET
Independent reporting on technology, markets & policy
TechEchelon
№01 / Anchor·CYBERSECURITY

Trump Administration Authorizes Private Firms to Launch Offensive Cyberattacks Against Foreign Criminal Networks

The Trump administration's presidential memorandum authorizes private cybersecurity firms to conduct offensive cyber operations against foreign criminal networks under federal oversight, drawing immediate concern from security researchers over legal risks and the difficulty of accurate attribution.

TE
TechEchelon Staff
AUG 13, 2026 · 03:02 PM ET · 2 MIN READ
via Wikipedia (Donald Trump)

The Trump administration issued a presidential memorandum on Wednesday authorizing private cybersecurity companies to conduct offensive cyber operations against foreign criminal networks, a significant shift in how the United States approaches cybercrime enforcement.

Under the new program, participating firms will operate "under the control and oversight" of the federal government, with authority to surveil and disrupt criminal networks operating abroad.

The Department of Justice and the Department of Homeland Security will jointly oversee the program. Companies seeking to participate must satisfy requirements related to "technical proficiency, proven performance of cyber operations, facility security," and other criteria outlined in the memorandum.

Participating firms will also be required to hold a bond or escrow of at least $1 million, which they will forfeit if they fail to comply with the terms of their contractual agreement with the government.

The memorandum draws a key boundary: private firms may only target groups that are "not an institutional part of a foreign government or wholly operated under a foreign government's direction." The document characterizes private businesses as "underutilized" forces in the fight against cybercrime.

"It is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime," the memorandum states.

The policy marks a departure from longstanding practice, under which the federal government conducted its own cyber operations rather than delegating offensive capabilities to third-party contractors. President Trump began laying the groundwork for private-sector involvement last year, according to earlier reporting.

Experts have raised substantive concerns about the program's practical and legal implications.

Jason Healey, a senior cyber conflict researcher at Columbia University, said "Anyone conducting these operations is doing so at substantial personal legal risk," according to Cybersecurity Dive. Jake Williams, vice president of research and development at Hunter Strategy, told TechCrunch that "Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas."

Among the operational concerns is the difficulty of accurately attributing attacks to groups that are unaffiliated with foreign governments — a distinction the memorandum treats as a firm boundary but one that analysts say is hard to enforce in practice.

Ben Bernstein, a manager for the cybersecurity advisors team at Huntress, highlighted the risk of collateral damage. "Threat actors don't launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network," Bernstein said. "That makes it practically impossible to 'strike back' without taking out innocent bystanders."

The question of how to distinguish criminal networks from state-affiliated actors adds another layer of complexity, as the line between organized cybercrime and state-sponsored operations is frequently blurred, analysts note.

How the administration will vet firms, adjudicate attribution disputes, and handle legal fallout from operations that inadvertently affect neutral third-party infrastructure remains to be seen — and those details are likely to shape whether the program produces results or creates new diplomatic and legal entanglements.

Disclaimer

TE
━ ABOUT THE BYLINE
TechEchelon Staff

TechEchelon Staff bylines are produced collectively by the newsroom for short, breaking, and wire-style coverage. Longer-form reporting is published under the responsible reporter's name.

More from the Staff
● THE BRIEF · DAILY NEWSLETTER

Five stories every morning. Before the opening bell.

Written for readers who already know the basics — markets, AI, and the policy decisions that shape both.

Mon — Fri · 06:30 ET · Free

No spam · Unsubscribe anytime