US Enlists Private Firms in Cybercrime Crackdown
A presidential memo lets vetted US companies run offensive cyber ops against foreign crime rings.

In a significant expansion of federal cyber power, the White House has authorized private American companies to carry out offensive hacking operations against foreign cybercrime groups, acting under direct government supervision. The move, formalized in a presidential memorandum issued on Wednesday, creates a formal channel for the private sector to move beyond defense and into active engagement with transnational criminal networks.
New Program, New Powers
The memorandum establishes a program managed by the National Coordination Center (NCC), which will allow companies that pass rigorous vetting to conduct what the administration terms 'cyber surveillance operations' and 'cyber effects operations.' These are aimed specifically at foreign cyber-enabled transnational criminal organizations (TCOs), targeting the infrastructure and systems these groups rely on.
This initiative is structured to keep the government firmly in control. Co-executive directors, appointed jointly by the Attorney General and the Secretary of Homeland Security, will oversee the program. Every proposed operation must receive written approval from these directors, ensuring that no action is taken without explicit federal sign-off.
Vetting and Contracts
Participation is not open to just any company. Firms must undergo a rigorous vetting process and sign formal contracts with either the Department of Justice (DOJ) or the Department of Homeland Security (DHS). As part of these agreements, companies may be required to post a bond or escrow of at least $1 million, a sum that would be forfeited if the company fails to comply with operational requirements.
Once cleared, these companies can enter into commercial agreements with other private entities to receive threat intelligence, and they can also work with federal, state, and other agencies to identify specific foreign threats. This creates a collaborative ecosystem where private expertise and government authority intersect.
Defining the Scope
The directive carefully delineates what is and is not allowed. Cyber surveillance operations are defined as covertly accessing systems to collect intelligence. Cyber effects operations, on the other hand, cover actions that disrupt, degrade, or destroy adversary information systems and infrastructure.
However, there is a clear red line: the program explicitly bars operations that would result in 'critical outcomes,' defined as actions likely to cause loss of life, serious injury, or that would rise to the level of a use of force or armed attack under international law. This is a deliberate limit, distinguishing this program from traditional military action.
Deconfliction and Oversight
Before any action is taken, proposed operations must undergo multi-agency deconfliction. This process involves law enforcement, the Department of State, the Department of the Treasury, the Department of War, the DOJ, and the Intelligence Community. The goal is to ensure that no operation conflicts with other ongoing government activities or international obligations.
The White House has also noted that target selection is restricted to non-state criminal groups. Importantly, foreign entities are assumed to be independent of foreign governments unless clear intelligence proves otherwise. This is a nuanced stance, acknowledging the often-blurred lines between state and non-state actors in cyberspace.
Safeguards for US Persons
Strict safeguards are in place to protect domestic interests. If a contractor discovers that an operation has accidentally breached a US person or a domestic system, it must immediately cease operations and notify the government. This is a critical provision, designed to prevent collateral damage to American citizens and infrastructure.
The program's design reflects a careful balancing act: enabling aggressive action against foreign criminals while maintaining legal and ethical boundaries. The requirement for immediate notification on accidental domestic breaches underscores the administration's awareness of the potential risks involved.
Why This Matters
This memorandum marks a significant shift in how the US government approaches cybercrime, potentially opening the door for a more aggressive, proactive stance against criminal groups that have long operated with relative impunity. By harnessing private-sector capabilities, the government gains access to a wider range of skills and resources, potentially increasing the frequency and effectiveness of operations.
This could mean a new era of public-private collaboration in cybersecurity, but it also raises important questions about accountability, oversight, and the potential for unintended consequences. The full impact of this program will depend on how it is implemented and how effectively the safeguards are enforced.
Sources
- SecurityWeek Original source
Continue Reading
Fortinet's Patch Wave Targets Authentication Gaps
Fortinet resolves eight flaws, including high-severity authentication bugs in FortiWeb and FortiManager.
Google Doc Credentials Leak Serves as a Cautionary Tale
A developer's habit of storing passwords in a shared Google Doc led to a search-indexed exposure of staging credentials.
Unauthenticated SAP Flaw Earns Maximum CVSS Score
SAP ships urgent patches for Commerce Cloud and other critical flaws rated up to 10.0.