President Donald Trump has signed a National Security Presidential Memorandum that directs the federal government to bring vetted private U.S. companies into offensive cyber operations targeting foreign criminal networks. The Aug. 12 order creates a program within the National Coordination Center of the Homeland Security Task Force and frames the move as an expansion of efforts against transnational cybercrime.

Under the plan, private firms would be allowed to propose and carry out certain cyber actions against systems linked to networks operating abroad, but only after federal vetting, contracting, and written government approval. The memorandum says the government will retain operational control while using private-sector capabilities against threats including ransomware, phishing, financial fraud, and sextortion.

How the program would work

The memorandum envisions a program jointly run by two executive directors, one from the Department of Justice and one from the Department of Homeland Security. Companies would need to contract with either DOJ or DHS, complete a vetting process, and post a bond of at least $1 million. That bond can be forfeited if a company breaks the program’s rules.

Approved firms would collect threat information and submit proposed operations to the National Coordination Center at Homeland Security. According to the memo, all actions would require the executive directors’ written approval and direction. The document states that companies may act only on the government’s authorization, rather than on their own initiative.

What activities are authorized

The order authorizes what it calls Cyber Surveillance Operations, defined as accessing systems without the owner’s permission or beyond otherwise authorized access. It also permits broader offensive actions aimed at systems tied to foreign criminal networks.

The memorandum specifically names networks involved in ransomware, phishing, financial fraud, and sextortion. It says private firms could be used to access, surveil, disrupt, or destroy systems connected to those organizations, so long as the activity falls within the government-approved framework.

Limits and legal guardrails

The public version of the memorandum sets some boundaries but leaves many operational details undisclosed. Operations that would produce what the memo calls Critical Outcomes are prohibited. If an action affects a U.S. person or a U.S.-based system, it must stop immediately and minimization procedures must be followed.

At the same time, the targeting rules themselves are contained in a classified annex, leaving only a narrow set of public guardrails available for outside review. That means the broad structure of the program is public, while the more detailed standards for how targets are selected are not.

Why the White House says it is needed

The memorandum states that it is U.S. policy to use all instruments of national power, including private-sector capabilities, to combat cybercrime. Its rationale points to the scale of transnational criminal activity online and the increasing sophistication of the groups behind it.

The document also cites the financial impact of crypto-related crime, saying scams involving digital assets have cost Americans billions. It further points to North Korean hackers as an example of actors increasingly laundering stolen cryptocurrency.

What comes next

The program is not set out as immediately operational in full detail. The memorandum gives a 60-day window before implementation guidance is due, meaning agencies still need to publish the instructions that will govern how the program is put into practice.

Until that guidance appears, key questions remain unresolved in public, including how the vetting process will be handled in practice and how the classified targeting framework will be applied. What is confirmed so far is the structure: vetted firms may participate only through federal contracts, under written approval, and under continuing government direction.

Source: decrypt.co