Trump Administration Authorizes Approved U.S. Firms to Conduct Offensive Cyber Operations Overseas

0
1

Key Takeaways

  • President Trump signed a National Security Presidential Memorandum authorizing vetted private firms to conduct offensive cyber operations against foreign criminal groups.
  • The program is overseen by a Homeland Security Task Force National Coordination Center, with executive directors from the Justice Department and Homeland Security managing contracts and oversight.
  • Participating companies must meet strict technical, facility‑security, and personnel‑background standards; each operation requires a signed contract and written sign‑off, and firms risk forfeiting at least a $1 million bond for violations.
  • Offensive actions are limited to cyber surveillance and cyber‑effects that do not cause loss of life, serious injury, or constitute a use of force under international law; mistakes affecting U.S. persons or systems trigger an immediate halt.
  • The Computer Fraud and Abuse Act remains applicable, and a true “hack‑back” authority would still require congressional legislation—two prior bills failed to advance.
  • Administration officials cite $20.8 billion in consumer losses from cyber‑enabled crime in 2025 and note that 73 % of U.S. adults have experienced an online scam or attack.
  • Critics warn that striking back without harming innocent infrastructure is nearly impossible because threat actors route attacks through compromised, innocuous devices and change targets rapidly.
  • Supporters argue that close public‑private collaboration is essential against organized cybercrime and autonomous AI‑driven attacks, emphasizing the importance of deconfliction to avoid undermining government operations.
  • The 60‑day deadline for publishing operating procedures will set the entry bar; a high threshold may steer work toward well‑funded defense contractors, while Congress is expected to weigh in on the constitutional implications.
  • No specific companies have been named as participants in the program to date.

President Trump’s New Cyber‑Enabled Crime Memorandum
On Wednesday, President Donald Trump signed a National Security Presidential Memorandum titled “Expanding Capabilities to Combat Transnational Cyber‑Enabled Crime.” The directive formally authorizes vetted private companies to carry out hacking operations against foreign criminal groups. By embedding the authority within a presidential memorandum rather than an executive order, the administration seeks to create a flexible yet accountable framework for offensive cyber actions. The memo instructs the Homeland Security Task Force’s National Coordination Center to establish the program, marking a notable shift toward leveraging private‑sector expertise in national‑security cyber missions.

Structure and Oversight of the Program
The memorandum places the program under the joint supervision of the Justice Department and the Department of Homeland Security. Executive directors from each agency will run the initiative, ensuring that legal and operational considerations are balanced. Approved firms will sign contracts with either Justice or Homeland Security, and no company receives blanket authority; each engagement must be individually authorized. This contractual approach is intended to maintain governmental oversight while allowing rapid deployment of specialized cyber capabilities.

Screening Requirements and Operational Authority
Before a firm can participate, it must undergo a rigorous screening process that evaluates technical proficiency, facility security, and the backgrounds of its personnel. Only after satisfying these criteria may a company receive written sign‑off to proceed with an operation. The memo defines two permissible activity types: cyber surveillance operations, which involve gathering intelligence on target networks, and cyber effects operations, which are described as disrupting or destroying a target’s systems. Both categories are tightly scoped to prevent overreach and to align with established legal boundaries.

Limitations, Prohibitions, and Safeguards
The memorandum explicitly bars any operation that is likely to kill or seriously injure individuals, as well as actions that would qualify as a use of force under international law. If a firm exceeds its approved parameters, it must cease activity immediately. The same immediate‑stop rule applies if the operation inadvertently affects a U.S. person or system. To further deter misconduct, participating firms are required to post a bond of at least $1 million, which is forfeited upon breach of contract terms. These safeguards aim to ensure that offensive cyber actions remain proportional and accountable.

Interaction with Existing Law and the Hack‑Back Debate
While the memorandum authorizes certain offensive cyber measures, it does not alter the Computer Fraud and Abuse Act (CFAA), which continues to apply to unauthorized access of computers. Consequently, a true “hack‑back” right—allowing private entities to strike back at attackers without legal liability—would still require an act of Congress. Two prior attempts to grant such authority, the Active Cyber Defense Certainty Act introduced by then‑Rep. Tom Graves in 2017 and again in 2019, failed to secure a floor vote. The current memorandum therefore operates within the existing statutory framework, relying on contractual oversight rather than substantive legal reform.

Administrative Rationale and Statistical Context
The White House justified the initiative by citing $20.8 billion in consumer losses attributed to cyber‑enabled crime in 2025 and noting that 73 % of U.S. adults have experienced an online scam or attack. The memo also builds upon Executive Order 14390, “Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens,” signed by Trump on March 6. By extending that order, the administration seeks to create a more aggressive posture against transnational cyber criminals while maintaining a veneer of legal continuity through the memorandum’s procedural safeguards.

Critiques: Collateral Damage and the Fluidity of Threat Infrastructure
Jason Kikta, former U.S. Cyber Command official and now CTO at Automox Inc., characterized the program as “a perpetual motion machine for billable threats,” suggesting concerns about endless contracting opportunities. Ben Bernstein, who leads the cybersecurity advisors team at Huntress Labs Inc., warned that threat actors rarely launch attacks from clearly identifiable servers; instead, they route traffic through compromised, innocuous infrastructure such as a vulnerable router at an Ohio dental office or a hospital network. He argued that striking back without harming bystanders is “close to impossible” on such terrain, and that adversary infrastructure often disappears within hours, leaving private operators “shooting at ghosts” by the time they complete target nomination and deconfliction review.

Supportive Views: Collaboration, Deconfliction, and AI‑Driven Threats
Kyle Hanslovan, co‑founder and CEO of Huntress Labs, endorsed the initiative, describing close public‑private collaboration as “no longer an option” against organized cybercrime. He highlighted autonomous AI attacks as an additional motivator for the program, stressing that effective deconfliction is critical to avoid disrupting long‑running government access operations that could jeopardize arrests and diplomatic leverage. Will Barker, a cybersecurity advisor at Huntress, echoed this sentiment, noting that the 60‑day guidance for publishing operating procedures will be the document worth watching because it establishes the entry threshold for participation. A high bar, he predicted, would funnel work toward well‑funded defense contractors, while congressional scrutiny is likely given the constitutional weight of allowing private firms to disrupt foreign systems.

Congressional Outlook and the Absence of Named Participants
Although the memorandum does not name any specific companies poised to join the program, analysts anticipate that the forthcoming operating procedures will shape the market for cyber‑offensive services. Barker expects Congress to become involved, weighing the national‑security implications against constitutional concerns about delegating offensive cyber authority to private entities. Until such legislative debate unfolds, the program remains a government‑guided effort, not an open‑season “free‑for‑all” for private hackers, with its ultimate scope contingent on how rigorously the adjudicatory framework is applied and how vigorously lawmakers choose to oversee it.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here